United States / Global voluntary use · framework

NIST AI RMF Generative AI Profile (NIST AI 600-1)

Cross-sectoral companion profile to NIST AI RMF focused on risks and risk-management actions specific to generative AI.

voluntaryU.S. National Institute of Standards and TechnologyVerified 23 Aug 2026

Applicability

Developers, deployers and users managing generative AI risks throughout the lifecycle.

Enforcement context

Voluntary reference framework.

Regulatory timeline

Material dates and status changes.

26 Jul 2024

NIST GenAI Profile

Cross-sectoral companion profile to NIST AI RMF focused on risks and risk-management actions specific to generative AI.

Source for this event →

CRG implementation mapping

Operational obligations and evidence expectations.

GAI-CONT

Content provenance and integrity

Assess provenance, content integrity and misuse controls where generated content can cause material harm.

Actor: all · Domain: transparency

Evidence: Provenance controls, watermark/label assessment and abuse monitoring.

GAI-EVAL

Generative AI evaluation

Evaluate relevant generative-AI risks with methods suited to the use context, including capability and failure testing.

Actor: all · Domain: evaluation

Evidence: Evaluation suite, results, limitations and remediation tracking.

GAI-SEC

Generative AI security testing

Assess prompt injection, data leakage, misuse, model/agent access and other relevant security risks.

Actor: all · Domain: security

Evidence: Threat model, red-team evidence, security test results and fixes.

Primary source

Verify the underlying instrument.

Cybatar's mapping is designed for AI governance and assurance work. Legal interpretation remains anchored to the current primary text and competent authority guidance.

Open NIST source