NIST’s August 2026 Initial Public Draft outlines a controlled way to use generative AI with CSF 2.0 analysis; use an organization-authorized tool, retain traceable source context, and require qualified review before organizational decisions.
The draft presents three notional applications; reviewing governance alignment, developing a current-state profile from organizational artifacts, and developing a target-state profile. The examples describe draft analysis and profile work, not validated deployment results.
Its operating guardrails are practical. Organizations are told to review an AI tool’s privacy and security settings, follow company policies before entering sensitive information, and use tools authorized by security and privacy teams. AI-generated content should be checked by qualified personnel, with applicability, scope, inputs, assumptions, and outputs validated before organizational decision-making.
For AI-assisted mappings and crosswalks, the draft calls for identifiers, source context, provenance, and status labels to remain attached to the result. It also highlights review where reference data is limited and confirmation that the materials used reflect the most current published version.
The status matters for governance teams. This is an Initial Public Draft, not a final or operative requirement, and it does not establish a legal duty, enforcement mechanism, penalty, or compliance deadline. Its examples are illustrative; the source reports no empirical measures of AI performance, retrieval effectiveness, or citation-verification effectiveness.