NIST’s preliminary Cyber AI Profile organizes AI cybersecurity planning around three CSF 2.0-based focus areas; securing AI systems, using AI for cyber defense, and preparing for AI-enabled attacks.
The draft takes a broad view of AI, covering systems such as large language models, generative AI, prediction and anomaly-detection systems, recommendation systems, automated and agentic systems, and reinforcement-learning systems. Its proposed priorities are adaptable; organizations may adjust them based on their environment, needs, and risk tolerance.
For enterprise programs, the profile provides a common structure for discussing AI-related cybersecurity outcomes across governance, identification, protection, detection, response, and recovery. Its considerations can inform work on AI inventories, supplier and data reviews, access controls, monitoring, incident response, recovery planning, and executive risk discussions. The draft’s priority levels are proposed rather than fixed requirements.
The document remains an initial preliminary draft of voluntary guidance. It was released for public comment from December 16, 2025, through January 30, 2026, and the supplied text does not establish whether NIST later issued a final profile. Nothing in the supplied material establishes a binding legal duty, effective date, enforcement mechanism, penalty, or mandatory compliance deadline.