What happened
On 24 September 2026, NIST's National Cybersecurity Center of Excellence (NCCoE) announced fresh resources for its Secure Software Development, Security and Operations (DevSecOps) project: the Artificial Intelligence section of the DevSecOps notional reference model was updated to reflect recent observations on AI security (guidance built on the NIST CSF to address cybersecurity risks related to AI development and use), and an 28 October 2026 webinar was scheduled on DevSecOps and agentic AI.
Why it matters
It is an in-window update to a NIST 'live document' reference model that practitioners use to place AI security controls inside DevSecOps pipelines — clarifying where agentic AI risk and AI-enabled software supply-chain security attach in the workflow.
Action needed
DevSecOps and application-security teams should review the updated AI section of the NCCoE notional reference model and attend/use the 28 October 2026 agentic AI webinar materials as mapping guidance.