A Request for Information from NIST’s Center for AI Standards and Innovation CAISI asked for input on secure practices and methodologies for AI agent systems on Jan. 8.
KEY FACTS
- Action Request for information on AI agent security
- Date Jan. 8 issuance
- Focus Autonomous agents that take real world actions
- Scope Novel risks, security practices, assessment methods, deployment constraints
The RFI targets AI systems that can act without constant human oversight and describes risks that challenge traditional cybersecurity assumptions, including non-deterministic outputs and changing data after deployment.
An AI Risk Management Framework released in January 2023 is presented as a baseline for managing AI risks across organizations and society, though the RFI signals a move toward more operational expectations for autonomous systems.
Related work referenced by the initiative includes an adversarial machine learning taxonomy, a test platform called Dioptra for measuring trustworthy characteristics, and a community profile for secure software development aimed at generative models AI SSDF community profile. The portfolio also addresses privacy engineering and updated identity guidance.
CISOs face a large volume of overlapping AI guidance and request concise, actionable materials such as digestible checklists rather than extensive reports to aid rapid implementation.
WHY IT MATTERS
Shifting standards toward operational controls for autonomous AI signals that AI risk is an immediate security concern for enterprises, not solely a governance or research topic.

