By NHI Mgmt Group Editorial TeamBased on HiddenLayer: “HiddenLayer “Awardable” for Department of Defense Work in the CDAO’s Tradewinds Solutions Marketplace” (June 2, 2026)

TL;DR: Detection, monitoring and protection for AI systems and AI agents are now in a federal procurement channel built for AI, ML, data and analytics capabilities after HiddenLayer says its AI security platform achieved Awardable status in the DoD CDAO’s Tradewinds Solutions Marketplace, and the shift matters because AI security is now being evaluated as an identity and lifecycle governance problem, not just a model-risk issue.


At a glance

What this is: HiddenLayer’s AI security platform achieved Awardable status in the DoD CDAO’s Tradewinds Solutions Marketplace, signalling that AI security is now being procured through a federal channel focused on AI, ML, data and analytics.

Why it matters: For IAM and security teams, the shift matters because AI security is moving into procurement and governance workflows that resemble identity lifecycle controls, especially where AI agents and operational deployment boundaries are concerned.


Context

Tradewinds awardable status is a procurement designation, but in this case the underlying subject is AI security for systems and AI agents across the AI lifecycle. The governance gap is that AI capabilities are no longer confined to model development; they now reach into discovery, supply chain, runtime monitoring, and operational protection.

For identity and security programmes, that matters because AI systems increasingly behave like governed runtime assets with attached permissions, dependencies, and lifecycle states. Once AI security enters a federal buying channel, procurement, assurance, and operational controls start to converge around the same questions practitioners already ask about NHI, workload identity, and agent governance.


Key questions

Q: How should teams govern AI systems that can take actions as well as generate outputs?

A: Treat the agent as a governed actor, not just a model output stream. Require action-level logging, tool-call traceability, authorization boundaries, and approval gates before the system can write to records or invoke downstream tools. If an AI system can change state, its authority must be scoped, monitored, and revocable like any other privileged non-human identity.

Q: Why do AI security tools belong in identity governance discussions?

A: Because they depend on identities, permissions, operators, and lifecycle decisions to function in real environments. Once a tool protects AI assets or workflows, it becomes part of the control model around who can deploy, manage, and review it. That makes IAM, access review, and accountability central to its use.

Q: What breaks when AI agents are given broad standing access?

A: Broad standing access breaks governance because the agent can move from one task to another without a fresh authorization check. That creates a control gap between intended scope and actual runtime behaviour. The result is weak accountability, limited containment, and audit trails that show activity without explaining why the activity was allowed.

Q: What does federal awardability change for AI security buyers?

A: It signals that buyers should expect evidence of lifecycle controls, monitoring, and supply chain assurance rather than only model performance claims. Procurement teams should ask whether the solution can be governed after purchase, not only demonstrated in a demo environment.


Technical breakdown

AI lifecycle security as a procurement control surface

When a security platform is evaluated inside a government marketplace, the subject is no longer only technical defence. The AI lifecycle includes discovery, supply chain security, attack simulation, runtime protection, and monitoring, which means procurement is implicitly asking whether the organisation can govern AI from intake to operational use. That creates a control surface similar to identity governance, where the asset has to be known, scoped, and monitored before it is trusted in production. Practical implication: treat AI security selection as part of governance design, not a late-stage tooling purchase.

Practical implication: evaluate AI security tools against lifecycle coverage, not isolated detection features.

AI agents introduce runtime identity and privilege questions

AI agents are not just models with outputs. They can act, call tools, and participate in workflows, which makes their security posture closer to NHI governance than traditional model assurance. If an agent can initiate actions in production, the security question becomes how that runtime behaviour is monitored, bounded, and separated from other identities and secrets. This is why agent security sits at the intersection of access control, workload identity, and operational monitoring. Practical implication: map every agent to its runtime permissions, dependencies, and revocation path before it reaches production.

Practical implication: inventory agent permissions and revocation paths before operational deployment.

AI supply chain risk now extends beyond model files

HiddenLayer’s positioning around AI supply chain security reflects a wider shift in attack surface. AI systems depend on models, artefacts, data, code, integration points, and deployment environments, so compromise can occur at multiple layers before a model ever runs. That broadens assurance from simple model evaluation into lifecycle trust management. The control problem is not only whether the model is safe, but whether the components around it are authenticated, validated, and continuously observed. Practical implication: assess the full AI supply chain as a governed dependency chain, not a single technology layer.

Practical implication: extend assurance to the full AI supply chain, including artefacts, integrations, and runtime dependencies.


Threat narrative

Attacker objective: The objective is to compromise AI behaviour, data integrity, or operational trust at the point where the system is trusted for real work.

  1. Entry occurs when an AI system or AI agent enters an environment through a governed procurement channel and becomes eligible for operational use.
  2. Credential or scope abuse follows when the deployed AI component is allowed to interact with data, tools, or workflows beyond the intended boundary.
  3. Escalation happens through adversarial manipulation, model compromise, or misuse of runtime access that expands the blast radius of the AI system.
  4. Impact is the compromise of AI decision integrity, operational trust, or protected data across the lifecycle of the deployed system.
  • 12,000 secrets in LLM training data: Truffle Security found 11,908 live API keys and passwords hard-coded in web pages captured by Common Crawl, a dataset used to train LLMs.
  • Microsoft SAS token exposure 2023: An over-permissive Azure SAS token in a Microsoft AI GitHub repo exposed 38TB, including workstation backups and Teams messages, for 3 years.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

AI security is becoming a governance category, not just a model-risk category. Awardable status in a federal procurement marketplace shows that buyers are starting to assess AI security as a lifecycle control problem. That changes the conversation from isolated model testing to operational trust, access boundaries, and ongoing monitoring. The practitioner takeaway is that AI security now belongs in procurement, identity, and runtime governance discussions at the same time.

AI agents force identity teams to think about runtime authority. Once an AI system can act through tools and workflows, it begins to resemble a governed non-human actor rather than a static model. That pushes the security conversation toward permissions, revocation, and oversight across the full execution path. The implication is that AI agent governance must be tied to the same control discipline used for other high-risk non-human identities.

AI lifecycle security now spans discovery, supply chain, and runtime enforcement. The article’s own framing makes clear that protection is no longer limited to detection at inference time. AI assets now move through an end-to-end lifecycle with distinct trust points, each of which can fail independently. Practitioners should therefore treat AI lifecycle control as a layered governance model, not a single defensive product category.

Federal procurement will accelerate category convergence in identity security. When government buying channels begin to recognise AI security as an awardable capability, the market starts to converge around integrated governance, monitoring, and assurance. That pressures practitioners to re-evaluate where AI security sits relative to NHI, workload identity, and security operations. The field is moving toward unified control of autonomous and non-autonomous machine actors.

What this signals

Procurement is becoming part of the AI security control plane. Once a capability is evaluated through a federal marketplace, the organisation is effectively deciding whether that system can be trusted as an operational actor, not just a technical artefact. That pushes security teams to align procurement, runtime monitoring, and lifecycle ownership before deployment.

AI agent governance now overlaps with NHI governance in practice. If an AI system can call tools, reach data, and execute tasks, its access path must be managed like a non-human identity with bounded authority. The governance lesson is simple: runtime permissions matter more than model claims when the system can act on its own.

AI supply chain controls will become a gating requirement for adoption. Discovery, training data, connectors, and runtime dependencies all shape the trust boundary of the system. Teams that do not map those dependencies will struggle to answer basic assurance questions when the system reaches production.


For practitioners

  • Map AI systems to lifecycle ownership Assign named owners to discovery, approval, runtime monitoring, and retirement for every AI system and AI agent in scope. The goal is to make governance continuous rather than a one-time deployment decision.
  • Inventory agent permissions and dependencies Document which tools, APIs, data stores, and secrets each AI agent can reach, then define the revocation path for each dependency. This creates a control baseline for operational review and incident containment.
  • Extend supplier review to AI supply chain inputs Review models, datasets, connectors, plugins, and hosted components as a single dependency chain. Validate where provenance, integrity, and approval boundaries break before the system is accepted for production use.
  • Tie procurement decisions to governance evidence Require evidence of monitoring, boundary enforcement, and lifecycle controls before an AI capability is approved for use. Procurement should confirm that security obligations are operational, not aspirational.

Key takeaways

  • AI security is moving into procurement channels where operational trust, runtime monitoring, and lifecycle control matter as much as model quality.
  • AI agents blur the line between model assurance and identity governance because their permissions, dependencies, and revocation paths become security controls.
  • Practitioners should evaluate AI systems as governed runtime actors and require evidence of supply chain assurance before deployment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI03 — Identity & Privilege AbuseAI agents with tool access create privilege and authority questions central to this article.
Recommendation — Map agent permissions and revocation paths to ASI03 before production approval.
OWASP Non-Human Identity Top 10NHI-03 — Vulnerable Third-Party NHIThe article stresses supply chain dependencies around AI systems and agents.
NHI-05 — Overprivileged NHIRuntime AI systems can accumulate access beyond intended operational scope.
Recommendation — Review AI supply chain dependencies for external identity exposure and approval gaps. Audit AI runtime access scopes and remove privileges that exceed task boundaries.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about governing who and what can act in production.
Recommendation — Apply PR.AA-05 to define and review AI system entitlements before deployment.
NIST AI RMFGOVERN — AI Governance and AccountabilityAwardability and lifecycle governance make AI accountability a central theme.
Recommendation — Use GOVERN to assign AI accountability, approval, and oversight across the lifecycle.

Key terms

  • AI Lifecycle: The AI lifecycle is the end-to-end path from problem framing to retirement. It covers the decisions that shape a system’s purpose, data, behaviour, deployment, oversight, and decommissioning. In practice, it is the governance map that shows where risk enters and where accountability must stay active.
  • AI supply chain: The AI supply chain is the full chain of models, datasets, prompts, tools, and vendors that influence a deployed AI system. It matters because trust cannot be assigned to the application alone. Practitioners need provenance, ownership, and dependency visibility to govern risk.
  • Runtime authority: Runtime authority is the permission an AI system has while it is actively deciding and acting, not just when it is approved. In governance terms, it is the point where access, tool use, and action scope become operational, which is why build-time review alone cannot prove safety.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org