NIST has opened a comment period on a concept paper exploring how organizations should identify, manage and authorize software and AI agents, marking an early but important step toward standards for non-human digital identity.
The work is being run through the National Cybersecurity Center of Excellence, which said it is interested in standards-based approaches for controlling access and actions taken by software agents, including AI agents. The comment period for the concept paper runs through April 2, 2026. According to the project description, the goal is to gather enough industry input to decide the scope, feasibility and value of a fuller project and whether a demonstration effort or other NCCoE outputs would best address the challenge.
NIST is explicit about the problem it is trying to solve. The agency says enterprises are moving from AI systems that generate text or graphics toward agents that can take actions such as deploying code to production with limited human supervision. Once systems can act instead of merely suggest, identity and authorization questions become more urgent: what exactly is the agent, who delegated authority to it, what can it do, and how should its actions be logged and constrained? Those issues already sit near the center of a commercial push in which AI agent identity becomes security priority and vendors work to manage non-human identities and AI agents across enterprise systems.
The significance of the concept paper is that NIST is not treating AI agent identity as a niche product feature. It is framing the issue as a standards and infrastructure problem. The project description says community input will inform later planning, including whether the agency develops a draft project description and practical guidance for organizations implementing AI agents. That is the kind of language that can precede architectures, reference implementations and procurement expectations.
The paper does not yet create a standard, but it does formalize the question inside NIST’s identity and cybersecurity machinery. For vendors building agent controls and for enterprises trying to decide how much authority to delegate to autonomous software, that alone is meaningful. The identity stack for AI agents is starting to move from market rhetoric into the standards process.
–
By the ID Tech Editorial Team





Follow Us