What happened
On 29 September 2026 NIST's National Cybersecurity Center of Excellence (NCCoE) published the summary of comments received on its Software and Agentic AI Identity and Authorization concept paper (600+ commenters across industry, government, academia), launched a new 'Software and Agentic AI Identity and Authorization Online Resource Hub' to publish/deliver project resources on a rolling basis, and announced that the NCCoE DevSecOps project will provide the first implementation use case demonstrating how AI agents can be identified, authenticated, and authorized within the software development lifecycle. Comments remain open on a rolling basis; an agentic AI + DevSecOps webinar is scheduled 28 October 2026. The summary highlights tensions the project is codifying, including probabilistic vs deterministic authorization, cryptographically signed intents/mandates, and lack of separation between data and control planes in LLMs.
Why it matters
NIST is a primary standard-setting body for US federal and enterprise AI security. This is a concrete in-window step in an active NIST project that will shape how AI agents are identified, authenticated, and authorized — the foundational control for agentic AI security. The first use case targets AI agents operating inside the software development lifecycle, where agents now hold code, credentials, and release privileges, so the resulting guidance will affect identity providers, CI/CD tooling vendors, and enterprise agent deployments.
Action needed
Organizations building or governing agentic systems (esp. those using AI agents in DevSecOps) should review the summary of comments and resource hub, submit feedback on a rolling basis (AI-Identity@nist.gov), and monitor for the coming identity-principles blog post and final guidance to map controls.