Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 3IT NewsAI

AI Agent Authorization Risks Remain a Gap in New NIST-CISA Token Security Guidance

CSO Online, Wednesday, September 16th, 2026

NIST IR 8587 covers token forgery and theft but leaves agent actions out of scope, with delegation chains unaddressed.

NIST IR 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse, produced with CISA, addresses what happens after authentication in single sign-on and API access: tokens carry proof of authentication or authorization, so an attacker who compromises one inherits access already granted.

NIST recommends continuous monitoring and tighter controls across the token lifecycle, and says the same guidelines apply to AI agents as to humans, while acknowledging that AI creates additional IAM challenges requiring new or expanded standards still being developed.

IDC's Yih Khai Wong notes the core mismatch: token hardening assumes the holder is a known, bounded actor, and an agentic system breaks that assumption.

more →  ·  More from AI →