{"id":90756,"date":"2026-06-30T14:58:09","date_gmt":"2026-06-30T14:58:09","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/90756\/"},"modified":"2026-06-30T14:58:09","modified_gmt":"2026-06-30T14:58:09","slug":"nists-cyber-center-moves-forward-with-cyber-ai-profile-agentic-ai-projects","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/90756\/","title":{"rendered":"NIST\u2019s cyber center moves forward with \u2018Cyber AI Profile,\u2019 agentic AI projects"},"content":{"rendered":"<p>The National Institute of Standards and Technology expects to advance high profile standards work around a \u201cCyber AI Profile\u201d and securing artificial intelligence agents this summer, amid a flurry of federal activity aimed at addressing both the risks and opportunities for AI and cybersecurity.<\/p>\n<p>NIST\u2019s National Cybersecurity Center of Excellence (NCCoE) is now running <a href=\"https:\/\/www.nccoe.nist.gov\/ai\" rel=\"nofollow noopener\" target=\"_blank\">six<\/a> distinct projects focused on the intersection of AI and cyber. But Cherilyn Pascoe, director of the NCCoE, said AI is popping up across the center\u2019s work, which focuses on practical guidance to advance secure technologies in collaboration with government agencies, industry and academia.<\/p>\n<p>\u201cI think AI is going to be part, if not a leading part, of every project going forward at the center,\u201d Pascoe said in an interview. \u201cIt is becoming so foundational to cybersecurity.\u201d<\/p>\n<p>Recent advancements in AI models like Anthropic\u2019s Claude Mythos have shown the ability to quickly find software vulnerabilities and create cyber exploits much faster than humans.<\/p>\n<p>President Donald Trump earlier this month <a href=\"https:\/\/federalnewsnetwork.com\/cybersecurity\/2026\/06\/ai-executive-order-sets-stage-for-new-cybersecurity-directives\/\" rel=\"nofollow noopener\" target=\"_blank\">signed an executive order aimed at addressing those risks<\/a>. The Cybersecurity and Infrastructure Security Agency subsequently <a href=\"https:\/\/federalnewsnetwork.com\/cybersecurity\/2026\/06\/ai-directive-focuses-patching-efforts-on-highest-risk-vulnerabilities\/\" rel=\"nofollow noopener\" target=\"_blank\">released an AI-focused, governmentwide directive<\/a> for agencies to prioritize the highest risk software vulnerabilities.<\/p>\n<p>Pascoe said the NCCoE is seeing AI adopted across multiple cybersecurity areas, including incident response, governance, and architecture. NIST is also starting to use AI for software security through its \u201cDevSecOps\u201d consortium.<\/p>\n<p>\u201d We\u2019re taking a look at how, you know, AI, including agentic AI, can be used to develop software, review software, as well as use software securely within an organization,\u201d Pascoe said. \u201cThat\u2019s a really exciting pivot that we\u2019ve been able to do. Last year AI, was not something that was as big of a piece of that project, and now over time, based off of community interest and where the models are heading, it\u2019s definitely become front and center for us to address as part of that work.\u201d<\/p>\n<p>Cyber AI profile<\/p>\n<p>The NCCoE for several years has been developing AI-specific cyber guidance, most notably as part of <a href=\"https:\/\/www.nccoe.nist.gov\/projects\/cyber-ai-profile\" rel=\"nofollow noopener\" target=\"_blank\">the \u201cCyber AI Profile.\u201d<\/a> The goal of that project is to explain how existing standards frameworks, like NIST\u2019s Cybersecurity Framework, can be applied to the fast-moving world of AI.<\/p>\n<p>\u201cRather than creating a whole new guidance document, we\u2019re looking at how can we tailor some of the existing frameworks to be able to address the evolving cybersecurity challenges associated with AI,\u201d Pascoe said.<\/p>\n<p>NIST is reviewing comments on an initial preliminary draft of the Cyber AI Profile.<\/p>\n<p>But during a series of recent webinars, NIST officials got feedback from industry and other community members about how to continue to build on the project. Pascoe said conversation topics included governance, applying \u201czero trust\u201d security practices to AI, supply chain security challenges, and tools like AI bills of material.<\/p>\n<p>\u201cThere are a lot of open questions that we\u2019re trying to work with the community to pull together resources across different standards bodies that are being developed by industry to be able to aggregate all of those resources together in one document that can provide a good roadmap for organizations to be able to adopt AI securely,\u201d Pascoe said.<\/p>\n<p>She added that the NCCoE expects to release the next version of the Cyber AI Profile draft this summer, with community feedback incorporated.<\/p>\n<p>Agentic AI interest<\/p>\n<p>Meanwhile, AI agents \u2013 or AI-based systems that can take actions autonomously rather than just generating outputs \u2013 have sparked both excitement and fear across the cybersecurity community. The NCCoE has been tackling that work through a \u201cSoftware and AI Agent Identity and Authorization\u201d <a href=\"https:\/\/www.nccoe.nist.gov\/projects\/software-and-ai-agent-identity-and-authorization\" rel=\"nofollow noopener\" target=\"_blank\">project<\/a>.<\/p>\n<p>Standards for identity security \u2013 work that NIST has spearheaded for over two decades \u2013 have primarily focused on humans. The NCCoE project is looking at how that can now be applied to AI agents, who will also need to be securely identified and authorized to access datasets and take actions across computer networks.<\/p>\n<p>\u201cIt\u2019s raising new questions like, how do you identify the agent and identify it separately from the human, as well as the other systems that the human is using,\u201d Pascoe explained. \u201cWhat authority and access does it have? What systems and data can access? What can it change?\u201d<\/p>\n<p>A draft project concept released by the NCCoE this year received comments from more than 600 organizations, Pascoe said.<\/p>\n<p>The NCCoE will now take those comments and develop a project description, which Pascoe said should be released this summer.<\/p>\n<p>\u201cThe standards are still being developed, the protocols, like [Model Context Protocol], are still being worked on,\u201d Pascoe said. \u201cOrganizations are still deploying agents in different use cases that are changing as more agents start to be deployed, and so we\u2019re relying on that expertise from the community to guide us on these efforts.\u201d<\/p>\n<p class=\"article-copyright\">Copyright<br \/>\n                            \u00a9\u00a02026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.\n                    <\/p>\n","protected":false},"excerpt":{"rendered":"The National Institute of Standards and Technology expects to advance high profile standards work around a \u201cCyber AI&hellip;\n","protected":false},"author":2,"featured_media":90757,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,53,47889,353,47890,18745,3733],"class_list":["post-90756","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-anthropic","tag-cherilyn-pascoe","tag-mythos","tag-national-cybersecurity-center-of-excellence","tag-national-institute-of-standards-and-technology","tag-sentinelone"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/90756","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=90756"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/90756\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/90757"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=90756"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=90756"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=90756"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}