Skip to main content
v2026.11,858 entries · CC-BY 4.0

NIST AI RMF Generative AI Profile: What AI 600-1 Adds

NIST AI 600-1, the Generative AI Profile, is a separate July 2024 publication that extends the base AI RMF (NIST AI 100-1) for generative AI specifically — naming twelve risks unique to or exacerbated by GAI (confabulation, CBRN information or capabilities, data privacy, and more) and suggesting actions tagged to the RMF’s Govern/Map/Measure/Manage subcategories.

Written and maintained by CASRAI Editorial Board

Last updated

NIST’s AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) is deliberately generic — it applies to any AI system. The Generative AI Profile, published separately as NIST AI 600-1 in July 2024, is where NIST gets specific about generative AI. It doesn’t replace the base framework or stand alone; it’s a profile of it, naming risks the base document doesn’t name and suggesting actions the base document doesn’t suggest.

What the Generative AI Profile actually is

NIST AI 600-1, titled Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, was approved by NIST’s Editorial Review Board on July 25, 2024 and published that month. In NIST’s own terminology, a “profile” is an implementation of the AI RMF’s functions, categories, and subcategories for a specific setting or technology — here, generative AI (GAI). NIST calls it a “cross-sectoral profile” because generative AI risk isn’t specific to one industry: the same profile applies whether the deployment is a customer-support chatbot, a research-summarization tool, or an internal coding assistant.

The document was developed pursuant to Section 4.1(a)(i)(A) of Executive Order 14110 on Safe, Secure, and Trustworthy Artificial Intelligence, which directed the Secretary of Commerce, acting through NIST, to produce a companion resource to the AI RMF specifically for generative AI. NIST assembled a Generative AI Public Working Group (GAI PWG) to inform it — an open, multistakeholder process that NIST says focused on four primary considerations: Governance, Content Provenance, Pre-deployment Testing, and Incident Disclosure. Those four considerations, not an attempt at full coverage, are what shaped which parts of the base framework the profile actually elaborates on.

For the base framework’s four functions themselves — Govern, Map, Measure, Manage — see our walkthrough of the AI RMF’s GMMM structure. This guide assumes that structure and focuses on what the Generative AI Profile adds on top of it.

The 12 risks it names that the base RMF doesn’t

The base AI RMF discusses risk in general terms — validity, safety, security, bias, privacy — without enumerating a fixed list of named risks. The Generative AI Profile does the opposite: Section 2 defines twelve risks NIST states are “unique to or exacerbated by” generative AI, each with its own subsection explaining the mechanism. NIST is explicit that this list is bounded by evidence: it covers risks with an existing empirical basis at the time of writing, not speculative risks that might arise in more advanced future systems. The twelve, as NIST names and defines them, are:

  • CBRN Information or Capabilities. Eased access to or synthesis of materially nefarious information or design capabilities related to chemical, biological, radiological, or nuclear weapons or other dangerous materials.
  • Confabulation. The production of confidently stated but erroneous or false content — what’s colloquially called “hallucination” — by which users may be misled.
  • Dangerous, Violent, or Hateful Content. Eased production of and access to violent, radicalizing, or threatening content, including recommendations to self-harm or commit illegal acts.
  • Data Privacy. Leakage and unauthorized use, disclosure, or de-anonymization of biometric, health, location, or other personal or sensitive data, including data used in training.
  • Environmental Impacts. Impacts from the high compute resource utilization involved in training or operating GAI models.
  • Harmful Bias or Homogenization. Amplification of historical, societal, and systemic biases, and performance disparities between subgroups or languages, including undesired homogeneity that skews outputs.
  • Human-AI Configuration. Human-AI interactions that lead to inappropriate anthropomorphization, automation bias, over-reliance, or emotional entanglement with a GAI system.
  • Information Integrity. A lowered barrier to generating content that doesn’t distinguish fact from opinion or fiction, or that can be used for large-scale mis- or disinformation.
  • Information Security. Lowered barriers for offensive cyber capabilities — automated vulnerability discovery, malware, phishing — and an increased attack surface for model weights and training data themselves.
  • Intellectual Property. Eased production or replication of copyrighted, trademarked, or licensed content without authorization, or exposure of trade secrets.
  • Obscene, Degrading, and/or Abusive Content. Eased production of and access to obscene or abusive imagery, including synthetic CSAM and nonconsensual intimate imagery of adults.
  • Value Chain and Component Integration. Non-transparent or untraceable integration of upstream third-party components — including improperly sourced training data — that reduce transparency or accountability for downstream users.

Two of these are worth calling out specifically because they’re the ones with no real analogue in the base RMF’s general vocabulary: confabulation, because the base framework’s “valid and reliable” characteristic doesn’t capture a system that is fluent and confident while being wrong, in the specific way LLMs are; and CBRN information or capabilities, because it’s a risk category that only makes sense once a model’s outputs include synthesized technical knowledge, not something a traditional software risk register has a slot for. NIST is careful to hedge the CBRN risk: it cites research finding that, at the time of writing, LLM outputs on biological threat creation provided minimal assistance beyond a search engine, and notes the physical production of a CBRN agent still requires expertise and materials a model can’t supply.

How the suggested actions are structured

Section 3 supplies the profile’s suggested actions, organized under the base RMF’s existing subcategories and tagged with the same function prefixes the base framework uses — GV (Govern), MP (Map), MS (Measure), MG (Manage) — followed by the subcategory number and an action index, e.g. GV-1.1-001 for the first suggested action under Govern 1.1. Each action is also cross-referenced to which of the twelve GAI risks it addresses and which AI RMF “trustworthy AI characteristic” it maps to (safe, valid and reliable, explainable and interpretable, and so on).

NIST is explicit that this is a partial map, not a complete one: “not every subcategory of the AI RMF is included in this document.” Suggested actions are listed only for the subcategories connected to the GAI PWG’s four primary considerations, and NIST states future revisions may add subcategories, risks, and actions as evidence accumulates. In other words, the Generative AI Profile is additive, not a replacement checklist — the base AI RMF and its Playbook remain applicable on their own for everything the profile doesn’t touch.

What it deliberately leaves out

Two scope limits matter for anyone using this as a compliance input rather than a reading exercise. First, the risk list is evidence-bounded: NIST names it as covering risks with an existing empirical base “at the time this profile was written,” explicitly excluding more speculative risks from future, more capable systems. Second, the suggested actions don’t cover the whole AI RMF — they’re concentrated on the four PWG considerations, so a subcategory the base framework has but the profile is silent on isn’t a signal that it doesn’t apply to generative AI; it’s a signal the profile hasn’t been extended to it yet.

The profile also isn’t a certification scheme, a conformity assessment, or a checklist to complete once. Like the base AI RMF, it’s voluntary guidance meant to be applied on an ongoing basis across a system’s lifecycle, and NIST leaves the specific thresholds, testing methods, and governance mechanics to the organization applying it.

Where it fits against other frameworks

The Generative AI Profile sits inside the broader landscape of AI governance frameworks and regulation covered elsewhere in this cluster:

How CASRAI’s NIKOLAI tracks this

Two of the profile’s twelve named GAI risks map onto elements in CASRAI’s own NIKOLAI project, an independent, unendorsed reference dictionary of frontier-AI-safety terminology. NIST names “Information Security” — the increased attack surface on model weights and training data — as one of the twelve; NIKOLAI’s N6 (Mitigations and Security) track operationalizes that same concern through elements like Security Control and Security Level, which record a developer’s actual model-weight and infrastructure security posture rather than just naming the risk category. CASRAI tracks this connection via NIKOLAI, not as an endorsed mapping to NIST’s taxonomy — see NIKOLAI for the full element set, and Mapping Declarations for how an organization would confirm how its own security posture maps to these terms.

FAQ

Is the Generative AI Profile mandatory?

No. Like the base AI RMF, NIST designed it for voluntary use. It carries no certification or conformity-assessment mechanism of its own; organizations and regulators may reference it, but the document itself doesn’t impose requirements.

Does the Generative AI Profile replace the base AI RMF?

No. It’s a profile of the base framework, not a substitute for it. The base AI RMF’s Govern, Map, Measure, and Manage functions still apply in full; the profile adds generative-AI-specific risks and a subset of additional suggested actions on top of them.

What’s the difference between the Generative AI Profile and the NIST AI RMF Playbook?

The Playbook, published alongside the base AI RMF in 2023, gives suggested actions for the base framework’s subcategories generally, across all AI systems. The Generative AI Profile does the same thing but scoped to generative AI specifically, and adds the twelve named GAI risk categories the Playbook doesn’t have.

Does the profile cover agentic AI or AI agents specifically?

Not as a separate category. AI 600-1 was published in July 2024 and its risk list and suggested actions are framed around generative AI broadly (content generation, LLM-based systems) rather than agentic behavior specifically. Where an agentic system’s risk stems from generating outputs — a confabulated tool call, leaked data in a generated response — the twelve risk categories still apply; risks that are specific to autonomous multi-step action aren’t separately enumerated here.

Is NIST AI 600-1 the final version, or is it still a draft?

It’s a final, published document — not a draft. Its publication history records approval by NIST’s Editorial Review Board on July 25, 2024. NIST states in the document itself that future revisions may add further subcategories, risks, and suggested actions as the evidence base grows, but as of publication there’s no superseding version.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · free to try

Ask about NIST AI RMF Generative AI Profile: What AI 600-1 Adds

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →