NIST AI 600-1: The Generative AI Profile as an Evidence Map

NIST AI 600-1 is the Generative AI Profile of the NIST AI Risk Management Framework: 12 risks that generative AI creates or makes worse, and 211 suggested actions to govern, map, measure and manage them. Most explainers stop at the list. This guide treats NIST AI 600-1 as what auditors, the Texas Attorney General and procurement teams now use it for: a map of the evidence an organization should be able to produce about every generative AI system it builds or deploys. It covers where the profile stands in 2026, after the executive order that commissioned it was revoked, where it carries legal weight, and how its actions line up with the EU AI Act and ISO/IEC 42001.

NIST AI 600-1 generative AI profile shown as an open ledger with twelve sealed risk columns

Key takeaways

  • NIST AI 600-1 was published on 26 July 2024 as a voluntary, cross-sectoral profile of AI RMF 1.0 for generative AI.
  • It names 12 risks and 211 suggested actions, each coded to an AI RMF subcategory (for example GV-1.1-001).
  • The executive order behind it was revoked in January 2025, yet the profile remains on nist.gov while AI RMF 1.0 is being revised.
  • Texas TRAIGA ties one of its affirmative defenses to substantial compliance with the profile, which turns voluntary guidance into litigation evidence.
  • The actions map cleanly onto EU AI Act duties for general-purpose AI and Article 50 transparency, so one evidence set can serve both regimes.

What is NIST AI 600-1?

NIST AI 600-1, formally the Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, is a companion document to the NIST AI Risk Management Framework (AI RMF 1.0, also catalogued as NIST AI 100-1). NIST released it on 26 July 2024, and it remains listed on the official AI RMF page. The document describes itself as a cross-sectoral profile: it applies to generative models and applications whatever the industry, in the same way a profile for cloud services or acquisition would. In its own words it is intended for voluntary use. It defines generative AI by reference to models that emulate the structure and characteristics of input data to generate derived synthetic content, which covers text, image, audio, video and code. The profile was built through NIST’s Generative AI Public Working Group. That group deliberately limited its scope to four primary considerations: Governance, Content Provenance, Pre-deployment Testing and Incident Disclosure. Those four themes explain why NIST AI 600-1 is strong on testing, provenance and disclosure and comparatively thin on topics such as workforce impact.

A profile, not a standard

NIST AI 600-1 does not replace the AI RMF, and it does not add new functions. It takes the four AI RMF functions (Govern, Map, Measure, Manage) and attaches generative-AI-specific actions to selected subcategories. The NIST text is explicit that not every subcategory is covered, and that the general AI RMF Playbook actions still apply. In practice that means two layers: the base framework, which you may already run for predictive systems (see our NIST AI RMF implementation guide), and the generative layer, which adds controls for confabulation, provenance, prompt-based attacks and third-party model components. It is also not a certification scheme. Nobody is “NIST AI 600-1 certified”. The practical question is whether an organization can show, action by action, which suggested actions it adopted, which it rejected and why, and what evidence supports the claim.

The 12 risks in NIST AI 600-1

The profile groups its risks into three families: technical risks, misuse risks and ecosystem or societal risks. Some risks cut across families. The table below summarizes each risk, who usually carries it and the nearest EU AI Act hook. <table header-row=”true”> <tr> <td>Risk</td> <td>What it covers</td> <td>Usually carried by</td> <td>Nearest EU AI Act hook</td> </tr> <tr> <td>CBRN information or capabilities</td> <td>Easier access to chemical, biological, radiological or nuclear weapon knowledge</td> <td>Model developer</td> <td>Art. 55 systemic-risk evaluation</td> </tr> <tr> <td>Confabulation</td> <td>Confident but false output (“hallucinations”)</td> <td>Developer and deployer</td> <td>Art. 15 accuracy (high-risk use)</td> </tr> <tr> <td>Dangerous, violent or hateful content</td> <td>Incitement, self-harm advice, illegal activity</td> <td>Developer and deployer</td> <td>Art. 55, Art. 5 prohibitions</td> </tr> <tr> <td>Data privacy</td> <td>Leakage, memorization, de-anonymization of personal data</td> <td>Both</td> <td>GDPR, Art. 10 data governance</td> </tr> <tr> <td>Environmental impacts</td> <td>Compute and energy use in training and inference</td> <td>Developer</td> <td>Art. 53 and Annex XI documentation</td> </tr> <tr> <td>Harmful bias or homogenization</td> <td>Amplified bias, performance gaps across groups or languages</td> <td>Both</td> <td>Art. 10, Art. 15</td> </tr> <tr> <td>Human-AI configuration</td> <td>Over-reliance, automation bias, emotional entanglement</td> <td>Deployer</td> <td>Art. 14 human oversight, Art. 50</td> </tr> <tr> <td>Information integrity</td> <td>Content that blurs fact and fiction, disinformation at scale</td> <td>Both</td> <td>Art. 50 transparency and marking</td> </tr> <tr> <td>Information security</td> <td>Lower barrier to cyberattacks, attacks on the model itself</td> <td>Both</td> <td>Art. 15 cybersecurity, Art. 55</td> </tr> <tr> <td>Intellectual property</td> <td>Reproduction of protected content, training on it</td> <td>Developer</td> <td>Art. 53(1)(c) copyright policy</td> </tr> <tr> <td>Obscene, degrading or abusive content</td> <td>Synthetic sexual content, including of minors</td> <td>Developer and deployer</td> <td>Art. 50(4) deepfake disclosure</td> </tr> <tr> <td>Value chain and component integration</td> <td>Opaque third-party models, data and components</td> <td>Deployer and integrator</td> <td>Art. 25 value chain, Art. 53(1)(b)</td> </tr> </table> Two of these deserve more attention than they usually get. Confabulation is the risk most organizations meet first, and we cover its governance separately in the biggest risk of generative AI. Value chain and component integration is the one most deployers underestimate: if you build on a hosted foundation model, most of your NIST AI 600-1 exposure sits in contracts and supplier evidence rather than in your own code.

Inside the 211 suggested actions

Each action in NIST AI 600-1 carries an Action ID that points to its AI RMF subcategory. GV-1.1-001 is the first suggested action for Govern 1.1; MS-2.5-003 would be the third action for Measure 2.5. Each action is tagged with the GAI risks it addresses and with the AI actor tasks it concerns. By our count of the published text, the profile contains 211 action IDs, distributed as follows: <table header-row=”true”> <tr> <td>Function</td> <td>Actions</td> <td>Share</td> </tr> <tr> <td>Govern (GV)</td> <td>57</td> <td>27%</td> </tr> <tr> <td>Map (MP)</td> <td>39</td> <td>18%</td> </tr> <tr> <td>Measure (MS)</td> <td>72</td> <td>34%</td> </tr> <tr> <td>Manage (MG)</td> <td>43</td> <td>20%</td> </tr> </table> Measure dominates, which reflects the working group’s focus on pre-deployment testing. The risk tags tell a second story. Counting how often each risk appears in the tags, information integrity leads with roughly 74 actions, followed by harmful bias and human-AI configuration (about 57 each) and information security (about 51). Environmental impacts appear on only about five actions. These are counts of tags, not a ranking of importance, but they show where NIST AI 600-1 expects most of the work to happen. Three practical consequences follow.

  1. Not every action applies to you. The profile says so directly: actions relevant to developers may not be relevant to deployers. Your first job is to filter by role.
  2. Actions are phrased as outcomes, not procedures. “Establish transparency policies and processes for documenting the origin and history of training data and generated data” (GV-1.2-001) tells you what must exist, not how to build it. The evidence design is yours.
  3. The four primary considerations are the backbone. If you can only resource part of the profile, start with governance, pre-deployment testing (including AI red teaming), content provenance and incident disclosure, because that is where the action density sits.

NIST AI 600-1 in 2026: orphaned, revised, still cited

NIST AI 600-1 was developed under Section 4.1 of Executive Order 14110. On 20 January 2025, Executive Order 14148 rescinded EO 14110. The profile was not withdrawn: it is still published by NIST and still listed alongside AI RMF 1.0. What changed is the direction of travel. The White House AI Action Plan of 23 July 2025 instructed NIST to revise the AI RMF to remove references to misinformation, diversity, equity and inclusion, and climate change. NIST’s own page now states that AI RMF 1.0 is being revised under the plan. No revised version of NIST AI 600-1 had been published at the time of writing. That matters for the profile more than for the base framework. By our tag count, information integrity (the category that addresses misinformation) and environmental impacts are both touched by the revision instruction, and information integrity is the most heavily tagged risk in the whole document. Organizations that built controls around those tags should keep them, because EU and state law still require them, but should expect the US text they cite to change. Meanwhile, NIST has kept publishing around the profile:

  • The preliminary draft of NIST IR 8596, the Cyber AI Profile, applying CSF 2.0 to AI, released on 16 December 2025 with comments due 30 January 2026 (see our NIST CSF guide).
  • The AI Agent Standards Initiative, announced on 17 February 2026 by the Center for AI Standards and Innovation, which addresses the agentic systems NIST AI 600-1 predates (the governance differences are covered in agentic AI vs generative AI).
  • A concept note for an AI RMF profile on trustworthy AI in critical infrastructure, released on 7 April 2026.

On the federal side, OMB memorandum M-25-21 (April 2025) replaced M-24-10 and requires minimum risk management practices for high-impact AI, including pre-deployment testing, impact assessment and ongoing monitoring, with alignment to NIST guidance encouraged (Hunton summary). Suppliers to federal agencies therefore still meet NIST AI 600-1 vocabulary in contracts, whatever its executive-order status.

Where NIST AI 600-1 carries legal weight

The profile is voluntary, but at least one statute gives it teeth. The Texas Responsible Artificial Intelligence Governance Act (HB 149), in force since 1 January 2026, lists the routes to an affirmative defense in Section 552.105(e). One of them is discovering a violation through an internal review process while substantially complying with the most recent version of the NIST Generative AI Profile, the Act’s own name for NIST AI 600-1, or another nationally or internationally recognized AI risk management framework. Other routes cover violations found through feedback, adversarial or red-team testing, or state agency guidelines. Our TRAIGA compliance guide sets out the full enforcement model. Two details make this defense harder to use than it looks.

  • “Substantially complies” is a factual claim. The Texas Attorney General will not accept a policy that cites NIST AI 600-1. The defense stands or falls on records: which actions were adopted, by whom, and what testing and monitoring actually ran.
  • “Most recent version” moves. If NIST publishes a revised profile, the benchmark for the defense moves with it. A control set frozen on the July 2024 text may no longer match.

NIST AI 600-1 also functions as a translation layer between regimes. NIST published a crosswalk between NIST AI 600-1 and Singapore’s AI Verify in May 2025, and the UC Berkeley CLTC GPAI risk-management profile extends the same RMF structure to foundation models with explicit references to the EU AI Act.

Mapping NIST AI 600-1 to the EU AI Act and ISO/IEC 42001

For organizations operating on both sides of the Atlantic, the useful question is not which framework to follow but which evidence satisfies several at once. The table below maps the four primary considerations of NIST AI 600-1 to their closest European and ISO counterparts. <table header-row=”true”> <tr> <td>NIST AI 600-1 consideration</td> <td>EU AI Act</td> <td>ISO/IEC 42001</td> </tr> <tr> <td>Governance (GV actions)</td> <td>Art. 17 quality management, Art. 53(1)(a) technical documentation for GPAI providers</td> <td>Clauses 5 and 6, Annex A policy and roles controls</td> </tr> <tr> <td>Pre-deployment testing (MS actions)</td> <td>Art. 55(1)(a) model evaluation and adversarial testing for systemic-risk GPAI, Art. 9 and 15 for high-risk systems</td> <td>Clause 8 operation, Annex A verification and validation controls</td> </tr> <tr> <td>Content provenance</td> <td>Art. 50 machine-readable marking and deepfake disclosure</td> <td>Annex A controls on information for interested parties</td> </tr> <tr> <td>Incident disclosure</td> <td>Art. 55(1)(c) serious incident reporting for systemic-risk GPAI, Art. 73 for high-risk systems (incident reporting guide)</td> <td>Clause 10 nonconformity and corrective action</td> </tr> </table> The European dates give this mapping urgency. Obligations for providers of general-purpose AI models applied from 2 August 2025, supported by the GPAI Code of Practice published in July 2025, and the Commission’s fining powers for GPAI providers apply from 2 August 2026. Article 50 transparency duties also apply from 2 August 2026, with a transition to 2 December 2026 for machine-readable marking on systems already on the market. High-risk obligations under Annex III now apply from 2 December 2027, following the Digital Omnibus, Regulation (EU) 2026/1744. ISO/IEC 42001 is a licensed standard, so we name its clauses rather than quote them. Its management-system structure is the natural container for NIST AI 600-1 actions: the profile supplies the generative-specific controls, and the standard supplies the cycle of policy, risk treatment, internal audit and improvement that turns them into a system (ISO 42001 explained).

Turning NIST AI 600-1 into evidence: a six-step method

The gap in most programmes is not knowledge of the 12 risks. It is the absence of a record that links each generative AI system to the actions chosen for it. This sequence closes that gap.

  1. Inventory every generative AI system and component. Include hosted models, embedded copilots and internal assistants. Record the model version, provider, purpose and your role (developer, deployer or both). An AI inventory is the precondition for everything else.
  2. Filter the 211 actions by role and use case. A deployer of a hosted model will set aside most CBRN and training-data actions and keep value chain, human-AI configuration, confabulation and information integrity actions. Record rejected actions with a reason; a documented “not applicable” is evidence too.
  3. Assign an owner and an artefact to each retained action. GV-1.2-001 becomes a data-provenance record; MS actions become test plans and results; MG actions become runbooks. Name the artefact before the work starts.
  4. Test before deployment and after every model change. Run evaluations for confabulation, harmful content and prompt injection on a fixed test set, and re-run them whenever the provider changes the model version. This is the core of the Measure function.
  5. Contract for the value chain. Require change notices, evaluation summaries and incident notification from model providers, as part of vendor due diligence. Without supplier evidence, the value chain risk cannot be managed, only accepted.
  6. Define incident disclosure before you need it. Decide thresholds, internal escalation and external reporting routes, including EU AI Act timelines where they apply, and keep the decision log.

Each step produces a record. Taken together, those records are what “substantial compliance” with NIST AI 600-1 looks like in front of a regulator, a customer’s security team or a court.

FAQ

What is NIST AI 600-1 in simple terms? NIST AI 600-1 is a free NIST document, published in July 2024, that adapts the AI Risk Management Framework to generative AI. It lists 12 risks that generative AI creates or amplifies, such as confabulation, data privacy leakage and information integrity, and proposes 211 suggested actions organized under the Govern, Map, Measure and Manage functions. It is voluntary and cross-sectoral: any organization that develops or deploys generative AI can use it, and it is not tied to a single industry or a certification scheme. Is NIST AI 600-1 still valid after EO 14110 was revoked? Yes. Executive Order 14148 rescinded EO 14110 on 20 January 2025, but NIST did not withdraw the profile, and it is still listed on the AI RMF page. The AI Action Plan of July 2025 directed NIST to revise the AI RMF, and NIST states that revision is under way, so a new version of the generative profile is possible. Until then, the July 2024 text is the current version. Is NIST AI 600-1 mandatory? Not in general. It is voluntary guidance. It becomes practically binding in three situations: when a contract or federal procurement clause references it, when a statute such as Texas TRAIGA builds it into an affirmative defense, and when an auditor or customer uses it as the benchmark for due diligence. In each case what counts is documented implementation, not a policy statement. How does NIST AI 600-1 relate to the EU AI Act? They are different instruments: NIST AI 600-1 is voluntary guidance, the EU AI Act is binding law. Their content overlaps heavily, though. Pre-deployment testing, content provenance and incident disclosure in the profile correspond to model evaluation and incident reporting for systemic-risk GPAI under Article 55, to Article 50 transparency duties and to Article 73 for high-risk systems. One evidence base, well structured, can support both. What is the difference between NIST AI 600-1 and the AI RMF? The AI RMF (NIST AI 100-1) is the general framework for all AI systems, with four functions and their categories and subcategories. NIST AI 600-1 is a profile of that framework for generative AI: it keeps the same structure, adds generative-specific risks and attaches suggested actions to selected subcategories. You apply the RMF and the Playbook first, then layer the profile on top for generative systems. How many risks and actions does NIST AI 600-1 contain? It defines 12 risks, from CBRN information and confabulation to value chain and component integration. By our count of the published text it contains 211 suggested action IDs: 57 under Govern, 39 under Map, 72 under Measure and 43 under Manage. Information integrity is the most frequently tagged risk, and environmental impacts the least.

Conclusion

NIST AI 600-1 is often summarized as a list of 12 risks. Its real value is narrower and more useful: it gives every generative AI system a set of coded actions against which an organization can show what it did. In 2026 that record matters more, not less. The executive order behind the profile is gone, but Texas has written it into an affirmative defense, federal buyers still use its vocabulary, and its actions line up with the EU AI Act obligations that now carry fines. Keep an eye on the NIST revision, because the benchmark will move. In the meantime, the work is the same under any version: inventory the systems, choose actions by role, attach evidence to each one and keep the decisions. AI Sigil links each generative AI system in the registry to its selected controls, test results and incident decisions, so the answer to “show us your NIST AI 600-1 compliance” is a report, not a reconstruction.

NIST AI 600-1: The Generative AI Profile as an Evidence Map

NIST AI 600-1 explained: the 12 generative AI risks, 211 suggested actions, its 2026 status, the Texas TRAIGA defense and the EU AI Act mapping.

Model Drift: When a Compliant Model Stops Complying

Model drift quietly turns a validated AI model into a non-compliant one. Learn the types, detection metrics and what EU AI Act Articles 15 and 72 require.

HIPAA Compliance Software: The 2026 AI-Era Buyer’s Guide

HIPAA compliance software was built for systems that store PHI, not for systems that infer from it. What a 2026 tool must cover, and what to demand.

AI Inventory: What Regulators Expect to Find in It

An AI inventory is the artefact every AI rule assumes. See which clauses compel one (EU AI Act, NIST, ISO 42001, OMB) and the fields each expects.

China AI Regulation in 2026: Filings, Labels and Liability

China AI regulation explained for foreign firms: CAC filings, AI content labels, companion AI rules, 2026 enforcement and the evidence to keep ready.

California SB 243: Companion Chatbot Duties After Adam’s Law

California SB 243 set the first companion chatbot rules. Adam's Law (SB 1119) added risk assessments, parental controls and independent audits from 2027.