The Artificial Intelligence Risk Management Framework (AI RMF 1.0, NIST AI 100-1, 2023) addresses the responsible use of AI systems in its full breadth and refers to the NIST CSF and the Risk Management Framework for the treatment of cybersecurity risks. It is currently being revised by NIST. The Cyber AI Profile builds on it and gives concrete shape to the cybersecurity dimension of AI risk management.
NIST AI RMF & Cyber AI Profile
Risk management for AI the NIST way: the AI Risk Management Framework and the new Cyber AI Profile (NIST IR 8596) give organizations a structured, prioritized framework for securing AI systems, using AI for defense and thwarting AI-enabled attacks.
2coordinated NIST publications: AI RMF and Cyber AI Profile
3focus areas: Secure, Defend and Thwart
6CSF 2.0 Functions from GOVERN through RECOVER
3Proposed Priority levels: High, Moderate, Foundational
Artificial intelligence changes the cybersecurity risk profile of organizations in both directions: it expands the attack surface to include models, agents, prompts and training data — and at the same time opens up new opportunities for defense. NIST addresses both sides with two coordinated publications: the AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) covers the responsible use of AI systems across the board and refers to the Cybersecurity Framework (CSF) and the Risk Management Framework for cybersecurity risks. With the Cyber AI Profile (NIST IR 8596), a Community Profile has been available since December 2025 that, for the first time, applies the CSF 2.0 structure specifically to the AI context and prioritizes Subcategories for each area of application. For European companies, the profile is particularly interesting because it can be combined with the binding requirements of the EU AI Act, NIS2 and ISO/IEC 42001.
The Essentials at a Glance
Six topic blocks — tap to expand.
The three focus areas at a glance
The Cyber AI Profile structures AI cybersecurity into three areas that complement and reinforce one another — tap a focus area.
- Securing AI System Components covers protecting AI components such as models, agents, algorithms, prompts and data.
ModelsAgentsAlgorithmsPromptsData
- Conducting AI-Enabled Cyber Defense identifies opportunities to use AI to improve cybersecurity processes.
Cybersecurity processes
- Thwarting AI-Enabled Cyber Attacks builds resilience against new AI-enabled attack vectors.
ResilienceAI-enabled attack vectors
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
NIST IR 8596 iprd — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), Initial Preliminary Draft
First CSF 2.0 Community Profile for AI cybersecurity, with the three focus areas Secure, Defend and Thwart; comment period until January 30, 2026.
Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1
Overarching framework for the responsible use of AI systems; refers to the CSF and RMF for cybersecurity risks and is currently being revised.
The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29
Base framework with the six Functions GOVERN through RECOVER, whose structure the Cyber AI Profile transfers to the AI context.
Control Overlays for Securing AI Systems (COSAiS) — NIST-Projekt
SP 800-53 control overlays under development for generative AI, predictive AI and agentic AI, serving as an implementation-oriented complement to the Cyber AI Profile.
Webinar „NIST Cyber AI Profile — Cybersecurity Framework 2.0 trifft KI“
VamiSec webinar on NIST IR 8596, the three focus areas and the synergies with the EU AI Act, NIS2 and ISO/IEC 42001.
Related Services
Building structured AI risk management based on NIST
VamiSec supports you with gap analyses against the Cyber AI Profile, advice on integrating it into your ISMS, audit support and training — as a consultancy that is itself certified to ISO/IEC 27001, with an ISO 27001 & 42001 Lead Auditor.