The U.S. National Institute of Standards and Technology (NIST) issued a public request for information (RFI) seeking input on how to better secure agentic AI systems as adoption expands across government and critical infrastructure environments. NIST’s Center for AI Standards and Innovation asked industry, researchers, and system operators to provide perspectives on security risks and mitigation strategies for these deployments.
NIST defined AI agents as deployments that combine one or more generative AI models with scaffolding software that enables planning and discretionary action, potentially via multiple coordinated sub-agents. The RFI highlights that agentic systems can introduce security risks distinct from traditional software and non-agentic AI, including susceptibility to hijacking, backdoor attacks, and other exploits that could impact public safety and trust; security leaders cited concerns that controls are lagging as agencies deploy GenAI capabilities quickly.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
The agency said responses to the RFI must be submitted through regulations.gov by March 9. NIST plans to use the feedback to develop technical guidelines, evaluation methods, and best practices for agentic AI security.
NIST's Center for AI Standards and Innovation published a request for information seeking public input on how to secure agentic AI deployments used across government and critical infrastructure. The notice identifies risks such as hijacking, backdoors, data poisoning, indirect prompt injection, and failures caused by misaligned objectives or specification gaming.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.