NIST AI Cybersecurity Framework Profile

Cybersecurity Framework Profile for Artificial Intelligence (NISTIR 8596)

United States

RAI-US-NA-CYBERSE-2025
Draft(Being written or scoped)
PolicyRisk ManagementGovernance and OversightSafety, Testing, and Evaluation
Export PDF

NISTIR 8596 provides voluntary guidance for organizations to manage cybersecurity risks in AI systems and leverage AI for enhanced cyber defense.

Overview

The National Institute of Standards and Technology (NIST) has released the preliminary draft of the Cybersecurity Framework Profile for Artificial Intelligence (NISTIR 8596), often referred to as the Cyber AI Profile. This significant document aims to provide organizations with comprehensive guidance for managing cybersecurity risks specifically related to Artificial Intelligence (AI) systems, while also identifying opportunities to leverage AI to enhance existing cybersecurity capabilities. Published on December 16, 2025, this preliminary draft is a crucial step in adapting established cybersecurity practices to the rapidly evolving landscape of AI technology. It is designed to be a voluntary framework, extending the recently updated NIST Cybersecurity Framework (CSF) 2.0 to address the unique challenges and opportunities presented by AI. The Cyber AI Profile is the culmination of extensive collaboration, involving over 6,500 contributors from government, academia, and industry, reflecting a broad consensus on the need for specialized guidance in this domain.

The framework is structured around the outcomes of the NIST Cybersecurity Framework 2.0, utilizing its familiar Functions, Categories, and Subcategories to integrate AI-specific considerations into an organization's overall cybersecurity program. Its core objective is to help organizations strategically adopt AI by providing a structured approach to understanding, examining, and addressing the cybersecurity concerns that arise from AI's advancements. The Cyber AI Profile emphasizes three key focus areas: securing AI system components, conducting AI-enabled cyber defense, and thwarting AI-enabled cyberattacks. This multi-faceted approach acknowledges that AI impacts cybersecurity in various ways, from the vulnerabilities it might introduce to the powerful tools it can offer for defense. The document is currently in a public comment period, which closed on January 30, 2026, allowing stakeholders to provide feedback that will inform the initial public draft and subsequent final versions.

Definitions

The Cybersecurity Framework Profile for Artificial Intelligence (NISTIR 8596) incorporates and builds upon a foundational understanding of key terms, many of which are derived from the broader NIST Cybersecurity Framework (CSF) 2.0 and the AI Risk Management Framework (AI RMF). While the preliminary draft itself would contain a dedicated glossary, the core concepts revolve around 'Artificial Intelligence (AI) Systems,' which broadly refers to engineered or natural systems that generate a particular output for a given set of inputs, with the ability to learn, reason, or adapt. The 'Cybersecurity Framework Profile' itself is defined by NIST as an application of CSF 2.0 to address shared interests and goals among organizations within a specific domain, in this case, AI. This means it tailors the generic cybersecurity outcomes of the CSF to the unique context of AI.

Other critical definitions implicitly or explicitly addressed include 'Cybersecurity Risk,' which pertains to the potential for loss or harm related to the use, operation, or reliance on AI systems due to a cyber event. This encompasses risks to the AI system itself, risks posed by AI to other systems, and risks from AI-enabled attacks. 'AI-enabled Cyber Defense' refers to the application of AI technologies and capabilities to enhance an organization's ability to protect, detect, respond to, and recover from cyber threats. Conversely, 'AI-enabled Cyber Attacks' describes malicious activities that leverage AI capabilities to increase their scale, sophistication, or effectiveness. The framework also considers 'AI System Components,' which include the various hardware, software, data, and models that constitute an AI system, each presenting potential cybersecurity vulnerabilities. Understanding these definitions is fundamental to effectively navigating and implementing the guidance provided within the Cyber AI Profile, enabling organizations to articulate and manage their AI-related cybersecurity posture.

Governance and Institutional Framework

The governance and institutional framework surrounding the NIST Cyber AI Profile is rooted in the National Institute of Standards and Technology's role as a non-regulatory agency tasked with developing standards, guidelines, and frameworks to enhance cybersecurity and promote innovation. The Cyber AI Profile itself is a voluntary framework, meaning it does not impose legally binding requirements but rather provides best practices and recommendations for organizations. Its development involved a collaborative, community-driven approach, with NIST actively soliciting input from a wide array of stakeholders, including government entities, industry leaders, academic institutions, and cybersecurity experts. This inclusive process ensures that the framework reflects diverse perspectives and addresses real-world challenges faced by organizations integrating AI.

At a strategic level, the Cyber AI Profile underscores the importance of clear leadership accountability for AI-related cybersecurity risks across the enterprise. It advocates for cross-functional teamwork, emphasizing that managing AI cybersecurity requires collaboration among legal, privacy, procurement, and security stakeholders. This integrated approach is crucial for establishing comprehensive policies and ensuring that AI considerations are embedded throughout an organization's governance structure. While NIST provides the framework, the responsibility for its implementation and adaptation rests with individual organizations, which are encouraged to integrate the profile's guidance into their existing risk management and cybersecurity programs. The framework also highlights the need for swifter policy updates within organizations to keep pace with the rapid advancements in AI technology and the evolving threat landscape.

Key Focus Areas

The NIST Cyber AI Profile is strategically organized around three primary focus areas, designed to provide a comprehensive approach to managing AI-related cybersecurity risks and opportunities. These areas are: Securing AI System Components (Secure), Conducting AI-Enabled Cyber Defense (Defend), and Thwarting AI-enabled Cyber Attacks (Thwart). The 'Secure' focus area addresses the inherent cybersecurity challenges associated with integrating AI into an organization's existing ecosystems and infrastructure. This involves identifying and mitigating vulnerabilities within the AI systems themselves, including their data, models, and underlying platforms. It encourages organizations to establish robust security controls for AI development, deployment, and maintenance, ensuring the integrity and confidentiality of AI assets.

The 'Defend' focus area explores the opportunities to leverage AI technologies to enhance an organization's overall cybersecurity posture. This involves utilizing AI for tasks such as advanced threat detection, anomaly identification, automated incident response, and predictive analytics to anticipate and prevent cyberattacks. The framework guides organizations on how to effectively integrate AI tools into their defensive operations, while also acknowledging the challenges and risks associated with relying on AI for critical security functions. Finally, the 'Thwart' focus area is dedicated to understanding and countering adversarial cyberattacks that are themselves enabled by AI. As attackers increasingly employ AI to scale phishing campaigns, create sophisticated deepfakes, and develop more potent malware, this section provides guidance on developing strategies and defenses to neutralize these advanced threats. By addressing these three distinct yet interconnected areas, the Cyber AI Profile offers a holistic framework for organizations to navigate the complex interplay between AI and cybersecurity.

Implementation Framework

The implementation framework for the NIST Cyber AI Profile is designed to be flexible and adaptable, allowing organizations to integrate its guidance into their existing cybersecurity and risk management programs. It is built upon the well-established structure of the NIST Cybersecurity Framework (CSF) 2.0, meaning organizations already familiar with the CSF can readily map the AI-specific considerations onto their current processes. The profile provides a systematic way to apply the CSF's core functions—Govern, Identify, Protect, Detect, Respond, and Recover—to AI systems and AI-related cybersecurity challenges. This layering approach ensures that AI considerations are not treated in isolation but are seamlessly integrated into an organization's broader cybersecurity strategy.

Organizations are encouraged to conduct a thorough assessment of their current AI landscape, identifying where AI systems are deployed, the data they process, and the potential cybersecurity risks they introduce or mitigate. The framework then guides them in prioritizing these risks and selecting appropriate controls and practices from the profile. Implementation involves establishing new policies and procedures, such as creating separate identities and credentials for AI systems, governing access controls for AI, and updating awareness and training programs to address AI-specific threats. Furthermore, the profile emphasizes the importance of extending supply chain diligence to include data provenance and integrity for AI systems, recognizing that the trustworthiness of AI often depends on the quality and security of its training data. NIST also plans to develop SP 800-53 “Control Overlays for Securing AI Systems” (COSAiS) to provide more granular, implementation-level guidance, complementing the outcome-oriented approach of the Cyber AI Profile.

Monitoring and Evaluation

Effective monitoring and evaluation are critical components of the NIST Cyber AI Profile, ensuring that organizations can continuously assess the effectiveness of their AI cybersecurity measures and adapt to the evolving threat landscape. The framework encourages organizations to establish robust mechanisms for tracking the performance of AI systems from a cybersecurity perspective, including their vulnerabilities, potential for misuse, and their contribution to defensive capabilities. This involves ongoing vigilance over AI system components, data inputs, model outputs, and interactions with other enterprise systems. Regular audits and assessments are recommended to identify any deviations from established security policies and to detect emerging risks that may not have been apparent during initial deployment. The goal is to foster a proactive approach to AI cybersecurity, moving beyond static compliance to dynamic risk management.

Evaluation within the Cyber AI Profile context extends to assessing the impact of AI on an organization's overall cybersecurity posture. This includes measuring the efficacy of AI-enabled cyber defense tools and techniques, as well as evaluating the organization's resilience against AI-powered cyberattacks. Organizations should develop key performance indicators (KPIs) and metrics tailored to AI cybersecurity, allowing them to quantify progress, identify areas for improvement, and justify investments in AI security. The framework also implicitly supports continuous feedback loops, where insights gained from monitoring and evaluation inform updates to policies, procedures, and technical controls. Given the rapid pace of AI development, continuous learning and adaptation are paramount. This involves staying informed about new AI security research, emerging threats, and best practices, and regularly updating the organization's Cyber AI Profile implementation to reflect the latest knowledge and capabilities.

Penalties, Liability, and Appeals

As a voluntary framework and a NIST Information Technology Laboratory (ITL) publication, the Cybersecurity Framework Profile for Artificial Intelligence (NISTIR 8596) does not directly impose legal penalties, establish liability, or define appeal processes. NIST's role is to provide guidance, standards, and best practices, not to enforce regulations or adjudicate disputes. Therefore, organizations adopting the Cyber AI Profile do so voluntarily to enhance their cybersecurity posture related to AI systems. The consequences of failing to implement the recommendations within the profile would not be direct legal sanctions from NIST. Instead, the implications would likely manifest in increased exposure to cybersecurity risks, potential data breaches, financial losses, reputational damage, and non-compliance with other existing or future binding regulations that may reference or align with NIST guidance.

However, while the profile itself is non-binding, it may indirectly influence future regulatory landscapes. As a widely recognized and respected source of cybersecurity guidance, the Cyber AI Profile could potentially serve as a benchmark for regulators and others regarding cybersecurity diligence concerning AI. In the event of a cybersecurity incident involving AI, an organization's adherence to (or deviation from) widely accepted frameworks like the Cyber AI Profile could be a factor in determining negligence, liability, or the adequacy of their security measures under existing laws or contracts. Therefore, while there are no direct penalties from NIST, the framework's adoption can play a significant role in an organization's overall legal and risk management strategy, influencing how they might fare in civil litigation or regulatory investigations by other bodies that do have enforcement powers.

Relationship to Other Instruments

The NIST Cybersecurity Framework Profile for Artificial Intelligence (NISTIR 8596) is designed to be a complementary instrument, building upon and integrating with existing foundational frameworks and guidance from NIST. Most notably, it is aligned with the NIST Cybersecurity Framework (CSF) 2.0, which defines high-level cybersecurity outcomes across various functions like Govern, Identify, Protect, Detect, Respond, and Recover. The Cyber AI Profile essentially applies the structure and principles of CSF 2.0 to the specific context of AI, providing AI-specific considerations for each of the CSF's categories and subcategories. This ensures a consistent and integrated approach to cybersecurity across an organization's entire technological landscape, preventing the creation of isolated AI security programs.

Furthermore, the Cyber AI Profile complements NIST's AI Risk Management Framework (AI RMF), which was released in 2023 and aims to improve the trustworthiness and reduce the risks associated with AI systems more broadly. While the AI RMF focuses on a wider range of AI risks, including bias, privacy, and safety, the Cyber AI Profile specifically hones in on the cybersecurity dimensions of AI. NIST envisions these three instruments—CSF 2.0, AI RMF, and the Cyber AI Profile—being used together to provide a holistic approach to managing AI-related risks. In parallel with the Cyber AI Profile, NIST is also developing SP 800-53 “Control Overlays for Securing AI Systems” (COSAiS), which will offer more implementation-level guidance to operationalize AI-related controls, further complementing the outcome-oriented approach of the Cyber AI Profile. This layered approach allows organizations to leverage a suite of NIST resources to address the multifaceted challenges of AI integration securely and responsibly.

International Alignment

While the NIST Cybersecurity Framework Profile for Artificial Intelligence (NISTIR 8596) is developed by a U.S. government agency, its foundational principles and the broader NIST Cybersecurity Framework (CSF) have gained significant international recognition and adoption. The CSF itself has been widely used by organizations globally as a flexible and adaptable tool for managing cybersecurity risk, making the Cyber AI Profile inherently amenable to international alignment. The challenges and opportunities presented by AI in cybersecurity are global in nature, affecting organizations regardless of their geographical location. Therefore, the guidance offered in the Cyber AI Profile, focusing on securing AI systems, leveraging AI for defense, and thwarting AI-enabled attacks, is broadly applicable across different national and regulatory contexts.

NIST frequently engages with international partners and standards bodies to promote global interoperability and best practices in cybersecurity and AI. Although the preliminary draft does not explicitly detail specific international alignment efforts within its text, the collaborative development process, involving a diverse community of interest, implicitly supports a globally informed perspective. The framework's emphasis on risk management, transparency, and accountability aligns with principles increasingly advocated by international organizations and foreign governments developing their own AI regulations and guidelines. As AI technology continues to transcend national borders, the voluntary nature and comprehensive scope of the Cyber AI Profile make it a valuable reference for organizations and policymakers worldwide seeking to establish robust AI cybersecurity practices, potentially contributing to a shared understanding and common approaches to securing AI systems on a global scale.

Implementation Timeline

MilestoneDateNotes
Preliminary Draft Release2025-12-16Initial release of NISTIR 8596 for public comment.
Public Comment Period Closes2026-01-30Deadline for stakeholders to submit feedback on the preliminary draft.
Cyber AI Workshop #22026-01-14Workshop to discuss the Preliminary Draft and updates on SP 800-53 COSAiS.
Initial Public Draft Release2026 (Planned)NIST plans to develop and release an initial public draft based on feedback.
Final Version ReleaseTo Be DeterminedAnticipated release after further revisions and public engagement.

Compliance Checklist

CheckRequired Action
AI System IdentificationIdentify all AI systems and components within the organization's ecosystem.
Risk AssessmentConduct comprehensive cybersecurity risk assessments specific to AI systems, including data, models, and infrastructure.
Governance IntegrationIntegrate AI cybersecurity considerations into existing organizational governance structures and risk management frameworks.
Policy ReviewReview and update existing cybersecurity policies and procedures to address AI-specific threats and opportunities.
Access Control for AIEstablish specific identity and access management policies for AI systems and their interactions with other systems.
Data Security for AIImplement robust data security measures for AI training data, models, and inferences, including provenance and integrity checks.
AI-Enabled Defense StrategyDevelop strategies for leveraging AI to enhance cyber defense capabilities (e.g., threat detection, anomaly identification).
AI Attack MitigationFormulate plans and deploy controls to thwart AI-enabled cyberattacks (e.g., deepfakes, advanced phishing).
Supply Chain SecurityExtend supply chain risk management to include AI components, third-party AI services, and data providers.
Awareness & TrainingProvide training to staff on AI system capabilities, limitations, evolving threats, and secure AI practices.
Continuous MonitoringImplement continuous monitoring and evaluation mechanisms for AI system cybersecurity performance and emerging risks.
Incident Response PlanningUpdate incident response plans to address AI-specific incidents and accelerate escalation and alignment during incidents.

Sources and References

SourceType
NIST IR 8596 ipd Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile)government
Plain English

The National Institute of Standards and Technology (NIST) has released a preliminary draft of its Cybersecurity Framework Profile for Artificial Intelligence (NISTIR 8596), offering voluntary guidance for organizations to manage cybersecurity risks in AI systems and leverage AI for enhanced cyber defense.

This framework is designed for any organization that develops, deploys, or uses Artificial Intelligence (AI) systems, aiming to help them understand and address the unique cybersecurity challenges and opportunities AI presents. It extends NIST’s widely adopted Cybersecurity Framework (CSF) 2.0, tailoring its principles to the specific context of AI. The guidance focuses on three key areas: - **Securing AI system components:** Protecting the data, models, and infrastructure that make up AI systems from vulnerabilities. - **Conducting AI-enabled cyber defense:** Using AI technologies to improve an organization’s ability to detect, respond to, and recover from cyber threats. - **Thwarting AI-enabled cyberattacks:** Developing strategies to counter malicious activities that leverage AI, such as sophisticated phishing or deepfakes.

Released as a preliminary draft on December 16, 2025, with public comments closing on January 30, 2026, this document is still under development, and a final version date is yet to be determined. As a voluntary NIST publication, it does not carry direct legal penalties or create binding obligations. However, organizations should be aware that while not legally mandated, adherence to such widely recognized guidance could serve as a benchmark. In the event of a cybersecurity incident involving AI, an organization's alignment with (or deviation from) this framework might be considered when assessing negligence or the adequacy of security measures under existing laws or contracts. A practical pitfall is the need for organizations to constantly update their policies and practices to keep pace with the rapid evolution of AI technology and its associated threats.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under NIST AI Cybersecurity Framework Profile. Not legal advice — verify against the official text before relying on it.

  1. #1Important

    Applies to: Organizations integrating AI systems.

    Organizations are encouraged to conduct a thorough assessment of their current AI landscape, identifying where AI systems are deployed...
  2. #2Important

    Applies to: Organizations integrating AI systems.

    Its core objective is to help organizations by providing a structured approach to understanding, examining, and addressing cybersecurity concerns.
  3. #3Important

    Applies to: Organizations integrating AI systems.

    It advocates for cross-functional teamwork, emphasizing that managing AI cybersecurity requires collaboration among legal, privacy, procurement, and security stakeholders.
  4. #4Important

    Applies to: Organizations integrating AI systems.

    The framework also highlights the need for swifter policy updates within organizations to keep pace with the rapid advancements in AI technology.
  5. #5Important

    Applies to: Organizations integrating AI systems.

    Implementation involves establishing new policies and procedures, such as creating separate identities and credentials for AI systems, governing access controls for AI...
  6. #6Important

    Applies to: Organizations integrating AI systems.

    This involves identifying and mitigating vulnerabilities within the AI systems themselves, including their data, models, and underlying platforms.
  7. #7Important

    Applies to: Organizations integrating AI systems.

    The 'Defend' focus area explores the opportunities to leverage AI technologies to enhance an organization's overall cybersecurity posture.
  8. #8Important

    Applies to: Organizations integrating AI systems.

    The 'Thwart' focus area is dedicated to understanding and countering adversarial cyberattacks that are themselves enabled by AI.
  9. #9Important

    Applies to: Organizations integrating AI systems.

    The profile emphasizes the importance of extending supply chain diligence to include data provenance and integrity for AI systems...
  10. #10Important

    Applies to: Organizations integrating AI systems.

    updating awareness and training programs to address AI-specific threats.
  11. #11ImportantContinuously

    Applies to: Organizations integrating AI systems.

    Effective monitoring and evaluation are critical components... ensuring that organizations can continuously assess the effectiveness of their AI cybersecurity measures.
  12. #12Important

    Applies to: Organizations integrating AI systems.

© Regulations.AI — created on 12-Feb-2026 using Gemini 2.5 Flash