# NIST AI 600-1 (Generative AI Profile): Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)

Source: https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1
Last updated: Sep 17, 2026

NIST AI 600-1, the Generative AI Profile of the AI RMF, was published on July 26, 2024 as a companion to AI RMF 1.0. It identifies twelve risks unique to or exacerbated by generative AI — including confabulation, data privacy, information integrity, information security, intellectual property, harmful bias and homogenization, and value chain and component integration — and lists more than 200 suggested actions mapped to AI RMF subcategories. It was one of the deliverables under Executive Order 14110 (October 2023), which has since been revoked, but the profile remains published and in use.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) |
| Type | Framework |
| Status | In force |
| Published | Jul 26, 2024 |
| Effective | Jul 26, 2024 |
| Applies to | Voluntary; organizations developing or deploying generative AI. Used by banks for chatbots, coding assistants, document summarization and other LLM use cases. |
| Official text | https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf |

## Key points

- Published July 26, 2024, 270 days after Executive Order 14110; part of a package that also included the dual-use foundation model guidance and a secure software development profile for generative AI.
- Enumerates twelve generative-AI risk categories: CBRN information or capabilities; confabulation; dangerous, violent or hateful content; data privacy; environmental impacts; harmful bias and homogenization; human-AI configuration; information integrity; information security; intellectual property; obscene, degrading or abusive content; and value chain and component integration.
- Provides a table of suggested actions, each tied to an AI RMF subcategory (e.g., Govern 1.2, Measure 2.7) and tagged to the risks it addresses, plus the AI actor tasks involved.
- Information-security risks include prompt injection, data poisoning and model extraction; confabulation covers false or fabricated outputs presented confidently.
- Emphasizes third-party and value-chain risk — relevant to banks that consume foundation models through vendors and cloud providers rather than building them.

## What changed for banks

The profile gave banks a vocabulary for generative-AI risks that model-risk guidance did not name, and a ready-made control set for LLM deployments. When the April 2026 interagency model-risk revision explicitly excluded generative and agentic AI, AI 600-1 became the closest thing to a standard control catalogue US banks can cite for customer chatbots and internal LLM tooling.

## Use cases it governs

- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [Customer-facing chatbots](https://www.bankingnewsai.com/ai-regulation/by-use-case#customer-chatbots)
- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Data & privacy](https://www.bankingnewsai.com/ai-regulation/by-use-case#data-privacy)
- [AI-generated code & coding agents](https://www.bankingnewsai.com/ai-regulation/by-use-case#ai-generated-code)

## What is NIST AI 600-1 and how does it apply to banks?

NIST AI 600-1 is the Generative AI Profile of the NIST AI Risk Management Framework, published on July 26, 2024 as a companion to AI RMF 1.0. It names twelve risks that are unique to or made worse by generative AI — CBRN information, confabulation, dangerous or hateful content, data privacy, environmental impacts, harmful bias and homogenization, human-AI configuration, information integrity, information security, intellectual property, obscene or abusive content, and value chain and component integration — and lists more than 200 suggested actions, each mapped to an AI RMF subcategory such as Govern 1.2 or Measure 2.7. It is voluntary and written for deployers as well as developers, which is the position most banks are in. For banks its importance grew in April 2026, when the interagency model risk guidance (SR 26-2, OCC Bulletin 2026-13, FIL-15-2026) placed generative and agentic AI outside its scope: AI 600-1 is now the closest thing to a standard control catalogue a US bank can cite for customer chatbots, coding assistants, document summarisation and other LLM uses, and Treasury's February 2026 FS AI RMF adapts the same framework for financial services.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| NIST AI 600-1, the twelve generative-AI risks | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | Confabulation, information security (prompt injection, data poisoning, model extraction), data privacy, harmful bias and homogenization, information integrity, intellectual property, human-AI configuration, value chain and component integration, plus CBRN, dangerous and obscene content and environmental impact. | Published Jul 26, 2024 | [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1) |
| NIST AI 600-1, suggested actions | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | 200+ actions tied to AI RMF subcategories and tagged to the risks they address and the AI actor tasks involved — the checklist a bank's AI control framework can adopt for LLM deployments. | Voluntary | [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1) |
| NIST AI RMF 1.0 (AI 100-1) | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | The parent framework: Govern, Map, Measure and Manage functions and seven trustworthiness characteristics that the profile's actions are organised under. | Since Jan 26, 2023 | [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1) |
| NIST AI RMF Playbook | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | Implementation suggestions for each RMF subcategory; AI 600-1 extends it for generative AI. | Since Jan 2023 | [NIST AI RMF Playbook](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-playbook) |
| NIST AI 100-2e2025 (adversarial machine learning) | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | The taxonomy behind the profile's information-security risk: evasion, poisoning, privacy and misuse attacks on predictive and generative systems, with mitigations. | Mar 24, 2025 | [NIST AI 100-2e2025 (Adversarial ML)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-2e2025) |
| NIST CAISI request for information on AI agent security | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) | Where the profile's generative-AI controls meet agents: indirect prompt injection, misaligned behaviour and constraining agent access. | Jan 12, 2026 | [CAISI RFI on AI agent security (2026)](https://www.bankingnewsai.com/ai-regulation/documents/nist-caisi-rfi-ai-agent-security-2026) |
| Interagency model risk guidance (SR 26-2 / OCC 2026-13 / FIL-15-2026) | [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve) | Generative and agentic AI 'are not within the scope of this guidance' and are managed through broader risk management and governance — the gap AI 600-1 fills for US banks. | In force from Apr 17, 2026 | [SR 26-2](https://www.bankingnewsai.com/ai-regulation/documents/fed-sr-26-2) |
| Treasury FS AI RMF and AI Lexicon | [U.S. Treasury](https://www.bankingnewsai.com/ai-regulation/treasury) | Adapts the NIST AI RMF, including its generative-AI content, to financial-services operations, regulation and consumer protection. | Feb 19, 2026 | [Treasury FS AI RMF and AI Lexicon (Feb 2026)](https://www.bankingnewsai.com/ai-regulation/documents/treasury-fs-ai-rmf-and-ai-lexicon-2026) |
| CFPB issue spotlight on chatbots | [CFPB](https://www.bankingnewsai.com/ai-regulation/cfpb) | The consumer-law consequence of confabulation: inaccurate chatbot answers and blocked access to a human can violate UDAAP and the Regulation E and Z duties. | Jun 2023 | [CFPB Chatbots in Consumer Finance (issue spotlight, 2023)](https://www.bankingnewsai.com/ai-regulation/documents/cfpb-chatbots-in-consumer-finance-2023) |
| FSB Sound Practices 6–11 | [FSB](https://www.bankingnewsai.com/ai-regulation/fsb) | Model selection, data governance, explainability, performance management, human oversight and cyber controls for generative and agentic AI — the international counterpart to the profile's action list. | Final report due Oct 2026 | [FSB AI sound practices consultation (June 2026)](https://www.bankingnewsai.com/ai-regulation/documents/fsb-ai-sound-practices-consultation-2026) |

AI 600-1 was one of the deliverables Executive Order 14110 assigned to NIST for 270 days after October 2023, published on the same day as the secure-software-development profile for generative AI (SP 800-218A) and the dual-use foundation model guidance. The Executive Order has since been revoked, but the profile is a standing NIST publication, remains in use, and NIST has said the underlying AI RMF is being revised under the 2025 AI Action Plan. Its structure is a risk list plus an action table: each of the twelve risks is defined, then the suggested actions are given with the RMF subcategory they implement, the risks they address and the AI actor tasks involved, so a bank can pick the rows that match its role — almost always deployer and integrator rather than model developer.

Four of the twelve risks carry most of the weight in banking. Confabulation is the chatbot and summarisation problem: fabricated balances, invented policy terms, wrong reasons, presented confidently. Information security is prompt injection, data poisoning and model extraction, the attack surface the CAISI agent-security work and NIST's adversarial-ML taxonomy elaborate. Data privacy covers the customer and employee data that flows into prompts, retrieval stores and fine-tuning. Value chain and component integration is the vendor question: most banks consume foundation models through cloud providers and platforms, and the profile's actions on provenance, third-party evaluation and integration testing are what an SR 23-4 vendor file for an AI provider should contain. Harmful bias and homogenization and information integrity matter wherever a generative system touches a customer decision or a public communication.

The profile's practical role in a bank is to be the control catalogue for the AI that the 2026 model risk guidance excludes. A generative-AI use case that is not a 'model' in the 2026 sense still needs a governance path, and examiners ask what it is; citing AI 600-1's actions — mapped to the RMF's Govern, Map, Measure and Manage functions — gives that path a recognised structure, and Treasury's FS AI RMF shows how to phrase it in financial-services terms. It does not replace validation for the scoring or monitoring models a generative system may call, and it does not by itself satisfy consumer-protection law; it is the layer between the two.

### What this means in practice

- Adopt the profile's action table as the control baseline for every LLM use case that falls outside the 2026 model definition, and record which actions are implemented, by whom, for each system.
- Map the four banking-relevant risks — confabulation, information security, data privacy, value chain — to owners: product for confabulation testing, security for prompt injection and poisoning, privacy for prompt and retrieval data, vendor management for the value chain.
- Use the value-chain actions as the specification for AI vendor due diligence under SR 23-4: provenance of training data, evaluation results, change notification, and what the provider will let the bank test.
- Pair the profile with the CFPB's chatbot findings for anything customer-facing: accuracy testing, dispute recognition and a route to a human are the legal consequence of the confabulation risk.
- Watch for the revised AI RMF under the 2025 AI Action Plan and the promised interagency RFI on AI and model risk; both will change how the profile is referenced, not whether it applies.

## FAQ

### What risks does NIST AI 600-1 cover?

Twelve categories specific to generative AI, including confabulation (hallucination), data privacy, information security (prompt injection, data poisoning), intellectual property, harmful bias and homogenization, human-AI configuration, and value chain and component integration.

### Is the Generative AI Profile still valid after Executive Order 14110 was revoked?

Yes. The profile was produced under EO 14110 but is a standing NIST publication; it remains available and is widely used by banks, though NIST has said the underlying AI RMF is being revised under the 2025 AI Action Plan.

### Does a bank need AI 600-1 if it only uses vendor LLMs?

The profile is explicitly written for deployers as well as developers, and its value-chain and component-integration risk category addresses exactly the vendor-supplied model scenario most banks are in.

## Compare

- [NIST AI RMF vs ISO 42001](https://www.bankingnewsai.com/ai-regulation/compare/nist-ai-rmf-vs-iso-42001): NIST AI RMF vs ISO/IEC 42001: Which Should a Bank Use?

## Which AI tools for banks does NIST AI 600-1 (Generative AI Profile) apply to?

- [Conversational AI](https://www.bankingnewsai.com/ai-tools/conversational-ai) — Generative AI risk: [Kasisto](https://www.bankingnewsai.com/vendors/kasisto) · [Glia](https://www.bankingnewsai.com/vendors/glia) · [interface.ai](https://www.bankingnewsai.com/vendors/interface-ai) · [Talkdesk](https://www.bankingnewsai.com/vendors/talkdesk) · [Personetics](https://www.bankingnewsai.com/vendors/personetics) · [Eltropy](https://www.bankingnewsai.com/vendors/eltropy) · [Backbase](https://www.bankingnewsai.com/vendors/backbase)
- [Enterprise AI assistants](https://www.bankingnewsai.com/ai-tools/enterprise-ai-assistants) — Generative AI risk management: [Microsoft Copilot](https://www.bankingnewsai.com/vendors/microsoft-copilot) · [ChatGPT Enterprise](https://www.bankingnewsai.com/vendors/openai-chatgpt-enterprise) · [Claude](https://www.bankingnewsai.com/vendors/anthropic-claude) · [Gemini Enterprise](https://www.bankingnewsai.com/vendors/google-gemini-enterprise) · [Amazon Bedrock](https://www.bankingnewsai.com/vendors/amazon-bedrock) · [GitHub Copilot](https://www.bankingnewsai.com/vendors/github-copilot)
- [Model risk and AI governance](https://www.bankingnewsai.com/ai-tools/model-risk-governance) — NIST AI RMF: [ValidMind](https://www.bankingnewsai.com/vendors/validmind) · [Credo AI](https://www.bankingnewsai.com/vendors/credo-ai) · [SAS Model Risk](https://www.bankingnewsai.com/vendors/sas-model-risk) · [Monitaur](https://www.bankingnewsai.com/vendors/monitaur) · [Yields](https://www.bankingnewsai.com/vendors/yields-io)

## Related documents

- [AI RMF critical-infrastructure profile (concept note)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-critical-infrastructure-profile-concept-note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure (Apr 7, 2026)
- [CAISI RFI on AI agent security (2026)](https://www.bankingnewsai.com/ai-regulation/documents/nist-caisi-rfi-ai-agent-security-2026) — Request for Information: Security Considerations for Artificial Intelligence Agents (Jan 12, 2026)
- [NIST IR 8596 (Cyber AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ir-8596) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft (Dec 16, 2025)
- [NIST COSAiS control overlays](https://www.bankingnewsai.com/ai-regulation/documents/nist-cosais-control-overlays) — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI (Aug 14, 2025)
- [NIST AI 100-2e2025 (Adversarial ML)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-2e2025) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) (Mar 24, 2025)
- [NIST SP 800-218A (SSDF profile for generative AI)](https://www.bankingnewsai.com/ai-regulation/documents/nist-sp-800-218a) — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (NIST SP 800-218A) (Jul 26, 2024)
- [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1) — Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (Jan 26, 2023)
- [NIST AI RMF Playbook](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-playbook) — AI Risk Management Framework Playbook (Jan 26, 2023)

Last reviewed Sep 17, 2026. Cite the official text (https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
