Skip to main content
Cyber AI Profile Workshop: What 1,400 Comments Reveal About Framework GapsCompliance & Audit
5 min readFor AI Governance Leaders

Cyber AI Profile Workshop: What 1,400 Comments Reveal About Framework Gaps

Workshop Insights

NIST's second Cyber AI Profile workshop in January 2026 highlighted a crucial tension in AI governance: organizations need cybersecurity guidance that's both specific enough to implement and adaptable to rapid technological changes. The workshop, which gathered over 1,400 public comments, focused on a draft aimed at helping organizations adapt the Cybersecurity Framework 2.0 for AI-related risks.

Participants acknowledged the draft's importance but also pointed out its shortcomings. Smaller organizations need detailed implementation resources, not just strategic frameworks. Agentic AI systems require controls that don't fit neatly into existing cybersecurity categories. Moreover, the taxonomy, or shared language for discussing AI risks across industries, remains inconsistent.

Development Timeline

The Cyber AI Profile didn't develop in isolation. NIST initiated this effort following feedback from cybersecurity and AI professionals that CSF 2.0, while comprehensive, didn't address AI-specific threat vectors or control requirements. The draft aimed to bridge this gap by identifying which CSF functions apply to AI systems and how.

The January workshop revealed significant gaps in this bridge. Participants requested use cases for operational technology environments, more examples of agentic AI scenarios, and clearer guidance on testing and evaluation. They also asked for machine-readable formats and flexible filtering, indicating that teams are trying to operationalize the Profile, not just read it.

NIST is now reviewing the 1,400+ comments to produce an Initial Public Draft. Additional working sessions and workshops are planned, with dates to be announced.

Identified Control Gaps

The workshop didn't focus on a single incident but exposed systemic control gaps that leave organizations vulnerable:

Inconsistent AI taxonomy. Without shared definitions, organizations struggle to communicate about AI risks across supply chains or regulatory boundaries. A "high-risk AI system" means different things to a financial services firm, a healthcare provider, and a manufacturing plant. The Cyber AI Profile aims to standardize that language, but participants noted the draft doesn't go far enough.

Lack of AI-specific testing guidance. Traditional penetration testing and vulnerability scanning don't capture adversarial machine learning risks, data poisoning vectors, or model drift. Participants highlighted the absence of performance metrics, benchmarking standards, and evaluation frameworks tailored to AI systems. This gap leaves teams uncertain if their controls are effective.

Weak accountability structures for AI cybersecurity outcomes. Organizations are experimenting with roles like chief AI officers and multidisciplinary governance bodies. However, there's no consensus on who owns cybersecurity risk when an AI system fails. Is it the data science team, the CISO, or the business unit deploying the model? The draft doesn't resolve this.

No controls for "shadow AI." Participants raised concerns about unauthorized AI tools entering the environment, insider threats using AI, and lack of visibility into how third-party models are trained. These issues require asset inventory practices, vendor due diligence protocols, and monitoring capabilities that most organizations haven't developed yet.

Inadequate supply chain integrity measures. The workshop highlighted cryptographic signing, AI Bills of Materials, and certification systems as potential controls. However, the draft doesn't specify how to implement them or when they're required.

Framework Requirements

The Cybersecurity Framework 2.0 outlines six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Each function includes categories and subcategories that map to specific outcomes. For AI systems, several requirements are critical:

Govern. Establish accountability structures for AI cybersecurity risk. CSF 2.0 requires defining roles and responsibilities, establishing oversight mechanisms, and integrating AI risk into enterprise risk management. The Cyber AI Profile needs to specify how these requirements apply when AI systems cross organizational boundaries or operate with partial autonomy.

Identify. Asset management (ID.AM) requires maintaining inventories of AI systems, data assets, and third-party dependencies. Risk assessment (ID.RA) involves evaluating AI-specific threats like adversarial inputs and model extraction attacks. The Profile must address how to inventory models you don't control and assess risks you can't fully observe.

Protect. Access control (PR.AC) and data security (PR.DS) take on new dimensions with AI. You're not just protecting data at rest; you're protecting training datasets, model weights, and inference APIs. The Profile needs to specify controls for each.

Detect. Anomaly detection (DE.AE) must account for model drift, performance degradation, and adversarial manipulation. Continuous monitoring (DE.CM) must track not just system logs, but model behavior and output quality.

The NIST AI Risk Management Framework provides complementary guidance on Govern, Map, Measure, and Manage functions specific to AI. However, it doesn't map directly to cybersecurity controls. That's the gap the Cyber AI Profile is meant to close.

Action Items for Your Team

Build your AI asset inventory now. Don't wait for the final Profile. Start documenting which AI systems you're using, where they came from, what data they touch, and who's responsible for them. Include SaaS tools with embedded AI features. This inventory is the foundation for every other control.

Establish AI governance accountability before you need it. Decide who owns cybersecurity risk for AI systems. If you're creating a chief AI officer role, define how it relates to the CISO. If you're forming an AI governance committee, give it clear authority and reporting lines. Document the structure in your risk management framework.

Test your AI systems like attackers will. Traditional scanning won't catch adversarial inputs or data poisoning. Start building adversarial simulation capabilities. If you're using third-party models, ask vendors what testing they've done and request validation evidence.

Require AI Bills of Materials from vendors. When you procure AI systems or services, demand transparency about training data sources, model architectures, and known limitations. Make this a standard part of vendor due diligence.

Document your human-in-the-loop requirements. Define where humans must review AI decisions, what training they need, and how you'll verify they're actually in the loop.

Join the community of interest. NIST is running working sessions as it develops the next draft. Your input now will shape requirements you'll need to meet later. Email [email protected] to join.

The Cyber AI Profile won't solve every AI cybersecurity problem, but it provides a common language, a baseline set of controls, and a framework for addressing AI-specific risks. That's more than most organizations have today.

You Might Also Like