NIST reports that its February 2026 concept paper on securing software and agentic AI identity and authorization received more than 600 responses. The comments will inform a future NCCoE project.
The summary describes strong commenter support for adapting established identity, authorization, and interoperability standards to agentic systems. Reported priorities include verifiable non-human identities, scoped and revocable credentials, delegation traceability, continuous authorization, richer audit evidence, governance layers, and privacy controls.
The reported priorities reflect stakeholder views and proposed approaches, not experimental validation or binding recommendations. NIST also notes that identified standards vary in maturity and that their inclusion does not constitute endorsement.
NIST says the NCCoE project will first address enterprise software-development use cases and later a consumer-owned-agent use case. Planned future work includes a draft project description and demonstrations of agentic identity and authorization controls; implementation results and effectiveness measurements are not yet provided.