# NIST IR 8596 (Cyber AI Profile): Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft

Source: https://www.bankingnewsai.com/ai-regulation/documents/nist-ir-8596
Last updated: Aug 26, 2026

NIST released the preliminary draft of NIST IR 8596, the Cybersecurity Framework Profile for Artificial Intelligence ('Cyber AI Profile'), on December 16, 2025, with comments due January 30, 2026. It applies the CSF 2.0 structure to three focus areas: securing AI system components (Secure), conducting AI-enabled cyber defense (Defend), and thwarting AI-enabled cyberattacks (Thwart). NIST said comments would inform an initial public draft expected in 2026; as of August 2026 that draft had not been published.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [NIST](https://www.bankingnewsai.com/ai-regulation/nist) |
| Type | Consultation |
| Status | Proposed · comment period closed |
| Published | Dec 16, 2025 |
| Comment deadline | Jan 30, 2026 |
| Applies to | Voluntary; organizations that use the NIST Cybersecurity Framework 2.0 and develop, deploy or defend against AI. Directly relevant to bank CISOs whose programs are CSF-aligned. |
| Official text | https://csrc.nist.gov/pubs/ir/8596/iprd |

## Key points

- Preliminary draft published December 16, 2025 by NIST's Computer Security Division; 45-day comment period closed January 30, 2026.
- Built on Cybersecurity Framework 2.0 (February 2024): for each CSF subcategory it explains what changes when the organization is securing AI, using AI for defense, or facing AI-enabled attackers.
- Three focus areas: Secure (AI components, data, models, pipelines), Defend (AI in SOC and detection workflows), Thwart (AI-augmented phishing, deepfakes, automated exploitation).
- Intended to be used with the AI RMF, AI 100-2 adversarial ML taxonomy and SP 800-53 controls rather than replace them.
- Next step is an initial public draft incorporating the preliminary-draft comments, then a final version.

## What changed for banks

For banks whose security programs are already mapped to CSF 2.0 — which examiners and the FFIEC cybersecurity tooling encourage — the Cyber AI Profile is the most direct route to extending existing control mapping to AI systems without adopting a new framework. It also formalizes the 'Thwart' angle: AI-enabled fraud and social engineering as a cybersecurity-program concern, not only a fraud-team concern.

## Use cases it governs

- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Fraud detection](https://www.bankingnewsai.com/ai-regulation/by-use-case#fraud)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)

## FAQ

### What is the NIST Cyber AI Profile?

A draft profile (NIST IR 8596) applying Cybersecurity Framework 2.0 to AI: securing AI systems, using AI for cyber defense, and defending against AI-enabled attacks. The preliminary draft was released December 16, 2025; comments closed January 30, 2026.

### Is NIST IR 8596 final?

No. As of August 2026 only the preliminary draft has been published. NIST has said an initial public draft will follow, then a final version.

## Related documents

- [AI RMF critical-infrastructure profile (concept note)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-critical-infrastructure-profile-concept-note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure (Apr 7, 2026)
- [CAISI RFI on AI agent security (2026)](https://www.bankingnewsai.com/ai-regulation/documents/nist-caisi-rfi-ai-agent-security-2026) — Request for Information: Security Considerations for Artificial Intelligence Agents (Jan 12, 2026)
- [NIST COSAiS control overlays](https://www.bankingnewsai.com/ai-regulation/documents/nist-cosais-control-overlays) — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI (Aug 14, 2025)
- [NIST AI 100-2e2025 (Adversarial ML)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-2e2025) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) (Mar 24, 2025)
- [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) (Jul 26, 2024)
- [NIST SP 800-218A (SSDF profile for generative AI)](https://www.bankingnewsai.com/ai-regulation/documents/nist-sp-800-218a) — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (NIST SP 800-218A) (Jul 26, 2024)
- [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1) — Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (Jan 26, 2023)
- [NIST AI RMF Playbook](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-playbook) — AI Risk Management Framework Playbook (Jan 26, 2023)

Last reviewed Aug 26, 2026. Cite the official text (https://csrc.nist.gov/pubs/ir/8596/iprd) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/nist-ir-8596
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
