NIST eyes late-September release for first AI security overlays
The agentic AI overlay is furthest along inside NIST's Center for AI Standards and Innovation, and for good reason. Prompt injection that tricks a model into deleting a codebase isn't theoretical, Vassilev said; attacks of that kind have already been seen.
TL;DR
NIST expects to release the first two draft publications in its Control Overlays for Securing AI Systems (COSAiS) series in late September, according to research supervisor Apostol Vassilev. The series adapts SP 800-53 controls for five AI use cases: predictive AI, generative AI, single-agent and multi-agent systems, and AI developer controls. The first release pairs a methodology overview with an overlay on using and fine-tuning predictive AI. Drafts on the remaining use cases will follow on an unspecified timeline. The overlays are provided as a starting point, NIST's FAQ states organizations aren't required to use them.

Vassilev's timeline, given to Inside Cybersecurity after a Billington Cybersecurity Summit panel on September 9, puts the first public drafts roughly 13 months after NIST published the COSAiS concept paper in August 2025. That concept paper kicked off a working-group process that included a January 2026 annotated outline and workshop. The five-publication series has been narrowing toward concrete control language since.
The first publication provides the overarching methodology for tailoring SP 800-53 controls to AI systems. The second tackles predictive AI, models used for classification, forecasting, and decision support, the kind of AI most federal contractors are already fielding in production environments. These two are the ones NIST expects to release for public comment this month. The remaining three (covering generative AI and LLMs, single-agent and multi-agent systems, and a dedicated developer-controls overlay) don't yet have release dates.
On the panel, Vassilev spotlighted the agentic AI work as a priority that NIST's Center for AI Standards and Innovation is driving. He cited a mathematical proof, which he authored and released June 9, showing that no finite set of guardrails can be universally robust against prompt injection. The operational stakes he described are concrete: an agentic system that reaches into external code repositories and ingests instructions to delete a codebase or exfiltrate proprietary files. "We have seen attacks of this kind already play out in the real world," Vassilev said.
Supply chain and the verification gap
Vassilev also pointed to a supply-chain problem that the overlays alone can't solve. He argued that aspects of AI system legitimacy cannot be verified through technical means, leaving supply-chain security to be "delegated to legal agreements." That's a hard admission from the person leading NIST's adversarial AI work, and it suggests the overlays will be supplemented by governance and leadership-level decisions rather than pure technical control mapping.
What changes Monday
For assessors, C3PAOs, and contractors whose systems touch predictive AI, the September drafts are worth reading for the control-selection logic and parameter values, these will shape how AI workloads are scoped into existing assessment processes even before any framework formally adopts them.
For everyone else, the September release is a signal to watch the agentic overlay's development. The research agenda outpaces the publication schedule, and the threat model Vassilev described isn't waiting for the comment period.
Published ·Deep Fathom