The comment window is closed. NIST CAISI's agent-security RFI (docket NIST-2025-0035) was due 9 March 2026. The summary of what people sent, NIST AI 800-5, posted 18 May. Prescriptive controls are still not in that file. Authorization design stays with the operator.

The news

NIST posted "CAISI Issues Request for Information About Securing AI Agent Systems" on 12 January 2026. The RFI, docket NIST-2025-0035, solicits input from industry, academia, and the security community on secure development and deployment of AI agent systems, defined as systems capable of planning and taking autonomous actions that impact real-world systems.

The RFI says some risks overlap with conventional software (authentication flaws, memory bugs). It focuses on risks from combining model outputs with software: models interacting with adversarial data such as indirect prompt injection; use of insecure or poisoned models; and models taking harmful actions without adversarial input, specification gaming or misaligned objectives.

Question topics include unique agent security threats and how they evolve; methods to improve security in development and deployment; gaps when applying existing cybersecurity approaches; measuring agent security and anticipating risks during development; and deployment interventions to constrain and monitor agent access.

Comments were due 9 March 2026, 11:59 p.m. Eastern Time, via regulations.gov under docket NIST-2025-0035. CAISI said responses would inform voluntary guidelines, best practices, and ongoing agent-security research.

On 18 May 2026, NIST published "Summary Analysis of Responses to the Request for Information Regarding Security Considerations for AI Agents" as NIST Trustworthy and Responsible AI 800-5, authored by Riggs, Hamin, Perry, Edelman, and Cihon. The abstract reports commenters widely agreed agents present novel security threats that barrier adoption, that fundamental cybersecurity principles remain relevant but require adaptation, and that government roles include implementation guidance, information-sharing, and standards promotion. The document summarizes stakeholder input. It is not a finalized control catalog.

Who is bound

NIST CAISI issued the RFI and published the summary. No private deployer is legally bound by the RFI itself. Effect lands through customer security reviews, federal contractor language, and internal risk committees that treat NIST publications as baseline reference.

Agent platform vendors, MCP/A2A gateway operators, and enterprises running tool-use workflows are the operational audience. Integrators inherit the model vendor's security deck and the customer's questionnaire. The RFI's indirect-injection emphasis maps to email, document, and web-fetch channels, not only the chat box.

What's new

800-5 records consensus on a gap field teams already report: perimeter and identity controls built for human-directed applications need adaptation for orchestration loops, persistent memory, and chained tool calls. The May 2026 summary does not ship SP 800-53 control overlays for agents. NIST's COSAiS concept papers describe those overlays as in development for single- and multi-agent use cases.

Pairing the January RFI with the February 2026 Agent Standards Initiative gives buyers a dated paper trail. Security input was solicited before interoperability listening sessions began in April 2026.

What it does not settle

Dates: RFI published 12 January 2026; comments due 9 March 2026; summary analysis NIST AI 800-5 published 18 May 2026. Docket: NIST-2025-0035 on regulations.gov. Scope: voluntary guidance and research synthesis, not enforceable private-sector regulation. Cost: security-engineering labor to implement constraints and monitoring; no NIST comment fee. Data: RFI asked for case studies; 800-5 aggregates responses without naming every submitter. Whether CAISI will publish prescriptive control overlays before year-end 2026 is UNKNOWN.

What to do now

CISO offices can use 800-5 as evidence for budget on agent authorization, tool-call logging, and memory isolation. Don't treat it as a completed control set. Red teams should exercise indirect injection through documents and fetched URLs, matching the RFI's adversarial-data framing.

Whether NIST will designate mandatory agent-security controls for federal systems before COSAiS overlays finalize is UNKNOWN.