Comply · United States
NIST AI RMF — Generative AI Profile (AI 600-1)
NIST's companion profile for generative-AI-specific risks.
The Generative AI Profile (NIST AI 600-1) is a companion to the AI RMF that identifies risks unique to or amplified by generative AI — such as confabulation, harmful or dangerous content, data privacy leakage, intellectual-property exposure, and information-integrity harms — and suggests actions across the Govern, Map, Measure, and Manage functions.
Who it applies to
Organizations deploying or building on generative AI and large language models, especially those already aligning to the NIST AI RMF.
Key obligations
- Identify GenAI-specific risks (confabulation, data leakage, IP, CBRN, harmful content)
- Apply RMF actions tailored to generative systems
- Test and red-team generative outputs
- Track provenance and information integrity
How Maetra maps agents to NIST GenAI Profile
Maetra's Secure module scans prompts and outputs for the generative-AI risks the profile calls out — injection, data exfiltration, and harmful content — while Comply captures the corresponding controls and evidence per agent.
In practice, Maetra:
- Scans and fingerprints each agent. Discover reads the agent’s code — its tools, data access and sensitivity, actions, model, and environment — into an evidence-backed profile tied to the exact file and commit.
- Decides what applies. That profile determines whether NIST GenAI Profile is in scope for the agent and which of its requirements apply.
- Auto-detects controls and surfaces gaps. Controls your code already satisfies are detected automatically from the scan; the rest become a clear list of gaps, each tied to the requirement and the evidence it still needs.
- Proves it and keeps it current. Close gaps with linked evidence or generated documents — reused across every framework the same control supports — and Maetra re-checks on each rescan and flags evidence that has gone stale.
Related frameworks
Prove NIST GenAI Profile compliance with Maetra
Classify your AI agents once and Maetra maps them to NIST GenAI Profile and every other framework it supports — generating the evidence and documentation, tracking gaps and deadlines, and sealing every decision in an immutable audit trail.