a NIST blog As AI matures, enterprises and customers are rapidly deploying agents seeking to unlock the next level of automation and productivity. Agentic AI shows potential to handle a multitude of use cases, from buying personal items on Amazon to customer service applications to enterprise security and software development. However, early agentic deployments are repeating a familiar pattern: prioritizing feature development and immediate value over security. This strategy is understandable. Strategic, financial and technical leaders want to demonstrate ROI for their AI investments. Enterprises are under pressure to innovate and drive organizational efficiencies. Individuals are seeking automated and personalized experiences. Moreover, agentic AI introduces a novel frontier of security challenges that "model-only" guardrails are not yet fully equipped to solve. While building a fully mature security framework in a fast-moving landscape takes time, reverting to outdated security practices risks eroding the core value AI agents provide. This post will discuss some of the current identity and authorization practices that present substantial security challenges for agentic AI systems. Many of the challenges discussed are not new and, put simply, are the same issues that have plagued identity management systems for decades. This post is intended as a reminder that as we sprint towards agentic implementations, deploying and building on existing foundational identity standards and best practices will better prepare implementers for future challenges. The topics covered in this post are drawn from public comments on the recent NCCoE Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization Concept Paper, and from extensive engagement with stakeholders in the agentic AI ecosystem. The goal of this NCCoE work is to accelerate the adoption of agentic AI by demonstrating how cybersecurity standards and best practices can reduce risk and realize agentic AI value. Security professionals have been telling users since
Back to the Future: Why Agentic AI Needs a Strong Identity Foundation | NIST
Read the original article
nist.gov →