NIST AI 600-1, the Generative AI Profile of the AI RMF, was published on July 26, 2024 as a companion to AI RMF 1.0. It identifies twelve risks unique to or exacerbated by generative AI — including confabulation, data privacy, information integrity, information security, intellectual property, harmful bias and homogenization, and value chain and component integration — and lists more than 200 suggested actions mapped to AI RMF subcategories. It was one of the deliverables under Executive Order 14110 (October 2023), which has since been revoked, but the profile remains published and in use.
| Document | NIST AI 600-1 (Generative AI Profile) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) |
| Issued by | National Institute of Standards and Technology — AI Risk Management Framework |
| Type | Framework |
| Status | In force |
| Published | Jul 26, 2024 |
| Effective | Jul 26, 2024 |
| Applies to | Voluntary; organizations developing or deploying generative AI. Used by banks for chatbots, coding assistants, document summarization and other LLM use cases. |
| Official source | nvlpubs.nist.gov ↗ |
| Use cases | Generative & agentic AI · Customer-facing chatbots · Cybersecurity · Third-party & vendor AI · Data & privacy |
What are the key points of NIST AI 600-1 (Generative AI Profile)?
- Published July 26, 2024, 270 days after Executive Order 14110; part of a package that also included the dual-use foundation model guidance and a secure software development profile for generative AI.
- Enumerates twelve generative-AI risk categories: CBRN information or capabilities; confabulation; dangerous, violent or hateful content; data privacy; environmental impacts; harmful bias and homogenization; human-AI configuration; information integrity; information security; intellectual property; obscene, degrading or abusive content; and value chain and component integration.
- Provides a table of suggested actions, each tied to an AI RMF subcategory (e.g., Govern 1.2, Measure 2.7) and tagged to the risks it addresses, plus the AI actor tasks involved.
- Information-security risks include prompt injection, data poisoning and model extraction; confabulation covers false or fabricated outputs presented confidently.
- Emphasizes third-party and value-chain risk — relevant to banks that consume foundation models through vendors and cloud providers rather than building them.
What did NIST AI 600-1 (Generative AI Profile) change for banks?
The profile gave banks a vocabulary for generative-AI risks that model-risk guidance did not name, and a ready-made control set for LLM deployments. When the April 2026 interagency model-risk revision explicitly excluded generative and agentic AI, AI 600-1 became the closest thing to a standard control catalogue US banks can cite for customer chatbots and internal LLM tooling.
What risks does NIST AI 600-1 cover?
Twelve categories specific to generative AI, including confabulation (hallucination), data privacy, information security (prompt injection, data poisoning), intellectual property, harmful bias and homogenization, human-AI configuration, and value chain and component integration.
Is the Generative AI Profile still valid after Executive Order 14110 was revoked?
Yes. The profile was produced under EO 14110 but is a standing NIST publication; it remains available and is widely used by banks, though NIST has said the underlying AI RMF is being revised under the 2025 AI Action Plan.
Does a bank need AI 600-1 if it only uses vendor LLMs?
The profile is explicitly written for deployers as well as developers, and its value-chain and component-integration risk category addresses exactly the vendor-supplied model scenario most banks are in.
| Date | Document | Status |
|---|---|---|
| Apr 7, 2026 | AI RMF critical-infrastructure profile (concept note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure | Proposed |
| Jan 12, 2026 | CAISI RFI on AI agent security (2026) — Request for Information: Security Considerations for Artificial Intelligence Agents | Proposed |
| Dec 16, 2025 | NIST IR 8596 (Cyber AI Profile) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft | Proposed |
| Aug 14, 2025 | NIST COSAiS control overlays — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI | Proposed |
| Mar 24, 2025 | NIST AI 100-2e2025 (Adversarial ML) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) | Final |
| Jan 26, 2023 | NIST AI RMF 1.0 — Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 | In force |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →