GovernanceCore
Voluntary frameworkUnited States

NIST AI Risk Management Framework: Generative AI Profile (NIST AI 600-1)

Names twelve risks unique to or amplified by generative AI (confabulation, CBRN uplift, harmful bias, data leakage) and maps suggested actions onto the AI RMF's four functions.

Status
Voluntary framework
Jurisdiction
United States · Standard
Adopted
Jul 26, 2024
In force
Jul 26, 2024
Enforcement date
Regulator / body
None (voluntary NIST guidance)
Sectors
Cross-sector
Extraterritorial
No

Key dates

  • Jul 26, 2024
    Published as a companion to the AI RMF

Risk areas addressed

Safety & robustnessSecurityMisinformationTransparencyGovernance & accountability

Who it applies to

Any organisation designing, developing or deploying generative AI systems.

Penalties & enforcement

None (voluntary framework).

Enforced by: None (voluntary NIST guidance)

Getting ready

NIST GenAI Profile carries no direct penalty today, so its value is evidential: teams adopt it to show a named standard behind their controls for safety & robustness, security and misinformation. Mapping an existing AI inventory against it is usually enough to surface the gaps, and that same evidence tends to carry over to the binding regimes that follow.

Official source

NIST AI 600-1

Related regulations

← All regulations