NIST’s Agentic AI Profile Isn’t Published Yet — What to Build Against in the Meantime

Search for “the NIST AI RMF Agentic Profile” and you’ll find content confidently describing a document that, as of mid-2026, hasn’t actually been published. What NIST has done is announce, in February 2026, that one is coming — and the gap between what exists now and what’s promised for later is exactly where an organisation’s agentic AI governance needs to sit today.

The NIST AI Risk Management Framework — GOVERN, MAP, MEASURE, MANAGE — has become the de facto US reference point for AI governance since its 2023 release, extended in 2024 by the Generative AI Profile (NIST AI 600-1) for foundation-model-specific risks. Neither document was written with autonomous, tool-using, multi-step agents in mind, and both show it: agentic systems exhibit risk properties — goal drift across autonomous steps, cascading multi-agent failures, tool-use permission scope — that sit outside the conceptual frame either document was built around.

What’s actually been announced, and what hasn’t shipped

In February 2026, NIST’s Center for AI Standards and Innovation launched the AI Agent Standards Initiative, aimed at voluntary guidelines covering agent identity and authorisation, security and risk management, and monitoring and logging — precisely the gaps the base RMF and the GenAI Profile leave open for autonomous systems. As of this writing, an AI Agent Interoperability Profile is planned, not published, with NIST indicating a target release in the fourth quarter of 2026. Organisations building agentic governance programmes now are, necessarily, building against a framework that doesn’t yet fully exist for this specific case.

Free · 4 minutes

Do you know where AI is already being used in your business — and what it can see?

Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.

That’s a genuinely different position from waiting for AI Act guidance on a settled question, and it’s worth treating differently. The core RMF structure — Govern, Map, Measure, Manage — is stable and won’t be rebuilt when the agentic-specific profile lands; it will be extended. An organisation that maps its current agentic deployments against those four functions today, using the interim principles already visible in the standards community’s public work — agent identity and authorisation, prompt-injection resistance, supply-chain integrity for agent configurations, human oversight integration, and lifecycle accountability — is building a governance foundation that gets extended, not replaced, once the formal profile ships.

Building against a moving target without waiting for it to land

The practical approach is treating the current gap as scaffolding rather than paralysis. Apply the Map function specifically to an agent’s tool-integration surface, its authorisation scope, and its interactions with other agents — not just its base model and training data, which is where the standard RMF Map guidance stops short for agentic cases. Apply Measure and Manage against the same interim principles NIST’s own standards community is already publishing ahead of the formal profile, so the eventual official guidance is a formalisation of practice already in place, not a prompt to start from zero.

Treat February 2026’s initiative announcement as the signal, not the standard itself, and build now against the direction it points rather than the document it hasn’t yet produced.

The organisations that will find the eventual formal profile easiest to adopt are the ones already thinking in its terms — identity, authorisation, monitoring, lifecycle accountability — well before it’s published, not the ones who treated the gap as a reason to wait. Governance built ahead of the standard tends to look, in hindsight, remarkably close to what the standard eventually formalises.

This is also where the EU AI Act and the NIST framework genuinely complement rather than compete: NIST provides the operational how of agentic risk management, voluntary and evolving; the AI Act provides the mandatory what, for any agentic system that qualifies as high-risk under its own criteria. An organisation building agentic governance now needs both lenses simultaneously — the regulatory obligation that already exists under the AI Act where applicable, and the operational discipline NIST is actively formalising but hasn’t finished. Neither lens alone is sufficient, and treating either as optional because the other exists is a governance gap waiting to be found.

An organisation waiting for the formal NIST profile before starting agentic governance work is, in practice, deploying agents today with no governance framework at all and planning to retrofit one whenever NIST finishes — a plan that assumes the deployment stays small and low-risk in the meantime, which is rarely how agentic adoption actually goes once a pilot proves useful. The interim principles already visible in the standards community’s public work are enough to start against now, imperfect as they are, and imperfect governance built today is a stronger position than perfect governance planned for a date that keeps moving.

While the agentic-specific profile is pending, the base AI RMF still crosswalks usefully against other frameworks — see crosswalking AI RMF, ISO 42001 and CSF.

Building an agentic AI governance baseline now, against the interim principles already public rather than waiting for NIST’s formal Q4 2026 profile, is exactly the kind of forward-positioned work a technology control assessment can scope — so the eventual formal guidance extends what already exists rather than triggering a rebuild.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Governance is what happens when nobody is watching.

Policies are easy. Consistent decision-making is harder. Understand where governance exists and where it has quietly become assumed.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming