Use NIST’s AI Risk Management Framework (AI RMF) as the lifecycle backbone for securing generative AI, and tailor it with NIST AI 600-1, the Generative AI Profile. Put the framework into operation through named owners, system-specific assessments, testing, decision gates, monitoring and documented risk decisions. Map the resulting program separately to ISO/IEC 42001 when a formal AI management system is useful, and to applicable laws such as the EU AI Act based on each system’s role, purpose, location and classification.
What framework should you use for generative AI security?
Start with the four AI RMF functions—Govern, Map, Measure and Manage—and apply them throughout the lifecycle: intake, procurement, design, deployment, operation and retirement. Use the Generative AI Profile to adapt those functions to generative AI risks; it is a profile against the AI RMF, not a standalone security control catalogue.
This is a governance and risk-management structure, not a substitute for ordinary cybersecurity practices, sector-specific controls, legal advice or a system-specific threat assessment. NIST describes its framework as “intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.”
How do the four AI RMF functions work in practice?
Govern: assign authority and set the rules
Establish policy, risk tolerance, executive accountability, training, inventory requirements and a review cadence. Name who can approve a use case, accept residual risk, stop deployment and authorize a return to service after an incident. Governance should remain involved across the other functions rather than ending with policy approval.
Free tools Windows power users keep installed
One-click scans. No signup required.
Set a clear escalation route for security, privacy, compliance, legal, model owners and business owners. A policy is only operational when teams know who makes each decision and what evidence that decision requires.
Map: understand the system and its setting
For each use case, record its intended purpose, users, deployment context, expected benefits, foreseeable harms, known limitations and human-oversight design. Document data flows, access boundaries, models, retrieval sources, tools, downstream systems and third-party components. Capture relevant legal and regulatory context, including where the system is used and who provides or deploys it.
Map the full supply chain, not just the model interface. A generative AI feature may depend on a hosted model, an orchestration layer, a vector store, retrieved documents, plugins or internal APIs; each can change the attack surface and responsibility boundaries.
Measure: test against defined conditions
Choose metrics and evaluation methods that fit the system’s context and consequences. Test before deployment and at a regular cadence in operation. Keep the test plan, test data or set description, conditions, results, limitations and unresolved findings so that reviewers can understand what was actually evaluated.
Rank #2
Depending on the use case, measure security, privacy, validity, reliability, bias, transparency and safety. Do not treat a successful demonstration or a model’s general capability claims as evidence that a specific workflow is safe or secure.
Manage: make and revisit risk decisions
Prioritize risks and decide whether to mitigate, transfer, avoid or accept each one. Record the decision-maker, rationale, required controls, residual risk and any conditions on use. Define monitoring thresholds, incident escalation, recovery and reassessment triggers before launch.
Revisit the decision when the model, prompt, data, retrieval corpus, permissions, supplier, use case or deployment context changes materially. Risk management is iterative: new findings may require tighter controls, a pause, rollback or deactivation.
Which generative AI risks should the control set address?
Prompt injection and unsafe agency
Test direct prompt injection supplied as user input and indirect prompt injection embedded in content an integrated application retrieves. Assess how attacks could cross tool boundaries, influence retrieved context or trigger downstream actions, especially when the model can access data stores or invoke tools.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
Keep consequential authorization and policy enforcement outside the model. Constrain tool permissions, validate proposed actions independently and require human approval where consequences warrant it. Include red-team exercises that examine attack paths across the full AI system, not just isolated prompts.
Data and model integrity
Track the provenance of training, fine-tuning and evaluation data, as well as third-party components and model versions. Assess poisoning risks where data or inputs can influence model behavior. After fine-tuning or a material model change, test whether safety and security controls still work rather than assuming prior results carry over.
Sensitive data and access
Document what sensitive information can enter prompts, be retrieved, reach a model provider or appear in outputs. Test access boundaries and unauthorized disclosure risks, and monitor for access attempts, inference, bypass and extraction behavior. Align monitoring and retention with the system’s data flows and applicable obligations.
Output reliability and downstream harm
For consequential uses, validate outputs and sources against the intended task, define human review, and provide a safe failure path when confidence or evidence is inadequate. Evaluate with empirical tests and source verification; anecdotal examples are not a substitute for repeatable assessment.
Rank #4
Operational readiness
Prepare incident escalation and disclosure procedures, monitoring, supplier responsibilities, rollback or deactivation steps, and a reassessment process for material changes. A control plan should explain not only how a system is allowed to operate, but how the organization will detect trouble and limit harm when controls fail.
What evidence should the program produce?
Build a linked evidence set that lets a reviewer follow a use case from proposal through operation. A policy alone cannot show how a particular system was assessed, tested or approved.
- AI system inventory and use-case or impact assessments.
- Risk register, residual-risk decisions and approval records.
- Supplier, model and component records, including version and change history.
- Data-flow, provenance and access-control documentation.
- Role and approval matrix, plus human-oversight design.
- Test plans, results, limitations and security red-team findings.
- Monitoring thresholds, incident procedures and rollback or deactivation plans.
- Periodic review records and reassessments after material changes.
Connect each item to the relevant system and risk. For example, a red-team finding should identify the affected use case, attack path, severity, owner, treatment decision and retest result.
Where do NIST, ISO/IEC 42001 and the EU AI Act fit?
These instruments serve different purposes and have different status. A company may use more than one: a risk-management playbook does not by itself establish a management system or determine legal compliance.
Best Value
| Instrument | Purpose and status | How to use it | Scope and timing |
|---|---|---|---|
| NIST AI RMF 1.0 | Voluntary risk-management guidance published by NIST on January 26, 2023. | Use Govern, Map, Measure and Manage as the lifecycle structure for organizational AI risk work. | Guidance for organizations; it is not itself a legal mandate. NIST has said AI RMF 1.0 is being revised as part of the White House AI Action Plan, so check NIST’s current status before relying on a particular edition. |
| NIST AI 600-1, Generative AI Profile | Voluntary NIST profile published July 26, 2024. | Use it to tailor AI RMF practices to generative AI, including governance, content provenance, pre-deployment testing and incident disclosure. | It supplements the lifecycle framework; it is not a complete replacement for cybersecurity controls or system-specific assessment. |
| ISO/IEC 42001:2023 | International standard published December 18, 2023, specifying requirements for an AI management system. | Consider it when an organization needs a formal system for establishing, implementing, maintaining and continually improving AI management. | It applies to organizations that provide or use AI-based products or services. It is not interchangeable with NIST’s voluntary framework and is not, by itself, a legal mandate. |
| EU AI Act, Regulation (EU) 2024/1689 | Binding EU regulation, adopted June 13, 2024. | Assess the organization’s legal role and each system’s intended purpose and classification; obtain legal review for the specific situation. | It requires a continuous, iterative and documented risk-management system for high-risk AI systems. The Act generally applies from August 2, 2026; Chapters I and II applied from February 2, 2025; specified provisions applied from August 2, 2025; and Article 6(1) and corresponding obligations apply from August 2, 2027. |
The EU AI Act’s dates do not make every generative AI system a high-risk system. Applicability depends on the system’s role, intended purpose, classification and circumstances. Determine the organization’s position rather than assuming the same duties attach to every model or deployment.
OWASP’s LLM Top 10 project page links a 2025 version and can inform a technical review. Check the current OWASP page before naming or mapping individual entries; do not treat a list of risk categories as a substitute for the organization’s own threat model.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How should teams set decision gates across the lifecycle?
Use gates to make risk ownership visible and prevent an incomplete assessment from quietly becoming a production system. Adapt the approvals to the organization’s authority model and the system’s consequences.
- Intake: A business owner states the intended purpose, users, expected benefit and proposed deployment context. Governance checks whether the use is within policy and assigns an accountable system owner.
- Assessment: The system owner and relevant security, privacy, legal and compliance leads map data, model, supplier and tool dependencies; identify harms and obligations; and record the risk assessment.
- Procurement and design: Owners confirm supplier responsibilities, data handling, access boundaries, human oversight and technical constraints. Unresolved requirements become tracked conditions, not informal assumptions.
- Pre-deployment review: The accountable approver reviews test results, red-team findings, mitigations, operational readiness and residual risk. The decision is proceed, proceed with conditions, defer, or reject.
- Operation: Owners monitor defined signals, manage incidents and review changes. Escalate when thresholds are crossed or the system no longer matches the approved purpose or context.
- Material change or retirement: Reassess changed components and use conditions before continued use. At retirement, remove or disable access and handle retained data and records under the organization’s applicable obligations.
At each gate, state who can approve, what evidence is required, which risks remain, and what event forces a new review. This turns a framework into an operating control rather than a document that is only consulted during an audit.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

