Reference · Cybersecurity
NIST SP 800-53 and AI Systems: What an Assessor Asks About AI Traffic
The control catalog, applied to AI models, agents and their tools
At a glance
- Current release
- SP 800-53 Release 5.2.0 (27 August 2025)
- AI overlays
- Drafts only; none final
- FIPS 140-2
- Historical list since 22 September 2026
NIST SP 800-53 Rev. 5 is the security and privacy control catalog behind federal system assessments, FedRAMP and many organizations' own control sets. It names no AI technology, and its controls apply to a system that calls a language model or runs an agent the same way they apply to any other component.SP 800-53 Rev. 5
When AI enters an assessed system, the questions concentrate in seven families: who may call which model or tool, what is logged and how it is protected, what changed and who approved it, and what crosses the boundary.
The catalog applies to AI traffic as written
Rev. 5 was published on 23 September 2020 and is maintained as numbered releases; Release 5.2.0, issued on 27 August 2025, added controls on software updates and patch integrity.Release 5.2.0 The baselines that select controls for Low, Moderate and High impact systems sit in a companion publication, SP 800-53B.SP 800-53B
A call from an application to a model provider is a connection to an external system, a prompt that carries personal data is an information flow, and an agent's tool call is the use of a function by a process acting for a user. Each already has a control.
Seven families carry most of the evidence
The mapping below is our reading of where AI traffic meets the catalog. The control text is NIST's.SP 800-53 Rev. 5
| Family | What an assessor asks about AI traffic | Evidence that answers it |
|---|---|---|
| AC: Access Control | Which models and tools each user, service and agent may call, and how a refused call is handled (AC-3, AC-4, AC-6) | Allowlists in force and the refusals they produced |
| AU: Audit and Accountability | Which AI events are logged, what each record holds, and how records are protected and retained (AU-2, AU-3, AU-9, AU-11) | The record itself, an integrity check over it, and the retention setting |
| CM: Configuration Management | The approved configuration of prompts, tools and models, and the record of changes to it (CM-2, CM-3, CM-8) | A versioned baseline, a change log with approvers, a component inventory |
| IA: Identification and Authentication | How agents and services are identified before they act (IA-2, IA-5, IA-9) | Credential issue and rotation records per agent |
| SC: System and Communications Protection | Which external AI services are reachable, over what transport, and with which cryptography (SC-7, SC-8, SC-13, SC-28) | The boundary configuration and the cryptographic module for each use |
| SI: System and Information Integrity | How prompts, responses and tool payloads are monitored and filtered (SI-4, SI-10, SI-15) | Detection findings and output filtering records |
| SR: Supply Chain Risk Management | Which model providers and tool servers the system depends on (SR-3) | A supplier inventory drawn from what actually runs |
NIST is writing AI overlays, and the base catalog applies until they land
NIST's Control Overlays for Securing AI Systems project adapts SP 800-53 controls to five AI use cases, including generative AI assistants and single-agent and multi-agent systems. A concept paper opened for comment on 14 August 2025, and an annotated outline for the predictive AI overlay followed on 8 January 2026.NIST AI overlays
No overlay is final as of this page's review date. An assessment today applies the base catalog and its baselines.
FedRAMP is moving to automated validation
FedRAMP 20x is in its third phase, with the pilots closed and the program describing it as the lasting path. FedRAMP will stop accepting new Rev5 certifications on 11 June 2027.FedRAMP 20x Under 20x, providers demonstrate security outcomes through automation-based validation, so evidence a system produces on its own carries further than evidence assembled by hand.
FIPS 140-3 is the only active validation
Every FIPS 140-2 certificate moved to the Cryptographic Module Validation Program's historical list on 22 September 2026, and FIPS 140-3 has been the validation standard since its effective date of 22 September 2019.FIPS 140-3 transition
SC-13 asks a system to implement the cryptography each use requires.SP 800-53 Rev. 5 · SC-13 For a system that sends prompts to a model and keeps records of them, that means the TLS connection, the integrity hashing of the records and any encryption at rest, each traced to the module that performs it.
Key dates
Timeline, drawn to scale
NIST SP 800-53, FIPS 140 and FedRAMP: the dates that move an AI assessment
- 22 September 2019FIPS 140-3 takes effect.
- 23 September 2020NIST SP 800-53 Rev. 5 published.
- 14 August 2025Concept paper for SP 800-53 control overlays for securing AI systems opens for comment.
- 27 August 2025SP 800-53 Release 5.2.0 issued, adding software update and patch integrity controls.
- 8 January 2026Annotated outline of the predictive AI overlay released for discussion.
- 22 September 2026All FIPS 140-2 certificates placed on the historical list.
- 11 June 2027FedRAMP stops accepting new Rev5 certifications.
Sources cited
- ×3NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations
- ×1NIST news: SP 800-53 Release 5.2.0 (27 August 2025)
- ×1NIST SP 800-53B, Control Baselines for Information Systems and Organizations
- ×1NIST: SP 800-53 Control Overlays for Securing AI Systems
- ×1FedRAMP 20x
- ×1NIST CMVP: FIPS 140-3 transition
Common gaps
Where AI components most often fall outside an assessment's evidence.
- AI calls left out of the boundary diagram. A model provider an application calls is an external connection. When it is missing from the boundary and the interconnection records, SC-7 and CA-3 findings follow.
- Application logs standing in for audit records. Debug logs rarely carry the identity, the outcome and the policy in force for each AI call, and they are usually mutable. AU-3 and AU-9 ask for both content and protection.
- Prompts and tool grants outside configuration control. A system prompt or an agent's tool list changes the system's behaviour. When neither has a baseline or an approver, CM-3 has nothing to test.
- Agents acting on a shared key. When every agent calls with the same application key, no record can say which agent acted. IA-9 and AU-10 both depend on a per-agent identity.
- Cryptographic uses with no certificate behind them. An assessor checks each cryptographic use against an active validation. Since 22 September 2026 that means a FIPS 140-3 certificate.
In practice
Last reviewed October 7, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.