The NIST AI RMF Generative AI Profile, in practice
By Sam Rivera, Founder, SentinelPanda · June 3, 2026 · 3 min read · AI Governance
The Generative AI Profile is the AI RMF customised for the systems your teams are actually shipping. Twelve risk areas, mapped to Govern, Map, Measure, Manage.
What AI 600-1 is
The Generative AI Profile (NIST AI 600-1, published July 2024) is a companion publication to the AI RMF 1.0 that adapts the framework specifically to generative AI systems. It does not replace the base RMF; it overlays GenAI-specific risk areas onto the same four functions, with concrete actions for each.
It is published as a Profile under the RMF's "profile" mechanism — the way NIST extends the base framework to specific contexts. Treat AI 600-1 the way you treat a NIST CSF profile for a particular sector: same structural verbs, customised to the work you actually do.
The twelve risk areas
- CBRN (chemical, biological, radiological, nuclear) information or capabilities provided by GenAI.
- Confabulation — fabricated or hallucinated content presented as factual.
- Dangerous, violent, or hateful content generation.
- Data privacy — exposure or inference of personal data via the model.
- Environmental impacts of training and inference.
- Harmful bias and homogenisation in outputs.
- Human-AI configuration risks — over-reliance, automation bias, role confusion.
- Information integrity — the model degrading the broader information ecosystem.
- Information security — the model and its surrounding system as attack surface.
- Intellectual property — generation infringing on copyright, trademarks, or other rights.
- Obscene, degrading, or abusive content involving minors or non-consenting individuals.
- Value chain and component integration — risks from third-party models, datasets, and tooling.
How it sits on the four functions
Govern actions emphasise that GenAI requires policies and oversight structures the base RMF does not specifically call out: human review thresholds for high-impact decisions, content provenance commitments, training data governance, model release decisions. The actions are concrete — "establish criteria for human review of GenAI-assisted decisions" rather than generic governance language.
Map actions push for specific GenAI characterisation: what model is being used, what training data, what fine-tuning, what intended and foreseeable misuses, what populations affected. Measure actions list GenAI-specific metrics — content provenance, factuality, fairness across demographic groups, robustness to adversarial prompting. Manage actions cover response to GenAI incidents, content provenance disclosure, and value-chain monitoring.
Using it operationally
AI 600-1 works best as a layered overlay. Start with the base AI RMF for the management programme; for each GenAI system, walk the twelve risk areas and produce one paragraph per area: "this risk is in scope because…", "this is the mitigation in place…", "this is the residual risk we accept and the monitoring metric we will track."
That artefact does triple duty: it is the AI RMF documentation, it feeds the ISO 42001 AI system impact assessment, and it produces the substance of the EU AI Act technical documentation. The twelve risk areas appear in regulatory guidance even outside the US — they have become a shared vocabulary across jurisdictions.
What to do this quarter
- Pick your highest-impact GenAI system and run AI 600-1 against it end-to-end (Govern actions + Map characterisation + Measure metrics + Manage response).
- Produce a one-page mapping of the twelve risk areas to your specific controls.
- For each "Measure" subcategory you adopt, define one concrete metric and a baseline test.
- Document the value-chain inventory: model, training data sources, fine-tuning data, tooling, plugins, hosting.
- Use the same artefact for ISO 42001 impact assessment, EU AI Act technical documentation, and US procurement responses.