CAISI published a Federal Register request for information on practices for measuring and improving the security of AI agent systems, citing hijacking, backdoors and indirect prompt injection. It asks about model-level, system-level and human-oversight controls, assessment methods, and ways to limit, modify and monitor deployment environments.
Why it matters
It is a US government solicitation focused specifically on agent security controls and how to measure them.
Key facts
As stated in the sources, with where to find them.
- Docket NIST-2025-0035; comments due March 9, 2026.Federal Register notice header
- Five topic areas: security threats and vulnerabilities (hijacking, backdoors, indirect prompt injection); security practices at model, agent-system and human-oversight levels; assessing agent security; limiting, modifying and monitoring deployment environments; additional considerations.Request for Information topics
Findings that cite this record
No tracked finding cites this record yet.
Key questions this bears on
- Can prompt injection against AI agents be reliably defended?Not reliably. Defenses reduce injection but none has eliminated it; limiting what untrusted input can trigger is the most defensible approach.
- Can AI agents defend and oversee systems on their own?Not yet. Agents are weak on realistic defensive benchmarks and monitors can be evaded; assistants help analysts who stay in charge.
Sources
Related records
Jun 3, 2026
Mar 24, 2025
Feb 17, 2026
Jul 1, 2026
May 7, 2026
May 1, 2026