โ†
AI Governance, Risk & Red Teaming
Aware ยท M12 ยท lesson 12 of 18 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
NIST AI 600-1 GenAI Profile - The 12 Risks and 200+ Suggested Actions
๐Ÿ“–
now learning

NIST AI 600-1 GenAI Profile - The 12 Risks and 200+ Suggested Actions

15 min

The NIST AI 600-1 Generative AI Profile is the most operationally useful document in the entire NIST AI ecosystem. It takes the abstract Govern/Map/Measure/Manage architecture from the AI RMF Core and turns it into 12 named risks and 200+ suggested actions distributed across the four functions and the AI lifecycle stages. Each suggested action carries an actor designation, provider, deployer, or both, and a function/category tag. The Profile is the operational substrate for a U.S.-anchored GenAI program in 2026 and the cross-walk evidence that anchors the EU AI Act Article 55 evaluation work, the OWASP LLM Top 10 testing scope, and the ISO 42001 A.6 / A.8 control evidence. This lesson walks each of the 12 risks, names the suggested-action density, builds the 12-risk applicability matrix, and ships the artifact your AI Governance Committee uses to track generative-AI exposure quarterly.

Why the GenAI Profile Matters - Both Sides of the Atlantic

NIST published the AI 600-1 GenAI Profile in July 2024 in response to Section 4.1(a)(ii) of Executive Order 14110, which directed NIST to develop "companion resources" to the AI RMF for generative AI. The Profile is voluntary but the practical weight is similar to the AI RMF Core: federal procurement references it; state procurement adopts it; tort and securities standards-of-care evolve around it; customer-assurance reviews demand alignment.

The reason the GenAI Profile travels well into EU AI Act compliance work: the 12 risks named in the Profile substantially overlap with the EU AI Act Recital 110 systemic-risk taxonomy that Article 55 GPAI-with-systemic-risk providers must evaluate, mitigate, report, and secure against. Three of the 12 risks (CBRN information harm, information integrity, harmful bias and homogenization) map directly to Recital 110 categories. The remaining nine inform the broader Article 9 risk-management-system work that Annex III high-risk deployers must operate on top of generative components.

For a 2026 program with both U.S. and EU exposure, the GenAI Profile is the operational substrate that satisfies NIST + EU + ISO 42001 simultaneously. The 12-risk applicability matrix the AI Governance Lead builds against the Profile is the same artifact that informs Article 55 evaluation evidence (for GPAI providers), Article 26 deployer-side mitigation work (for downstream deployers), and the ISO 42001 A.6 impact-assessment evidence. Write once, cite three times, the cross-walk pattern continues.

The Twelve Risks - Named and Defined

The GenAI Profile identifies twelve distinct risks particular to or significantly exacerbated by generative AI. Each risk carries a definition in the Profile, an enumeration of risk indicators, and a set of suggested actions for mitigation. The twelve:

Risk 1 - CBRN Information or Capabilities

Lowered barriers to entry for chemical, biological, radiological, and nuclear weapons material or capability information. The risk arises when generative models provide step-by-step synthesis information for dangerous substances, identification of dual-use research materials, or vulnerability information on critical infrastructure. The Profile's suggested actions emphasize pre-deployment evaluation against CBRN evaluation suites, output filtering, and partnership with national CBRN agencies (in the U.S., the National Counterproliferation Center and similar). Most enterprise deployers will not develop CBRN capability themselves; the actor-mapping for these actions emphasizes the provider side, with deployer-side actions limited to acceptable-use policy enforcement.

Risk 2 - Confabulation

Generation of erroneous content with high apparent confidence, the "hallucination" pattern in colloquial language. The Profile treats confabulation as a primary risk for any GenAI deployment because the user-facing harm is direct: a confabulated medical recommendation, a confabulated legal citation, a confabulated credit-eligibility statement. Suggested actions span the provider side (training-time mitigations, evaluation against confabulation benchmarks) and the deployer side (retrieval-augmentation patterns, output verification, user-facing disclosure of confidence limits, human-review pathways). This is the most-cited GenAI risk in 2026 audit reviews.

Risk 3 - Dangerous, Violent, or Hateful Content

Generation of content that promotes violence, self-harm, hate speech, harassment, or comparable harms. The Profile's actor-mapping spans provider-side training-time safety alignment, output classification, refusal training; and deployer-side acceptable-use policy enforcement, content moderation, escalation pathways. The Article 5(1)(a) prohibited-practice manipulation overlay and the Digital Services Act overlay for EU customer-facing platforms compound this risk.

Risk 4 - Data Privacy

Unauthorized exposure of personal data through training-data memorization, prompt-injection extraction, model inversion, or membership inference. The Profile's suggested actions span the provider side (training-data sanitization, differential-privacy techniques, model-extraction resistance) and the deployer side (PII scrubbing in prompts, output PII filtering, GDPR Article 22 / 25 / 35 overlay, user-facing privacy notice). The OWASP LLM02 (sensitive information disclosure) overlay maps to this risk.

Risk 5 - Environmental

Energy and water consumption associated with training and inference; greenhouse-gas emissions; cooling-system water use. The Profile's actor-mapping is provider-side-heavy (training-energy disclosure, efficient-architecture choices) with deployer-side actions on inference-time optimization (batching, caching, smaller models where appropriate). The CSRD / EU sustainability-reporting overlay for EU operations compounds this risk.

Risk 6 - Human-AI Configuration

Misalignment between the AI system's intended human-interaction design and actual user behavior: automation bias, over-reliance on AI outputs, under-reliance leading to ignored useful outputs, distortion of decision-making. The Profile emphasizes Article 14-style human-oversight design, training of users on appropriate reliance, calibration of confidence-presentation, and ongoing measurement of human-AI interaction patterns. Deployer-heavy actor-mapping.

Risk 7 - Intellectual Property

Generation of content that infringes copyrights, trademarks, patents, or trade secrets. Includes training-data infringement risk, output-similarity infringement risk, and prompt-injected IP exfiltration. The Profile's actor-mapping spans provider-side training-data licensing (the Article 53(1)(c) copyright policy overlap) and deployer-side output-screening, indemnification analysis, and acceptable-use-policy restrictions. The U.S. Copyright Office's continuing guidance on AI-assisted works and the EU GPAI Code of Practice copyright chapter both inform 2026 practice.

Risk 8 - Obscene, Degrading, or Abusive Content

Generation of obscene content including child sexual abuse material (CSAM); degrading or abusive content targeting individuals or groups; non-consensual intimate imagery (NCII). The Profile names this risk separately from Risk 3 because the legal-overlay severity is higher: CSAM generation is criminally prohibited in essentially every jurisdiction; NCII generation triggers state-by-state criminal exposure in the U.S. and Member-State-by-Member-State exposure in the EU. The Profile's actor-mapping is heavily provider-side (training-time filtering, CSAM-detection partnerships with NCMEC and IWF, refusal training) with deployer-side acceptable-use policy and escalation-to-law-enforcement pathways.

Risk 9 - Information Integrity

Generation of content that distorts factual information, including political misinformation, scientific misinformation, public-health misinformation, and impersonation. The Profile actor-mapping spans provider-side training-time alignment, output-truthfulness evaluation, and deployer-side disclosure (Article 50(2) machine-readable marking; Article 50(4) deepfake disclosure; Article 50 public-interest text disclosure). The EU AI Act Recital 110 systemic-risk taxonomy names information-integrity-harm-to-democratic-processes-or-public-safety as a designated systemic risk for Article 55 GPAI providers.

Risk 10 - Information Security

Lowered barriers to entry for cybersecurity exploitation: generation of exploit code, social-engineering content, malware variants, phishing campaigns at scale. Includes risks to the AI system's own security: prompt injection, model extraction, training-data extraction. The Profile's actor-mapping spans provider-side cybersecurity-evaluation suites (cf. Article 55(1)(d) cybersecurity protection) and deployer-side red-teaming under OWASP LLM Top 10 / Agentic Top 10 + MITRE ATLAS coverage. NIST AI RMF Measure 2.7 red-team work is the operational evidence.

Risk 11 - Value Chain and Component Integration

Risks arising from the GenAI supply chain: foundation-model upstream provenance, fine-tuning data sources, prompt-engineering libraries, retrieval-augmentation infrastructure, agent-tool ecosystems. The Profile names this risk separately because the cascade-failure pattern is unique to GenAI: a vulnerability in an upstream foundation model or a poisoned RAG retrieval source can compromise every downstream deployer simultaneously. Suggested actions span ML-BoM / SBOM-AI documentation (CycloneDX 1.7 + CDXA), upstream-provider attestation review (Annex XI / XII receivables for GPAI), and downstream-deployer cooperation requirements.

Risk 12 - Harmful Bias and Homogenization

Generation of content that exhibits or amplifies harmful biases; homogenization of outputs that reduces diversity of perspectives or marginalizes underrepresented groups. The Profile treats bias separately from Risk 3 (dangerous content) because the harm pattern is statistical rather than instance-by-instance. Suggested actions span provider-side training-time bias mitigation, evaluation against bias benchmarks, and deployer-side audit (cf. NYC LL 144 four-fifths-rule analysis, EEOC Title VII disparate-impact framework), fairness-metric selection (demographic parity, equalized odds, predictive parity), and ongoing monitoring for bias drift.

The Actor-Mapping - Provider Actions vs. Deployer Actions vs. Both

The Profile distinguishes suggested actions by actor: GV (Govern), MP (Map), MS (Measure), MG (Manage) cross-referenced by actor type (training, design, development, deployment, monitoring). The actor-mapping is implicit through the activity type but reads cleanly into the EU AI Act actor classification:

  • Provider-side actions (training, design, development) cross-walk to EU AI Act Article 16 obligations for non-GPAI providers, Article 53 + Article 55 for GPAI providers, ISO 42001 Annex A.6 lifecycle controls.
  • Deployer-side actions (deployment, monitoring) cross-walk to EU AI Act Article 26 obligations, Article 27 FRIA, Article 73 incident reporting, ISO 42001 A.8 information for users.
  • Both-actor actions (governance, third-party risk management) cross-walk to EU AI Act Article 4 literacy, Article 17 QMS at organizational level, ISO 42001 A.2 policies + A.10 third-party relationships.

For a deployer building on top of a foundation model, the actor-mapping decides which suggested actions are operationally owned vs. which are reliant on the upstream provider's compliance. The deployer-side actions go into the deployer's runbook; the provider-side actions go into the procurement-contract checklist and the Annex XII receivable verification work.

Suggested-Action Density - Where the Operational Work Concentrates

The 200+ suggested actions are not evenly distributed across the 12 risks. The Profile concentrates operational guidance on the risks where deployer-side action is most consequential. Approximate density:

  • Confabulation (Risk 2): ~30 suggested actions. The highest-density risk because the operational mitigations (retrieval augmentation, output verification, human-review pathways, confidence-disclosure) span the whole AI lifecycle.
  • Information Security (Risk 10): ~25 suggested actions. Cybersecurity-evaluation density driven by the OWASP / ATLAS cross-walk.
  • Harmful Bias and Homogenization (Risk 12): ~25 suggested actions. Bias-mitigation density driven by the multi-jurisdiction overlay (EEOC, NYC LL 144, Texas TRAIGA, EU AI Act).
  • Data Privacy (Risk 4): ~20 suggested actions. GDPR overlay drives density.
  • Information Integrity (Risk 9): ~20 suggested actions. Article 50 disclosure overlay drives density.
  • Value Chain and Component Integration (Risk 11): ~15 suggested actions. ML-BoM / Annex XII overlay drives density.
  • Dangerous Content (Risk 3) + Obscene Content (Risk 8): ~15-20 suggested actions combined. Legal-overlay severity drives a smaller density but a higher action criticality.
  • IP (Risk 7): ~15 suggested actions. Copyright Office / GPAI Code of Practice copyright chapter overlap drives density.
  • Human-AI Configuration (Risk 6): ~15 suggested actions. Article 14 human-oversight design drives density.
  • CBRN (Risk 1): ~10 suggested actions. Provider-side-heavy; deployer actions limited to acceptable-use policy.
  • Environmental (Risk 5): ~10 suggested actions. CSRD overlap drives density for EU operations.

For a deployer-side program, the workload concentrates on Risks 2, 10, 12, 4, 9, 11. The provider-side workload is distributed differently with heavier weight on Risks 1, 3, 8, 5.

The Twelve-Risk Applicability Matrix - The L1 Artifact

The L1 artifact for this lesson is a 12-risk applicability matrix: rows for each of the 12 risks, columns for each GenAI system in the portfolio, cells with applicability status (yes / no / partial), suggested-action coverage status (number of suggested actions operating / number applicable), and remediation backlog notes. A representative matrix for an enterprise with 6 GenAI systems in May 2026:

  • System 1 - Customer-service chatbot on Anthropic Claude: Risks 2 (confabulation), 4 (data privacy), 9 (information integrity), 10 (information security), 11 (value chain), 12 (harmful bias) all applicable; Risks 1, 3, 8 deferred to upstream provider; Risk 5 partial (deployer-side inference-time optimization). Suggested-action coverage 65%; remediation backlog includes confabulation-evaluation suite expansion and bias monitoring.
  • System 2, Internal coding assistant (Copilot Enterprise): Risks 2, 7 (IP, code-similarity infringement), 10, 11 applicable; Risks 3, 4, 6, 8, 9, 12 limited; CBRN N/A; Risk 5 partial. Suggested-action coverage 70%; remediation backlog includes IP scanning expansion and prompt-injection coverage.
  • System 3, Marketing-content generator (Adobe Firefly + DALL-E): Risks 7 (IP), 9 (information integrity, Article 50(2)/50(4) overlap), 11 (value chain), 12 (bias) applicable; Risks 2, 3, 8 (deepfake / NCII risk) partial. Suggested-action coverage 55%; remediation backlog includes Article 50(2) C2PA / SynthID integration and NCII detection.
  • System 4 - Generative video for product demos (Sora / Runway): Risks 7, 9 (especially Article 50(4) deepfake), 8 (NCII risk), 11, 12 applicable; Risks 2, 3 partial. Suggested-action coverage 45%; remediation backlog priority.
  • System 5 - Internal Llama 3.1-405B fine-tune for IT-helpdesk agent: All 12 risks applicable because the fine-tune triggered Article 25(1)(b) transfer (customer is provider for fine-tune); non-signatory upstream creates elevated burden on most risks. Suggested-action coverage 50%; remediation backlog substantial.
  • System 6 - Voice agent (ElevenLabs synthetic voice for customer-experience metrics): Risks 2, 4, 6, 9 (Article 50(2) audio marking), 10, 12 applicable; Risk 3 partial (workplace-emotion-recognition Article 5(1)(f) review). Suggested-action coverage 60%; remediation backlog includes Article 50(2) audio marking.

Six systems ร— 12 risks = 72 cells, with applicability status and coverage percentage per cell. The matrix is the artifact procurement and engineering use to prioritize FY26 GenAI risk work. The AI Governance Committee sees the matrix quarterly.

Cross-Walk to EU AI Act Recital 110 - The Systemic-Risk Bridge

Recital 110 of the EU AI Act enumerates the systemic risks the Commission has identified for GPAI-with-systemic-risk providers: CBRN, cyberattacks, large-scale discrimination, misinformation harming democratic processes or public safety, large-scale violation of fundamental rights, loss of control over autonomous AI, uncertainty about reproducibility and predictability. The cross-walk to the GenAI Profile 12 risks:

  • CBRN (Recital 110) โ†” Risk 1 (GenAI Profile)
  • Cyberattacks (Recital 110) โ†” Risk 10 (GenAI Profile)
  • Large-scale discrimination (Recital 110) โ†” Risk 12 (GenAI Profile)
  • Misinformation harming democratic processes or public safety (Recital 110) โ†” Risk 9 (GenAI Profile)
  • Large-scale violation of fundamental rights (Recital 110) โ†” Risks 3, 4, 8, 12 (GenAI Profile, combined)
  • Loss of control over autonomous AI (Recital 110) โ†” Risk 6 (GenAI Profile, plus OWASP Agentic Top 10 overlay)
  • Uncertainty about reproducibility / predictability (Recital 110) โ†” Risks 2 and 11 (GenAI Profile)

The cross-walk informs Article 55 evaluation evidence for GPAI-with-systemic-risk providers and downstream-deployer mitigation work. A deployer building on top of a designated GPAI model can cite Profile-aligned evaluations as part of its Article 55 reliance evidence. A provider can cite the Profile's 12-risk taxonomy as the operational version of Recital 110 for its evaluation methodology.

Three Program Archetypes - Which Risks Get Priority When

Archetype 1 - Customer-Facing Consumer GenAI Deployment

Priority risks: 2 (confabulation), 3 (dangerous content), 4 (data privacy), 8 (obscene content if user-generated), 9 (information integrity), 10 (information security). The customer-experience surface drives risk concentration. Article 50 disclosure overlay is heavy. GDPR Article 22 / 35 overlay is heavy. The L4 governance operating plan should prioritize content-moderation, refusal training, and user-facing disclosure design.

Archetype 2 - Internal Productivity GenAI Deployment (Coding Assistant, Writing Assistant)

Priority risks: 2, 7 (IP), 10, 11 (value chain). The internal-employee-facing surface concentrates risk on confabulation, IP infringement (especially code-similarity), supply-chain (foundation-model upstream), and prompt-injection. Article 5(1)(f) workplace emotion-recognition prohibition is a separate constraint to enforce. Article 4 literacy is critical because users are employees making decisions on AI outputs.

Archetype 3 - Generative-Content Marketing / Creative Deployment

Priority risks: 7 (IP), 8 (NCII deepfake), 9 (information integrity: Article 50(2) + 50(4) overlap), 11 (value chain), 12 (bias in generated imagery / text). The brand-customer surface drives risk on copyright, deepfake disclosure, machine-readable marking, and bias in generated outputs. The Article 50(2) Dec 2, 2026 acceleration is the immediate forcing function.

Common GenAI Profile Mistakes

Mistake 1 - Treating the Profile as a Research Document

The Profile is operational guidance with 200+ suggested actions. Treating it as a research document and skipping the suggested-action coverage analysis leaves the program without the operational substrate for NIST AI RMF Measure 2 trustworthiness evaluation. The 12-risk applicability matrix is the deployment-ready artifact, not a literature review.

Mistake 2 - Assuming Uniform Suggested-Action Density Across Risks

The 200+ suggested actions are concentrated on Risks 2, 10, 12, 4, 9, 11 for deployer-side work. Programs that allocate equal effort across all 12 risks miss the operational reality. Effort should follow the deployer-side density distribution.

Mistake 3 - Skipping the Actor-Mapping

The Profile's suggested actions are tagged by activity type (training, design, development, deployment, monitoring). Without the actor-mapping, a deployer-side program tries to implement provider-side training-time mitigations it cannot operate. The actor-mapping decides what goes in the deployer runbook vs. the procurement-contract checklist.

Mistake 4 - Operating GenAI Risk Management in Isolation From Annex III High-Risk

GenAI risk management is not a separate program from high-risk system management. A GenAI deployment that is also Annex III ยง4 employment (e.g., AI-generated candidate interview questions) carries both the GenAI Profile risk coverage AND the Annex III high-risk obligation set. The 12-risk matrix integrates with the tiering memo, not parallel to it.

Mistake 5 - Skipping the Recital 110 Cross-Walk

For organizations deploying GenAI built on GPAI-with-systemic-risk models, the Recital 110 cross-walk is the bridge between Profile-aligned evaluation evidence and Article 55 compliance evidence. Skipping the cross-walk leaves the program with two parallel artifacts instead of one cross-walked artifact.

Mistake 6 - Treating the 12-Risk Matrix as Static

The matrix is a living document. Quarterly refresh plus triggered updates on new GenAI deployments, vendor model upgrades, Profile updates (NIST updates the Profile periodically), Commission guidance updates (especially Article 55 evaluation methodology), and Recital 110 systemic-risk taxonomy refinements.

Key Takeaways

  • NIST AI 600-1 GenAI Profile is the operational substrate for GenAI risk management. Published July 2024; voluntary but practically mandatory through federal procurement, state procurement, tort standard of care, customer assurance.
  • 12 named risks plus 200+ suggested actions. CBRN; confabulation; dangerous/violent/hateful content; data privacy; environmental; human-AI configuration; IP; obscene/harmful content; information integrity; information security; value chain and component integration; harmful bias and homogenization.
  • Suggested actions tagged by activity type, training, design, development, deployment, monitoring, that read cleanly into EU AI Act actor classification (provider, deployer, both).
  • Suggested-action density concentrates on deployer-relevant risks. Risks 2 (confabulation), 10 (information security), 12 (bias), 4 (privacy), 9 (information integrity), 11 (value chain) carry the heaviest deployer-side density.
  • The 12-risk applicability matrix is the L1 artifact. Rows for risks, columns for systems, cells with applicability and coverage status, remediation backlog notes. Quarterly AI Governance Committee review.
  • Recital 110 cross-walk is the bridge to EU AI Act Article 55 evidence. All seven Recital 110 categories map to GenAI Profile risks; cross-walk informs Article 55 evaluation for GPAI providers and deployer-side reliance evidence.
  • Three program archetypes weight the risks differently. Customer-facing consumer; internal productivity; generative-content marketing. The matrix structure is the same; the priority distribution differs.
  • The Profile complements OWASP LLM Top 10 + MITRE ATLAS. OWASP names the attack class; ATLAS names the technique; the Profile names the risk + suggested actions. Use all three in red-team reports.
  • Provider-vs-deployer actor mapping is essential. Deployer-side actions go into the runbook; provider-side actions go into the procurement-contract checklist and the Annex XII receivable verification.
  • The matrix is a living document. Quarterly refresh plus triggered updates on new deployments, vendor upgrades, Profile updates, Commission guidance, Recital 110 refinements.