NIST Generative AI Profile (NIST AI 600-1) — Companion to the AI Risk Management Framework
United States · NIST AI 600-1
NIST's voluntary GenAI Profile is the leading federal playbook for managing risks unique to generative AI: hallucinations, harmful content, intellectual property leakage, data poisoning, and CBRN misuse. Federal contractors and many enterprises adopt it as the de facto AI risk-management baseline.
Technical detail
NIST AI 600-1 (July 26, 2024). A profile of the NIST AI RMF (AI 100-1) targeting 12 risks unique to or exacerbated by generative AI, with 200+ recommended actions mapped to the RMF's Govern/Map/Measure/Manage functions. Implements directives in EO 14110 (since revoked) and remains the NIST baseline referenced by EO 14179 and the 2025 AI Action Plan.
Who is protected: End users of generative AI systems, including consumers exposed to AI hallucinations or harmful outputs
Who must comply: Voluntary; federal agencies and contractors typically adopt under OMB M-25-21 / M-25-22 baseline requirements
Key facts
| Jurisdiction | United States |
|---|---|
| Level | Federal |
| Status | In effect |
| Protection strength | Limited protection |
| Effective date | 2024-07-26 |
| Enacted | 2024-07-26 |
| Citation | NIST AI 600-1 |
| Enforced by | National Institute of Standards and Technology (no enforcement; widely incorporated by reference) |
| Private right of action | No — agency enforcement only |
| Penalties | No direct penalties; incorporated into federal procurement and OMB AI risk management requirements |
| Topics | automated decision-making · AI disclosure and transparency · consumer protection |
| Last verified | 2026-06-17 |
| Official source | NIST AI 600-1 — Generative AI Profile (July 2024) ↗ |
More AI rules in United States
- Trump AI Innovation & Security EO (June 2026) · In effect
- FERC order directing PJM and other grid operators to reform · Enacted (not yet in effect)
- Chatrie v. United States (Fourth Amendment protection for lo · Blocked / in litigation
- Kids Internet and Digital Safety Act (KIDS Act) (H.R. 7757) · Proposed / pending
- NAIC AI Evaluation Tool Pilot (12 states, 2026) · Proposed / pending
- FTC Proposed Policy Statement — AI Accuracy (July 2026) · Proposed / pending
Related automated decision-making rules elsewhere
- CA EO N-6-26 (AI Workforce) · In effect
- Arkansas public entity AI/ADS policy mandate (Act 848, 2025) · In effect
- Connecticut algorithmic rent ban — HB 8002 (eff. Jan 1, 2026) · In effect
- San Diego algorithmic rent price-fixing ban (Ord. O-21955, May 2025) · In effect
- Minneapolis algorithmic rent ban (Ord. 2025-010, eff. Mar 1, 2026) · In effect
- Seattle algorithmic rent-fixing ban (Ord. 127241 / SMC 7.34, July 2025) · In effect
See something wrong or out of date? Submit a correction — every entry must carry a verifiable official source.