NIST Generative AI Profile (NIST AI 600-1) — Companion to the AI Risk Management Framework
United States · NIST AI 600-1
NIST's voluntary GenAI Profile is the leading federal playbook for managing risks unique to generative AI: hallucinations, harmful content, intellectual property leakage, data poisoning, and CBRN misuse. Federal contractors and many enterprises adopt it as the de facto AI risk-management baseline.
Technical detail
NIST AI 600-1 (July 26, 2024). A profile of the NIST AI RMF (AI 100-1) targeting 12 risks unique to or exacerbated by generative AI, with 200+ recommended actions mapped to the RMF's Govern/Map/Measure/Manage functions. Implements directives in EO 14110 (since revoked) and remains the NIST baseline referenced by EO 14179 and the 2025 AI Action Plan.
Who is protected: End users of generative AI systems, including consumers exposed to AI hallucinations or harmful outputs
Who must comply: Voluntary; federal agencies and contractors typically adopt under OMB M-25-21 / M-25-22 baseline requirements
Key facts
| Jurisdiction | United States |
|---|---|
| Level | Federal |
| Status | In effect |
| Protection strength | Limited protection |
| Effective date | 2024-07-26 |
| Enacted | 2024-07-26 |
| Citation | NIST AI 600-1 |
| Enforced by | National Institute of Standards and Technology (no enforcement; widely incorporated by reference) |
| Private right of action | No — agency enforcement only |
| Penalties | No direct penalties; incorporated into federal procurement and OMB AI risk management requirements |
| Topics | automated decision-making · AI disclosure and transparency · consumer protection |
| Last verified | 2026-06-17 |
| Official source | NIST AI 600-1 — Generative AI Profile (July 2024) ↗ |
More AI rules in United States
- FTC Act Section 5 (unfair/deceptive AI) · In effect
- TAKE IT DOWN Act · In effect
- FCRA (AI in credit & background checks) · In effect
- ECOA / Regulation B (AI credit discrimination) · In effect
- Title VII / ADA (AI hiring) · In effect
- COPPA + 2025 Rule (childrens data) · In effect
Related automated decision-making rules elsewhere
- CCPA/CPRA + ADMT Regulations · In effect
- Colorado AI Act (repealed) · Repealed / replaced
- SB 26-189 (Colorado ADMT Law) · Enacted (not yet in effect)
- AI Video Interview Act · In effect
- HB 3773 (AI Employment Discrimination) · In effect
- TRAIGA · In effect
See something wrong or out of date? Submit a correction — every entry must carry a verifiable official source.