# AI RMF critical-infrastructure profile (concept note): Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure

Source: https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-critical-infrastructure-profile-concept-note
Last updated: Aug 26, 2026

On April 7, 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, the first new AI RMF profile since the 2024 Generative AI Profile. The profile is meant to guide critical-infrastructure operators toward specific risk-management practices when adopting AI-enabled capabilities and to help them communicate trustworthiness requirements to developers and suppliers. NIST is developing it through a community of interest (mailing list and Slack) rather than a fixed comment deadline, and no draft profile had been released as of August 2026.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) |
| Type | Consultation |
| Status | Proposed |
| Published | Apr 7, 2026 |
| Applies to | Voluntary; operators of critical infrastructure. Financial services is a designated US critical-infrastructure sector, so banks are in scope of the eventual profile. |
| Official text | https://www.nist.gov/programs-projects/concept-note-ai-rmf-profile-trustworthy-ai-critical-infrastructure |

## Key points

- Concept note published April 7, 2026; project page last updated July 17, 2026.
- Goal: sector-neutral practices for AI in critical infrastructure, expressed as an AI RMF profile so operators can map to Govern/Map/Measure/Manage.
- Emphasizes communicating trustworthiness requirements across AI and infrastructure lifecycles and supply chains — i.e., pushing requirements to vendors.
- Input invited from industry, regulators, policymakers and academia through an open community of interest; discussion drafts to follow.
- Financial services is one of the sixteen US critical-infrastructure sectors, though the concept note does not single it out.

## What changed for banks

This is the first AI RMF profile aimed at operators rather than at a technology, and it is the vehicle most likely to carry sector-level expectations for banks. Because it is being written to help operators pass requirements to suppliers, it will likely inform what banks demand of AI vendors under third-party risk programs.

## Use cases it governs

- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)

## FAQ

### Does the NIST critical-infrastructure AI profile apply to banks?

Financial services is a US critical-infrastructure sector, so banks are within the intended audience, but the profile is voluntary and only a concept note (April 7, 2026) exists so far.

### When will the critical-infrastructure AI RMF profile be published?

NIST has not given a date. It released a concept note on April 7, 2026 and is developing discussion drafts through a community of interest.

## Related documents

- [CAISI RFI on AI agent security (2026)](https://www.bankingnewsai.com/ai-regulation/documents/nist-caisi-rfi-ai-agent-security-2026) — Request for Information: Security Considerations for Artificial Intelligence Agents (Jan 12, 2026)
- [NIST IR 8596 (Cyber AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ir-8596) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft (Dec 16, 2025)
- [NIST COSAiS control overlays](https://www.bankingnewsai.com/ai-regulation/documents/nist-cosais-control-overlays) — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI (Aug 14, 2025)
- [NIST AI 100-2e2025 (Adversarial ML)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-2e2025) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) (Mar 24, 2025)
- [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) (Jul 26, 2024)
- [NIST SP 800-218A (SSDF profile for generative AI)](https://www.bankingnewsai.com/ai-regulation/documents/nist-sp-800-218a) — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (NIST SP 800-218A) (Jul 26, 2024)
- [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1) — Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (Jan 26, 2023)
- [NIST AI RMF Playbook](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-playbook) — AI Risk Management Framework Playbook (Jan 26, 2023)

Last reviewed Aug 26, 2026. Cite the official text (https://www.nist.gov/programs-projects/concept-note-ai-rmf-profile-trustworthy-ai-critical-infrastructure) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-critical-infrastructure-profile-concept-note
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
