It is a summary of comments, not a control catalog.
Treat 800-5 as a dated paper trail: the RFI opened 12 January 2026, comments closed 9 March, the summary posted 18 May. Use it to budget authorization, tool-call logging, and memory isolation. Don't use it as a pass/fail overlay. The next document you want is a COSAiS control overlay, and that file is not this one.
NIST AI 800-5 tells you what respondents said after CAISI's agent-security RFI closed on 9 March 2026. Commenters agreed the threats are novel and that ordinary cybersecurity still applies if you adapt it. They did not hand NIST a finished overlay. COSAiS work sits downstream. Don't paste 800-5 into a contract as if it were SP 800-53.
Read it for the threat list and the government roles people asked for: implementation guidance, information-sharing, standards. Then keep your own authorization, logging, and human-approval design. The RFI docket is NIST-2025-0035.
NIST Trustworthy and Responsible AI 800-5, "Summary Analysis of Responses to the Request for Information Regarding Security Considerations for AI Agents" (published May 18, 2026; authors Jared Riggs, Maia Hamin, Neil Perry, Benjamin Edelman, Peter Cihon), synthesizes stakeholder input to a Center for AI Standards and Innovation (CAISI) Request for Information on securing AI agent systems. The publication page lists report number 800-5 and states commenters widely agreed that AI agents present novel security threats that hinder adoption, that fundamental cybersecurity principles remain relevant but require adaptation, and that government can help through implementation guidance, information-sharing, and standards promotion. The underlying RFI (Federal Register docket NIST-2025-0035) was announced January 12, 2026 with comments due March 9, 2026 at 11:59 PM Eastern via regulations.gov. This Record piece treats 800-5 as the authoritative NIST synthesis of that docket; where the full PDF was not retrievable from NIST servers at reader time, thematic detail is cross-checked against the public abstract, the January 2026 CAISI RFI notice, and independent docket surveys that catalog filing positions: always labeled when not quoted from 800-5 itself.
Claim of novelty
Program artifact, not a new control catalog. 800-5 is a meta-analysis of RFI responses, not a replacement for NIST SP 800-53, the AI Risk Management Framework (NIST AI 100-1), or the Generative AI Profile (NIST AI 600-1). Its novelty is procedural and diagnostic: CAISI asked deployers, developers, and researchers how agent security differs from conventional software and chatbot risk, then published a structured consensus and divergence map to steer overlays, evaluations, and voluntary guidance.
Distinct risk framing in the RFI (CAISI news release, January 12, 2026). The RFI explicitly scoped beyond shared software vulnerabilities (authentication flaws, memory bugs) to risks arising when model outputs drive software actions: indirect prompt injection via adversarial external content, insecure or poisoned models, and non-adversarial misalignment (specification gaming, harmful actions even with benign prompts). 800-5's abstract confirms commenters treated these agentic combinations as novel adoption barriers.
Agent category claim repeated across filings (docket surveys). Independent review of March 2026 filings (Technology Policy Institute Docket Roundup, June 2, 2026) reports over 80 substantive comments. Recurring justification: agents combine non-deterministic reasoning, delegated authority, persistent memory, and multi-step autonomous action at machine speed: shifting security from "what text is generated" to "what execution is permitted" (BCG filing paraphrased in TPI summary). 800-5's adaptation thesis aligns: legacy controls assume human-initiated, deterministic steps; agents break both assumptions.
Overlay path versus parallel regime (commenter consensus per TPI). The most common filing position: attributed in TPI to Amazon, Microsoft, ITI, CSET, Hitachi, USTelecom: urges extending existing frameworks (AI RMF, SP 800-53, Cybersecurity Framework, SP 800-218A secure SDLC) with agent-specific overlays/profiles rather than inventing a separate compliance regime. Amazon's "security box" framing (constraints as enabling infrastructure) captured in TPI typifies the mood. 800-5 government-role list (implementation guidance, information-sharing, standards) matches that extend-not-replace posture.
Threat prioritization: indirect prompt injection (filing cluster). TPI highlights consensus that indirect prompt injection is the top cited threat, with Perplexity, Frontier Model Forum, Elastic, and CrowdStrike arguing for at least one deterministic enforcement layer outside the model; FAI/CSET cited adaptive attacks bypassing model-level injection defenses at high success rates: rejecting "the model will refuse" as a sole control. Whether 800-5 ranks threats identically is UNKNOWN without full PDF text; the RFI question set and abstract's "novel threats" language are consistent with this emphasis.
Identity and least-privilege sub-debates (filings). TPI catalogs agent identity as first-class non-human principals (Okta, Twilio, OpenID Foundation, Cloudflare, Ericsson zero-trust "new insiders") with SP 800-63 foundations deemed incomplete for agents. Control stack recommendations cluster on least privilege, sandboxing/VM isolation (Cognition AI favoring VMs over containers for kernel sharing concerns), and runtime governance with rollback (Booz Allen, Palo Alto, Splunk, Elastic "Agentic SOC" proposal). Risk-tiered human oversight for consequential actions appears in ServiceNow, Docusign ($1M renewal without checkpoint scenario), Intuit, Okta filings per TPI.
COSAiS linkage (NIST CSRC project). Control Overlays for Securing AI Systems (COSAiS) plans NISTIR 8605 series volumes, including 8605D for single- and multi-agent use cases, with drafts anticipated through 2026–2027 (COSAiS annotated outline, January 2026). 800-5 informs that overlay track; it doesn't publish overlay controls itself.
What was measured and on which data
RFI process (measurable inputs).
| Stage | Date / artifact | Source |
|---|---|---|
| RFI published | Federal Register docket NIST-2025-0035; CAISI news January 12, 2026 | https://www.nist.gov/news-events/news/2026/01/caisi-issues-request-information-about-securing-ai-agent-systems |
| Comment deadline | March 9, 2026, 11:59 PM ET | Same |
| Submissions channel | regulations.gov docket NIST-2025-0035 | regulations.gov |
| Synthesis published | NIST AI 800-5, May 18, 2026 | NIST publication page |
| Substantive comments (external count) | 80+ filings (TPI docket roundup) | TPI, June 2, 2026 |
RFI question domains (CAISI release). Unique threats and evolution; development and deployment security improvements; gaps in existing cybersecurity approaches; measurement and anticipatory risk assessment; deployment interventions constraining and monitoring agent access in environment.
800-5 abstract outcomes (NIST publication page). Wide agreement: novel threats; adoption barrier; principles relevant but need adaptation; government roles: implementation guidance, information-sharing, standards.
Thematic coding from docket surveys (not necessarily verbatim 800-5 section headers). TPI extracts ten takeaway clusters: (1) extend existing frameworks; (2) agents categorically unlike software and chatbots; (3) indirect prompt injection priority with out-of-model enforcement; (4) agent identity debate; (5) least privilege + isolation + runtime governance; (6) immature observability: calls for agent behavior baselines and rollback; (7) risk-scaled human oversight; (8) trade associations favor voluntary risk-based guidance with economic growth arguments; (9) data provenance reframed as security; (10) shared infrastructure asks: benchmarks, CVE-like AI vulnerability database, MITRE ATLAS extensions, reliability protocols, updated incident definitions (Anthropic/Microsoft note FISMA SP 800-61 ill-fit for authorized agent harm), ISAC-style sharing.
Frameworks cited across filings (TPI). NIST AI RMF; SP 800-53; SP 800-218A; SP 800-207 zero trust; MITRE ATLAS; OWASP Top 10 for Agentic Applications/LLMs; ISO/IEC 42001.
Concrete repeated asks (TPI). Agent-specific profile/overlay; deterministic policy enforcement layer; scoped agent credentials; least privilege across tools/APIs/code execution; runtime monitoring with rollback; risk-tiered human oversight; standardized evaluation depth.
Sector listening sessions (external schedule). CSA research notes reference CAISI sector sessions in healthcare, finance, and education scheduled April 2026: post-deadline qualitative input not captured in March filings alone.
What 800-5 did not measure. No controlled red-team bake-off of agent products; no inter-rater reliability on comment coding published in abstract; no dollar cost of controls; no pass/fail vendor scores.
Reading order for security teams. Start CAISI January RFI for threat vocabulary → 800-5 abstract and full PDF when available for NIST-weighted synthesis → COSAiS NISTIR 8605 roadmap for impending SP 800-53 overlay drafts → TPI or regulations.gov comment threads for dissent and sector specifics → OWASP agentic top 10 and MITRE ATLAS for test libraries while overlays mature.
Federal Register and docket mechanics. The RFI appeared in the Federal Register ecosystem under NIST-2025-0035 (TPI cites Federal Register publication January 8, 2026; CAISI press release January 12, 2026). Comments submitted by March 9, 2026 constitute the empirical corpus 800-5 analyzes. regulations.gov hosts machine-readable comment metadata and attachments: reproducible source for anyone auditing whether 800-5 faithfully represents a given filer.
Government roles unpacked (800-5 abstract).
- Implementation guidance: translate consensus controls into playbooks agencies and contractors can operationalize without waiting for full NISTIR 8605 finalization; CAISI voluntary guidance track.
- Information-sharing: ISAC-style agent incident patterns, vulnerability disclosures, and sector alerts; commenters proposed CVE-like AI databases and MITRE ATLAS extensions (Lockheed Martin, AI Policy Network per TPI).
- Standards promotion: coordinate with ISO/IEC 42001, OWASP, OpenID agent identity work, and SP 800-53 overlay series rather than duplicating numbering.
Indirect prompt injection: filing depth (TPI). Beyond ranking, filings stress concealment: attacks that execute harmful tool actions while final user-visible chat appears benign: aligning with UK/US red-team competition findings on dual-objective attacks (external arXiv:2603.15714 competition cited in security literature concurrent with RFI). Model-level refusal is explicitly rejected as sufficient; deterministic policy enforcement and input sanitization pipelines are the recurring mitigation pattern.
Multi-agent and protocol risks (COSAiS scope). COSAiS use cases include multi-agent systems: filings reference MCP, A2A, and orchestrator loops where lateral movement crosses agent trust boundaries. 800-5 sets stage for 8605D overlays covering single- and multi-agent deployments; buyers running orchestrators should not assume single-agent RFI answers fully cover peer-agent delegation.
Baseline fairness
Voluntary synthesis. Unless contractually incorporated, 800-5 is advisory: same voluntary posture as AI RMF and GenAI Profile unless agency policy mandates CAISI artifacts.
Commenter self-selection. Filings skew toward large technology firms, trade associations, and security vendors with Washington capacity; ACT and similar groups warn against guidance that assumes hyperscale resources: small developers may be underrepresented relative to enterprise commenters (TPI point 8).
Docket survey bias. TPI roundup is editorial synthesis, not NIST: useful for themes, not a substitute for reading 800-5 or primary comments when auditing compliance arguments.
Extend-not-replace consensus may undercount dissent. TPI presents dominant position; individual comments may dispute overlay timing or warn against over-regulation: 800-5 full text should document minority views; UNKNOWN from abstract alone.
No production agent benchmark. Comments describe experiences and proposals; empirical measurement of agent attack success rates in 800-5 scope is limited to cited third-party studies in filings (e.g., adaptive attack statistics referenced by FAI/CSET in TPI) rather than NIST-run experiments.
International framing. EU AI Act and other jurisdictions appear in comment threads but 800-5 is U.S. NIST product: cross-border mapping left to buyers.
Timing. Comments closed March 9, 2026; agent products and CVE landscape evolved before May publication: fast-moving threat intel may lag.
What was not tested
- Mandatory federal certification or "NIST-approved agent" status: not claimed in abstract.
- Final SP 800-53 control overlays for agents: COSAiS NISTIR 8605D drafts still in pipeline.
- Multimodal agents, embodied robotics, or hardware agent stacks beyond filing examples.
- Quantified national adoption barrier (dollars or percentage): qualitative consensus only.
- Uniform evaluation harness across commenters: no ARIA-style executed pilot (contrast NIST AI 700-2 ARIA report in prior Record lineage).
- Long-horizon autonomous agents (multi-day persistence) as standardized test category in 800-5.
- Small-business deployment economics: ACT wrinkle noted in TPI not resolved in abstract.
- Binding procurement rules: 800-5 informs; FAR/DFARS changes UNKNOWN.
- Full-text verification of every quoted industry position against 800-5 sections when PDF unavailable.
Enterprise gaps. 800-5 doesn't ship runnable controls, SCAP content, or OSCAL overlay files: planning artifact. Runtime policy engines, MCP server pinning, and secrets scoping remain vendor- and buyer-built. Whether U.S. AI Safety Institute will require CAISI agent evaluations for frontier testers is UNKNOWN.
Code / weights / data public?
Primary publication: NIST page: https://www.nist.gov/publications/summary-analysis-responses-request-information-regarding-security-considerations-ai (May 18, 2026).
PDF retrieval: NIST nvlpubs URL for NIST.AI.800-5 returned 404 at reader time: verify DOI/PDF link on publication page before citing page numbers in contracts.
RFI source: CAISI announcement: https://www.nist.gov/news-events/news/2026/01/caisi-issues-request-information-about-securing-ai-agent-systems
Docket comments: regulations.gov search filter NIST-2025-0035: public comment text.
COSAiS project: https://csrc.nist.gov/Projects/cosais: overlay methodology and NISTIR 8605 series plan.
Secondary docket analysis: TPI Docket Roundup: https://techpolicyinstitute.org/publications/artificial-intelligence/securing-ai-agent-systems-recommendations-in-the-nist-rfi-filings/
No model weights, agent binaries, or annotation datasets: policy synthesis only.
Monday use or why not
Use 800-5 now when:
- Enterprise or federal security governance already maps to NIST AI RMF and SP 800-53: 800-5 provides CAISI-endorsed language that agent threats are novel but adaptation beats reinvention.
- Procurement teams need stakeholder-aligned vocabulary for agent RFP security sections before NISTIR 8605D lands.
- CISO office is standing up agent governance: abstract plus RFI questions supply checklist themes: injection, poisoned models, misalignment, access constraint, monitoring.
- You participate in COSAiS Slack or overlay comment periods: 800-5 signals which filing clusters NIST likely elevated.
Concrete Monday actions aligned with filing consensus (buyer-owned until overlays publish):
- Policy layer outside model: implement deterministic allowlists for tools, paths, and network egress; treat model output as untrusted input to policy engine (Perplexity/Frontier Model Forum position in TPI).
- Agent identity: issue scoped credentials per agent/workflow, not shared human API keys; plan revocation at machine speed (Okta/Twilio cluster).
- Least privilege: per-tool caps; VM or strong isolation for code execution agents when container kernel sharing is unacceptable (Cognition AI position).
- Runtime monitoring: log tool calls with rollback/containment playbooks; baseline agent behavior before "Agentic SOC" maturity (Elastic/Splunk themes).
- Risk-tiered human approval: high-impact actions (financial, data exfil, production config) require checkpoints; document intentional autonomy bounds (Docusign scenario).
- Map to existing controls: start SP 800-53 AC, AU, SI, RA families for gap analysis against agent loops; COSAiS anticipates tailored overlays rather than new numbering.
- Comment and track COSAiS: overlays-securing-ai@list.nist.gov and COSAiS Slack for 8605D agent volumes.
Defer treating 800-5 as compliance clearance when:
- You need legally defensible health, finance, or safety validation: build domain golden sets beyond RFI anecdotes.
- Legal team requires prescriptive control IDs: wait for NISTIR 8605D draft or map OWASP agentic top 10 operationally until then.
- Organization has no agents in production: abstract is planning signal, not urgent retrofit.
Procurement wording. Require vendors to describe deterministic enforcement, agent credential model, tool scope, monitoring, and update regression after model changes: cite NIST AI 800-5 as process evidence of industry consensus on adaptation need, not as a single pass/fail threshold.
Trade association economic framing (TPI point 8). CTA, CCIA, CTIA, USTelecom, BSA, TechNet, ITI, CEI, ACT emphasize voluntary risk-based guidance: tension with security vendor calls for mandatory baselines. 800-5 abstract's standards promotion role sits between these positions.
Human oversight scaling (filings). Risk-tiered checkpoints appear for financial transactions, data destruction, external communications, and privilege elevation: not uniform human-in-the-loop on every tool call.
Observability immaturity (Partnership on AI, Splunk, CSET per TPI). Logging standards for agent trajectories remain underdeveloped; SIEM integrations for agent tool graphs are buyer-built today.
Data provenance as security (Nielsen, Cloudflare, OpenID, JACS per TPI). Filings reframe training and retrieval provenance as integrity controls: signed metadata and attested permissions: relevant to poisoned-context risks named in January RFI.
Incident response gap (Anthropic, Microsoft filings per TPI). Authorized agents causing harm may not fit SP 800-61 incident categories; buyers should define agent-specific severity rubrics before first production incident.
Healthcare, finance, education listening sessions (April 2026 schedule). Sector sessions post-comment deadline add qualitative requirements: regulated buyers should monitor CAISI sector outputs.
Contrast with chatbot security programs. Traditional LLM guardrails focus on content safety of completions; 800-5 thread centers execution authority. A chatbot passing content filters may still violate 800-5 themes if tool routers execute unreviewed shell commands.
Research infrastructure asks (TPI point 10). Princeton reliability protocols, Google agent benchmarks, shared evaluation environments: 800-5 documents demand; NIST measurement programs may supply partial answers over time.
Foundation for Defense of Democracies filing (March 9, 2026). Called for SP 800-160 and SP 800-218 updates for agentic AI, minimum engineering requirements on action authority and tool invocation security, MITRE ATLAS expansion: example of substantive filing 800-5 corpus likely summarizes.
What changes after 800-5 for federal contractors. No immediate new control IDs: but FISMA agencies referencing COSAiS timelines should expect agent overlays in SP 800-53 family planning horizons; 800-5 is early evidence for budget forecasts, not audit checklist replacement.
Relation to the last paper in the line
NIST AI 100-1 (AI RMF 1.0, January 2023). Govern, Map, Measure, Manage functions: 800-5 feeds Map and Govern discourse for agentic systems without replacing RMF.
NIST AI 600-1 (GenAI Profile, July 2024). Catalogs GAI risks and suggested actions; agent tool-use and autonomy extend GAI themes. 800-5 is agent-specific security synthesis; 600-1 remains broader voluntary profile.
COSAiS / NISTIR 8605 series (2026–2027 roadmap). Operational successor line: 800-5 RFI responses and 800-5 summary analysis supply requirements input for 8605D (single- and multi-agent overlays). Predictive AI annotated outline (January 2026) is earlier volume A track.
SP 800-53 and SP 800-53B control baselines. Federal FISMA anchor; commenters want overlays, not replacement. TPI notes AC, AU, SI, RA families as likely adaptation targets: full 800-5 section mapping UNKNOWN without PDF.
SP 800-218A secure SDLC. Development-time agent security practices cited across filings for extending SSDF to agent pipelines.
MITRE ATLAS and OWASP agentic lists. Industry taxonomies commenters propose extending for agent kill chains, tool invocation, and multi-agent lateral movement.
NIST AI 700-2 ARIA pilot (November 2025: prior Record in repository lineage). ARIA operationalizes Measure with human testing and CoRIx trees on guardrail validity in toy scenarios: complementary to 800-5's security-focused RFI; neither substitutes for the other.
CISA agentic AI advisory (May 2, 2026: external). Operational deployment guidance on tool authorization, memory isolation, human-in-the-loop triggers: parallel executive-branch signal; not NIST 800-5 but buyers should read together for U.S. government theme alignment.
EU AI Act GPAI obligations (enforcement milestones 2026). Third regulatory layer for operators regardless of U.S. framework choice: 800-5 doesn't map EU conformity.
Buyer synthesis. Read 600-1 for what to worry about in GAI; read 700-2 for how NIST once measured guardrail validity with humans; read 800-5 for what the ecosystem told NIST about agent security gaps and adaptation; track COSAiS for what NIST will likely codify next in SP 800-53 overlay form.