GovernanceCore
Voluntary frameworkUnited States

Secure Software Development Practices for Generative AI and Dual-Use Foundation Models (SP 800-218A)

Extends the Secure Software Development Framework to generative AI, adding practices for training-data provenance, model weight protection and supply-chain integrity.

Status
Voluntary framework
Jurisdiction
United States · Standard
Adopted
Jul 26, 2024
In force
Jul 26, 2024
Enforcement date
Regulator / body
None (voluntary NIST guidance)
Sectors
Technology, Cross-sector
Extraterritorial
No

Key dates

  • Jul 26, 2024
    Published as an SSDF companion

Risk areas addressed

SecuritySafety & robustnessData governance

Who it applies to

Producers of generative AI and dual-use foundation models, and organisations acquiring them.

Penalties & enforcement

None (voluntary framework).

Enforced by: None (voluntary NIST guidance)

Getting ready

NIST SP 800-218A carries no direct penalty today, so its value is evidential: teams adopt it to show a named standard behind their controls for security, safety & robustness and data governance. Mapping an existing AI inventory against it is usually enough to surface the gaps, and that same evidence tends to carry over to the binding regimes that follow.

Official source

NIST SP 800-218A, CSRC

Related regulations

← All regulations