NIST's GenAI Profile Is Voluntary. Your Customers Didn't Get the Memo.
NIST released its Generative AI Profile, NIST AI 600-1, on July 26, 2024, as a companion to the AI Risk Management Framework that was released in January 2023. I keep coming back to this document because it is the rare government artifact that is both voluntary and genuinely useful. It names twelve risks specific to generative AI and attaches each one to a numbered suggested action you can put in a checklist. Most framework documents do not work that way.
The problem is the label. The AI RMF is, in its own words, “intended for voluntary use,” and the GenAI Profile inherits that posture. It is offered for voluntary use by any organization. The people asking you to prove your AI is governed are not asking voluntarily. Enterprise buyers lean on SOC 2 attestation to force vendors to document controls. Defense contractors face CMMC and NIST SP 800-171. Neither regime has any language about generative AI. The best control content sits on a voluntary framework, and the mandatory machinery runs on a track that does not know GenAI exists.
I wrote earlier about the runtime side of this gap, in Auditing the Unpredictable. That post argued point-in-time audits cannot certify software that decides its own tool calls. This one is the adjacent problem: the controls themselves. What do you actually document when you document GenAI governance? NIST gave us a usable answer, and almost nobody has wired it into the attestation regimes buyers already demand.
The profile is a control catalog, not a philosophy
The GenAI Profile came out of NIST’s Generative AI Public Working Group under Executive Order 14110, and it limits its focus to four primary considerations: governance, content provenance, pre-deployment testing, and incident disclosure. Section 2 lists twelve risks that are “novel to or exacerbated by” generative AI: CBRN information, data privacy, intellectual property, information integrity, harmful bias. The categories are familiar, but the document defines them with unusual precision.
Two things about the document show how carefully it was written.
The first is confabulation. NIST uses that word instead of “hallucination,” and it says why: the term hallucination anthropomorphizes the model, which is itself a risk the profile catalogs under Human-AI Configuration. The definition is precise. Confabulation is “the production of confidently stated but erroneous or false content by which users may be misled or deceived.” That combination, confident and false, is the actual failure mode, and it is more useful to someone writing controls than “hallucination,” which sounds like the model has a personality.
The second is the structure. Section 3 turns each risk into numbered actions, and that is the part a compliance team can actually use. GV-1.3-001 tells you which factors to weigh when you set risk tiers for a GenAI system. GV-1.3-002 tells you to establish minimum performance and assurance thresholds as part of a go/no-go deployment policy. GV-1.3-007 tells you to write a plan to halt development or deployment of a system that poses unacceptable negative risk. GV-1.6-001 tells you to enumerate every organizational GenAI system into an inventory. GOVERN 6.1 and 6.2 cover third-party risk and contingency. MANAGE 4.3 covers communicating incidents to affected parties.
Those are controls, with IDs, and you can put them in a spreadsheet, assign owners, and check them off. Most AI governance writing stops at principles and never gets this far.
The gap is in the mechanism, not the content
All of that control content is attached to a voluntary framework, while the two regimes that actually compel documentation have nothing to say about GenAI.
SOC 2 is the AICPA’s attestation framework for service organization controls over security, availability, processing integrity, confidentiality, and privacy. It is how enterprise SaaS buyers make vendors prove their controls exist, and it has no native language for generative AI. The accounting profession is only starting to figure out what “assurance over AI” means, and it is borrowing. The Journal of Accountancy’s reporting on CPAs as AI system evaluators describes firms evaluating systems against the NIST AI RMF and ISO/IEC 42001 because the United States has no dedicated standard. One practitioner quoted there warns that without one, “there will be a ton of specific, narrow-scope criteria that are industry-specific or technology-specific.”
The defense side is in flux too, and I have written about that here. CMMC matters to this argument not as an AI framework but as the template for what an AI attestation regime would look like: point-in-time, control-based, buyer-enforced. Right now that template is itself under review.
There is one detail that makes the bridge feel closer to built than it is. NIST points at SOC in its own document. In its third-party risk guidance, the profile recommends “statement on standards for attestation engagement (SSAE) reports to help with third-party transparency and risk management for GAI systems.” SSAE reports are the engine under SOC 2. NIST wrote the bridge into its own document but stopped short of building it.
A roadmap that does not invent a new universe
The advice I would give a mid-sized firm follows directly from that. Do not stand up a parallel AI governance program. Take the profile’s control content and slot it into the attestation regime your buyers already make you run.
- Inventory every GenAI system, per GV-1.6. If you cannot enumerate them, you cannot govern them, and an assessor will not treat governance by anecdote as a control.
- Set risk tiers (GV-1.3), establish the deployment thresholds (GV-1.3-002), and write the halt condition (GV-1.3-007) before you need it.
- Map the four considerations onto controls you already have. Provenance maps to data classification and logging. Pre-deployment testing maps to your SDLC and change management. Incident disclosure maps to your incident response process. Governance maps to whoever owns the AI systems, which most firms have not actually assigned.
- Use the profile’s SSAE recommendation as the ask when you evaluate a model or API vendor. If you already collect SOC 2 reports from vendors, extend that request to the AI pieces.
The point is not that SOC 2 already covers GenAI. It does not, and the SOC market is itself under strain from the “fast and easy” attestation mills the Journal of Accountancy has been writing about. The point is that you already have a mechanism your buyers accept, and the profile gives you the content to feed into it.
The gap is a missing standard that fuses NIST’s content to a mandatory mechanism. Until someone writes that standard, mid-sized firms are bridging it by hand. Doing that inside your existing attestation regime is less work and more likely to survive an assessor than building a parallel governance universe nobody asked for.
Bottom line
NIST shipped the best control content available for GenAI governance and attached it to a voluntary framework. The mechanisms that actually force documentation, SOC 2 and the defense regimes, have no native GenAI language. That is the gap, and it is a market gap more than a regulatory one. The firms that come out of this ahead will be the ones that stop waiting for a standard and start feeding the profile’s controls into the attestation machine their buyers already run.
Sources
- AI Risk Management Framework — NIST
- NIST AI 600-1: AI RMF Generative AI Profile — NIST, July 2024
- NIST AI Resource Center (AIRC) — NIST
- Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure — NIST
- System and Organization Controls (SOC) Suite of Services — AICPA
- A New Frontier: CPAs as AI System Evaluators — Journal of Accountancy, November 2025
- Promises of “fast and easy” threaten SOC credibility — Journal of Accountancy, February 2026