Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • RECEIVERSHIPS—Senators revive bill to claw back executive pay when banks fail
    • BLOG TRACKER—Noteworthy blog posts and other commentary
    • CRIMES AND OFFENSES—Consumer Federation: Online scams cost Americans approximately $119 billion per year
    • ENFORCEMENT ACTIONS—Nonprofits oppose Colony Ridge settlement, argue proposed relief falls outside pleaded case
    • FINANCIAL TECHNOLOGY—Banking trades respond to NIST’s AI Agent Security RFI
    • PRUDENTIAL REGULATION—FDIC’s Hill details sweeping overhaul of supervisory and regulatory framework
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Banking and Finance Law Daily Wrap Up, FINANCIAL TECHNOLOGY—Banking trades respond to NIST’s AI Agent Security RFI, (Mar 12, 2026)

    Organizations Mentioned:American Bankers Association | Bank Policy Institute | Competitive Enterprise Institute | Federal Trade Commission | Independent Community Bankers of America

    By George M. Gullo, J.D.

    The groups urge NIST’s CAISI to issue voluntary, risk scaled guardrails to promote AI agent security.

    The National Institute of Standards and Technology’s (NIST) Center for AI Standards and Innovation (CAISI) opened a Request for Informa ...

    By George M. Gullo, J.D.

    The groups urge NIST’s CAISI to issue voluntary, risk scaled guardrails to promote AI agent security.

    The National Institute of Standards and Technology’s (NIST) Center for AI Standards and Innovation (CAISI) opened a Request for Information (RFI) on how to measure and improve the security of AI agent systems—systems that can take autonomous actions with real world effects. The notice narrowed the scope to agentic systems that affect “external state”; i.e., not ordinary chatbots or retrieval augmented generation without autonomous orchestration. The request sought concrete practices for bounding actions, assessing vulnerabilities, and monitoring deployment environments. Comments were due Mar. 9, 2026.

    Structure and scope. CAISI structured its questions across five domains: (1) threats, risks, and vulnerabilities; (2) security practices; (3) assessment methods and upstream transparency; (4) limiting and monitoring deployment environments; and (5) additional needs (e.g., research priorities and government collaboration). The RFI pointed to existing NIST resources—the Artificial Intelligence Risk Management Framework (AI RMF), an adversarial machine learning (ML) taxonomy, and NIST Special Publication (SP) 800 53 controls—while asking for agent specific gaps, including multi agent risks, patching/updating agents, and reversible “undoes, rollbacks, or negations” for unwanted action sequences.

    Banking and finance commenters. BITS (the technology policy arm of the Bank Policy Institute) and the American Bankers Association (ABA) urge CAISI to convene industry to produce a concise, voluntary, technology neutral package, which would entail a controlled sharing profile with risk scaled tiers, plus reference architectures and National Cybersecurity Center of Excellence (NCCoE) style practice guides for secure counterparty interactions and automated integrations. The intent is common terminology and baseline information elements that reduce duplicative reviews while preserving flexibility.

    Integration factsheet. The joint Bank Policy Institute/BITS–ABA comment proposes a “Foundational” tier built around an Agent Integration Factsheet (purpose, boundaries, permissions, oversight) and a “Data Dependency Label” (provenance, constraints, refresh cadence), with an “Enhanced” tier used when higher risk or complexity justifies more detail. Documentation would be exchanged through controlled channels rather than posted publicly by default.

    Community bank guardrails. The Independent Community Bankers of America (ICBA) recommends treating agents as a higher risk AI category because they act, not merely advise, and emphasize strong identity orchestration—“Know Your Agent” (KYA)—so institutions can identify which agent acted, what it was authorized to do, and who approved that authority. In its letter, ICBA stresses constrained by default deployments, clear vendor accountability, robust auditability and traceability, and practical undo/rollback processes to contain or remediate unwanted action sequences.

    Assessment and monitoring. ICBA also calls for scenario testing that mirrors operations (e.g., manipulation via emails, documents, or web content), attribution ready audit trails, and change management expectations for vendor delivered updates that might silently expand an agent’s authority. Monitoring should focus on observable outcomes—such as unusual access, abnormal volumes, deviations from expected workflows—and enable rapid containment.

    Policy enablers. The Competitive Enterprise Institute (CEI) underscores that antitrust uncertainty can chill collaborative security work on systemic agent vulnerabilities and urges inter agency alignment as the Department of Justice (DOJ) and the Federal Trade Commission (FTC) reassess competitor collaboration guidance. CEI also asks that the 2014 DOJ/FTC cybersecurity information sharing policy statement be modernized to cover agent specific artifacts (e.g., prompt injection patterns, poisoning signatures) and encourages regulatory sandboxes as controlled environments to test mitigations, including rollbacks.

    Threats and evolution. Commenters focus on the idea that agent risk is operational and real world. They point out that an unsafe action can resemble a legitimate automated step unless systems are designed for attribution and confined authority. Community banks stress manipulation of systems via untrusted inputs and the outsized blast radius in interconnected banking stacks, amplifying the RFI’s emphasis on prompt injection and backdoors with practical context about error reversibility and customer impact.

    Assessment transparency. The controlled sharing profile from the Bank Policy Institute/BITS–ABA submission offers downstream deployers a common vocabulary for what to exchange—purpose, access, data dependencies, safeguards—without exposing exploit enabling detail, while ICBA focuses assessments on whether actions are attributable, auditable, and stoppable in production. CEI’s antitrust alignment point could enable coordinated vulnerability disclosure and cross firm evaluations. Together, these submissions address the RFI’s questions about what to document, how to share it, and how to avoid disclosures that create new vulnerabilities.

    Additional considerations. The banking trade groups favor CAISI led, cross sector templates and NCCoE practice guides to create common language and reduce duplicative due diligence without creating de facto mandates. ICBA highlights standardized vendor transparency and change notification practices to manage third party dependency. Also, CEI points to inter agency antitrust alignment and experimentation via sandboxes. These proposals complement the RFI’s calls for research, collaboration, and international scanning by offering implementable artifacts and policy scaffolding.

    Implications for banks. CAISI indicated it may use the RFI to develop evaluation methods and technical guidelines and best practices specific to agent systems. If CAISI adopts the commenters’ suggestions, banks and counterparties could exchange a concise agent assurance packet via controlled channels, backed by machine to machine credentials, attribution ready logs, and clear stop controls. The model would streamline third party reviews while centering oversight on bounded delegation, auditability, and rapid containment—principles already familiar to model risk, third party risk, cybersecurity and information risk management, and operations/information technology teams.

    Companies: American Bankers Association; Bank Policy Institute; Competitive Enterprise Institute; Independent Community Bankers of America

    RegulatoryActivity: AINews BankingOperations FinancialIntermediaries FinTech

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use