A profile for generative AI

Lesson 1 of 5 in Generative AI Risks and Bias: NIST-AI-600-1 and SP 1270.

When the AI RMF shipped in January 2023, ChatGPT was two months old. The framework’s process was general enough to cover generative AI — but its examples, and most of its readers’ instincts, were built on predictors: scorers, rankers, classifiers. Generative systems fail differently. They invent facts, leak training data, produce synthetic people, and form parasocial bonds with users. The RMF needed a translation layer.

That layer is NIST-AI-600-1, the Generative AI Profile, published 26 July 2024. It is a cross-sectoral use-case profile of the RMF — the flagship demonstration of the profile mechanism you met in the last module. It does two things: names twelve risk categories that are unique to or intensified by generative AI, and maps roughly 200 suggested actions onto the Govern/Map/Measure/Manage subcategories you already know. Nothing in it replaces the RMF; everything in it assumes you are running the RMF and asks what changes when the system generates.

Before memorizing twelve categories, install the profile’s sharpest analytical distinction: which risks are genuinely novel, and which are old risks with new scale?

Genuinely novel — no meaningful pre-GenAI analogue: confabulation (a predictor can be wrong, but only a generator can fabricate a convincing court case), and human-AI configuration (nobody formed an emotional attachment to a credit-scoring model).

Amplified — classic risks whose cost curve collapsed: privacy (models now memorize and regurgitate training data), information integrity (deepfakes existed in 2018; what changed is that persuasive synthetic media now costs cents), bias (one foundation model’s skew propagates into thousands of downstream products — and adds homogenization, everyone inheriting the same skew), security (prompt injection is new in form, but it is the latest chapter of input-validation attacks), and IP (scraping-scale training turned a niche doctrine into NYT v. OpenAI).

The distinction is practical, not academic: amplified risks can borrow decades of existing controls and case law. Novel risks cannot — which is why confabulation and emotional entanglement are where governance programs are weakest.

Key terms: generative AI, AI RMF profile, confabulation, foundation model, hallucination

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.