NIST Cyber AI Profile pushes agencies toward operational choices
The guidance tackles what framework-level documents don't, the non-deterministic behavior of generative AI systems and the post-deployment monitoring federal buyers need to budget for.
TL;DR
NIST's Cyber AI Profile aims to bridge the gap between high-level AI guidance and the procurement and deployment decisions federal agencies make every day. Built on the Cybersecurity Framework (CSF 2.0), the profile organizes AI risk around three focus areas: securing AI systems, AI-enabled cyber defense, and thwarting AI-enabled cyberattacks. The unspoken challenge driving the work, according to NIST program manager Kat Megas, is that generative AI systems don't behave like traditional software, they drift over time, and pre-deployment testing alone won't catch it.
Federal agencies have no shortage of AI guidance. What they've lacked is a document that tells them what to do differently when the system they're buying doesn't behave like software. NIST's Cyber AI Profile, detailed by program manager Kat Megas in an interview with Federal News Network, is the agency's attempt to fill that gap.
The core challenge, Megas explained, is that generative AI systems are non-deterministic. Traditional software testing assumes you can run the same input through a system and get the same output, and once tested, you can reliably predict behavior. AI doesn't cooperate. "You have to realize that while you may acquire a software package," Megas said, "there is the potential for what they call drift over time." The operational implication is significant: pre-deployment testing, the backbone of federal technology acquisition, isn't enough anymore.
The profile, built on CSF 2.0, structures the problem around three focus areas, securing AI systems, conducting AI-enabled cyber defense, and thwarting AI-enabled cyberattacks. But the document's real contribution may be what it implies for procurement. Agencies buying AI-enabled tools need to budget for post-deployment monitoring, not just acquisition-time evaluation. That means staffing, tooling, and ongoing measurement programs that persist long after the contract is signed.
For the federal cybersecurity practitioner, the message is practical: the compliance checklist doesn't end at deployment. The system you're responsible for today may behave differently six months from now, and the profile is NIST's way of saying that's your problem to watch.
Published ·Deep Fathom