Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →NIST AI 600-1 Generative AI Profile
Issued by
National Institute of Standards and Technology (NIST), U.S. Department of Commerce
- September 30, 2026 · Correction — Corrected the twelve risk categories to match NIST AI 600-1 section 2, and removed statements that treated revoked EO 14110 as current. (Cody Maxwell)
This companion to NIST AI RMF 1.0 addresses generative AI risks. It covers large language models and multimodal foundation models (general-purpose models that handle text, images, and audio).
Applies To
Overview
NIST AI 600-1, formally titled 'Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,' was published in final form on July 26, 2024, in response to Executive Order 14110 on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (October 2023). The profile extends the National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF 1.0, January 2023) by mapping its four core functions (GOVERN, MAP, MEASURE, and MANAGE) to twelve generative-AI-specific risk categories. These categories cover risks the base AI RMF does not fully address. Examples include confabulation (AI stating false information confidently), intellectual property, and information integrity. Others are homogenization of outputs (many systems giving similar answers) and dangerous capabilities with dual uses. NIST AI 600-1 is structured as a profile, a prioritised set of outcomes drawn from the AI RMF Core, rather than a standalone standard or regulation. It is intended for use by AI developers, deployers, and operators and does not favour any particular technology or vendor. The document was developed through an open public comment process and reflects input from industry, academia, civil society, and international partners. EO 14110 was revoked in January 2025, but the profile remains published and in use, including in federal AI guidance. While voluntary for private-sector organisations, the profile is increasingly referenced in federal procurement solicitations, sector-specific regulatory guidance, and enterprise AI governance programmes. Enterprises building, fine-tuning (further training on their own data), or deploying generative AI systems, including retrieval-augmented generation (RAG) architectures (AI that answers from company documents), copilot tools (built-in AI assistants), and AI-assisted decision systems, should map internal controls to the twelve risk categories and associated suggested actions.
Key Requirements
- •CBRN Information or Capabilities: easier access to information that helps create chemical, biological, radiological, or nuclear weapons.
- •Confabulation: confidently presenting false or made-up content as fact.
- •Dangerous, Violent, or Hateful Content: easier production of violent, radicalizing, or threatening content, including encouragement of self-harm.
- •Data Privacy: leaking, inferring, or misusing personal data, including sensitive data memorized during training.
- •Environmental Impacts: the energy and resources used to train and run large models.
- •Harmful Bias and Homogenization: amplifying bias, and many systems producing the same narrow outputs.
- •Human-AI Configuration: over-reliance on AI, misplaced trust, and poorly designed human oversight.
- •Information Integrity: generating or spreading misleading content and synthetic media at scale.
- •Information Security: attacks on AI systems, such as prompt injection and data poisoning, and AI-assisted cyberattacks.
- •Intellectual Property: using or reproducing copyrighted or protected material without permission.
- •Obscene, Degrading, and/or Abusive Content: producing obscene or abusive imagery, including non-consensual intimate images.
- •Value Chain and Component Integration: risks from third-party models, data, and components that are not fully visible to the deployer.
What Your Organization Must Do
- →Map all generative AI systems currently in development or deployment to the twelve NIST AI 600-1 risk categories by assigning a responsible owner (e.g., AI risk lead or product owner) for each category and documenting gaps against the suggested actions in the profile.
- →Update the enterprise AI governance policy to explicitly address generative AI risks, including hallucination thresholds, chemical, biological, radiological, and nuclear (CBRN) misuse safeguards, and content moderation standards, and present the revised policy to the board or risk committee for approval within 90 days of system deployment or profile adoption.
- →Establish a confabulation and output quality monitoring programme with defined measurement cadences (at minimum quarterly), documented acceptable error rate thresholds, and a disclosure protocol for material confabulation incidents affecting end users or regulated decisions.
- →Require all third-party generative AI vendors and foundation model providers to supply model cards and system cards (documents describing how a model was built, tested, and should be used) and documentation of where training data came from as a contractual condition of procurement; assign third-party risk management to review these against profile requirements before contract execution.
- →Conduct a training data and output intellectual property review for any model being fine-tuned or deployed, engaging legal counsel to assess copyright exposure, and implement output filtering or attribution controls (blocking or crediting output that may copy protected work) where infringement risk is identified.
- →Align internal generative AI security controls with the profile's information security requirements by tasking the cybersecurity team to test for prompt injection (hidden instructions that trick the AI), data poisoning (tampering with training data), and model extraction (copying a model through repeated queries) vulnerabilities on a defined schedule (at minimum annually or after significant model updates), and report findings to the AI risk governance function.
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Governance Controls
Operational controls that implement requirements from this regulation.
Frequently Asked Questions
- Is NIST AI 600-1 mandatory for private companies?
- No. NIST AI 600-1 is voluntary for private-sector organizations. However, it is increasingly referenced in federal procurement solicitations, so companies selling generative AI solutions to U.S. government agencies may face contractual pressure to align with its requirements.
- How does NIST AI 600-1 differ from the NIST AI RMF 1.0?
- The AI RMF 1.0 is a general-purpose AI risk management framework. NIST AI 600-1 is a companion profile that applies its four functions to twelve risks specific to generative AI. Examples include confabulation, information integrity, and information security.
- Which twelve risk categories does NIST AI 600-1 address?
- The twelve risks are CBRN information or capabilities, confabulation, and dangerous, violent, or hateful content. They also include data privacy, environmental impacts, harmful bias and homogenization, and human-AI configuration. The rest are information integrity, information security, intellectual property, obscene, degrading, and/or abusive content, and value chain and component integration.
- Do federal agencies have to comply with NIST AI 600-1?
- The profile was written in response to Executive Order 14110, which was revoked in January 2025. It remains a voluntary NIST publication. Federal agencies follow current OMB guidance on AI, which may point to NIST resources such as this profile.
- What does NIST AI 600-1 require for third-party generative AI vendors?
- The profile calls for organizations to assess third-party model and component risks across the generative AI supply chain. In practice, this means requiring vendors to provide model cards, system cards, and training data provenance documentation, and reviewing those materials against profile requirements before contract execution.
- How should a compliance team handle hallucination risk under NIST AI 600-1?
- The profile suggests measuring and monitoring confabulation, validating outputs, and deciding in advance how to disclose material errors. It does not set a required measurement cadence. Quarterly measurement is a reasonable starting point for most deployments.
- What does NIST AI 600-1 require for retrieval-augmented generation (RAG) systems?
- The profile does not treat RAG as a separate risk category, but several categories apply directly. Confabulation controls should check that answers are grounded in the retrieved documents. Information Security covers prompt injection hidden in retrieved content. Value Chain and Component Integration covers third-party data sources and models behind the system.
- What human oversight mechanisms does NIST AI 600-1 require for generative AI?
- The Human-AI Configuration category calls for oversight matched to the risk of each application, not one fixed standard. Higher-risk uses, such as regulated decisions or vulnerable users, warrant more direct human review. In practice, document which outputs need human sign-off before use, and base that list on the cost of getting it wrong.
- What does NIST AI 600-1 require for data provenance and training data lineage?
- Data provenance is not one of the twelve risk categories, but it runs through the profile's suggested actions. They cover tracking where training data and generated content came from, especially for intellectual property, data privacy, and third-party components. For vendor models, ask for model cards and documentation of training data sources before signing.
- How should compliance teams address prompt injection risk under NIST AI 600-1?
- Prompt injection falls under the profile's Information Security category, alongside data poisoning and model extraction. The suggested actions call for testing against these attacks regularly and after significant model updates. Cover both direct injection by users and indirect injection through retrieved or ingested content.
