01NIST AI RMF: the overarching framework
The Artificial Intelligence Risk Management Framework (AI RMF 1.0, NIST AI 100-1, 2023) addresses the responsible use of AI systems in its full breadth and refers to the NIST CSF and the Risk Management Framework for the treatment of cybersecurity risks. It is currently being revised by NIST. The Cyber AI Profile builds on it and gives concrete shape to the cybersecurity dimension of AI risk management.
02Cyber AI Profile: a Community Profile for CSF 2.0
The Cybersecurity Framework Profile for Artificial Intelligence (NIST IR 8596) is a Community Profile that applies the Functions, Categories and Subcategories of the NIST CSF 2.0 to the AI context — as a complement to, not a replacement for, existing frameworks. The Initial Preliminary Draft was released in December 2025, developed by NIST with contributions from MITRE; the public comment period ran from December 16, 2025 to January 30, 2026 and will feed into the Initial Public Draft.
03Three focus areas: Secure, Defend, Thwart
The profile structures AI cybersecurity into three focus areas: Securing AI System Components (Secure) covers protecting AI components such as models, agents, algorithms, prompts and data. Conducting AI-Enabled Cyber Defense (Defend) identifies opportunities to use AI to improve cybersecurity processes. Thwarting AI-Enabled Cyber Attacks (Thwart) builds resilience against new AI-enabled attack vectors — the three areas complement and reinforce one another.
04Structure: six Functions, prioritized Subcategories
The profile organizes its recommendations along the six CSF 2.0 Functions GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. Each Subcategory receives a Proposed Priority per focus area — 1 (High), 2 (Moderate) or 3 (Foundational), where Foundational explicitly does not mean “low priority”. This is complemented by AI-specific Considerations and Informative References, for example to NIST SP 800-53, OWASP resources and MITRE ATLAS.
05Connecting to the EU AI Act and ISO/IEC 42001
The Cyber AI Profile is a voluntary, technology-neutral guideline — and precisely for that reason a useful tool for implementing binding EU requirements. The cybersecurity requirements for high-risk AI systems under Art. 15 of the AI Act, the risk management obligations under NIS2 and an AI management system in accordance with ISO/IEC 42001 can all be underpinned in a structured way with the profile's prioritized Subcategories.
06Getting started and outlook: COSAiS
The profile presupposes an existing cybersecurity program: the way in is a gap assessment of the existing ISMS against the AI-extended Subcategories and an organization-specific weighting of the three focus areas. In addition, NIST is developing the Control Overlays for Securing AI Systems (COSAiS) based on SP 800-53 — with use cases for generative AI, predictive AI and agentic AI (single- and multi-agent).