RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The record · 100 retrospective records ↗

The record / Safety & policy

Safety & policy / From the record · 26 July 2024 event · prepared 16 September 2026

NIST's generative AI profile named thirteen specific risks

Published in July 2024, the Generative AI Profile extends the AI RMF with risks and suggested actions specific to generative systems.

Visual published with the cited source for this record: NIST's generative AI profile named thirteen specific risks
Visual published with the cited source, shown for identification of the record. Credit: nist.gov · source page ↗ Rights: owner-review-pending.

A companion document for generative systems

On 26 July 2024, NIST published the Generative AI Profile, formally titled 'Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile' and catalogued as NIST AI 600-1. The publication record describes it as a 'cross-sectoral profile of and companion resource for the AI Risk Management Framework...for Generative AI,' produced in response to a directive in Executive Order 14110 that NIST issue generative-AI-specific guidance. A profile, in NIST's terminology, does not replace the base framework; it applies the same four functions, Govern, Map, Measure and Manage, set out on the AI RMF page, to a named technology category rather than introducing a new structure.

Thirteen risks and hundreds of suggested actions

NIST's own summary, on its technical reports page, describes the profile as covering '13 risks and more than 400 actions that developers can take to manage them,' developed with input from a public working group of roughly 2,500 participants. That scale of action list is itself informative: rather than a short set of high-level principles, the profile is built as a reference a team can consult for specific, function-mapped suggestions once it has identified which of the thirteen risk categories applies to its system. As with the base framework, the actions are suggested practice, not binding requirements, and NIST does not test or certify a system's compliance with them.

What a profile changes and what it does not

The profile's practical effect is to give organisations already using the AI RMF a generative-AI-specific checklist instead of asking them to derive one from the generic framework unaided. It does not resolve the limits of the base framework: adoption is voluntary, the specific measurement methods for each of the thirteen risks are left to the adopting organisation, and no certification follows from citing it. The profile also postdates the executive order that requested it by about nine months, illustrating that 'guidance directed by an order' and 'guidance published' are different milestones with different dates, worth distinguishing when tracing a compliance timeline. As a living technical reference, its content, as retrieved on 16 September 2026, may already differ in detail from the version first issued in July 2024.

  • Which of the profile's thirteen risk categories are actually relevant to this system's modality and deployment context?
  • Of the suggested actions under the relevant categories, which has the organisation implemented, and which has it merely reviewed?
  • Does the organisation's evidence distinguish 'we consulted NIST AI 600-1' from 'we tested against a threshold NIST specified,' given the profile specifies no such threshold?

Read this way, the profile is best treated as a structured prompt for a team's own risk analysis, not as a document whose citation substitutes for that analysis.

Sources & reading trail

Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile ↗

Confirms the publication date and describes the profile as a companion to the AI RMF produced under Executive Order 14110.

Source published: 26 July 2024 · Retrieved: 16 September 2026

AI RMF Technical Reports ↗

States the profile covers 13 risks and over 400 suggested actions, developed with a 2,500-person working group.

Source published: Not established · Retrieved: 16 September 2026

AI Risk Management Framework ↗

Confirms the four-function structure the profile extends and that the profile followed the base framework in July 2024.

Source published: Not established · Retrieved: 16 September 2026

Papers and official documents establish the record; the reading and the questions are Model Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.