If you have touched an AI system authorization package in the last six months, you have probably heard the term NIST COSAiS AI control overlays thrown around a security working group meeting without much explanation. COSAiS stands for Control Overlays for Securing AI Systems, and it is NIST’s answer to a problem every ISSO working an AI package already knows about: SP 800-53 was not written with generative AI, fine-tuned models, or autonomous agents in mind. The overlays are how NIST is closing that gap, one use case at a time.
This post breaks down what COSAiS actually covers, which overlays are published versus still in draft, and what it means for the ATO package sitting on your desk right now.
What Are NIST COSAiS AI Control Overlays?
COSAiS is a NIST project that extends the SP 800-53 control catalog with overlays purpose-built for AI systems. An overlay, in NIST language, is not a new control catalog — it is a tailored subset and supplementation of existing 800-53 controls, plus new control guidance, mapped to a specific system type or use case. Cloud systems have overlays. Privacy has overlays. Now AI systems get their own, because a control written for a static application server does not translate cleanly to a model that retrains itself on new data or an agent that takes autonomous action inside your network.
The project sits under NIST’s Computer Security Resource Center and is being developed with public comment cycles, the same way most 800-series guidance gets built. That matters for your planning horizon: these overlays are not final law yet, but they are the direction control assessors and AOs are already leaning toward when an AI system lands on their desk.
The Five AI Use-Case Overlays
COSAiS does not treat “AI system” as one category. NIST split the problem into five distinct use cases, because the risk profile of a chatbot built on a commercial LLM looks nothing like the risk profile of a multi-agent system making autonomous decisions inside a mission network.
- Generative AI assistants — using or adapting an existing gen-AI tool (think chatbots, copilots, and document-drafting assistants built on a foundation model you did not train yourself).
- Fine-tuning predictive AI — taking a predictive model and retraining it on your own data for a specific mission function.
- Single-agent AI systems — one autonomous agent operating with defined boundaries and permissions.
- Multi-agent AI systems — multiple agents coordinating, handing off tasks, or negotiating with each other, which multiplies the attack surface and the assurance questions.
- Developing AI systems — building a model from the ground up, which pulls in supply chain, training data provenance, and secure development controls that a system integrator using someone else’s model never has to think about.
If you are working an ISSO role today, the first two use cases are the ones you are most likely to run into — a mission team wants to bolt a commercial gen-AI assistant onto an existing system boundary, or a data science team wants to fine-tune a predictive model on operational data. The agent-based overlays are coming, but they are behind the assistant and fine-tuning work in the publication queue.
Publication Status: What’s Out and What’s Still Coming
Here is where a lot of ISSOs get tripped up — COSAiS is not one document you download and apply. Each use case overlay is on its own publication timeline, and as of mid-2026, most of them are still in draft or have not been released for public comment at all.
| Overlay | Status |
|---|---|
| Fine-tuning predictive AI | Discussion draft released January 8, 2026; public comment period closed February 13, 2026 |
| Generative AI assistants | Not yet published as a standalone final overlay |
| Single-agent AI systems | Not yet published |
| Multi-agent AI systems | Not yet published |
| Developing AI systems | Not yet published |
The predictive AI overlay is the furthest along, having already gone through a public comment window in early 2026. The agent-focused overlays — single-agent, multi-agent, and the development overlay — are still working their way through NIST’s internal drafting process. Final publication across the full set is expected sometime in late 2026 to 2027, not all at once. If your program is authorizing an AI system this year, you are almost certainly authorizing against 800-53 baseline controls with agency-specific AI tailoring, not a finished COSAiS overlay.
How COSAiS Extends NIST SP 800-53
COSAiS is not a competitor to 800-53 — it is built on top of it. NIST released SP 800-53 Release 5.2.0 in August 2025, adding controls around secure software updates and deployment governance (SA-15(13) logging syntax, SA-24 design for cyber resiliency, and the SI-02(07) root cause analysis enhancement). Those controls were not written specifically for AI, but they matter directly to AI systems: a fine-tuned model that gets pushed as a software update needs the same integrity validation and root-cause-analysis discipline as any other deployment.
COSAiS layers AI-specific tailoring on top of that baseline rather than replacing it. When the overlays finalize, expect them to reference existing control families — access control, system and information integrity, configuration management — with AI-specific implementation guidance and, in some cases, new controls addressing things like model provenance, training data integrity, and agent authorization boundaries that the current catalog does not directly address.
What This Means for Your ATO Package Today
Here is the practical problem: your AO is not going to sit on an AI system authorization for a year waiting on a finished overlay. DoD has already built a parallel path for this. As covered in how to get an ATO for an AI system in DoD, the department separates the AI model assessment — the “Assess Only” construct under the DoD AI Cybersecurity Risk Management Tailoring Guide — from the hosting infrastructure’s authorization, which still runs through traditional RMF or cATO. Your body of evidence has to cover both halves: model performance and behavior on one side, infrastructure security controls on the other.
That split exists precisely because COSAiS is not finished. Assess Only gives programs a way to evaluate model-specific risk without waiting for a finalized overlay to tell them exactly which controls apply. Once COSAiS overlays publish, expect the Assess Only construct and the overlays to converge — the overlay will likely become the control mapping that Assess Only assessments get scored against.
How to Prepare Now
You do not need a finished overlay to start building a defensible package. A few things worth doing now:
- Identify which of the five COSAiS use cases your system actually falls under — a gen-AI assistant bolted onto an existing app is a very different assessment than a fine-tuned predictive model.
- Document training data provenance and model update procedures now, even without a control number to hang them on — assessors will ask for this regardless of overlay status.
- Map your existing 800-53 controls (especially SI, SA, and AC family) to the AI-specific risks in your system, and note where you had to write your own tailoring rationale.
- Keep the Assess Only body of evidence and the infrastructure ATO evidence organized separately — they get evaluated by different people on different timelines.
- Watch the COSAiS project page for the agent-focused overlays; if your system involves any autonomous decision-making, that draft will directly affect your control set once it lands.
Common Questions About COSAiS
Is COSAiS mandatory right now?
No. As of mid-2026, only one overlay — fine-tuning predictive AI — has even gone through a public comment cycle, and it is still a discussion draft, not a final publication. Nothing in COSAiS is mandatory yet. What is mandatory is the underlying SP 800-53 control catalog your AI system already has to comply with, plus whatever AI-specific tailoring your component or agency has issued in the meantime.
What do I do if my AI system needs an ATO before COSAiS finishes?
You authorize it the way DoD programs are authorizing AI systems today: 800-53 baseline controls, agency or component AI tailoring guidance where it exists, and the Assess Only construct to separate model risk from infrastructure risk. Document your tailoring decisions and rationale carefully — when the overlay for your use case does publish, you want a paper trail showing your control selections were reasoned, not improvised, so remapping to the final overlay is a documentation exercise instead of a redesign.
How does COSAiS relate to CSRMC?
They operate at different altitudes. CSRMC — the Cybersecurity Risk Management Construct DoD announced in September 2025 to eventually replace legacy RMF — is the overarching process framework: Design, Build, Test, Onboard, Operations, with tenets like continuous monitoring, automation, and reciprocity built in. COSAiS is a control-catalog-level overlay that plugs into 800-53. An AI system moving through CSRMC’s five phases will still need to satisfy whatever control set applies to it, and once COSAiS overlays are final, that control set is what CSRMC-phase assessments will point to for AI-specific systems.
Why This Is Worth Tracking Now, Not Later
It is tempting to file COSAiS under “wait until it’s final” and move on. That is a mistake for two reasons. First, AOs and control assessors are already forming opinions about what AI-specific control coverage should look like, and those opinions are being shaped by the discussion drafts that are public right now. If you show up to an assessment having read the predictive AI overlay draft and mapped your fine-tuned model against it, you are having a very different conversation than the ISSO who has never heard of COSAiS.
Second, the AI systems landing on ISSO desks this year are not going to disappear once the overlays publish. They will need to be reassessed against the final control set, and the amount of rework that takes depends entirely on how well the original authorization was documented. An ISSO who tailored 800-53 controls thoughtfully and kept a clear rationale trail will have a straightforward remapping exercise. An ISSO who treated the AI system like any other application will be redoing a chunk of the package from scratch.
COSAiS is going to change how AI systems get authorized across DoD and federal agencies, but it is not there yet. The ISSOs and ISSMs who come out ahead on this will be the ones who understand the five use cases now and can speak fluently about which one their system belongs to when the AO asks.
If you want help thinking through how an AI system in your portfolio maps to this framework, or want a second set of eyes on an Assess Only package before it goes up the chain, coaching sessions are open and built around exactly this kind of practical, package-level problem.

Leave a Reply