NIST GenAI Profile and TEVV
NIST’s **AI Risk Management Framework (AI RMF 1.0)** (Jan 2023) is a voluntary, cross-sector guide to manage AI risks and promote trustworthy use. The **Generative AI Profile** (NIST AI 600-1, published July 26, 2024) is a companion prof...
What it is
NIST’s AI Risk Management Framework (AI RMF 1.0) (Jan 2023) is a voluntary, cross-sector guide to manage AI risks and promote trustworthy use. The Generative AI Profile (NIST AI 600-1, published July 26, 2024) is a companion profile for generative AI risks across the lifecycle. The NIST AI Resource Center (AIRC) hosts resources to operationalize the RMF, including TEVV—test, evaluation, verification, and validation.
Visual Spec & Architecture Diagram
NIST TEVV cycle: Test → Evaluate → Verify → Validate (loop) tied to GenAI profile risk management boxes (Govern/Map/Measure/Manage literacy). Dated 'check live NIST'. No fake agency seal.
Why it matters
US practice often points to NIST for *how to think about* measurement and governance—even when statutes differ by sector. Literacy: RMF is voluntary and flexible; it is not a product certification by itself.
How it works (plain)
- Govern / Map / Measure / Manage (RMF core functions at a high level).
- Use the GenAI Profile to surface generative-specific risks (hallucination, data leakage, misuse, etc.—as categories).
- Run TEVV activities so claims match observed behavior under varied conditions.
- Document outcomes (AIRC Playbook suggests actions and documentation practices).
Not legal advice. Confirm current NIST pages; AIRC notes AI RMF 1.0 is being revised.
Everyday example
A building code gives design principles; inspectors still verify the finished structure. RMF + TEVV is the principles + verification habit for AI.
Try it
Pick one AI feature. Write one Map risk, one Measure test idea, and one Manage control—in your own words.
Myths
- ⚠️ Myth: “We follow NIST” means we are compliant with every law.
- ✓ Reality: RMF is voluntary risk management; legal duties come from statutes/agencies/contracts.
- ⚠️ Myth: TEVV is only pre-launch.
- ✓ Reality: AIRC framing is ongoing trustworthiness under changing conditions.
Sources
- NIST GenAI Profile (AI 600-1): https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence ↗
- NIST AI RMF 1.0: https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10 ↗
- NIST AIRC: https://airc.nist.gov/ ↗
- DOI GenAI Profile: https://doi.org/10.6028/NIST.AI.600-1 ↗
