From risks to actions: how the profile plugs into the RMF
Lesson 3 of 5 in Generative AI Risks and Bias: NIST-AI-600-1 and SP 1270.
The taxonomy is half the profile. The other half is roughly 200 suggested actions, each keyed to an RMF subcategory and tagged with the risk categories it addresses. That indexing is the whole trick: the profile does not build a new framework for generative AI — it routes GenAI-specific work into the machine you already run. Five action clusters carry most of the weight:
- Pre-deployment testing and red-teaming (MEASURE 2): structured adversarial probing against the twelve categories — jailbreaks, injection, memorization extraction, CBRN uplift — by people rewarded for breaking the system, before users can.
- Provenance and disclosure (MEASURE 2, MANAGE 4): watermarking, content credentials and metadata, and user-facing “this is AI” disclosure — the technical menu NIST AI 100-4 catalogues.
- Incident disclosure and response (GOVERN 5, MANAGE 4): defined GenAI incident types, escalation paths, and external reporting channels — the plumbing that laws like California SB 53 now attach deadlines to.
- Value-chain governance (GOVERN 6, MAP 4, MANAGE 3): model cards and data provenance demanded from upstream, update-notice clauses, contingency plans for deprecations.
- Decommissioning (MANAGE 2.4): the ability to switch a generative feature off — with data disposition and user communication planned — decided before launch, not during the crisis.
Now drill the mapping the way practitioners use it: an incident or design worry arrives, and you route it — which risk, which mitigation, which function owns it? The classifier below pairs each risk with its primary mitigation cluster. Real programs apply several controls per risk; your job here is the best-fit primary control, because that is the muscle procurement reviews and incident triage actually exercise.
Interactive sorting exercise: Match each GenAI risk scenario to the mitigation cluster that addresses it most directly.
Tool: AI Incident Tabletop — Run the drill for real: triage a GenAI deployment against the twelve risk categories, then manage a live incident — escalation, reporting clocks, and the decommissioning decision — in the Incident Tabletop simulator.
Key terms: red-teaming, provenance, watermarking (AI content), prompt injection, model card
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.