AI Regulation Tracker · NIST · Consultation

What does AI RMF critical-infrastructure profile (concept note) say about AI in banking?

Published Apr 7, 2026 · Last reviewed Aug 26, 2026

On April 7, 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, the first new AI RMF profile since the 2024 Generative AI Profile. The profile is meant to guide critical-infrastructure operators toward specific risk-management practices when adopting AI-enabled capabilities and to help them communicate trustworthiness requirements to developers and suppliers. NIST is developing it through a community of interest (mailing list and Slack) rather than a fixed comment deadline, and no draft profile had been released as of August 2026.

DocumentAI RMF critical-infrastructure profile (concept note)Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure
Issued byNational Institute of Standards and Technology — AI Risk Management Framework
TypeConsultation
StatusProposed
PublishedApr 7, 2026
Applies toVoluntary; operators of critical infrastructure. Financial services is a designated US critical-infrastructure sector, so banks are in scope of the eventual profile.
Official sourcenist.gov
Use casesAI governance (general) · Third-party & vendor AI · Cybersecurity

What are the key points of AI RMF critical-infrastructure profile (concept note)?

  • Concept note published April 7, 2026; project page last updated July 17, 2026.
  • Goal: sector-neutral practices for AI in critical infrastructure, expressed as an AI RMF profile so operators can map to Govern/Map/Measure/Manage.
  • Emphasizes communicating trustworthiness requirements across AI and infrastructure lifecycles and supply chains — i.e., pushing requirements to vendors.
  • Input invited from industry, regulators, policymakers and academia through an open community of interest; discussion drafts to follow.
  • Financial services is one of the sixteen US critical-infrastructure sectors, though the concept note does not single it out.

What did AI RMF critical-infrastructure profile (concept note) change for banks?

This is the first AI RMF profile aimed at operators rather than at a technology, and it is the vehicle most likely to carry sector-level expectations for banks. Because it is being written to help operators pass requirements to suppliers, it will likely inform what banks demand of AI vendors under third-party risk programs.

Does the NIST critical-infrastructure AI profile apply to banks?

Financial services is a US critical-infrastructure sector, so banks are within the intended audience, but the profile is voluntary and only a concept note (April 7, 2026) exists so far.

When will the critical-infrastructure AI RMF profile be published?

NIST has not given a date. It released a concept note on April 7, 2026 and is developing discussion drafts through a community of interest.

DateDocumentStatus
Jan 12, 2026CAISI RFI on AI agent security (2026)Request for Information: Security Considerations for Artificial Intelligence AgentsProposed
Dec 16, 2025NIST IR 8596 (Cyber AI Profile)Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draftProposed
Aug 14, 2025NIST COSAiS control overlaysControl Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AIProposed
Mar 24, 2025NIST AI 100-2e2025 (Adversarial ML)Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025)Final
Jul 26, 2024NIST AI 600-1 (Generative AI Profile)Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)In force
Jan 26, 2023NIST AI RMF 1.0Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1In force

Follow every document these regulators publish

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →