Skip to main content
Your Cyber AI Profile Won't Fix AI RiskAdversarial Security
4 min readFor AI Governance Leaders

Your Cyber AI Profile Won't Fix AI Risk

The Conventional Wisdom

Many in the cybersecurity community believe that by building the right profile for the NIST Cybersecurity Framework, they can simply add AI risk management to their existing security programs. This view was reinforced at NIST's Cyber AI Profile Workshop in April, where participants discussed integrating AI-specific risks into existing frameworks and incorporating AI into enterprise risk management practices.

The logic seems sound. You've implemented the CSF. Your team knows how to identify, protect, detect, respond, and recover. Why not apply that expertise to AI systems?

Why This Approach Falls Short

The issue is that cybersecurity frameworks are designed for systems you control. AI systems, especially those using foundation models or third-party components, operate differently. You don't control the training data, can't audit the model weights, and often deal with probabilistic outputs instead of deterministic code paths.

While workshop participants acknowledged AI's dual-use nature as both a defense tool and an attack vector, they still treated AI as just another technology needing security controls. This overlooks a critical point: AI systems introduce epistemic risks that traditional cybersecurity controls can't handle.

When a firewall fails, you know it. But when an AI model degrades due to a shift in production data, you might not notice for months. If an adversary poisons your training pipeline, there's no intrusion detection signature to catch it. Discussions on "adaptive identity management for non-human identities" and "securing feedback loops" hint at this, but the CSF structure pushes you toward familiar controls rather than new risk disciplines.

The Evidence

Workshop participants struggled with "measurable benchmarks to assess AI performance" and "understanding AI behavior, including response variability." They emphasized "human-in-the-loop processes" and bridging knowledge gaps between AI researchers and cybersecurity professionals.

These aren't cybersecurity problems; they're model risk management issues.

Suggestions like "cryptographic signing for models" and "AI SBOM" aim to use supply chain security tools for validation problems. Knowing your model's components' provenance doesn't ensure reliable performance under production conditions. The focus on "data governance" and "data security throughout its lifecycle" treats symptoms, not the core challenge: deploying systems whose behavior you can't fully specify or predict.

NIST has already published the AI Risk Management Framework in 2023, which includes Govern, Map, Measure, and Manage functions specifically for AI systems. Yet, the Cyber AI Profile initiative suggests applying the NIST Cybersecurity Framework to AI challenges, indicating a reluctance to adopt the different disciplines AI systems require.

What to Do Instead

Start with SR 11-7, even if you're not in financial services. The Federal Reserve's model risk management guidance emphasizes that models need validation, not just security controls. You need independent review of conceptual soundness, ongoing performance monitoring, and outcome analysis. These practices apply whether you're validating a credit risk model or a large language model for customer service.

Build your AI governance program around three distinct risk streams that your cybersecurity framework won't capture:

Model Performance Risk: Establish validation evidence requirements before deployment. Define acceptable performance bounds and monitor for distribution shifts. This is statistical quality control, not penetration testing.

Epistemic Risk: Document model limitations and use restrictions. Your security team can't do this alone. You need data scientists who understand the model's training distribution and can articulate where it will fail.

Governance Risk: Implement the Plan-Do-Check-Act cycle from ISO/IEC 42001. Treat AI as a management system, not an IT asset. Your CISO shouldn't own this alone.

Then layer cybersecurity controls on top. Secure your training pipelines, implement rate limiting on model APIs, and use responsible disclosure processes for model vulnerabilities. But recognize these controls address only one dimension of AI risk.

The workshop participants who emphasized "multidisciplinary collaboration across legal, technical, procurement, and governance teams" understood this. You can't secure what you haven't validated, and you can't validate what your governance structure doesn't require.

When the Conventional Wisdom Is Right

The Cyber AI Profile is valuable for one critical use case: organizations using AI for cyber-defense activities. If you're deploying anomaly detection models or automated incident response systems, the CSF provides the right lens. You're securing your security stack.

The workshop's focus on "thwarting AI-enabled cyber-attacks" fits neatly into traditional cybersecurity. Defending against AI-powered phishing or automated reconnaissance requires the same detect-and-respond capabilities you'd use for any advanced threat.

For organizations just starting to think about AI risk, any framework is better than none. The CSF's widespread adoption means your security team already speaks its language. Using it as a bridge to more comprehensive AI governance is practical.

But don't mistake the bridge for the destination. Your AI systems need model risk management, not just cybersecurity controls. Recognizing that distinction sooner will help you build governance structures that actually address the risks AI introduces.

The Cyber AI Profile will give you a checklist. What you need is a validation framework.

You Might Also Like