Skip to main content
Public Comment on Docket NIST-2025-0035 · Submitted March 4, 2026

Security Considerations for Artificial Intelligence Agents

A 12-page public comment responding to the NIST CAISI Request for Information on AI agent security. Proposes six policy recommendations grounded in patent-pending Cryptographic Runtime Governance.

Executive Summary

Key Recommendations to CAISI

1.

Mandate sealed reference states for all autonomous AI deployments

2.

Require continuous runtime measurement against sealed baselines

3.

Adopt tiered verification, from self-attestation to gateway checks to outside audit

4.

Mandate offline verifiability for air-gapped and DDIL environments

5.

Standardize artifact formats using existing cryptographic primitives

6.

Require privacy-preserving disclosure for cross-boundary attestation

Coverage

Topics Addressed

Section 1

Threat Landscape

Runtime integrity threats including behavioral drift, policy circumvention, and retroactive evidence fabrication in agentic AI systems.

Section 2

Security Practices

Sealed policy artifacts, continuous integrity measurement, and signed governance receipts as foundational security practices.

Section 3

Assessment & Measurement

Tiered verification framework progressing from self-attestation through gateway checks to outside verification.

Section 4

Environment Controls

gateway architecture as a zero-trust policy decision point; effecting decisions is per-deployment wiring. Runtime governance for cloud, edge, and air-gapped deployments.

Section 5

Additional Considerations

Privacy-preserving selective disclosure and alignment with the existing NIST framework vocabulary.

Foundations

Standards Referenced

NIST SP 800-53 Rev. 5NIST AI RMF 1.0NIST SP 800-218 (SSDF)NIST AI 100-2e2025EO 14110