Chronicle/Policy & standards

NIST proposes SP 800-53 control overlays for securing AI, including single- and multi-agent systems

PolicyStandardSignificance assistant-drafted

NIST released a concept paper for Control Overlays for Securing AI Systems (COSAiS), which would tailor SP 800-53 security controls to AI use cases. The planned use cases include generative AI assistants, predictive AI, single-agent systems, multi-agent systems and controls for AI developers, informed by the AI 100-2 E2025 taxonomy. As of the project page, only an annotated outline for the predictive AI overlay (January 8, 2026) had followed; agent overlays had not been published.

Why it matters

Agent-specific SP 800-53 overlays would give federal agencies and contractors auditable control baselines for agents; their absence is a notable gap.

Key facts

As stated in the sources, with where to find them.

  • Five use cases: using and fine-tuning generative AI assistants; using and fine-tuning predictive AI; single-agent AI systems; multi-agent AI systems; security controls for AI developers.Concept paper announcement; COSAiS project page
  • The project page lists only two dated updates: the August 14, 2025 concept paper and a January 8, 2026 predictive AI annotated outline (feedback due February 13, 2026).COSAiS project page, news

Findings that cite this record

No tracked finding cites this record yet.

Sources

Related records