Design Partner ProgramWe're accepting applications for the next cohort of design partners in finance, insurance, healthcare, and HR. Apply now →

meilynx

Reference · Cybersecurity

NIST SP 800-53 and AI Systems: What an Assessor Asks About AI Traffic

The control catalog, applied to AI models, agents and their tools

Last reviewed October 7, 2026

At a glance

Current release
SP 800-53 Release 5.2.0 (27 August 2025)
AI overlays
Drafts only; none final
FIPS 140-2
Historical list since 22 September 2026

NIST SP 800-53 Rev. 5 is the security and privacy control catalog behind federal system assessments, FedRAMP and many organizations' own control sets. It names no AI technology, and its controls apply to a system that calls a language model or runs an agent the same way they apply to any other component.SP 800-53 Rev. 5

When AI enters an assessed system, the questions concentrate in seven families: who may call which model or tool, what is logged and how it is protected, what changed and who approved it, and what crosses the boundary.

The catalog applies to AI traffic as written

Rev. 5 was published on 23 September 2020 and is maintained as numbered releases; Release 5.2.0, issued on 27 August 2025, added controls on software updates and patch integrity.Release 5.2.0 The baselines that select controls for Low, Moderate and High impact systems sit in a companion publication, SP 800-53B.SP 800-53B

A call from an application to a model provider is a connection to an external system, a prompt that carries personal data is an information flow, and an agent's tool call is the use of a function by a process acting for a user. Each already has a control.

Seven families carry most of the evidence

The mapping below is our reading of where AI traffic meets the catalog. The control text is NIST's.SP 800-53 Rev. 5

FamilyWhat an assessor asks about AI trafficEvidence that answers it
AC: Access ControlWhich models and tools each user, service and agent may call, and how a refused call is handled (AC-3, AC-4, AC-6)Allowlists in force and the refusals they produced
AU: Audit and AccountabilityWhich AI events are logged, what each record holds, and how records are protected and retained (AU-2, AU-3, AU-9, AU-11)The record itself, an integrity check over it, and the retention setting
CM: Configuration ManagementThe approved configuration of prompts, tools and models, and the record of changes to it (CM-2, CM-3, CM-8)A versioned baseline, a change log with approvers, a component inventory
IA: Identification and AuthenticationHow agents and services are identified before they act (IA-2, IA-5, IA-9)Credential issue and rotation records per agent
SC: System and Communications ProtectionWhich external AI services are reachable, over what transport, and with which cryptography (SC-7, SC-8, SC-13, SC-28)The boundary configuration and the cryptographic module for each use
SI: System and Information IntegrityHow prompts, responses and tool payloads are monitored and filtered (SI-4, SI-10, SI-15)Detection findings and output filtering records
SR: Supply Chain Risk ManagementWhich model providers and tool servers the system depends on (SR-3)A supplier inventory drawn from what actually runs
Control identifiers from NIST SP 800-53 Rev. 5; the questions and evidence are our reading. NIST SP 800-53 Rev. 5

NIST is writing AI overlays, and the base catalog applies until they land

NIST's Control Overlays for Securing AI Systems project adapts SP 800-53 controls to five AI use cases, including generative AI assistants and single-agent and multi-agent systems. A concept paper opened for comment on 14 August 2025, and an annotated outline for the predictive AI overlay followed on 8 January 2026.NIST AI overlays

No overlay is final as of this page's review date. An assessment today applies the base catalog and its baselines.

FedRAMP is moving to automated validation

FedRAMP 20x is in its third phase, with the pilots closed and the program describing it as the lasting path. FedRAMP will stop accepting new Rev5 certifications on 11 June 2027.FedRAMP 20x Under 20x, providers demonstrate security outcomes through automation-based validation, so evidence a system produces on its own carries further than evidence assembled by hand.

FIPS 140-3 is the only active validation

Every FIPS 140-2 certificate moved to the Cryptographic Module Validation Program's historical list on 22 September 2026, and FIPS 140-3 has been the validation standard since its effective date of 22 September 2019.FIPS 140-3 transition

SC-13 asks a system to implement the cryptography each use requires.SP 800-53 Rev. 5 · SC-13 For a system that sends prompts to a model and keeps records of them, that means the TLS connection, the integrity hashing of the records and any encryption at rest, each traced to the module that performs it.

Key dates

Timeline, drawn to scale

NIST SP 800-53, FIPS 140 and FedRAMP: the dates that move an AI assessment

In effect as of October 7, 2026UpcomingChanges in 2026 and 2027
202120222023202420252026202723 SEP 2020Rev. 5 published27 AUG 2025Release 5.2.022 SEP 2026FIPS 140-2 historical11 JUN 2027No new FedRAMP Rev5
Dates from NIST CSRC, the FIPS 140-3 transition page and FedRAMP 20x. Status as of October 7, 2026.
  • 22 September 2019FIPS 140-3 takes effect.
  • 23 September 2020NIST SP 800-53 Rev. 5 published.
  • 14 August 2025Concept paper for SP 800-53 control overlays for securing AI systems opens for comment.
  • 27 August 2025SP 800-53 Release 5.2.0 issued, adding software update and patch integrity controls.
  • 8 January 2026Annotated outline of the predictive AI overlay released for discussion.
  • 22 September 2026All FIPS 140-2 certificates placed on the historical list.
  • 11 June 2027FedRAMP stops accepting new Rev5 certifications.

Sources cited

Common gaps

Where AI components most often fall outside an assessment's evidence.

  • AI calls left out of the boundary diagram. A model provider an application calls is an external connection. When it is missing from the boundary and the interconnection records, SC-7 and CA-3 findings follow.
  • Application logs standing in for audit records. Debug logs rarely carry the identity, the outcome and the policy in force for each AI call, and they are usually mutable. AU-3 and AU-9 ask for both content and protection.
  • Prompts and tool grants outside configuration control. A system prompt or an agent's tool list changes the system's behaviour. When neither has a baseline or an approver, CM-3 has nothing to test.
  • Agents acting on a shared key. When every agent calls with the same application key, no record can say which agent acted. IA-9 and AU-10 both depend on a per-agent identity.
  • Cryptographic uses with no certificate behind them. An assessor checks each cryptographic use against an active validation. Since 22 September 2026 that means a FIPS 140-3 certificate.

Last reviewed October 7, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.