NIST Generative AI Profile (AI 600-1)
Published July 2024 as NIST AI 600-1, the Generative AI Profile adapts the AI RMF Core to the specific risks of generative AI systems. It identifies 12 GAI-specific risk areas and provides over 400 suggested actions mapped to the Govern, Map, Measure, and Manage functions.
The 12 GAI Risk Areas
NIST identifies these risks by section number within AI 600-1 §2. The section numbers below are NIST's own; they are the only identifiers a reader can look up in the publication.
| Risk Area | AI 600-1 § | Description | Core Mapping |
|---|---|---|---|
| CBRN Information or Capabilities | §2.1 | Chemical, biological, radiological, nuclear weaponization assistance | MANAGE-1, MANAGE-2 |
| Confabulation | §2.2 | Fabricated outputs presented as factual ("hallucination") | MEASURE-2, MANAGE-2 |
| Dangerous, Violent, or Hateful Content | §2.3 | Generation of harmful, violent, or self-harm content | MANAGE-1, MANAGE-2 |
| Data Privacy | §2.4 | Training data extraction, PII leakage, membership inference | GOVERN-3, MAP-2, MEASURE-1 |
| Environmental Impacts | §2.5 | Compute and energy intensity of training/inference | GOVERN-1, MAP-3 |
| Harmful Bias and Homogenization | §2.6 | Amplification of societal bias; output homogenization and model collapse | GOVERN-3, MEASURE-2, MANAGE-2 |
| Human-AI Configuration | §2.7 | Over-reliance, automation bias, anthropomorphism | GOVERN-2, MAP-4 |
| Information Integrity | §2.8 | Disinformation, deepfakes, synthetic media at scale | MANAGE-1, MANAGE-3 |
| Information Security | §2.9 | Lowered barriers to offensive cyber capability; expanded attack surface; cyberattack assistance and malware generation | MANAGE-1, MANAGE-2 |
| Intellectual Property | §2.10 | Copyright infringement, training data rights, output ownership | GOVERN-3, MAP-5 |
| Obscene, Degrading, and/or Abusive Content | §2.11 | Hate speech, harassment, non-consensual synthetic imagery | MANAGE-1, MANAGE-2 |
| Value Chain and Component Integration | §2.12 | Third-party model, data, and tool dependencies | GOVERN-4, MAP-3, MANAGE-4 |
Primary source: NIST AI 600-1, §2 (Overview of Risks Unique to or Exacerbated by GAI). https://doi.org/10.6028/NIST.AI.600-1
Note on transparency and explainability: AI 600-1 §2 has no "non-transparent / unexplainable output" risk area. Explainability is addressed in AI RMF 1.0 (AI 100-1) as the Explainable and Interpretable trustworthiness characteristic — cite that, not AI 600-1.
Action Structure
Each risk area includes actions organised by Core function:
§2.2 (Confabulation) example actions:
GOVERN-2.1: Establish policies for hallucination risk tolerance
MAP-2.3: Identify use cases where confabulation is unacceptable
MEASURE-2.1: Implement groundedness metrics (e.g., citation verification)
MANAGE-2.2: Deploy retrieval-augmented generation with citation enforcement
Relationship to AI RMF 1.0
AI 600-1 does not replace AI 100-1. It is a Profile that:
- Retains all Core functions and categories
- Adds GAI-specific subcategories and actions
- References the same Playbook structure
- Requires implementing organisations to also address base AI RMF risks
Citation
- Instrument: NIST AI 600-1 — Artificial Intelligence Risk Management Framework: Generative AI Profile
- Publisher: National Institute of Standards and Technology
- Date: July 2024
- URL: https://airc.nist.gov/AI_RMF_Knowledge_Base/Generative_AI
- DOI: https://doi.org/10.6028/NIST.AI.600-1
- Status: Voluntary Profile; intended to be used with AI RMF 1.0