NIST just locked down identity tokens — but explicitly admitted AI agent authorization is still a gap
NIST IR 8587 (final Sep 15, 2026) delivers comprehensive token security guidance — signed identity tokens, access tokens, SSO assertions, key protection, short-lived credentials. But Section 1.1.1 admits: AI/agent access risks need separate guidance. NIST and CISA know the gap; token controls alone won't stop rogue agents.
TrustAI Editorial · September 17, 2026
Read article