NIST AI 600-1, the Generative AI Profile, is a cross-sectoral companion profile to the NIST AI RMF 1.0 published by National Institute of Standards and Technology (NIST) on July 26, 2024. It defines 12 generative-AI risk categories and maps more than 200 suggested actions onto the RMF's Govern, Map, Measure, and Manage subcategories. The profile was developed pursuant to Executive Order 14110 — Safe, Secure, and Trustworthy AI § 4.1(a)(i)(A) and remains in force as a voluntary reference following that order's rescission.
The named authors are Chloe Autio, Jesse Dunietz, Patrick Hall, Shomik Jain, Kamie Roberts, Reva Schwartz, Martin Stanley, and Elham Tabassi. The document carries DOI https://doi.org/10.6028/NIST.AI.600-1.
What the profile is
A profile, in the AI RMF framework, implements the RMF's functions, categories, and subcategories for a specific setting. NIST AI 600-1 is a cross-sectoral profile that applies the RMF to generative AI and generative foundation models specifically. Where NIST AI 100-1 (RMF 1.0) is the general framework, NIST AI 600-1 is its generative-AI-specific instantiation. Both are voluntary, and together they serve as a US federal common vocabulary for AI risk management, referenced by SB 53, the Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment), and state attorney-general AI guidances.
12 GAI risk categories
The profile enumerates 12 categories of generative-AI risk:
- CBRN information or capabilities — eased access to chemical, biological, radiological, or nuclear design or synthesis information.
- Confabulation — plausible but false outputs (hallucinations).
- Dangerous, violent, or hateful content.
- Data privacy — leakage of training data, re-identification.
- Environmental impacts — training and inference energy and water use.
- Harmful bias or homogenization — discriminatory outputs; algorithmic monocultures.
- Human-AI configuration — anthropomorphism, inappropriate reliance.
- Information integrity — deepfakes, disinformation at scale.
- Information security — cyber-offense uplift.
- Intellectual property — unauthorized reproduction or ingestion of copyrighted works.
- Obscene, degrading, and/or abusive content — including CSAM.
- Value chain and component integration — risks from third-party data, models, and compute.
Suggested-action mapping
Suggested actions are labeled with AI RMF subcategory codes and tagged with the GAI risks they address, organized under the RMF's four functions:
- Govern (GV-) — organizational culture, policies, roles, and third-party and IP governance.
- Map (MP-) — contextualization, impact assessment, stakeholder engagement.
- Measure (MS-) — benchmarks, red-teaming, incident tracking, content provenance.
- Manage (MG-) — prioritization, decommissioning, continuous monitoring, feedback loops.
Appendix A identifies four primary considerations explicitly prioritized by NIST's Generative AI Public Working Group (GAI PWG): governance, content provenance, pre-deployment testing, and incident disclosure.
Key claims
The profile advances several positions:
- Generative AI introduces risks that are novel, or exacerbates existing AI risks (confidence: high).
- Voluntary standards supplement but do not substitute for mandatory safeguards; NIST explicitly disclaims recommendations of specific entities (confidence: high).
- Empirically demonstrated risks take priority over speculative future risks. This framing is contested: it is a stylistic choice that contrasts with the FLI and CAIS framing, which emphasizes speculative but high-severity risk (confidence: contested).
Authority and status
The profile was developed pursuant to Executive Order 14110 — Safe, Secure, and Trustworthy AI § 4.1(a)(i)(A). Although EO 14110, the order that commissioned it, was rescinded on January 20, 2025, NIST AI 600-1 has not been withdrawn and continues to operate as a voluntary reference. It is frequently invoked in state laws and private AI governance programs.
Relationships
- depends-on: NIST AI Risk Management Framework (AI RMF 1.0) — this profile is a GAI-specific implementation of RMF 1.0
- supersedes: (none — complement, not replacement)
- related: Executive Order 14110 — Safe, Secure, and Trustworthy AI — commissioning authority (§ 4.1(a)(i)(A))
- related: National Institute of Standards and Technology (NIST) — publishing agency
- supports: California SB 53 — Transparency in Frontier AI Act, Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment), State AG AI Guidances (CA, NJ, MA, OR) — these reference NIST standards
- related: AI Safety Cases and Frameworks, Frontier Compliance Framework (February 2026), A Taxonomy of Systemic Risks from General-Purpose AI — comparable risk taxonomies
- related: Anthropic's Responsible Scaling Policy (Version 3.1), OpenAI Preparedness Framework V.2 — private RSPs map onto similar risk categories