Security Considerations for Artificial Intelligence Agents
A 12-page public comment responding to the NIST CAISI Request for Information on AI agent security. Proposes six policy recommendations grounded in patent-pending Cryptographic Runtime Governance.
Key Recommendations to CAISI
Mandate sealed reference states for all autonomous AI deployments
Require continuous runtime measurement against sealed baselines
Adopt tiered verification, from self-attestation to gateway checks to outside audit
Mandate offline verifiability for air-gapped and DDIL environments
Standardize artifact formats using existing cryptographic primitives
Require privacy-preserving disclosure for cross-boundary attestation
Topics Addressed
Threat Landscape
Runtime integrity threats including behavioral drift, policy circumvention, and retroactive evidence fabrication in agentic AI systems.
Security Practices
Sealed policy artifacts, continuous integrity measurement, and signed governance receipts as foundational security practices.
Assessment & Measurement
Tiered verification framework progressing from self-attestation through gateway checks to outside verification.
Environment Controls
gateway architecture as a zero-trust policy decision point; effecting decisions is per-deployment wiring. Runtime governance for cloud, edge, and air-gapped deployments.
Additional Considerations
Privacy-preserving selective disclosure and alignment with the existing NIST framework vocabulary.