The Generative AI Profile — NIST AI 600-1 — is the document that makes the AI Risk Management Framework usable for organizations deploying large language models. The framework itself is deliberately technology-neutral; the profile names twelve risks that are unique to or made worse by generative AI, and sets out suggested actions against each function of the AI RMF core.
Published in July 2024, it remains the most practical free reference for anyone writing an AI policy that has to survive contact with a real deployment. This guide covers the twelve risks, how the suggested actions are structured, and how the profile fits alongside ISO 42001.

What the Generative AI Profile is
A profile, in AI RMF terms, is an implementation of the framework’s functions, categories and subcategories for a specific setting, application or technology. NIST AI 600-1 is a cross-sectoral profile: it addresses risks arising from activities common across sectors — the use of large language models, cloud-based services, acquisition — rather than the concerns of one industry.
It sits on top of the AI RMF 1.0, which NIST released in January 2023 for voluntary use, and it was developed with input from NIST’s Generative AI Public Working Group. That group’s focus is worth knowing, because it shapes what the profile covers well: governance, content provenance, pre-deployment testing and incident disclosure.
The twelve risks in the Generative AI Profile
NIST’s list, in its own order and with its own names:
| # | Risk | In short |
|---|---|---|
| 1 | CBRN Information or Capabilities | Eased access to or synthesis of information supporting chemical, biological, radiological or nuclear weapons |
| 2 | Confabulation | Confidently stated but false content — what everyone else calls hallucination |
| 3 | Dangerous, Violent, or Hateful Content | Easier production of violent, inciting, radicalizing or self-harm content |
| 4 | Data Privacy | Leakage, unauthorized disclosure or de-anonymization of personal and sensitive data |
| 5 | Environmental Impacts | Consequences of high compute utilization in training and operation |
| 6 | Harmful Bias or Homogenization | Amplified societal bias, performance disparities between groups, and output homogeneity |
| 7 | Human-AI Configuration | Anthropomorphizing, automation bias, over-reliance, algorithmic aversion |
| 8 | Information Integrity | Lowered barriers to generating content that blurs fact, opinion and fiction at scale |
| 9 | Information Security | Lowered barriers to offensive cyber capability, plus a larger attack surface on the models themselves |
| 10 | Intellectual Property | Easier replication of copyrighted or licensed content, and exposure of trade secrets |
| 11 | Obscene, Degrading, and/or Abusive Content | Synthetic abusive imagery, including CSAM and non-consensual intimate images |
| 12 | Value Chain and Component Integration | Untraceable third-party components, improperly obtained data, weak supplier vetting |
Each risk in the profile carries a trustworthy AI characteristic — safe, explainable and interpretable, privacy-enhanced, secure and resilient, and so on — which is how a risk in the profile connects back to the framework’s own vocabulary.
The two most useful entries for a real deployment
Confabulation is the one every organization meets in week one. NIST’s framing is precise and worth borrowing: content that is confidently presented and erroneous, including outputs that diverge from the input or contradict earlier statements in the same context. That definition gives you something to test against, which “hallucination” does not.
Human-AI Configuration is the one most policies miss entirely. The risk is not the model; it is the arrangement between the person and the model — over-reliance, automation bias, emotional entanglement, or the opposite failure where staff distrust a system that is performing well. Controls for it are procedural and training-based rather than technical, which is why they get left out of an engineering-led risk assessment.
How the suggested actions are organized
The profile does not stop at naming risks. For each one it offers suggested actions arranged against the AI RMF core functions — govern, map, measure and manage — and tied to specific framework subcategories. That structure is what makes it usable as a control set: you can take a subcategory you have already adopted and read off the generative-AI-specific actions that belong under it.
Two caveats NIST states plainly. The actions are suggested, not required — this is voluntary guidance, and there is no certification against it. And the profile’s coverage reflects the working group’s four focus areas, with future revisions expected to add subcategories, risks and actions as evidence accumulates. Treat it as a strong starting set rather than a complete one.
Using the Generative AI Profile alongside ISO 42001
The two are complementary, and the division of labor is clean. ISO/IEC 42001 gives you a certifiable management system — scope, leadership, risk process, objectives, internal audit, management review — and its controls are written at the level of an organization running AI. The Generative AI Profile gives you a risk taxonomy and specific actions for one technology class. Neither replaces the other.
In practice: run the management system to ISO 42001, and use the profile’s twelve risks as the starting inventory for your AI risk assessment wherever generative AI is in scope. It supplies vocabulary an auditor will recognize and a defensible reason for why your risk register contains what it contains — which is more than an internally invented list can offer. Our comparison of ISO 42001 and the NIST AI RMF covers where the two frameworks overlap in detail.
Frequently asked questions
What is NIST AI 600-1?
The Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, published by NIST in July 2024. It is a cross-sectoral profile of the AI RMF 1.0 for generative AI.
Can we certify against the Generative AI Profile?
No. Like the AI RMF itself it is voluntary guidance with no certification scheme. ISO/IEC 42001 is the certifiable option.
How many risks does it define?
Twelve, listed above — described by NIST as unique to or exacerbated by generative AI.
Does it tell us what controls to implement?
It offers suggested actions organized by AI RMF function and subcategory. They are a starting set to be selected from according to your context, not a checklist to be completed.
Is it still current?
It remains published by NIST as the generative AI profile of the AI RMF, and NIST has continued to develop further profiles for specific settings. The profile itself anticipates revision as evidence about generative AI risk accumulates.
Where this leaves you
The Generative AI Profile is the fastest way to give an AI risk assessment a defensible spine. Take the twelve risks as your inventory, keep NIST’s names so that your register speaks the same language as your auditors and customers, work the suggested actions under the govern, map, measure and manage functions you already run, and pay particular attention to confabulation and human-AI configuration — the two that show up in every deployment and are missing from most policies.
References
- NIST AI 600-1 — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, July 2024.
- NIST — AI Risk Management Framework — the AI RMF 1.0 and its associated profiles and resources.
More on AI governance
- The Generative AI Profile — you are here
- The NIST AI Risk Management Framework
- ISO 42001 vs NIST AI RMF
- NIST AI RMF documentation templates
Risk registers, policies and assessment templates mapped to the framework are in the NIST AI RMF Toolkit, or start with the free ISO templates.