{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/nist-ai-100-2-e2025-security-of-agents-2025/",
 "asOf": "2026-09-26",
 "id": "nist-ai-100-2-e2025-security-of-agents-2025",
 "date": "2025-03-24",
 "datePrecision": "day",
 "title": "NIST AI 100-2 E2025 taxonomy adds a dedicated section on security of AI agents",
 "lane": "policy",
 "kind": "standard",
 "summary": "NIST released the 2025 edition of its adversarial machine learning taxonomy, co-authored with the UK AI Security Institute and US AI Safety Institute staff. Unlike the 2023 edition, it includes a section on the security of agents, noting that tool-using agents are exposed to direct and indirect prompt injection and that hijacking can lead to arbitrary code execution or data exfiltration.",
 "whyItMatters": "It is the reference US government taxonomy that COSAiS overlays and CAISI agent work build on.",
 "actors": [
  "nist",
  "uk-aisi",
  "us-caisi"
 ],
 "topics": [
  "standards-and-guidance",
  "prompt-injection",
  "data-exfiltration"
 ],
 "atlas": [
  "untrusted-content",
  "tools",
  "sandbox"
 ],
 "artifacts": [
  "agentdojo"
 ],
 "sources": [
  {
   "url": "https://csrc.nist.gov/pubs/ai/100/2/e2025/final",
   "publisher": "NIST",
   "title": "Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2 E2025)",
   "date": "2025-03-24",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-2e2025.pdf",
   "publisher": "NIST",
   "title": "NIST AI 100-2 E2025 (PDF)",
   "date": "2025-03-24",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Section 3.5 'Security of Agents' states agents are vulnerable to direct and indirect prompt injection and that tool use lets attackers hijack agents to execute arbitrary code or exfiltrate data.",
   "locator": "Section 3.5"
  },
  {
   "fact": "Section 3.6 cites AgentDojo as a framework for measuring agent vulnerability to prompt injection via tool-returned data, and AgentHarm among jailbreak benchmarks.",
   "locator": "Section 3.6 Benchmarks"
  },
  {
   "fact": "The E2023 edition had no dedicated agents section (its prompt injection coverage was Sections 3.3-3.4).",
   "locator": "E2023 table of contents"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [
  "agent-data-exfiltration",
  "indirect-prompt-injection"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}