IA-9 Overlay: Identification and Authentication of Non-Person Actors in AI Systems
The candidate control list for NISTIR 8605B includes evidence controls (AC-16, AU-3, AU-10, AU-12, and SA-8(22)) that presuppose a binding between an action and an actor. No IA-family control on the candidate list defines how a non-person actor obtains an authenticated identity. AU-3 requires “the identity of the subject associated with the event,” but nothing on the list defines what that identifier is for an autonomous agent, who issues it, or how an assessor would test that it is authoritative. The consequence is vacuous non-repudiation: AU-10 asserted over a self-asserted subject is not weak evidence. It is a control with no testable assertion in it. An assessor running SP 800-53A procedures against the evidence controls as currently listed has no way to determine whether the actor identifier in a record is authoritative or self-asserted. Signed records with unverifiable subjects are weaker artifacts than they look. IA-9 (Service Identification and Authentication) is the natural home. Unlike AU-3(1) or CA-2(1), IA-9 is not inherited from the Moderate or High baselines, so the gap is real rather than assumed satisfied by baseline inheritance.
Authors
- Bradley B (ORCID: https://orcid.org/0009-0003-0688-4265)
- Thadi Murali (ORCID: https://orcid.org/0009-0008-7732-6021)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-29
- DOI
- https://doi.org/10.5281/zenodo.23069129
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00