What happened
NIST, with CISA support, finalized NIST IR 8587, 'Protecting Tokens and Assertions from Forgery, Theft, and Misuse,' providing implementation guidance for protecting digitally-signed tokens/assertions (SSO, API access) from post-authentication misuse. The publication builds on NIST SP 800-53 updates and responds to Executive Order 14306. Coverage published Sept 16, 2026 (CSOonline) reports that AI-agent actions are explicitly out of scope of the current guidance, but NIST states the same token-hardening principles should apply to AI agents while acknowledging that agentic-AI access risk 'creates additional IAM challenges that require further guidelines and, in some cases, new or expanded standards and protocols' — i.e., NIST/CISA flag agent authorization as unresolved and under active work via the parallel NIST AI Agent Standards Initiative.
Why it matters
This is a general (non-AI-specific) identity/token security standard, so it sits at the edge of scope, but it directly shapes near-term AI-agent security posture: it's the first finalized NIST guidance to explicitly name AI-agent token/authorization handling as an acknowledged standards gap, and enterprises deploying agentic AI are being told to apply token-hardening controls now while NIST develops agent-specific extensions.
Action needed
Apply NIST IR 8587's token-lifecycle hardening (short-lived tokens, continuous monitoring, tighter post-auth controls) to AI-agent-held credentials as an interim measure; track the NIST AI Agent Standards Initiative for forthcoming agent-specific identity/authorization standards.