
A companion document for generative systems
On 26 July 2024, NIST published the Generative AI Profile, formally titled 'Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile' and catalogued as NIST AI 600-1. The publication record describes it as a 'cross-sectoral profile of and companion resource for the AI Risk Management Framework...for Generative AI,' produced in response to a directive in Executive Order 14110 that NIST issue generative-AI-specific guidance. A profile, in NIST's terminology, does not replace the base framework; it applies the same four functions, Govern, Map, Measure and Manage, set out on the AI RMF page, to a named technology category rather than introducing a new structure.
Thirteen risks and hundreds of suggested actions
NIST's own summary, on its technical reports page, describes the profile as covering '13 risks and more than 400 actions that developers can take to manage them,' developed with input from a public working group of roughly 2,500 participants. That scale of action list is itself informative: rather than a short set of high-level principles, the profile is built as a reference a team can consult for specific, function-mapped suggestions once it has identified which of the thirteen risk categories applies to its system. As with the base framework, the actions are suggested practice, not binding requirements, and NIST does not test or certify a system's compliance with them.
What a profile changes and what it does not
The profile's practical effect is to give organisations already using the AI RMF a generative-AI-specific checklist instead of asking them to derive one from the generic framework unaided. It does not resolve the limits of the base framework: adoption is voluntary, the specific measurement methods for each of the thirteen risks are left to the adopting organisation, and no certification follows from citing it. The profile also postdates the executive order that requested it by about nine months, illustrating that 'guidance directed by an order' and 'guidance published' are different milestones with different dates, worth distinguishing when tracing a compliance timeline. As a living technical reference, its content, as retrieved on 16 September 2026, may already differ in detail from the version first issued in July 2024.
- Which of the profile's thirteen risk categories are actually relevant to this system's modality and deployment context?
- Of the suggested actions under the relevant categories, which has the organisation implemented, and which has it merely reviewed?
- Does the organisation's evidence distinguish 'we consulted NIST AI 600-1' from 'we tested against a threshold NIST specified,' given the profile specifies no such threshold?
Read this way, the profile is best treated as a structured prompt for a team's own risk analysis, not as a document whose citation substitutes for that analysis.
Sources & reading trail
Confirms the publication date and describes the profile as a companion to the AI RMF produced under Executive Order 14110.
Source published: 26 July 2024 · Retrieved: 16 September 2026
States the profile covers 13 risks and over 400 suggested actions, developed with a 2,500-person working group.
Source published: Not established · Retrieved: 16 September 2026
Confirms the four-function structure the profile extends and that the profile followed the base framework in July 2024.
Source published: Not established · Retrieved: 16 September 2026
Papers and official documents establish the record; the reading and the questions are Model Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.