Your organization is deploying AI that learns, adapts, and makes decisions without explicit programming. The gap between your current controls and what AI demands isn't just technical, it's structural.
NIST is developing the Cyber AI Profile, reflecting a broader industry recognition: AI-related cybersecurity risks require governance frameworks that can adapt while maintaining accountability. The workshop process that generated over 1,400 comments revealed what practitioners already know: you need both strategic oversight and practical implementation guidance, especially if you're not a Fortune 500 company with dedicated AI governance teams.
This checklist helps you assess whether your governance structure can handle AI cybersecurity risks. It's built around the dual requirements participants emphasized during NIST's public dialogue, enterprise risk management and implementation-level controls.
Introduction: What This Checklist Covers
This checklist evaluates your organization's readiness to govern AI systems from a cybersecurity perspective. It addresses three layers: strategic governance, operational controls, and accountability mechanisms. Each item requires a yes/no answer with clear evidence. If you can't point to a specific artifact, policy, or process, the answer is no.
The checklist doesn't cover AI ethics broadly or general data governance. It focuses on cybersecurity risks specific to AI adoption: model integrity, adversarial attacks, supply chain transparency, and decision accountability.
Prerequisites
Before starting this assessment, confirm you have:
An inventory of AI systems in production or pilot. You can't govern what you haven't identified. This includes both AI tools you've deployed and third-party AI services your teams are using.
Access to your current cybersecurity risk register. You'll need to verify whether AI-specific risks appear and how they're classified.
Clarity on who owns AI governance today. If the answer is "everyone" or "IT," you're not ready for this checklist. Assign a temporary owner to complete the assessment.
Checklist Items
1. Have you established a multidisciplinary AI governance body with defined decision rights?
Don't confuse a steering committee that reviews AI projects with a governance body that can halt deployments. Your governance structure needs representation from cybersecurity, legal, compliance, IT operations, and business units using AI.
Good looks like: A charter that specifies who approves AI system deployments, who reviews model changes, and who investigates incidents. Meeting minutes that show actual decisions, not just status updates.
2. Does your Cybersecurity Risk Register include AI-specific threat scenarios?
Generic "data breach" entries don't cut it. AI introduces distinct risks: adversarial inputs designed to manipulate model outputs, model inversion attacks that extract training data, and supply chain compromises that poison training datasets.
Good looks like: Risk entries that reference specific AI attack vectors, assign severity levels based on your AI use cases, and map to controls designed for AI systems, not retrofitted network security controls.
3. Can you produce an AI Bill of Materials for each production AI system?
You wouldn't deploy software without knowing its dependencies. AI systems have dependencies too: training datasets, pre-trained models, APIs, and libraries. Participants in NIST's workshop highlighted AI Bills of Materials as critical for supply chain integrity.
Good looks like: Documentation for each AI system that lists training data sources, model provenance, third-party components, and update history. You should be able to trace a model output back to its training inputs.
4. Have you defined and documented human-in-the-loop requirements for AI-driven decisions?
Automation is the point of AI, but workshop participants emphasized that human-in-the-loop processes remain the current standard for AI accountability. The question isn't whether humans stay involved, it's where and how.
Good looks like: Process documentation that specifies which AI decisions require human review, who's qualified to perform that review, and what happens when a human overrides the AI. Include escalation paths for contested decisions.
5. Do you have testing protocols specific to AI system integrity and performance?
Your standard penetration testing and vulnerability scanning don't evaluate whether an AI model degrades over time or responds predictably to edge cases. Workshop participants identified testing and evaluation as a common challenge.
Good looks like: Test plans that include adversarial input testing, model drift monitoring, and performance benchmarking against known datasets. Results should feed back into your risk register and trigger re-evaluation when thresholds are breached.
6. Can you demonstrate transparency in how AI systems reach decisions affecting cybersecurity posture?
If your AI-powered security tool blocks a transaction or flags an anomaly, can you explain why? Transparency supports both accountability and incident investigation.
Good looks like: Logging that captures model inputs, outputs, and confidence scores. Documentation of model logic that's accessible to auditors and investigators, even if the underlying algorithm is complex.
7. Have you classified AI systems by cybersecurity risk level and applied differentiated controls?
Not all AI carries the same risk. An AI chatbot answering HR questions poses different cybersecurity concerns than an AI system managing network access decisions.
Good looks like: A classification scheme (high/medium/low or similar) tied to specific control requirements. High-risk AI systems should have stricter testing, more frequent reviews, and enhanced monitoring.
8. Do you maintain an inventory of "shadow AI" usage across your organization?
Workshop participants raised shadow AI as a visibility challenge. Your teams are using AI tools whether you've approved them or not, ChatGPT, coding assistants, data analysis platforms.
Good looks like: A discovery process that identifies unapproved AI tool usage, an intake process for evaluating new tools, and policy that defines acceptable use. You're not trying to ban AI; you're bringing it into your governance perimeter.
Common Mistakes
Treating AI governance as a technology problem. Your CISO can't own this alone. AI governance requires cross-functional coordination because AI decisions affect operations, compliance, and business outcomes.
Waiting for perfect guidance before acting. NIST workshop participants specifically requested that guidelines avoid being too specific because technology changes quickly. Build flexible governance structures that can adapt, rather than waiting for prescriptive standards.
Applying existing control frameworks without modification. Your SOC 2 controls weren't designed for systems that learn from data. Adapt your control design to address AI-specific risks like model poisoning and data drift.
Confusing AI ethics frameworks with cybersecurity governance. Fairness and bias matter, but they're distinct from cybersecurity risks. This checklist focuses on confidentiality, integrity, and availability of AI systems.
Next Steps
Score your results. If you answered no to more than three items, your governance structure has critical gaps. Start with items 1, 2, and 4, governance body, risk register, and human-in-the-loop requirements. These create the foundation for everything else.
If you scored well, your next step is stress-testing these controls against a realistic scenario: What happens when a third-party AI service you depend on is compromised? Can your governance structure respond effectively?
NIST continues developing the Cyber AI Profile with input from practitioners facing these challenges daily. You don't need to wait for final guidance to start building adaptable governance. The organizations that get this right will be those that establish flexible structures now, then refine them as both technology and standards evolve.





