Voluntary frameworkUnited States
NIST AI Risk Management Framework: Generative AI Profile (NIST AI 600-1)
Names twelve risks unique to or amplified by generative AI (confabulation, CBRN uplift, harmful bias, data leakage) and maps suggested actions onto the AI RMF's four functions.
Status
Voluntary framework
Jurisdiction
United States · Standard
Adopted
Jul 26, 2024
In force
Jul 26, 2024
Enforcement date
—
Regulator / body
None (voluntary NIST guidance)
Sectors
Cross-sector
Extraterritorial
No
Key dates
- Jul 26, 2024Published as a companion to the AI RMF
Risk areas addressed
Safety & robustnessSecurityMisinformationTransparencyGovernance & accountability
Who it applies to
Any organisation designing, developing or deploying generative AI systems.
Penalties & enforcement
None (voluntary framework).
Enforced by: None (voluntary NIST guidance)
Getting ready
NIST GenAI Profile carries no direct penalty today, so its value is evidential: teams adopt it to show a named standard behind their controls for safety & robustness, security and misinformation. Mapping an existing AI inventory against it is usually enough to surface the gaps, and that same evidence tends to carry over to the binding regimes that follow.