Skip to main content
> NIST AI Profile

NIST Cyber AI Profile (IR 8596)

Mapping CSF 2.0 to AI-specific risks across your organization

Established: December 2025 (Initial Preliminary Draft) Last Updated: December 2025 Scope: United States (applicable globally)
3
CSF 2.0 Focus Areas

What is the NIST Cyber AI Profile (IR 8596)?

The NIST Cyber AI Profile is a draft Community Profile of the Cybersecurity Framework 2.0, published as NIST IR 8596 on December 16, 2025. It organizes AI cybersecurity work using CSF 2.0 Functions, Categories, and Subcategories across three focus areas: securing the AI systems you run, conducting AI-enabled cyber defense, and thwarting AI-enabled attacks. NIST developed it over about a year with a community of interest of more than 6,500 people. The document is a preliminary draft rather than a final standard, and the guidance is voluntary rather than a regulation. The public comment period closed January 30, 2026, and NIST plans to release an initial public draft during 2026. If your program already tracks to CSF 2.0, the profile shows which existing outcomes to extend for AI instead of building a separate framework.

// What is NIST AI Profile?

NIST's Cyber AI Profile (IR 8596) maps the Cybersecurity Framework 2.0 to AI-specific risks. It was developed with input from over 6,500 contributors and released as an initial preliminary draft in December 2025.

The profile organizes AI security into three focus areas: securing the AI systems you deploy, using AI to strengthen your defensive capabilities, and building resilience against AI-enabled attacks from adversaries. Each focus area maps to existing CSF 2.0 functions and categories, which means organizations already tracking against CSF 2.0 can extend their programs to cover AI risk without starting from scratch.

For most mid-market organizations, this profile is the clearest path from "we know AI is a risk" to "here's exactly what to evaluate." It builds on the framework structure your compliance program probably already references and adds the AI-specific categories that CSF 2.0 alone doesn't cover.

// Inside NIST AI Profile

The Cyber AI Profile organizes AI cybersecurity into three focus areas, each mapping to CSF 2.0 core functions. Organizations assess their AI risk posture across all three focus areas based on their specific AI deployment and threat profile.

1

Focus Area 1: Securing AI System Components (Secure)

Securing the AI systems your organization deploys and operates. This focus area addresses risks in your own AI tools, models, and integrations.

AI Asset Inventory

Identifying and cataloging all AI systems, models, and integrations across the organization -- including shadow AI adopted without IT approval.

AI Risk Assessment

Evaluating risks specific to deployed AI: data poisoning, prompt injection, model theft, training data exposure, and excessive agency.

AI Access Controls

Least privilege for AI systems and agents. Controlling what data AI can access, what actions agents can take, and what permissions models inherit.

AI Data Protection

Securing training data, RAG corpora, and data flowing to and from AI models -- including classification, encryption, and retention controls.

2

Focus Area 2: Conducting AI-Enabled Cyber Defense (Defend)

Using AI to strengthen your organization's cybersecurity capabilities -- AI-powered detection, analysis, and response.

AI-Enhanced Detection

Deploying AI for threat detection, anomaly identification, and security monitoring while managing the risks of relying on AI-driven alerts.

AI-Assisted Response

Using AI for incident analysis, automated containment, and response prioritization -- with appropriate human oversight for critical decisions.

Validation and Testing

Ensuring AI-powered security tools function as intended through regular testing, adversarial validation, and performance monitoring.

3

Focus Area 3: Thwarting AI-Enabled Cyber Attacks (Thwart)

Building resilience against adversaries who use AI to enhance their attacks -- AI-generated phishing, deepfakes, automated vulnerability discovery, and AI-orchestrated campaigns.

AI Threat Awareness

Understanding how attackers use AI: automated reconnaissance, AI-generated phishing, deepfake social engineering, and AI-assisted exploitation.

Adaptive Defenses

Updating detection and response capabilities to address AI-enhanced attack techniques that evade traditional security controls.

Workforce Preparedness

Training staff to recognize AI-enhanced threats -- particularly AI-generated phishing, deepfake audio/video, and sophisticated social engineering.

Note: The Cyber AI Profile uses CSF 2.0's Implementation Tiers (1-4) and Profile mechanism. Organizations develop a Current Profile describing their AI security posture and a Target Profile defining their objectives, using the gap between them to prioritize improvements. Because it maps directly to CSF 2.0, organizations already using the framework can extend their existing assessments.

// Who Must Comply

  • 1 Federal contractors deploying or managing AI systems
  • 2 Organizations already tracking against NIST CSF 2.0 that have adopted AI
  • 3 Industries with AI in critical operations (healthcare, financial services, energy, transportation)
  • 4 Companies seeking structured AI governance and risk management maturity
  • 5 Any organization wanting a recognized framework for AI security assessment

// Key Requirements

AI Asset Inventory

Catalog all AI systems, models, agents, and integrations across your organization including shadow AI

AI Risk Assessment

Evaluate AI-specific risks including data poisoning, prompt injection, model theft, and excessive agency

AI Access Controls

Apply least privilege to AI systems controlling data access, agent permissions, and model capabilities

AI Monitoring

Monitor AI system behavior including model queries, agent actions, and data flows to detect anomalies

AI Incident Response

Extend incident response plans to cover AI-specific scenarios like model compromise, agent manipulation, and data extraction

AI Governance

Establish organizational governance for AI adoption, usage policies, and accountability at the enterprise level

// Enforcement & Penalties

The Cyber AI Profile is a voluntary framework with no direct enforcement mechanism -- the same model as NIST CSF 2.0. However, federal contracts increasingly require CSF alignment, and the AI Profile extends that expectation to AI-specific risks. Organizations using AI in regulated industries may face additional scrutiny from sector-specific regulators.

Maximum Penalty

No direct regulatory fines (voluntary framework)

Examples:

  • Federal contract requirements expanding to include AI security posture assessments
  • Increased liability exposure if an AI-related breach occurs without documented risk management
  • Regulatory attention from sector-specific agencies (HHS for healthcare AI, SEC for financial AI)
  • Procurement requirements from enterprise customers expecting documented AI governance

// Cyber Insurance Impact

The insurance industry is beginning to add AI-specific questions to cyber policy applications. As AI-related claims increase, expect carriers to reference the Cyber AI Profile the same way they currently reference CSF 2.0 -- as evidence of mature risk management. Organizations that can demonstrate alignment with the profile's three focus areas will have an advantage during underwriting as carriers formalize their AI risk assessment criteria.

// Common Questions

Is the NIST Cyber AI Profile mandatory?

No. The Cyber AI Profile is voluntary guidance, and it is still a preliminary draft (NIST IR 8596, published December 16, 2025). NIST has no enforcement authority over private organizations, and the profile carries no fines. What it carries is influence. Federal contracts and enterprise procurement questionnaires already reference NIST CSF 2.0, and the Cyber AI Profile extends that same structure to AI risk. Sector regulators tend to treat NIST material as the reference point for reasonable practice. Treat alignment as a way to answer customer, insurer, and auditor questions with evidence, not as a legal obligation.

How is the Cyber AI Profile different from the NIST AI Risk Management Framework?

They answer different questions and sit on different frameworks. The AI Risk Management Framework (NIST AI 100-1, released January 26, 2023) covers trustworthy AI broadly, including fairness, transparency, safety, and validity, organized under four functions: Govern, Map, Measure, and Manage. Its Generative AI Profile (NIST AI 600-1, July 2024) applies that structure to generative systems. The Cyber AI Profile is a Community Profile of Cybersecurity Framework 2.0 and deals only with cybersecurity: securing AI systems, defending with AI, and resisting AI-enabled attacks. Most organizations use both, with the AI RMF driving governance decisions and the Cyber AI Profile driving security outcomes.

Should we wait for the final version before acting on it?

Waiting costs you a year and buys very little. The comment period closed January 30, 2026, NIST held a workshop on January 14, 2026, and an initial public draft is planned for 2026. The parts most likely to survive editing are the parts you should start with anyway, because the profile is built on CSF 2.0 outcomes that are already final and on three focus areas NIST has held consistent throughout. Knowing which AI systems you run, who and what can reach them, and what an AI incident would look like in your environment is useful work under any version of the document. Do that now and refine when the next draft lands.

How do we assess our organization against the Cyber AI Profile?

Start with an inventory, because you cannot manage AI risk you cannot see. Shadow AI, AI features switched on inside vendor products, and agent integrations usually outnumber the systems on the official list. From there, a gap assessment compares your current state to the CSF 2.0 outcomes the profile calls out, using the Current Profile and Target Profile pattern CSF 2.0 already defines. Technical validation comes next. Our AI security testing covers prompt injection, agent permission abuse, data exposure through retrieval pipelines, and model integrations that inherit far more access than anyone intended. We map every finding back to the framework so your report reads as evidence, not a list of bugs.

How does the Cyber AI Profile relate to the OWASP AI security lists?

They work at different altitudes and pair well. The Cyber AI Profile tells you which cybersecurity outcomes to manage across AI, in CSF 2.0 language your governance, audit, and board reporting already use. The OWASP AI security lists, covering LLM applications and agentic AI applications, tell your engineers and testers what the attacks actually look like: prompt injection, improper output handling, vector and embedding weaknesses, excessive agency. Use the profile to decide what to govern and report on. Use OWASP to decide what to test. MITRE ATLAS adds adversary technique detail when you need to describe how a specific attack would run against your stack.

// Related Frameworks

Guide last reviewed: September 1, 2026

Ready to Strengthen Your Defenses?

Schedule a free consultation with our security experts to discuss your organization's needs.

Or call us directly at (445) 273-2873