Agent security standards and regulation
A source-led map of how agent identity, delegation, runtime decisions and evidence relate to technical guidance and applicable obligations.
Read with care
Separate control design from compliance.
Standards, draft material, voluntary frameworks and binding laws have different force. Each reference below states one control implication and the remaining customer obligation. Product controls can support evidence; they do not confer certification or guarantee compliance.
01 / Architectural guidance
Architectural guidance
NIST AI RMF and agent authorityHow can agent action controls support AI risk management?NIST SP 800-207 zero trust for agentsHow do zero-trust concepts apply to an agent action?NIST agent identity concept paperWhat identity and authorization questions does NIST raise for software agents?OWASP Agent Control StandardWhat does an agent control hook need to enforce?MCP authorization specificationWhat does MCP transport authorization establish?MITRE ATLAS for agent threatsHow should an agent authority threat model use ATLAS?NSA MCP security guidanceWhere should MCP guidance affect agent tool architecture?
02 / Regulatory and assurance context
Regulatory and assurance context
PCI DSS and payment agentsWhat evidence matters when agents touch a cardholder-data environment?HIPAA and healthcare agentsWhat changes when an agent accesses electronic PHI?DORA and financial agentsHow does autonomous action affect ICT operational resilience?NIS2 and critical infrastructure agentsWhere do agent controls fit NIS2 cyber-risk measures?EU AI Act and agent controlsWhen are agent action logs relevant under the AI Act?GDPR and autonomous processingWhat must an agent preserve when processing personal data?FedRAMP and agent servicesWhat does an agent service need within a federal cloud authorization boundary?CMMC and defense agentsHow should agent access to CUI be scoped?
03 / National guidance
National guidance
Architecture discussion