Book an Appointment

NIST AI RMF & Cyber AI Profile

Risk management for AI the NIST way: the AI Risk Management Framework and the new Cyber AI Profile (NIST IR 8596) give organizations a structured, prioritized framework for securing AI systems, using AI for defense and thwarting AI-enabled attacks.

Artificial intelligence changes the cybersecurity risk profile of organizations in both directions: it expands the attack surface to include models, agents, prompts and training data — and at the same time opens up new opportunities for defense. NIST addresses both sides with two coordinated publications: the AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) covers the responsible use of AI systems across the board and refers to the Cybersecurity Framework (CSF) and the Risk Management Framework for cybersecurity risks. With the Cyber AI Profile (NIST IR 8596), a Community Profile has been available since December 2025 that, for the first time, applies the CSF 2.0 structure specifically to the AI context and prioritizes Subcategories for each area of application. For European companies, the profile is particularly interesting because it can be combined with the binding requirements of the EU AI Act, NIS2 and ISO/IEC 42001.

The Essentials at a Glance

01

NIST AI RMF: the overarching framework

The Artificial Intelligence Risk Management Framework (AI RMF 1.0, NIST AI 100-1, 2023) addresses the responsible use of AI systems in its full breadth and refers to the NIST CSF and the Risk Management Framework for the treatment of cybersecurity risks. It is currently being revised by NIST. The Cyber AI Profile builds on it and gives concrete shape to the cybersecurity dimension of AI risk management.

02

Cyber AI Profile: a Community Profile for CSF 2.0

The Cybersecurity Framework Profile for Artificial Intelligence (NIST IR 8596) is a Community Profile that applies the Functions, Categories and Subcategories of the NIST CSF 2.0 to the AI context — as a complement to, not a replacement for, existing frameworks. The Initial Preliminary Draft was released in December 2025, developed by NIST with contributions from MITRE; the public comment period ran from December 16, 2025 to January 30, 2026 and will feed into the Initial Public Draft.

03

Three focus areas: Secure, Defend, Thwart

The profile structures AI cybersecurity into three focus areas: Securing AI System Components (Secure) covers protecting AI components such as models, agents, algorithms, prompts and data. Conducting AI-Enabled Cyber Defense (Defend) identifies opportunities to use AI to improve cybersecurity processes. Thwarting AI-Enabled Cyber Attacks (Thwart) builds resilience against new AI-enabled attack vectors — the three areas complement and reinforce one another.

04

Structure: six Functions, prioritized Subcategories

The profile organizes its recommendations along the six CSF 2.0 Functions GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER. Each Subcategory receives a Proposed Priority per focus area — 1 (High), 2 (Moderate) or 3 (Foundational), where Foundational explicitly does not mean “low priority”. This is complemented by AI-specific Considerations and Informative References, for example to NIST SP 800-53, OWASP resources and MITRE ATLAS.

05

Connecting to the EU AI Act and ISO/IEC 42001

The Cyber AI Profile is a voluntary, technology-neutral guideline — and precisely for that reason a useful tool for implementing binding EU requirements. The cybersecurity requirements for high-risk AI systems under Art. 15 of the AI Act, the risk management obligations under NIS2 and an AI management system in accordance with ISO/IEC 42001 can all be underpinned in a structured way with the profile's prioritized Subcategories.

06

Getting started and outlook: COSAiS

The profile presupposes an existing cybersecurity program: the way in is a gap assessment of the existing ISMS against the AI-extended Subcategories and an organization-specific weighting of the three focus areas. In addition, NIST is developing the Control Overlays for Securing AI Systems (COSAiS) based on SP 800-53 — with use cases for generative AI, predictive AI and agentic AI (single- and multi-agent).

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

NIST · 2025

NIST IR 8596 iprd — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), Initial Preliminary Draft

First CSF 2.0 Community Profile for AI cybersecurity, with the three focus areas Secure, Defend and Thwart; comment period until January 30, 2026.

NIST · 2023

Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1

Overarching framework for the responsible use of AI systems; refers to the CSF and RMF for cybersecurity risks and is currently being revised.

NIST · 2024

The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29

Base framework with the six Functions GOVERN through RECOVER, whose structure the Cyber AI Profile transfers to the AI context.

NIST · 2025

Control Overlays for Securing AI Systems (COSAiS) — NIST-Projekt

SP 800-53 control overlays under development for generative AI, predictive AI and agentic AI, serving as an implementation-oriented complement to the Cyber AI Profile.

VamiSec GmbH · 2026

Webinar „NIST Cyber AI Profile — Cybersecurity Framework 2.0 trifft KI“

VamiSec webinar on NIST IR 8596, the three focus areas and the synergies with the EU AI Act, NIS2 and ISO/IEC 42001.

Building structured AI risk management based on NIST

VamiSec supports you with gap analyses against the Cyber AI Profile, advice on integrating it into your ISMS, audit support and training — as a consultancy that is itself certified to ISO/IEC 27001, with an ISO 27001 & 42001 Lead Auditor.