Skip to main content
What Does NIST's New AI Security Program Mean for My Compliance Strategy?Privacy & Data Protection
6 min readFor Legal & Compliance Officers

What Does NIST's New AI Security Program Mean for My Compliance Strategy?

Questions started landing in my inbox the day NIST announced its new program for the cybersecurity and privacy of AI. They're coming from compliance officers who've spent years building frameworks around SR 11-7, GDPR, and ISO 27001, and who now face a landscape where their AI RMF implementation needs to integrate with their cybersecurity controls, privacy program, and vendor risk processes.

NIST isn't just publishing another guideline. They're creating a dedicated program that will coordinate across the AI RMF, Cybersecurity Framework, Privacy Framework, and NICE Workforce Framework for Cybersecurity. For compliance teams, this means your current control environment is about to become more integrated and specific.

Here's what practitioners are asking right now.

Does this replace the AI RMF or add to it?

It adds to it. The AI RMF covers the full spectrum of AI risks, from fairness to transparency to safety. This new program focuses on three specific risk areas:

  1. Securing AI systems (protecting training data, preventing model extraction, managing data leakage)
  2. Defending against AI-enabled attacks (like deepfake phishing, AI-assisted reconnaissance, automated vulnerability scanning)
  3. Using AI to strengthen cybersecurity and privacy controls

The program will produce community profiles that adapt existing frameworks. They're starting with a Cybersecurity Framework profile for AI, providing specific subcategory mappings and implementation guidance for AI-related controls. If you've built CSF profiles before, you know how valuable these are for translating high-level functions into audit-ready evidence.

Our vendor contracts don't mention AI-specific security. What should we be asking?

Start with the three risk categories NIST laid out. For any vendor providing AI capabilities, your due diligence should now cover:

Securing the AI system: How is training data protected? What controls prevent model extraction or membership inference attacks? If the model was trained on your data, what guarantees do you have against data leakage when other customers query it?

AI-enabled threats: Does the vendor's security awareness training address deepfakes and AI-generated phishing? Have they updated their authentication controls to account for voice synthesis and video manipulation?

AI in security tools: If the vendor uses AI for threat detection or access analysis, what's the false positive rate? Can they explain why the system flagged something? (NIST explicitly calls out the need for explainability in AI-powered security tools.)

The program is developing a testbed called Dioptra for evaluating machine learning systems under diverse conditions. You won't run vendor models through it yourself, but you can ask vendors whether they've tested against adversarial conditions and what their robustness metrics look like.

We just finished our ISO/IEC 42001 implementation. Do we need to redo our Annex A controls?

Not redo, but you'll likely need to expand some of them. ISO/IEC 42001's Annex A includes controls for AI system security (A.2.3), data quality (A.3.2), and model monitoring (A.6.1.5). What's changing is the specificity of threats and the integration points with your broader security program.

For example, your A.2.3 control on AI system security probably addresses access controls and infrastructure hardening. NIST's program will give you specific guidance on protecting machine learning infrastructure, managing dependencies across your organization's data assets, and accounting for new threat vectors like model poisoning or prompt injection.

Your data asset inventory (likely part of your GDPR compliance or your CSF Asset Management function) needs to account for datasets used in model training, validation sets, and production inference data. NIST notes that as business units adopt AI, you'll need to reevaluate the relative importance of data assets. A dataset that was low-risk for traditional analytics might be high-risk if it's feeding a customer-facing model.

How does this affect our privacy program?

NIST identifies three AI-specific privacy risks your Data Protection Impact Assessment should cover:

Re-identification risk: AI can re-identify individuals across disparate datasets more effectively than traditional analytics. If you're training models on pseudonymized data, your risk assessment needs to account for the model's analytic power, not just the pseudonymization technique.

Data leakage from training: Models can memorize and reveal training data. If you're training on personal data, you need controls to prevent membership inference attacks and data extraction.

Amplified surveillance: AI's predictive capabilities can reveal insights about people that they never disclosed. Your purpose limitation analysis under GDPR should consider what the model can infer, not just what you collected.

NIST has published draft guidelines on differential privacy (SP 800-226) and is building a privacy-enhancing technologies testbed. If you're implementing privacy-preserving techniques like Federated Learning or Differential Privacy, these resources will help you evaluate whether your implementation actually provides the privacy guarantees you're claiming.

Our security team wants to use AI for threat hunting. What governance does that need?

NIST warns that AI-powered threat hunting might increase false positives, which means your security team needs different skills and your governance needs new controls. Before you deploy AI in your security operations:

Define acceptable false positive rates. Document what threshold your team can operationally handle. An AI tool that flags 1,000 alerts per day is useless if your team can investigate 50.

Require explainability. You need to understand why the system flagged something. "The model said so" isn't sufficient for incident response or for explaining decisions to auditors.

Update your NICE Framework competencies. NIST recently added Security of AI as a competency area in the NICE Workforce Framework for Cybersecurity. Your security analysts need training on how AI systems fail, how to interpret model outputs, and how to detect when an adversary is using AI against you.

Account for it in your AI Management System. If you're ISO/IEC 42001 certified, AI used for security operations is still an AI system under your governance scope. It needs the same risk assessment, validation, and monitoring as your customer-facing models.

When will we see actual requirements or standards?

NIST is starting with a community profile for the Cybersecurity Framework, developed through the National Cybersecurity Center of Excellence (NCCoE). Community profiles typically take 12-18 months from kickoff to publication, but draft versions come out earlier for comment.

The program will coordinate with federal agencies and international efforts, which means what NIST publishes will likely influence regulatory expectations. If you're in financial services, expect your examiners to eventually ask how you've addressed the AI-specific risks NIST identifies. If you're subject to the EU AI Act, the technical specifications NIST develops will inform how you demonstrate compliance with Article 15 (accuracy, robustness, and cybersecurity requirements).

Where should I focus right now?

Three things you can do before the formal guidance drops:

  1. Map your AI inventory to your data asset inventory. Identify which datasets feed which models, and reassess their risk classification based on AI-specific threats.

  2. Update your vendor risk questionnaires. Add questions about model security, AI-enabled threat defenses, and explainability of AI-powered tools.

  3. Review your security awareness training. If you haven't updated your phishing simulations to include deepfakes or AI-generated content, do it now. NIST specifically calls out AI voice generators as a threat requiring updated training.

The program website is live, and they're accepting feedback at [email protected]. If you've got specific use cases or gaps in existing frameworks, now's the time to submit them. These community profiles are most useful when they address real implementation challenges, not theoretical risks.

Your compliance strategy doesn't need a complete overhaul. It needs targeted expansion in three areas: securing AI systems, defending against AI-enabled attacks, and governing your own use of AI in security operations. NIST is building the roadmap. Your job is to start walking it.

You Might Also Like