ai-cybersecuritytrade-pressNewsThe Broadside2 min read

NIST NCCoE advances Cyber AI Profile, agent identity work

NIST is treating AI as plumbing for cybersecurity programs, which means old control maps will need uncomfortable new seams.


TL;DR

Federal News Network reports that NIST’s National Cybersecurity Center of Excellence is moving six AI-cyber projects, including a summer revision of the Cyber AI Profile and agent identity work that drew comments from more than 600 organizations. Primes, contractors, managed service providers and C3PAOs should read this as early architecture guidance, not certification text. The unresolved question is whether NIST will map existing Cybersecurity Framework, DevSecOps and supply-chain practices tightly enough to change compliance evidence.

Federal News Network’s useful detail is not that NIST has more AI work. Everyone has more AI work. The news is that the National Cybersecurity Center of Excellence is treating artificial intelligence as part of the security architecture itself, with six projects now sitting at the intersection of AI and cybersecurity and a revised Cyber AI Profile draft expected this summer.

That matters because the Cyber AI Profile is not being framed as a separate compliance universe. NIST’s project page describes it as a Cybersecurity Framework-based community profile for the cybersecurity of AI and AI used for cybersecurity, with risk areas including AI systems, AI-enabled attacks and AI-enabled defense: https://www.nccoe.nist.gov/projects/cyber-ai-profile. In other words, NIST is trying to answer the practical question contractors are already facing: when AI is inside incident response, software review, governance and architecture, which parts of the existing cyber program still apply cleanly and which parts need adaptation?

The agent work is the sharper operational problem. Pascoe told Federal News Network that NCCoE’s Software and AI Agent Identity and Authorization project is asking how to identify an AI agent separately from a human, what authority it has, what systems and data it can reach, and what it can change. That is not abstract policy work for primes, managed service providers or C3PAOs. It is access control, logging, authorization boundaries and evidence. If an AI agent reviews code, opens tickets, changes configurations or queries production data, the old answer of “the user did it” becomes a lazy answer very quickly.

NIST is still in guidance mode. The initial preliminary draft of NIST IR 8596, the Cybersecurity Framework Profile for Artificial Intelligence, was published in December 2025 and its public comment period has closed: https://csrc.nist.gov/pubs/ir/8596/iprd. The summer draft may give practitioners useful mappings across Cybersecurity Framework functions, DevSecOps, supply chain controls and AI governance. Or it may remain a high-level roadmap that contractors must translate themselves before a contracting officer, agency CIO shop or CISA-backed requirement turns it into procurement language.

For Monday morning, nobody should rewrite a System Security Plan because NCCoE is revising a profile. But contractors embedding AI into security tooling should start inventorying where agents and AI-assisted systems make decisions, take actions, touch controlled data or produce compliance evidence. The Cyber AI Profile is likely to become the vocabulary for those conversations before it becomes a requirement. That is usually how NIST guidance enters the bloodstream.


Published ·Deep Fathom