Global Software AI
1 min read

Managing generative-AI risk with the NIST profile

NIST's Generative AI Profile extends the AI RMF with concrete actions for governance, data provenance, testing, and incident disclosure.

By Tim Crouch

More from AI Security

NIST's Generative AI Profile takes the AI Risk Management Framework and applies it to systems that create text, code, images, audio, and other content. It does not present generative AI as one new vulnerability. Instead, it describes a risk landscape shaped by confabulation, data privacy, information integrity, bias, intellectual property, cybersecurity, environmental impact, and third-party dependencies.

The primary CISSP lens is Domain 1, Security and Risk Management. NIST organizes the work around governance, content provenance, pre-deployment testing, and incident disclosure. Leaders need defined risk tolerances, accountable roles, inventories, policies, and processes for deciding when a system should be restricted or deactivated. The profile is deliberately voluntary and adaptable, but it expects decisions to be documented and tied to the organization's context.

Domain 2, Asset Security, is central because generative-AI systems consume and produce sensitive information. Data provenance, classification, ownership, retention, privacy, and third-party data handling affect whether outputs can be trusted and whether information is exposed. Treating prompts, training data, embeddings, models, and generated content as managed assets makes the risks concrete.

Domain 8, Software Development Security, appears in the emphasis on testing before deployment, documenting limitations, securing supply chains, and connecting AI controls to existing development governance. Domain 7, Security Operations, carries those controls into production through monitoring, incident disclosure, escalation, recovery, and ongoing review.

The useful point is that generative-AI risk cannot be handled by a single content filter. Organizations need a lifecycle process that joins governance, data management, engineering, testing, and incident response. NIST provides a large catalogue of suggested actions, but the practical task is prioritization: identify the harms that matter in your use case, assign owners, select measurable controls, and keep revisiting the decision as the system and evidence change.