Last updated:
NIST AI RMF Profiles are tailored implementations of the NIST AI Risk Management Framework. NIST defines three types: use-case profiles for specific applications, cross-sectoral profiles that apply across industries, and temporal profiles describing an organisation's Current and Target state. The first cross-sectoral profile, the Generative AI Profile (NIST AI 600-1), was published in July 2024.
What types of AI RMF profile are there?
Use-case profiles. Targeted implementations of the AI RMF functions for a specific use case or scenario, such as hiring or fair lending.
Cross-sectoral profiles. Applicable across industries and use cases, without being tied to one sector or technology.
Temporal profiles. A Current Profile describes how AI risk is managed today. A Target Profile describes the outcomes needed to reach the desired state. The gap between them is the roadmap.
A single profile can belong to more than one type. The Generative AI Profile is both a use-case profile and a cross-sectoral one.
What is the Generative AI Profile?
NIST AI 600-1, published in July 2024, was the first cross-sectoral companion to AI RMF 1.0. It identifies 12 risk categories either unique to or exacerbated by generative AI, and sets out suggested actions mapped back to the framework's four core functions: GOVERN, MAP, MEASURE and MANAGE. Because those actions map to the existing Core, an organisation already using the AI RMF can adopt it as an extension instead of a separate programme.
How do Current and Target Profiles work in practice?
Temporal profiles are the mechanism most organisations skip. A Current Profile is an honest assessment of what is happening today, and it usually surfaces AI systems nobody had registered. A Target Profile states the intended outcomes, informed by risk appetite, sector expectations and regulatory obligations. Governance work then becomes a tracked set of gaps with owners, instead of an open-ended compliance exercise. The constraint is almost always the Current Profile, because you cannot profile an inventory you do not have.
Are there profiles for financial services and agentic AI?
Yes. This is where profiles have moved fastest. The FS AI RMF, published by the US Treasury with the Cyber Risk Institute in February 2026, aligns to the NIST AI RMF and works as a financial services overlay with 230 control objectives. The Cloud Security Alliance has published an agentic AI profile covering risks specific to autonomous, tool-using systems. Both show the intended pattern, where NIST provides the Core and communities build the sector and technology layers on top.
Real world example:
A healthcare provider adopting LLMs for clinical note-taking builds a Current Profile and discovers three separate LLM deployments across two departments, none of them formally registered. It applies the Generative AI Profile to assess them against the 12 GenAI risk categories, and finds that data-leakage and confabulation risks are unmitigated for the scribing use case. The Target Profile sets the required outcomes: no patient identifiers sent to third-party endpoints, and clinician review before any note enters the record. The gap between the two profiles becomes a tracked remediation plan with named owners and dates.




