NIST and CISA Converge: Agentic AI Is an Identity Problem
Both agencies conclude agentic AI intensifies existing governance gaps rather than requiring a new security discipline.
TL;DR
NIST's NCCoE published a concept paper in February on applying identity standards to AI agents; CISA followed in May with joint international guidance on secure adoption of agentic AI. Both reach the same conclusion: autonomous agents that independently choose tools, call APIs, and initiate transactions don't need a novel security architecture. They need the identity governance agencies were already supposed to have, unified visibility across human and non-human identities, least-privilege enforcement, and lifecycle management. Agencies with identity governance already tight absorb less new risk. The rest face a prerequisite they haven't finished.
In February, NIST's National Cybersecurity Center of Excellence published a concept paper asking whether existing identity standards (identification, authentication, authorization, auditing, non-repudiation) could govern AI agents without a new architecture. In May, CISA and international partners released guidance on the secure adoption of agentic AI. The documents differ in scope but converge on the same conclusion: agentic AI is an identity governance problem, not a novel threat category.
The CISA guidance is direct about what goes wrong. Agentic AI can expand the attack surface, enable privilege creep, produce behavioral misalignment, and generate obscure event records. The recommended mitigations are familiar to anyone who's implemented a zero-trust architecture: avoid broad or unrestricted access, begin with low-risk use cases, and account for agentic AI security in the organization's existing security model and risk posture.
What makes AI agents different from conventional service accounts is velocity and chaining. Agents can be spun up faster, granted broad privileges, and left running without the lifecycle discipline applied to human users. An agent that independently chooses among tools, calls APIs, and initiates transactions creates an audit trail that's harder to reconstruct, especially if the agency can't consistently identify which agent acted, who owns it, and what permissions it held at the time.
The practical takeaway is uncomfortable. Agencies whose identity governance is already wired tight (unified visibility across human and non-human identities, least-privilege enforcement, lifecycle management) inherit less new risk from agentic AI. Everyone else faces a prerequisite they haven't finished. The NIST concept paper's comment period closed in April; whether the NCCoE proceeds to a full demonstration project depends on the feedback received. But the direction of travel is clear. Identity governance isn't a companion control for agentic AI. It's the control.
Published ·Deep Fathom