On April 7, 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, the first new AI RMF profile since the 2024 Generative AI Profile. The profile is meant to guide critical-infrastructure operators toward specific risk-management practices when adopting AI-enabled capabilities and to help them communicate trustworthiness requirements to developers and suppliers. NIST is developing it through a community of interest (mailing list and Slack) rather than a fixed comment deadline, and no draft profile had been released as of August 2026.
| Document | AI RMF critical-infrastructure profile (concept note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure |
| Issued by | National Institute of Standards and Technology — AI Risk Management Framework |
| Type | Consultation |
| Status | Proposed |
| Published | Apr 7, 2026 |
| Applies to | Voluntary; operators of critical infrastructure. Financial services is a designated US critical-infrastructure sector, so banks are in scope of the eventual profile. |
| Official source | nist.gov ↗ |
| Use cases | AI governance (general) · Third-party & vendor AI · Cybersecurity |
What are the key points of AI RMF critical-infrastructure profile (concept note)?
- Concept note published April 7, 2026; project page last updated July 17, 2026.
- Goal: sector-neutral practices for AI in critical infrastructure, expressed as an AI RMF profile so operators can map to Govern/Map/Measure/Manage.
- Emphasizes communicating trustworthiness requirements across AI and infrastructure lifecycles and supply chains — i.e., pushing requirements to vendors.
- Input invited from industry, regulators, policymakers and academia through an open community of interest; discussion drafts to follow.
- Financial services is one of the sixteen US critical-infrastructure sectors, though the concept note does not single it out.
What did AI RMF critical-infrastructure profile (concept note) change for banks?
This is the first AI RMF profile aimed at operators rather than at a technology, and it is the vehicle most likely to carry sector-level expectations for banks. Because it is being written to help operators pass requirements to suppliers, it will likely inform what banks demand of AI vendors under third-party risk programs.
Does the NIST critical-infrastructure AI profile apply to banks?
Financial services is a US critical-infrastructure sector, so banks are within the intended audience, but the profile is voluntary and only a concept note (April 7, 2026) exists so far.
When will the critical-infrastructure AI RMF profile be published?
NIST has not given a date. It released a concept note on April 7, 2026 and is developing discussion drafts through a community of interest.
| Date | Document | Status |
|---|---|---|
| Jan 12, 2026 | CAISI RFI on AI agent security (2026) — Request for Information: Security Considerations for Artificial Intelligence Agents | Proposed |
| Dec 16, 2025 | NIST IR 8596 (Cyber AI Profile) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft | Proposed |
| Aug 14, 2025 | NIST COSAiS control overlays — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI | Proposed |
| Mar 24, 2025 | NIST AI 100-2e2025 (Adversarial ML) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) | Final |
| Jul 26, 2024 | NIST AI 600-1 (Generative AI Profile) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) | In force |
| Jan 26, 2023 | NIST AI RMF 1.0 — Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 | In force |
Follow every document these regulators publish
6 curated AI stories for banking executives · Every morning · Free
Subscribe to BankingNewsAI →