AI Governance Institute

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
VoluntaryFrameworkUS

NIST AI 600-1 Generative AI Profile

Issued by

National Institute of Standards and Technology (NIST), U.S. Department of Commerce

liveEffective 2024-07-26NIST AI 600-1Updated September 2026
Official document →

This companion to NIST AI RMF 1.0 addresses generative AI risks. It covers large language models and multimodal foundation models (general-purpose models that handle text, images, and audio).

Applies To

U.S. federal agencies following OMB AI guidanceFederal contractors and vendors providing generative AI solutions to U.S. government agenciesEnterprises developing or fine-tuning large language models or multimodal foundation modelsOrganisations deploying generative AI in customer-facing, employee-facing, or decision-support rolesAI risk, compliance, and legal functions responsible for model governance and documentationCybersecurity teams managing prompt injection, adversarial attack, and model integrity risksProcurement and third-party risk teams evaluating generative AI vendor risk

Overview

NIST AI 600-1, formally titled 'Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,' was published in final form on July 26, 2024, in response to Executive Order 14110 on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (October 2023). The profile extends the National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF 1.0, January 2023) by mapping its four core functions (GOVERN, MAP, MEASURE, and MANAGE) to twelve generative-AI-specific risk categories. These categories cover risks the base AI RMF does not fully address. Examples include confabulation (AI stating false information confidently), intellectual property, and information integrity. Others are homogenization of outputs (many systems giving similar answers) and dangerous capabilities with dual uses. NIST AI 600-1 is structured as a profile, a prioritised set of outcomes drawn from the AI RMF Core, rather than a standalone standard or regulation. It is intended for use by AI developers, deployers, and operators and does not favour any particular technology or vendor. The document was developed through an open public comment process and reflects input from industry, academia, civil society, and international partners. EO 14110 was revoked in January 2025, but the profile remains published and in use, including in federal AI guidance. While voluntary for private-sector organisations, the profile is increasingly referenced in federal procurement solicitations, sector-specific regulatory guidance, and enterprise AI governance programmes. Enterprises building, fine-tuning (further training on their own data), or deploying generative AI systems, including retrieval-augmented generation (RAG) architectures (AI that answers from company documents), copilot tools (built-in AI assistants), and AI-assisted decision systems, should map internal controls to the twelve risk categories and associated suggested actions.

Key Requirements

  • •CBRN Information or Capabilities: easier access to information that helps create chemical, biological, radiological, or nuclear weapons.
  • •Confabulation: confidently presenting false or made-up content as fact.
  • •Dangerous, Violent, or Hateful Content: easier production of violent, radicalizing, or threatening content, including encouragement of self-harm.
  • •Data Privacy: leaking, inferring, or misusing personal data, including sensitive data memorized during training.
  • •Environmental Impacts: the energy and resources used to train and run large models.
  • •Harmful Bias and Homogenization: amplifying bias, and many systems producing the same narrow outputs.
  • •Human-AI Configuration: over-reliance on AI, misplaced trust, and poorly designed human oversight.
  • •Information Integrity: generating or spreading misleading content and synthetic media at scale.
  • •Information Security: attacks on AI systems, such as prompt injection and data poisoning, and AI-assisted cyberattacks.
  • •Intellectual Property: using or reproducing copyrighted or protected material without permission.
  • •Obscene, Degrading, and/or Abusive Content: producing obscene or abusive imagery, including non-consensual intimate images.
  • •Value Chain and Component Integration: risks from third-party models, data, and components that are not fully visible to the deployer.

What Your Organization Must Do

  • →Map all generative AI systems currently in development or deployment to the twelve NIST AI 600-1 risk categories by assigning a responsible owner (e.g., AI risk lead or product owner) for each category and documenting gaps against the suggested actions in the profile.
  • →Update the enterprise AI governance policy to explicitly address generative AI risks, including hallucination thresholds, chemical, biological, radiological, and nuclear (CBRN) misuse safeguards, and content moderation standards, and present the revised policy to the board or risk committee for approval within 90 days of system deployment or profile adoption.
  • →Establish a confabulation and output quality monitoring programme with defined measurement cadences (at minimum quarterly), documented acceptable error rate thresholds, and a disclosure protocol for material confabulation incidents affecting end users or regulated decisions.
  • →Require all third-party generative AI vendors and foundation model providers to supply model cards and system cards (documents describing how a model was built, tested, and should be used) and documentation of where training data came from as a contractual condition of procurement; assign third-party risk management to review these against profile requirements before contract execution.
  • →Conduct a training data and output intellectual property review for any model being fine-tuned or deployed, engaging legal counsel to assess copyright exposure, and implement output filtering or attribution controls (blocking or crediting output that may copy protected work) where infringement risk is identified.
  • →Align internal generative AI security controls with the profile's information security requirements by tasking the cybersecurity team to test for prompt injection (hidden instructions that trick the AI), data poisoning (tampering with training data), and model extraction (copying a model through repeated queries) vulnerabilities on a defined schedule (at minimum annually or after significant model updates), and report findings to the AI risk governance function.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Governance Controls

Operational controls that implement requirements from this regulation.

AGT-001Agent Permission BoundariesAGT-002Agent Prompt Injection DefenseAGT-004Multi-Agent Trust HierarchyAGT-007Agent Scope and Task BoundariesAGT-009Agent and Non-Human Identity ManagementAGT-010Agent Knowledge Source IntegrityAGT-011Agent Behavior Monitoring and Anomaly DetectionAGT-012Agent Kill Switch and Emergency StopAGT-016Agentic AI Deployment Readiness AssessmentAGT-017Agentic Autonomy Expansion CriteriaAGT-018Agent Data Modification Blast-Radius ContainmentAGT-019AI Tool and Plugin Supply Chain Risk AssessmentAGT-020RAG Retrieval Boundary Controls for Regulated DataAGT-021Human Oversight Classification Rationale LogAGT-022Agentic AI Governance Tooling AttestationAGT-023Agentic AI Security Assessment, CBRN and Cyber EspionageAGT-024AI Permission Escalation Tabletop Exercise ProgramAGT-028Agent External System Access BoundariesBRD-001Director AI Literacy and Competency AssessmentBRD-002AI Governance Committee Charter and Decision RightsBRD-005AI Governance Maturity AssessmentBRD-006AI Risk Tolerance and Appetite DocumentationBRD-008Voluntary AI Governance Adequacy StandardBRD-009Unified Multi-Framework AI Risk RegisterCMP-001Multi-Jurisdiction AI Regulatory Compliance MappingCMP-002International AI Standards Monitoring WorkflowCMP-008Federal AI Regulatory Monitoring and Pre-Deployment VettingHOC-001AI System Risk ClassificationHOC-002Human Approval Gate for Consequential AI DecisionsHOC-004Automation Bias PreventionMGV-001AI Model Preview and Staged Release PolicyMGV-002AI System Intake and Approval WorkflowMGV-003AI Governance Program Milestone FrameworkMGV-004Continuous AI Assurance Function DesignMGV-005Generative AI Input Data ClassificationMGV-006RAI Benchmark-Aligned Evaluation FrameworkMGV-007Emerging AI Modality Classification and Governance ExtensionMGV-008AI-Generated Deliverable Disclosure and Citation StandardsMGV-009AI Capability Claim Substantiation StandardMGV-010AI Output Pre-Publication Verification for High-Stakes ClaimsMON-003AI Bias and Fairness MonitoringPRC-003Third-Party AI Model EvaluationPRC-008Vendor Model Update Disclosure and Re-Assessment ProtocolPRC-009AI Vendor Concentration Risk AssessmentPRC-010AI Vendor Financial Stability AssessmentPRC-011Federal AI Procurement Submission and Review ProcessPRC-012AI Safety Index and Benchmark MonitoringPRC-013AI Platform Conflict-of-Interest AssessmentPRC-014Shadow AI and Third-Party Widget Inventory and ClassificationPRC-015Procurement-Stage AI Governance ConditionsPRC-016AI Developer Tool Data Boundary ControlsSAF-001Hallucination Detection and MitigationSCT-001Anthropomorphic and Companion AI SafeguardsSCT-002Clinical AI Governance Committee CharterSCT-004Insurance Sector AI Documentation StandardsSCT-006Self-Hosted Open-Weight AI Model GovernanceSCT-007Consumer and External AI Tool Acceptable Use PolicySCT-009AI System Algorithm RegisterSEC-001Prompt Injection PreventionSEC-005Adversarial Robustness TestingSEC-006Deepfake Impersonation Defense for Approvals and Payments

Frequently Asked Questions

Is NIST AI 600-1 mandatory for private companies?
No. NIST AI 600-1 is voluntary for private-sector organizations. However, it is increasingly referenced in federal procurement solicitations, so companies selling generative AI solutions to U.S. government agencies may face contractual pressure to align with its requirements.
How does NIST AI 600-1 differ from the NIST AI RMF 1.0?
The AI RMF 1.0 is a general-purpose AI risk management framework. NIST AI 600-1 is a companion profile that applies its four functions to twelve risks specific to generative AI. Examples include confabulation, information integrity, and information security.
Which twelve risk categories does NIST AI 600-1 address?
The twelve risks are CBRN information or capabilities, confabulation, and dangerous, violent, or hateful content. They also include data privacy, environmental impacts, harmful bias and homogenization, and human-AI configuration. The rest are information integrity, information security, intellectual property, obscene, degrading, and/or abusive content, and value chain and component integration.
Do federal agencies have to comply with NIST AI 600-1?
The profile was written in response to Executive Order 14110, which was revoked in January 2025. It remains a voluntary NIST publication. Federal agencies follow current OMB guidance on AI, which may point to NIST resources such as this profile.
What does NIST AI 600-1 require for third-party generative AI vendors?
The profile calls for organizations to assess third-party model and component risks across the generative AI supply chain. In practice, this means requiring vendors to provide model cards, system cards, and training data provenance documentation, and reviewing those materials against profile requirements before contract execution.
How should a compliance team handle hallucination risk under NIST AI 600-1?
The profile suggests measuring and monitoring confabulation, validating outputs, and deciding in advance how to disclose material errors. It does not set a required measurement cadence. Quarterly measurement is a reasonable starting point for most deployments.
What does NIST AI 600-1 require for retrieval-augmented generation (RAG) systems?
The profile does not treat RAG as a separate risk category, but several categories apply directly. Confabulation controls should check that answers are grounded in the retrieved documents. Information Security covers prompt injection hidden in retrieved content. Value Chain and Component Integration covers third-party data sources and models behind the system.
What human oversight mechanisms does NIST AI 600-1 require for generative AI?
The Human-AI Configuration category calls for oversight matched to the risk of each application, not one fixed standard. Higher-risk uses, such as regulated decisions or vulnerable users, warrant more direct human review. In practice, document which outputs need human sign-off before use, and base that list on the cost of getting it wrong.
What does NIST AI 600-1 require for data provenance and training data lineage?
Data provenance is not one of the twelve risk categories, but it runs through the profile's suggested actions. They cover tracking where training data and generated content came from, especially for intellectual property, data privacy, and third-party components. For vendor models, ask for model cards and documentation of training data sources before signing.
How should compliance teams address prompt injection risk under NIST AI 600-1?
Prompt injection falls under the profile's Information Security category, alongside data poisoning and model extraction. The suggested actions call for testing against these attacks regularly and after significant model updates. Cover both direct injection by users and indirect injection through retrieved or ingested content.