AI Policy Wiki
Dashboard

NIST AI 600-1 — Generative AI Profile

high confidence · updated 2026-06-06

Cross-sectoral NIST companion profile to the AI RMF 1.0 for generative AI (July 2024). Defines 12 GAI risk categories and maps 200+ suggested actions to Govern/Map/Measure/Manage subcategories. Commissioned under EO 14110 § 4.1(a)(i)(A); remains in force post-rescission.

NIST AI 600-1, the Generative AI Profile, is a cross-sectoral companion profile to the NIST AI RMF 1.0 published by National Institute of Standards and Technology (NIST) on July 26, 2024. It defines 12 generative-AI risk categories and maps more than 200 suggested actions onto the RMF's Govern, Map, Measure, and Manage subcategories. The profile was developed pursuant to Executive Order 14110 — Safe, Secure, and Trustworthy AI § 4.1(a)(i)(A) and remains in force as a voluntary reference following that order's rescission.

The named authors are Chloe Autio, Jesse Dunietz, Patrick Hall, Shomik Jain, Kamie Roberts, Reva Schwartz, Martin Stanley, and Elham Tabassi. The document carries DOI https://doi.org/10.6028/NIST.AI.600-1.

What the profile is

A profile, in the AI RMF framework, implements the RMF's functions, categories, and subcategories for a specific setting. NIST AI 600-1 is a cross-sectoral profile that applies the RMF to generative AI and generative foundation models specifically. Where NIST AI 100-1 (RMF 1.0) is the general framework, NIST AI 600-1 is its generative-AI-specific instantiation. Both are voluntary, and together they serve as a US federal common vocabulary for AI risk management, referenced by SB 53, the Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment), and state attorney-general AI guidances.

12 GAI risk categories

The profile enumerates 12 categories of generative-AI risk:

  1. CBRN information or capabilities — eased access to chemical, biological, radiological, or nuclear design or synthesis information.
  2. Confabulation — plausible but false outputs (hallucinations).
  3. Dangerous, violent, or hateful content.
  4. Data privacy — leakage of training data, re-identification.
  5. Environmental impacts — training and inference energy and water use.
  6. Harmful bias or homogenization — discriminatory outputs; algorithmic monocultures.
  7. Human-AI configuration — anthropomorphism, inappropriate reliance.
  8. Information integrity — deepfakes, disinformation at scale.
  9. Information security — cyber-offense uplift.
  10. Intellectual property — unauthorized reproduction or ingestion of copyrighted works.
  11. Obscene, degrading, and/or abusive content — including CSAM.
  12. Value chain and component integration — risks from third-party data, models, and compute.

Suggested-action mapping

Suggested actions are labeled with AI RMF subcategory codes and tagged with the GAI risks they address, organized under the RMF's four functions:

  • Govern (GV-) — organizational culture, policies, roles, and third-party and IP governance.
  • Map (MP-) — contextualization, impact assessment, stakeholder engagement.
  • Measure (MS-) — benchmarks, red-teaming, incident tracking, content provenance.
  • Manage (MG-) — prioritization, decommissioning, continuous monitoring, feedback loops.

Appendix A identifies four primary considerations explicitly prioritized by NIST's Generative AI Public Working Group (GAI PWG): governance, content provenance, pre-deployment testing, and incident disclosure.

Key claims

The profile advances several positions:

  • Generative AI introduces risks that are novel, or exacerbates existing AI risks (confidence: high).
  • Voluntary standards supplement but do not substitute for mandatory safeguards; NIST explicitly disclaims recommendations of specific entities (confidence: high).
  • Empirically demonstrated risks take priority over speculative future risks. This framing is contested: it is a stylistic choice that contrasts with the FLI and CAIS framing, which emphasizes speculative but high-severity risk (confidence: contested).

Authority and status

The profile was developed pursuant to Executive Order 14110 — Safe, Secure, and Trustworthy AI § 4.1(a)(i)(A). Although EO 14110, the order that commissioned it, was rescinded on January 20, 2025, NIST AI 600-1 has not been withdrawn and continues to operate as a voluntary reference. It is frequently invoked in state laws and private AI governance programs.

Relationships