The NIST AI RMF and the Generative AI Profile
The NIST AI RMF core is deliberately technology-neutral, which is a strength and, for generative AI, a gap. Foundation models introduce risks that a general framework can only gesture at: confabulation, the easy generation of harmful or illegal content, data-privacy leakage from training data, and the amplification of bias at scale. So in July 2024 NIST published a companion, the Generative AI Profile (NIST AI 600-1), to make those risks concrete.
What the GenAI Profile adds
The Profile is not a new framework. It is a cross-sectoral Profile of the existing AI RMF that identifies twelve risks unique to or amplified by generative AI, and then lists hundreds of suggested actions, organised by the same four Functions, to help you manage them.
- Named GenAI risks: confabulation, dangerous or violent content, data privacy, harmful bias, information integrity, intellectual property, obscene content, and CBRN or cyber-uplift among them.
- Actions mapped to Govern, Map, Measure and Manage, so they slot straight into the RMF structure you already use.
- A bridge to real controls: content provenance, red-teaming, evaluation and incident response for model behaviour.
The GenAI Profile is NIST's way of saying the RMF still works for foundation models — you just need to point it at the risks that only show up when the model can generate.
Layer it on, do not restart
If you already run the AI RMF core, adopting the GenAI Profile is additive: you keep your Govern baseline and your per-system Map, Measure and Manage work, and you overlay the GenAI-specific risks and actions for the systems that actually use generative models. Your classical ML systems do not need it; your foundation-model features do.
In Compliance One you track the AI RMF core across your whole AI estate and layer the GenAI Profile on top for the generative systems, with everything cross-mapped to your ISO 42001 controls. You get one coherent picture of AI risk instead of two disconnected exercises.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map Compliance One to your environment.