Timeline

NIST publishes Generative AI Profile for the AI Risk Management Framework

Issued under Biden's October 2023 executive order, the voluntary profile applies NIST's 2023 risk framework specifically to generative systems.

  • Government & policy
  • Minor

The US National Institute of Standards and Technology published a Generative AI Profile extending its AI Risk Management Framework, the voluntary risk-management standard it had released in January 2023. The profile applied the original framework’s structure specifically to generative systems, and its development had been directed by President Biden’s October 2023 executive order on AI, which tasked NIST with producing generative-AI-specific guidance.

Like the parent framework, the profile was voluntary rather than binding: it gave organisations a structured way to identify and manage risks across the generative-AI lifecycle — covering areas such as hallucinated or fabricated content, non-consensual deepfakes, data provenance and disclosure, and the involvement of multiple actors (model developers, fine-tuners and deployers) who might each bear different responsibility for a given harm. It did not create new legal obligations or certification requirements.

The publication was one of the more concrete deliverables to emerge from the executive order’s various directives before a change in administration altered the US federal government’s approach to AI governance; NIST’s AI Safety Institute, which had contributed to the underlying framework, was later renamed the Center for AI Standards and Innovation. As with the base AI RMF, the profile’s influence depended on voluntary adoption by companies and agencies rather than enforcement.