What happened
On 29 September 2026, the NIST National Cybersecurity Center of Excellence (NCCoE) released a summary of comments received on its draft concept paper 'Accelerating the Adoption of Software and AI Agent Identity and Authorization' (the February 2026 draft by Booth, Fisher, Galluzzo and Roberts, whose comment period ran Feb 5 - Apr 2, 2026). The summary is now live on a new Software and Agentic AI Identity and Authorization Online Resource Hub. The concept paper frames five focus areas for agentic identity work: identification, authorization, access delegation, logging/transparency, and tracking data flows, and asks whether the NCCoE should build practice-guide demonstrations of how existing identity/authorization standards apply to AI agents.
Why it matters
This is a concrete step in NIST's AI Agent Standards Initiative (which covers industry-led standards, community protocols, and agent identity/security research). It signals the direction NIST is heading for agent identity and authorization — the control plane that CISOs and platform teams are being pushed to implement — and gives practitioners advance visibility into where NIST-based agent identity requirements are likely to land (per-agent workload identities, least privilege, tamper-proof audit trails, and the 'on behalf of' human-binding of agent actions).
Action needed
Practitioners building agent IAM should track the NCCoE Software and Agentic AI Identity project page and prepare to pilot the recommended patterns (unique agent identities, scoped short-lived credentials, delegated-authority logging). Feed comments via the NCCoE resource hub when the next draft opens.