model releaseObservedPublished: 13h ago

NIST explores challenges in credential sharing, human-in-loop as part of agentic AI project

The National Institute of Standards and Technology is pulling back the curtain on findings that will inform an upcoming project on artificial intelligence agents and identity considerations, in a recent blog post exploring challenges in credential sharing and relying on human-in-the-loop controls. “As AI matures, enterprises and customers are rapidly deploying agents seeking to unlock the next level of automation and productivity. Agentic AI shows potential to handle a multitude of use cases, from buying personal items on Amazon to customer service applications to enterprise security and software development,” NIST argues in a Aug. 27 blog post . The post says, “However, early agentic deployments are repeating a familiar pattern: prioritizing feature development and immediate value over security.” The post provides findings from comments on a Feb. 5 concept paper outlining plans to launch a project at NIST’s National Cybersecurity Center of Excellence on best practices and standards on identity and authorization for software and artificial intelligence agents. NIST says the post also draws “from extensive engagement with stakeholders in the agentic AI ecosystem. The goal of this NCCoE work is to accelerate the adoption of agentic AI by demonstrating how cybersecurity standards and best practices can reduce risk and realize agentic AI value.” The project is intended to complement a broader NIST agentic AI standards initiative announced in mid-February. The post is written by NIST’s Bill Fisher and Ryan Galluzzo. It starts with looking at credential sharing, explaining how “individuals giving their personal and enterprise credentials to agents has quickly become a common pattern for enabling agent access to data, applications, and services.” NIST says, “Sharing credentials – between humans or agents – creates accountability gaps that can result in any number of security, privacy, and legal issues. This is particularly true for sectors that require non-repudiation as a core security feature, such as in financial transactions or the sharing of health information.” “Consumer-facing scenarios present a greater challenge as enterprises have little to no control over the agentic identity and may struggle to distinguish an agent from a human, especially if user credentials are shared with the agent, allowing for user impersonation,” according to the post. NIST explains, “While standards bodies such as Fast Identity Online (FIDO) are looking at ways to issue agent authenticators that can be bound to user identities, this work is still in early phases. Broadly, there is recognition that for consumer scenarios, the ‘secure path’ will also need to be the ‘easy path’ or credential sharing and impersonation will continue to proliferate.” Static and long-lived credentials can also cause problems because the “ubiquity of AI technology and its cross-cutting application to any number of use cases has put pressure on many individuals and organizations to deploy and test agentic functionality, with little regard for identity best practices,” according to the post. Another aspect is deploying agents with local user accounts. The post says, “While this deployment model is convenient, and many developers prefer to work locally, giving agents local account access allows the agent to both impersonate the user and act with broadly scoped access.” “Agents running commands with user authorization undermines non-repudiation and exposes the organization to potential downstream consequences when an agent performs actions without the full understanding or consent of the user. Additionally, local agentic deployments make it hard to have a centrally managed agentic identity repository and encourages other challenging [identity and access management] practices such as static credentials that are stored in local files,” according to the post. Finally, the post looks at human-in-the-loop, noting “many still see Human-in-the-Loop (HITL) as a fundamental element of agentic control.” “Like IAM solutions of the past, durable agentic identity and authorization design requires enterprises to consider both the usability and security considerations for HITL. While standards may not exist to govern this challenge, the agentic ecosystem is currently forming best practices to alleviate HITL concerns,” the post says. The NCCoE is planning to do a series of blog posts related to the project and will launch an “online resource hub and NIST publications to support the adoption of IAM standards and best practices for software and AI agents,” according to NIST. NIST says the next post in the series will “highlight some of the identity and authorization principles necessary for durable agentic design.” -- Sara Friedman (sfriedman@iwpnews.com) Article Type: Daily News Sara Friedman tags: AI Weight: -20

Download social card
Copy launch post

Why this byte is shareable

Signal quality

observed

Confidence badge and source context included.

Entity anchor

AI News

Clear company or model context for distribution.

Export ready

1200 x 630 card

Optimized for X, LinkedIn, and chat previews.

Why it matters

AI News can change capability, routing, cost, or product scope for builders shipping against current model APIs.

Suggested launch post

Use this in X threads, community posts, internal team chats, or launch recaps.

NIST explores challenges in credential sharing, human-in-loop as part of agentic AI project

Why it matters: AI News can change capability, routing, cost, or product scope for builders shipping against current model APIs.

Source: Insidecybersecurity
https://a2zai.ai/bytes/nis...
Post to X
Copy text

Permalink: https://a2zai.ai/bytes/nist-explores-challenges-in-credential-sharing-human-in-loop-as-part-of-agentic--6e456370

Social card: https://a2zai.ai/bytes/nist-explores-challenges-in-credential-sharing-human-in-loop-as-part-of-agentic--6e456370/opengraph-image

Social and community

Discussion