The National Institute of Standards and Technology expects to advance high profile standards work around a “Cyber AI Profile” and securing artificial intelligence agents this summer, amid a flurry of federal activity aimed at addressing both the risks and opportunities for AI and cybersecurity.
NIST’s National Cybersecurity Center of Excellence (NCCoE) is now running six distinct projects focused on the intersection of AI and cyber. But Cherilyn Pascoe, director of the NCCoE, said AI is popping up across the center’s work, which focuses on practical guidance to advance secure technologies in collaboration with government agencies, industry and academia.
“I think AI is going to be part, if not a leading part, of every project going forward at the center,” Pascoe said in an interview. “It is becoming so foundational to cybersecurity.”
Recent advancements in AI models like Anthropic’s Claude Mythos have shown the ability to quickly find software vulnerabilities and create cyber exploits much faster than humans.
President Donald Trump earlier this month signed an executive order aimed at addressing those risks. The Cybersecurity and Infrastructure Security Agency subsequently released an AI-focused, governmentwide directive for agencies to prioritize the highest risk software vulnerabilities.
Pascoe said the NCCoE is seeing AI adopted across multiple cybersecurity areas, including incident response, governance, and architecture. NIST is also starting to use AI for software security through its “DevSecOps” consortium.
” We’re taking a look at how, you know, AI, including agentic AI, can be used to develop software, review software, as well as use software securely within an organization,” Pascoe said. “That’s a really exciting pivot that we’ve been able to do. Last year AI, was not something that was as big of a piece of that project, and now over time, based off of community interest and where the models are heading, it’s definitely become front and center for us to address as part of that work.”
Cyber AI profile
The NCCoE for several years has been developing AI-specific cyber guidance, most notably as part of the “Cyber AI Profile.” The goal of that project is to explain how existing standards frameworks, like NIST’s Cybersecurity Framework, can be applied to the fast-moving world of AI.
“Rather than creating a whole new guidance document, we’re looking at how can we tailor some of the existing frameworks to be able to address the evolving cybersecurity challenges associated with AI,” Pascoe said.
NIST is reviewing comments on an initial preliminary draft of the Cyber AI Profile.
But during a series of recent webinars, NIST officials got feedback from industry and other community members about how to continue to build on the project. Pascoe said conversation topics included governance, applying “zero trust” security practices to AI, supply chain security challenges, and tools like AI bills of material.
“There are a lot of open questions that we’re trying to work with the community to pull together resources across different standards bodies that are being developed by industry to be able to aggregate all of those resources together in one document that can provide a good roadmap for organizations to be able to adopt AI securely,” Pascoe said.
She added that the NCCoE expects to release the next version of the Cyber AI Profile draft this summer, with community feedback incorporated.
Agentic AI interest
Meanwhile, AI agents – or AI-based systems that can take actions autonomously rather than just generating outputs – have sparked both excitement and fear across the cybersecurity community. The NCCoE has been tackling that work through a “Software and AI Agent Identity and Authorization” project.
Standards for identity security – work that NIST has spearheaded for over two decades – have primarily focused on humans. The NCCoE project is looking at how that can now be applied to AI agents, who will also need to be securely identified and authorized to access datasets and take actions across computer networks.
“It’s raising new questions like, how do you identify the agent and identify it separately from the human, as well as the other systems that the human is using,” Pascoe explained. “What authority and access does it have? What systems and data can access? What can it change?”
A draft project concept released by the NCCoE this year received comments from more than 600 organizations, Pascoe said.
The NCCoE will now take those comments and develop a project description, which Pascoe said should be released this summer.
“The standards are still being developed, the protocols, like [Model Context Protocol], are still being worked on,” Pascoe said. “Organizations are still deploying agents in different use cases that are changing as more agents start to be deployed, and so we’re relying on that expertise from the community to guide us on these efforts.”
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.