Download Privacy Needle App

Type to search

Cybersecurity

NIST-CISA Token Security Guidance Leaves AI Agent Risks Unaddressed

Share

The National Institute of Standards and Technology (NIST), with assistance from the Cybersecurity and Infrastructure Security Agency (CISA), has released new guidance on securing identity and access tokens that notably excludes the specific authorisation risks posed by autonomous AI agents.

The report, titled “Protecting Tokens and Assertions from Forgery, Theft, and Misuse” (NIST IR 8587), provides frameworks for protecting digitally signed tokens used in single sign-on (SSO) and API access. It focuses on the lifecycle of tokens after authentication to prevent attackers from exploiting stolen or forged credentials to gain unauthorised access.

While NIST recommends applying similar security principles to AI agents as it does to humans, the agency acknowledged that agentic systems create unique identity and access management (IAM) challenges. NIST noted that further guidelines and potentially new standards or protocols are required to address these specific risks.

Challenges in Agentic Identity

Security experts warn that AI agents break the traditional security assumption that a token holder is a known, bounded actor. Yih Khai Wong, a senior research manager at IDC Asia/Pacific, noted that enterprises must maintain visibility into who provisions an agent’s credentials and ensure access is revoked immediately upon task completion.

The risk of delegation also introduces complexity. Amit Kumar Jena, head of AI development at Kanerika, explained that as an agent acts on behalf of a user and invokes various tools or services, determining whose authority is being exercised becomes increasingly difficult as the chain of command grows.

Furthermore, prompt injection attacks could steer an agent holding a valid token toward performing actions that the original user never requested. Because the token itself remains legitimate, standard verification processes may fail to detect such misuse.

Mitigating Token Misuse

To counter these threats, analysts suggest that Chief Information Security Officers (CISOs) should treat AI agents as low-trust, non-human identities, granting only the minimum access required for a specific task. Jena advised that higher-risk actions performed by agents should require explicit human approval.

The importance of robust token security was highlighted earlier this year when a public GitHub repository, believed to be maintained by a CISA contractor, was found to contain sensitive government credentials, including AWS and GitHub access tokens.

Beyond identity management, organisations must address the context of token use. Jonathan Ong, a senior analyst at Omdia, warned against the assumption that a valid token automatically implies legitimate activity. He suggested correlating activity across security domains to detect anomalies, such as tokens being used from unusual locations or at unexpected times.

To limit the impact of a potential compromise, Neil Shah of Counterpoint Research recommended using audience restrictions and cryptographically binding tokens to specific clients. The NIST report also points toward shared-signal mechanisms, such as the Continuous Access Evaluation Profile (CAEP) and Risk Incident Sharing and Coordination (RISC), to help connected systems respond dynamically to changing security conditions.

In DevOps environments, where credentials can be exposed in source code or automated pipelines, Shah argued that enterprises should move away from static tokens in favour of short-lived credentials.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.