Control Overlays for Securing AI Systems: SP 800-53 Rev. 5 controls adapted for AI-specific risks in data, models, and agentic systems.
Who this is for: Security engineers and ISSMs extending existing 800-53 baselines to cover AI workloads, FedRAMP and RMF authorization teams preparing for AI-specific control overlays, assessors evaluating AI system security within federal environments, and architects integrating adversarial ML defenses into production AI pipelines.
Critical Assessor Notice: Boundaries of Cryptographic Evidence
SWT3 witness anchors prove that specific operational controls were active at a specific point in time. They do not replace the assessor's independent judgment, professional expertise, or regulatory authority. Assessors must verify that anchored evidence is sufficient, appropriate, and relevant to the specific assessment context. Each regulatory framework retains its own assessment authority, methodology, and determination standards.
Zero Draft Released July 29, 2026. NIST published the COSAiS zero draft on July 29, 2026. Public comment is open until September 16, 2026. This guide has been updated to reflect the zero draft content. Organizations operating under SP 800-53 Rev. 5 should submit comments during this window and begin aligning AI-specific control implementations with the draft overlay guidance.
| Full Name | Control Overlays for Securing AI Systems (COSAiS) |
| Authority | NIST (National Institute of Standards and Technology) |
| Status | Zero draft published July 29, 2026. Public comment open until September 16, 2026. |
| Reference URL | csrc.nist.gov/Projects/cosais |
| Scope | AI-specific overlays for SP 800-53 Rev. 5 security and privacy controls |
| Use Cases | Predictive AI (zero draft), Generative AI (zero draft), Single-agent AI, Multi-agent AI, AI developer security (planned) |
| Integrates | SP 800-53 Rev. 5, AI RMF (AI 100-1), Adversarial ML taxonomy, OWASP Agentic AI threats |
| SWT3 Procedures Mapped | 15 primary mappings across 9 control families |
Control Overlays for Securing AI Systems (COSAiS) is a NIST initiative that adapts the SP 800-53 Rev. 5 security and privacy control catalog to address risks unique to artificial intelligence. Rather than creating an entirely new control framework, COSAiS builds on the existing 800-53 baseline by defining AI-specific enhancements, parameter guidance, and supplemental controls for each relevant control family.
The project integrates guidance from multiple NIST publications into a cohesive overlay structure:
COSAiS addresses five use cases: Predictive AI (classical ML systems, included in the zero draft), Generative AI (large language models, diffusion models, and multimodal systems, included in the zero draft), Single-agent AI, Multi-agent AI systems, and AI developer security (planned). Each overlay specifies which 800-53 controls require AI-specific parameters, supplemental guidance, or entirely new control enhancements.
COSAiS does not replace SP 800-53. It operates as an overlay, meaning organizations that have already implemented 800-53 baselines can layer the AI-specific guidance on top of their existing controls. For each targeted control, the overlay may specify: additional parameters (e.g., frequency of model integrity checks), supplemental guidance for AI contexts (e.g., how SI-07 applies to model weights rather than firmware), or new control enhancements specific to machine learning pipelines.
This layered approach is particularly valuable for federal agencies and FedRAMP-authorized systems that are adding AI capabilities to existing ATOs. The overlay provides a structured path to extend authorization boundaries without rebuilding the entire control baseline.
Public Comment Open. The COSAiS zero draft was published on July 29, 2026. NIST is accepting public comments until September 16, 2026. The control family mappings and SWT3 procedure alignments in this guide are based on the zero draft content, published outline, and the known integration points with SP 800-53 Rev. 5. These mappings will be refined as NIST incorporates public feedback and publishes the final overlay specifications. Submit comments via the NIST COSAiS project page or through the NIST Slack collaboration channel.
COSAiS targets specific SP 800-53 Rev. 5 control families where AI systems introduce risks not adequately addressed by the baseline controls. The following table summarizes the families, the specific controls identified for AI-specific overlay guidance, and the focus area for each.
| Family | Controls | AI-Specific Focus |
|---|---|---|
| SI (System & Info Integrity) | SI-03, SI-04, SI-07, SI-10, SI-12, SI-15, SI-17, SI-18, SI-19, SI-23 | Model integrity, adversarial robustness, contamination detection, input validation |
| CA (Security Assessment) | CA-03, CA-07, CA-08 | Model evaluation, adversarial testing, supply chain assessment |
| RA (Risk Assessment) | RA-03, RA-05 | AI-specific risk analysis, threat modeling |
| SC (System & Comms Protection) | SC-05, SC-07, SC-23, SC-28, SC-32, SC-43 | Model transport security, inference channel protection |
| SR (Supply Chain Risk) | SR-04, SR-11 | Model sourcing, dependency validation, weights verification |
| AU (Audit & Accountability) | AU-02, AU-06 | Inference audit trails, model decision logging |
| CM (Configuration Management) | CM-02, CM-03, CM-04, CM-05, CM-06 | Model versioning, deployment integrity, change control |
| AC (Access Control) | AC-03, AC-06, AC-22, AC-39 | Model access, inference authorization |
| SA (System & Services Acquisition) | SA-08, SA-11, SA-15, SA-17 | Secure SDLC for AI/ML pipelines |
Each COSAiS-enhanced control maps to one or more SWT3 witness procedures. When an organization deploys the SWT3 protocol alongside their 800-53 baseline, these procedures generate cryptographic evidence that the AI-specific control requirements are being met at runtime.
| COSAiS Control | 800-53 Family | SWT3 Procedure | What It Witnesses |
|---|---|---|---|
| SI-07 (Software/Firmware Integrity) | SI | AI-GRD.1 |
Guardrail integrity verification |
| SI-04 (System Monitoring) | SI | AI-DRIFT.1, AI-DRIFT.2 |
Model drift detection and threshold monitoring |
| SI-10 (Information Input Validation) | SI | AI-GRD.2 |
Content safety filter (input validation) |
| SI-19 (Data Quality) | SI | AI-DATA.3 |
Data quality assurance |
| CA-08 (Penetration Testing) | CA | AI-REDTEAM.1 |
Adversarial testing results |
| CA-07 (Continuous Monitoring) | CA | AI-PERF.1 |
Performance monitoring |
| RA-03 (Risk Assessment) | RA | AI-RISK.1 |
Risk quantification |
| RA-05 (Vulnerability Monitoring) | RA | AI-CYBER.1 |
Vulnerability assessment |
| SR-04 (Provenance) | SR | AI-SUPPLY.1 |
Model supply chain provenance |
| SR-11 (Component Authenticity) | SR | AI-MDL.5 |
Model weights hash verification |
| AU-02 (Event Logging) | AU | AI-LOG.1 |
Inference audit trail |
| CM-03 (Configuration Change Control) | CM | AI-MDL.6 |
Adapter stack versioning |
| CM-05 (Access Restrictions for Change) | CM | AI-ACC.1 |
Access control for model changes |
| AC-06 (Least Privilege) | AC | AI-ACC.1 |
Inference authorization |
| SC-28 (Protection of Information at Rest) | SC | AI-SEC.1 |
Model encryption at rest |
The following cards show how specific SWT3 procedures map to COSAiS-enhanced controls. Each card includes the control context, the evidence the procedure generates, and assessor guidance for FedRAMP and RMF environments.
COSAiS context: SI-07 under the AI overlay extends beyond traditional software and firmware integrity to cover model weights, guardrail configurations, and inference pipeline components. The overlay requires organizations to verify that safety guardrails have not been tampered with, bypassed, or degraded between deployments.
What AI-GRD.1 witnesses: Each inference request passes through a guardrail check. The SWT3 anchor records whether the guardrail was active, which version was loaded, and whether the input or output was flagged. This creates a per-inference integrity trail that maps directly to SI-07 assessment objectives.
Sample anchor: SWT3-E-VULTR-AI-GRD1-PASS-1723305600-a1b2c3d4e5f6
In FedRAMP environments, SI-07 already requires integrity verification mechanisms. When evaluating AI workloads, request the SWT3 anchor stream for AI-GRD.1 and confirm that guardrail versions are consistent across deployment boundaries. A gap between the guardrail version in the anchor and the version in the CM baseline indicates a configuration drift finding.
COSAiS context: SI-04 under the AI overlay extends system monitoring to include model behavioral drift, performance degradation, and distribution shift detection. Traditional monitoring tools do not detect when a model's output distribution changes over time, which the overlay treats as a system integrity concern.
What AI-DRIFT.1 witnesses: The procedure records drift metrics at configurable intervals, capturing statistical measures of output distribution change, confidence score trends, and threshold exceedances. AI-DRIFT.2 adds consequence-mapped thresholds that link drift severity to operational impact categories.
Sample anchor: SWT3-E-VULTR-AI-DRIFT1-PASS-1723305600-f6e5d4c3b2a1
For RMF packages, SI-04 continuous monitoring evidence should include drift trend data alongside traditional IDS/SIEM logs. Request the AI-DRIFT.1 anchor history and look for threshold breach patterns. If AI-DRIFT.2 is also deployed, verify that consequence mappings align with the system's FIPS 199 impact level.
COSAiS context: SR-04 under the AI overlay addresses the provenance of pre-trained models, fine-tuning datasets, and third-party model components. Unlike traditional software supply chain controls that focus on code repositories and build pipelines, the AI overlay requires organizations to document the origin, training lineage, and modification history of model artifacts.
What AI-SUPPLY.1 witnesses: The procedure records the model source (registry, organization, version), any fine-tuning applied, and the hash of the model artifact at the point of deployment. This creates a verifiable chain from model origin through deployment that satisfies SR-04 provenance requirements.
Sample anchor: SWT3-E-VULTR-AI-SUPPLY1-PASS-1723305600-c3d4e5f6a1b2
In FedRAMP High and Moderate baselines, SR-04 provenance requirements are already mandatory. For AI workloads, verify that AI-SUPPLY.1 anchors include the model registry source and artifact hash. Cross-reference these hashes against the organization's approved model inventory. Any model deployed without a matching AI-SUPPLY.1 anchor represents an undocumented supply chain dependency.
COSAiS context: CA-08 under the AI overlay extends penetration testing to include adversarial ML attacks: prompt injection, model evasion, data poisoning, model extraction, and membership inference. The overlay draws on the NIST Adversarial ML taxonomy and OWASP Agentic AI threat models to define the scope of adversarial testing requirements.
What AI-REDTEAM.1 witnesses: The procedure records adversarial test campaigns, including the attack types exercised, the success/failure rate of each attack, and the remediation status of identified vulnerabilities. Each test campaign mints an anchor that links the test results to the model version and deployment environment.
Sample anchor: SWT3-E-VULTR-AI-REDTEAM1-PASS-1723305600-b2a1f6e5d4c3
CA-08 penetration testing in RMF and FedRAMP contexts already requires annual or event-driven testing. For AI systems, verify that the AI-REDTEAM.1 anchor stream covers the adversarial attack categories relevant to the system's threat model. At minimum, expect evidence of prompt injection testing for generative AI systems and evasion testing for predictive AI systems. Cross-reference test dates with model deployment dates to confirm testing occurred before production release.
Organizations operating under SP 800-53 Rev. 5 already have a mature control baseline. Adding AI capabilities to those systems introduces risks that the existing controls were not designed to address: model tampering, training data poisoning, adversarial evasion, inference side-channel attacks, and autonomous agent behavior. COSAiS provides the structured path to extend existing baselines rather than building parallel governance from scratch.
Federal agencies and cloud service providers adding AI features to authorized systems face a practical challenge: how to document AI-specific controls within the existing SSP structure. COSAiS overlays map directly to 800-53 control families, which means the AI-specific enhancements slot into the same control descriptions, assessment procedures, and continuous monitoring plans that assessors already evaluate. SWT3 procedures generate the runtime evidence that populates those control narratives with verifiable data.
If your organization already maintains an 800-53 baseline, COSAiS is not a new framework to adopt. It is a set of AI-specific parameters and enhancements that layer on top of what you already have. The SWT3 procedure mapping in this guide identifies exactly which procedures generate evidence for each enhanced control, allowing security teams to deploy targeted witnessing without disrupting existing control implementations.
Third-party assessors and C3PAOs evaluating AI workloads within FedRAMP or RMF boundaries can use the procedure mapping table as a checklist. Each SWT3 procedure corresponds to a specific 800-53 control enhancement, and each anchor provides cryptographically verifiable evidence of control operation. This transforms AI governance assessment from interview-based evaluation to evidence-based verification.
The following Python example demonstrates how to generate SWT3 witness evidence for COSAiS-aligned controls. This snippet witnesses a guardrail integrity check (AI-GRD.1), which maps to the SI-07 overlay enhancement.
from swt3_ai import Witness
w = Witness(
tenant="YOUR_TENANT",
signing_key="YOUR_HMAC_KEY",
agent_id="cosais-guardrail-agent"
)
# Witness guardrail integrity (SI-07 overlay)
anchor = w.witness(
procedure="AI-GRD.1",
model_id="gpt-4o-2024-08-06",
factor_a="guardrail_version=v2.4.1",
factor_b="input_flagged=false",
factor_c="output_flagged=false",
verdict="PASS"
)
print(f"COSAiS SI-07 evidence: {anchor.fingerprint}")
# SWT3-E-VULTR-AI-GRD1-PASS-1723305600-a1b2c3d4e5f6
For TypeScript, Rust, C#, Ruby, and Swift SDK examples, see the SDK documentation. All seven SDKs produce cross-language-compatible fingerprints using the same locked formula.