← All Articles

Your NIST 800-53 Controls Already Cover AI Agents — The Complete Mapping

February 19, 2026 · 10 min read
1,189
total controls
47
apply to AI agents
14
control families
4
trust boundaries

The Four Trust Boundaries

Zone 1 — Human Zone

Governance, authorisation, user intent. Controls: AC-3, AC-6, AU-2, AU-3, PM-9

Zone 2 — Agent Execution

Isolated environment. Controls: SC-39, CM-7, SC-4, SC-28, SI-3

Zone 3 — Enterprise Systems

IAM for non-human identities. Controls: IA-8, IA-2, AC-2, SC-7, SI-10

Zone 4 — AI Model Provider

Supply chain security. Controls: SA-12, SA-9, SR-3, SC-7, SC-8

Control Family Mapping

Family Controls Zone
AC (Access Control)AC-2, AC-3, AC-4, AC-5, AC-6, AC-17, AC-201, 3
AU (Audit)AU-2, AU-3, AU-6, AU-12All
CM (Configuration)CM-2, CM-3, CM-7, CM-82
IA (Identification)IA-2, IA-4, IA-5, IA-82, 3
SC (System & Comms)SC-4, SC-7, SC-8, SC-12, SC-13, SC-28, SC-392, 3, 4
SI (Integrity)SI-3, SI-4, SI-5, SI-102, 3
SR (Supply Chain)SR-2, SR-3, SR-54
SA (Acquisition)SA-4, SA-9, SA-124
Key insight: AI agents aren’t a new category of risk. They’re a new surface for existing categories of risk. Leverage established frameworks rather than adopting new ones.

Implementation

  1. Inventory all AI agents, capabilities, data access, and trust boundary crossings
  2. Gap Analysis — Map existing controls against AI agent requirements
  3. Extend Controls — Update policies, configure IAM for non-human identities
  4. Monitor & Iterate — Establish continuous monitoring for behavioural anomalies

Need help implementing this?

First strategy session is complimentary. We typically respond within 4 hours.