Who this is for: Security engineers and ISSMs extending existing 800-53 baselines to cover AI workloads, FedRAMP and RMF authorization teams preparing for AI-specific control overlays, assessors evaluating AI system security within federal environments, and architects integrating adversarial ML defenses into production AI pipelines.

Critical Assessor Notice: Boundaries of Cryptographic Evidence

SWT3 witness anchors prove that specific operational controls were active at a specific point in time. They do not replace the assessor's independent judgment, professional expertise, or regulatory authority. Assessors must verify that anchored evidence is sufficient, appropriate, and relevant to the specific assessment context. Each regulatory framework retains its own assessment authority, methodology, and determination standards.

Zero Draft Released July 29, 2026. NIST published the COSAiS zero draft on July 29, 2026. Public comment is open until September 16, 2026. This guide has been updated to reflect the zero draft content. Organizations operating under SP 800-53 Rev. 5 should submit comments during this window and begin aligning AI-specific control implementations with the draft overlay guidance.

1. Quick Reference

Full NameControl Overlays for Securing AI Systems (COSAiS)
AuthorityNIST (National Institute of Standards and Technology)
StatusZero draft published July 29, 2026. Public comment open until September 16, 2026.
Reference URLcsrc.nist.gov/Projects/cosais
ScopeAI-specific overlays for SP 800-53 Rev. 5 security and privacy controls
Use CasesPredictive AI (zero draft), Generative AI (zero draft), Single-agent AI, Multi-agent AI, AI developer security (planned)
IntegratesSP 800-53 Rev. 5, AI RMF (AI 100-1), Adversarial ML taxonomy, OWASP Agentic AI threats
SWT3 Procedures Mapped15 primary mappings across 9 control families

Contents

1. Quick Reference 2. What is COSAiS 3. Draft Status Note 4. Control Families Enhanced by COSAiS 5. SWT3 Procedure Mapping 6. Procedure Detail Cards 7. Why This Matters 8. SDK Example 9. Related Guides

2. What is COSAiS

Control Overlays for Securing AI Systems (COSAiS) is a NIST initiative that adapts the SP 800-53 Rev. 5 security and privacy control catalog to address risks unique to artificial intelligence. Rather than creating an entirely new control framework, COSAiS builds on the existing 800-53 baseline by defining AI-specific enhancements, parameter guidance, and supplemental controls for each relevant control family.

The project integrates guidance from multiple NIST publications into a cohesive overlay structure:

COSAiS addresses five use cases: Predictive AI (classical ML systems, included in the zero draft), Generative AI (large language models, diffusion models, and multimodal systems, included in the zero draft), Single-agent AI, Multi-agent AI systems, and AI developer security (planned). Each overlay specifies which 800-53 controls require AI-specific parameters, supplemental guidance, or entirely new control enhancements.

Relationship to SP 800-53

COSAiS does not replace SP 800-53. It operates as an overlay, meaning organizations that have already implemented 800-53 baselines can layer the AI-specific guidance on top of their existing controls. For each targeted control, the overlay may specify: additional parameters (e.g., frequency of model integrity checks), supplemental guidance for AI contexts (e.g., how SI-07 applies to model weights rather than firmware), or new control enhancements specific to machine learning pipelines.

This layered approach is particularly valuable for federal agencies and FedRAMP-authorized systems that are adding AI capabilities to existing ATOs. The overlay provides a structured path to extend authorization boundaries without rebuilding the entire control baseline.

3. Draft Status Note

Public Comment Open. The COSAiS zero draft was published on July 29, 2026. NIST is accepting public comments until September 16, 2026. The control family mappings and SWT3 procedure alignments in this guide are based on the zero draft content, published outline, and the known integration points with SP 800-53 Rev. 5. These mappings will be refined as NIST incorporates public feedback and publishes the final overlay specifications. Submit comments via the NIST COSAiS project page or through the NIST Slack collaboration channel.

4. Key 800-53 Control Families Enhanced by COSAiS

COSAiS targets specific SP 800-53 Rev. 5 control families where AI systems introduce risks not adequately addressed by the baseline controls. The following table summarizes the families, the specific controls identified for AI-specific overlay guidance, and the focus area for each.

Family Controls AI-Specific Focus
SI (System & Info Integrity) SI-03, SI-04, SI-07, SI-10, SI-12, SI-15, SI-17, SI-18, SI-19, SI-23 Model integrity, adversarial robustness, contamination detection, input validation
CA (Security Assessment) CA-03, CA-07, CA-08 Model evaluation, adversarial testing, supply chain assessment
RA (Risk Assessment) RA-03, RA-05 AI-specific risk analysis, threat modeling
SC (System & Comms Protection) SC-05, SC-07, SC-23, SC-28, SC-32, SC-43 Model transport security, inference channel protection
SR (Supply Chain Risk) SR-04, SR-11 Model sourcing, dependency validation, weights verification
AU (Audit & Accountability) AU-02, AU-06 Inference audit trails, model decision logging
CM (Configuration Management) CM-02, CM-03, CM-04, CM-05, CM-06 Model versioning, deployment integrity, change control
AC (Access Control) AC-03, AC-06, AC-22, AC-39 Model access, inference authorization
SA (System & Services Acquisition) SA-08, SA-11, SA-15, SA-17 Secure SDLC for AI/ML pipelines

5. SWT3 Procedure Mapping

Each COSAiS-enhanced control maps to one or more SWT3 witness procedures. When an organization deploys the SWT3 protocol alongside their 800-53 baseline, these procedures generate cryptographic evidence that the AI-specific control requirements are being met at runtime.

COSAiS Control 800-53 Family SWT3 Procedure What It Witnesses
SI-07 (Software/Firmware Integrity) SI AI-GRD.1 Guardrail integrity verification
SI-04 (System Monitoring) SI AI-DRIFT.1, AI-DRIFT.2 Model drift detection and threshold monitoring
SI-10 (Information Input Validation) SI AI-GRD.2 Content safety filter (input validation)
SI-19 (Data Quality) SI AI-DATA.3 Data quality assurance
CA-08 (Penetration Testing) CA AI-REDTEAM.1 Adversarial testing results
CA-07 (Continuous Monitoring) CA AI-PERF.1 Performance monitoring
RA-03 (Risk Assessment) RA AI-RISK.1 Risk quantification
RA-05 (Vulnerability Monitoring) RA AI-CYBER.1 Vulnerability assessment
SR-04 (Provenance) SR AI-SUPPLY.1 Model supply chain provenance
SR-11 (Component Authenticity) SR AI-MDL.5 Model weights hash verification
AU-02 (Event Logging) AU AI-LOG.1 Inference audit trail
CM-03 (Configuration Change Control) CM AI-MDL.6 Adapter stack versioning
CM-05 (Access Restrictions for Change) CM AI-ACC.1 Access control for model changes
AC-06 (Least Privilege) AC AI-ACC.1 Inference authorization
SC-28 (Protection of Information at Rest) SC AI-SEC.1 Model encryption at rest

6. Procedure Detail Cards

The following cards show how specific SWT3 procedures map to COSAiS-enhanced controls. Each card includes the control context, the evidence the procedure generates, and assessor guidance for FedRAMP and RMF environments.

AI-GRD.1 → SI-07 (Software, Firmware, and Information Integrity)

Guardrail Integrity Verification

COSAiS context: SI-07 under the AI overlay extends beyond traditional software and firmware integrity to cover model weights, guardrail configurations, and inference pipeline components. The overlay requires organizations to verify that safety guardrails have not been tampered with, bypassed, or degraded between deployments.

What AI-GRD.1 witnesses: Each inference request passes through a guardrail check. The SWT3 anchor records whether the guardrail was active, which version was loaded, and whether the input or output was flagged. This creates a per-inference integrity trail that maps directly to SI-07 assessment objectives.

Sample anchor: SWT3-E-VULTR-AI-GRD1-PASS-1723305600-a1b2c3d4e5f6

Assessor Tip

In FedRAMP environments, SI-07 already requires integrity verification mechanisms. When evaluating AI workloads, request the SWT3 anchor stream for AI-GRD.1 and confirm that guardrail versions are consistent across deployment boundaries. A gap between the guardrail version in the anchor and the version in the CM baseline indicates a configuration drift finding.

AI-DRIFT.1 → SI-04 (System Monitoring)

Model Drift Detection

COSAiS context: SI-04 under the AI overlay extends system monitoring to include model behavioral drift, performance degradation, and distribution shift detection. Traditional monitoring tools do not detect when a model's output distribution changes over time, which the overlay treats as a system integrity concern.

What AI-DRIFT.1 witnesses: The procedure records drift metrics at configurable intervals, capturing statistical measures of output distribution change, confidence score trends, and threshold exceedances. AI-DRIFT.2 adds consequence-mapped thresholds that link drift severity to operational impact categories.

Sample anchor: SWT3-E-VULTR-AI-DRIFT1-PASS-1723305600-f6e5d4c3b2a1

Assessor Tip

For RMF packages, SI-04 continuous monitoring evidence should include drift trend data alongside traditional IDS/SIEM logs. Request the AI-DRIFT.1 anchor history and look for threshold breach patterns. If AI-DRIFT.2 is also deployed, verify that consequence mappings align with the system's FIPS 199 impact level.

AI-SUPPLY.1 → SR-04 (Provenance)

Model Supply Chain Provenance

COSAiS context: SR-04 under the AI overlay addresses the provenance of pre-trained models, fine-tuning datasets, and third-party model components. Unlike traditional software supply chain controls that focus on code repositories and build pipelines, the AI overlay requires organizations to document the origin, training lineage, and modification history of model artifacts.

What AI-SUPPLY.1 witnesses: The procedure records the model source (registry, organization, version), any fine-tuning applied, and the hash of the model artifact at the point of deployment. This creates a verifiable chain from model origin through deployment that satisfies SR-04 provenance requirements.

Sample anchor: SWT3-E-VULTR-AI-SUPPLY1-PASS-1723305600-c3d4e5f6a1b2

Assessor Tip

In FedRAMP High and Moderate baselines, SR-04 provenance requirements are already mandatory. For AI workloads, verify that AI-SUPPLY.1 anchors include the model registry source and artifact hash. Cross-reference these hashes against the organization's approved model inventory. Any model deployed without a matching AI-SUPPLY.1 anchor represents an undocumented supply chain dependency.

AI-REDTEAM.1 → CA-08 (Penetration Testing)

Adversarial Testing Results

COSAiS context: CA-08 under the AI overlay extends penetration testing to include adversarial ML attacks: prompt injection, model evasion, data poisoning, model extraction, and membership inference. The overlay draws on the NIST Adversarial ML taxonomy and OWASP Agentic AI threat models to define the scope of adversarial testing requirements.

What AI-REDTEAM.1 witnesses: The procedure records adversarial test campaigns, including the attack types exercised, the success/failure rate of each attack, and the remediation status of identified vulnerabilities. Each test campaign mints an anchor that links the test results to the model version and deployment environment.

Sample anchor: SWT3-E-VULTR-AI-REDTEAM1-PASS-1723305600-b2a1f6e5d4c3

Assessor Tip

CA-08 penetration testing in RMF and FedRAMP contexts already requires annual or event-driven testing. For AI systems, verify that the AI-REDTEAM.1 anchor stream covers the adversarial attack categories relevant to the system's threat model. At minimum, expect evidence of prompt injection testing for generative AI systems and evasion testing for predictive AI systems. Cross-reference test dates with model deployment dates to confirm testing occurred before production release.

7. Why This Matters

Organizations operating under SP 800-53 Rev. 5 already have a mature control baseline. Adding AI capabilities to those systems introduces risks that the existing controls were not designed to address: model tampering, training data poisoning, adversarial evasion, inference side-channel attacks, and autonomous agent behavior. COSAiS provides the structured path to extend existing baselines rather than building parallel governance from scratch.

For FedRAMP and RMF Authorization

Federal agencies and cloud service providers adding AI features to authorized systems face a practical challenge: how to document AI-specific controls within the existing SSP structure. COSAiS overlays map directly to 800-53 control families, which means the AI-specific enhancements slot into the same control descriptions, assessment procedures, and continuous monitoring plans that assessors already evaluate. SWT3 procedures generate the runtime evidence that populates those control narratives with verifiable data.

For Organizations with Existing 800-53 Baselines

If your organization already maintains an 800-53 baseline, COSAiS is not a new framework to adopt. It is a set of AI-specific parameters and enhancements that layer on top of what you already have. The SWT3 procedure mapping in this guide identifies exactly which procedures generate evidence for each enhanced control, allowing security teams to deploy targeted witnessing without disrupting existing control implementations.

For Assessors Evaluating AI Systems

Third-party assessors and C3PAOs evaluating AI workloads within FedRAMP or RMF boundaries can use the procedure mapping table as a checklist. Each SWT3 procedure corresponds to a specific 800-53 control enhancement, and each anchor provides cryptographically verifiable evidence of control operation. This transforms AI governance assessment from interview-based evaluation to evidence-based verification.

8. SDK Example

The following Python example demonstrates how to generate SWT3 witness evidence for COSAiS-aligned controls. This snippet witnesses a guardrail integrity check (AI-GRD.1), which maps to the SI-07 overlay enhancement.

from swt3_ai import Witness

w = Witness(
    tenant="YOUR_TENANT",
    signing_key="YOUR_HMAC_KEY",
    agent_id="cosais-guardrail-agent"
)

# Witness guardrail integrity (SI-07 overlay)
anchor = w.witness(
    procedure="AI-GRD.1",
    model_id="gpt-4o-2024-08-06",
    factor_a="guardrail_version=v2.4.1",
    factor_b="input_flagged=false",
    factor_c="output_flagged=false",
    verdict="PASS"
)

print(f"COSAiS SI-07 evidence: {anchor.fingerprint}")
# SWT3-E-VULTR-AI-GRD1-PASS-1723305600-a1b2c3d4e5f6

For TypeScript, Rust, C#, Ruby, and Swift SDK examples, see the SDK documentation. All seven SDKs produce cross-language-compatible fingerprints using the same locked formula.