Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
NIST Confronts the AI-Framework GapGRC Frameworks
5 min readFor GRC Leaders

NIST Confronts the AI-Framework Gap

The Challenge

NIST identified a structural problem: existing frameworks weren't designed to handle AI-specific risks. The AI Risk Management Framework (AI RMF) addressed AI safety, transparency, and accountability, but it operated separately from the Cybersecurity Framework and Privacy Framework. Organizations using all three faced a coordination problem with no clear integration path.

The technical gap was clear. AI poses re-identification risks through its analytic power across datasets and potential data leakage from model training. AI voice generators create new phishing vectors that bypass traditional awareness training. Machine learning infrastructure introduces attack surfaces that don't align with existing control families. Meanwhile, AI capabilities could improve threat hunting and privacy protection, but the frameworks offered no guidance on deploying AI defensively.

NIST couldn't issue new guidance for every AI use case. They needed a systematic approach to adapt existing frameworks so organizations could integrate AI risk management into their current GRC programs without maintaining parallel compliance structures.

The Environment and Constraints

NIST operates under constraints that commercial vendors don't face. Their frameworks must remain technology-neutral to stay relevant as AI evolves, yet specific enough to drive actual control implementation. They can't mandate specific tools or architectures. Every update must work for both the Fortune 500 CISO with dedicated AI security teams and the mid-market compliance officer managing AI risks alongside everything else.

The stakeholder landscape complicated the work. Industry needed practical guidance immediately, government agencies required coordination across federal AI initiatives, and academia was producing new research on adversarial machine learning faster than standards bodies could incorporate it. NIST had to balance urgency with the deliberative process that makes their frameworks credible.

The program also had to account for AI's dual nature. The same organization might use AI for threat detection while defending AI-powered customer service systems from adversarial attacks and ensuring AI-driven analytics don't violate privacy commitments. A framework adaptation that addressed only offensive AI threats or only AI system security would leave critical gaps.

The Approach Taken

NIST established a dedicated program for the cybersecurity and privacy of AI rather than issuing standalone guidance documents. This program structure allowed sustained focus and coordination across multiple framework updates.

They started with existing research and publications. The Secure Software Development Practices for Generative AI and Dual-Use Foundation Models (NIST SP 218A) and Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2) provided technical foundations. Draft Guidelines for Evaluating Differential Privacy Guarantees (NIST SP 800-226) addressed privacy-specific concerns. The NICE Framework's recent addition of Security of AI as a competency area signaled workforce implications.

The technical infrastructure included Dioptra, a test platform for evaluating machine learning algorithms under diverse conditions, and a PETs Testbed for investigating privacy-enhancing technologies and their suitability for protecting machine learning models from privacy attacks.

The National Cybersecurity Center of Excellence (NCCoE) launched a community profile project to adapt the Cybersecurity Framework first, then assess impacts on the Privacy Framework, AI Risk Management Framework, and NICE Framework. This approach builds on proven community profile methodology used for other technologies and use cases.

The community profile focuses on three specific risk sources: cybersecurity and privacy risks from organizational AI use, defending against AI-enabled attacks, and using AI for cyber defense and improved privacy protections.

Results and Metrics

NIST published the program framework and opened stakeholder engagement channels. The program website went live with a dedicated contact point ([email protected]) for feedback and questions. The community profile development process launched through NCCoE with a defined scope covering the three risk categories.

The structural outcome matters more than publication counts. Organizations now have a roadmap for integrating AI risk management into existing GRC programs rather than treating AI as a separate compliance domain. The community profile approach means adaptations will reflect practitioner input, not just theoretical risk models.

What They Would Do Differently

NIST's announcement doesn't address what they'd change, but the approach reveals implicit lessons. Starting with a community profile for the Cybersecurity Framework before tackling the Privacy Framework and AI RMF simultaneously suggests they learned from past framework integration challenges. Phased adaptation prevents the coordination problems that emerge when multiple frameworks update independently.

The program structure itself, establishing a sustained effort rather than issuing point-in-time guidance, acknowledges that AI risks evolve faster than traditional framework update cycles can address. If NIST had started this work two years earlier, they'd likely have focused on different AI capabilities and threat vectors.

Takeaways for Your Team

Don't wait for final NIST guidance to start integrating AI risks into your GRC program. The three risk categories NIST identified give you a structure for inventory work you can do now:

Map your AI attack surface. Update your data asset inventory to account for machine learning infrastructure, training datasets, and model dependencies. Your existing cybersecurity controls may not adequately protect AI components, and you won't know the gaps until you document what you're protecting.

Reassess control effectiveness for AI-enabled threats. If your anti-phishing training doesn't address AI voice generators, it's already outdated. Review your security awareness program, incident response procedures, and detective controls through an AI threat lens. The control that detects traditional phishing may not flag AI-generated variants.

Evaluate AI use in your security stack with the same rigor you apply to AI risks. If you're deploying AI for threat hunting, document the false positive rate, understand the explainability limitations, and train your security team on the specific skills needed to interpret AI-generated alerts. AI as a defensive tool introduces its own risks.

Prepare for data dependency mapping. As business units adopt AI solutions, you'll need enterprise visibility into data flows that training and inference operations create. Your current data governance program probably doesn't account for model training data leakage or the re-identification risks AI analytics create across previously siloed datasets.

The NIST program signals that AI risk management is moving from a specialized concern to a core GRC function. Organizations that integrate AI risks into existing frameworks now will have functioning programs when regulators start asking specific questions. Those that treat AI as a separate compliance workstream will face coordination costs that NIST is explicitly trying to help you avoid.

NIST Cybersecurity Framework

Promotional banner for the Pentest Readiness checklist download

You Might Also Like