Cybersecurity
– Yasmin Dwiputri & Data Hazards Project / Better Images of AI / CC BY 4.0

The U.S. National Institute of Standards and Technology (NIST) has released guidelines on AI security.

A preliminary draft of the Cybersecurity Framework Profile for Artificial Intelligence builds on the existing NIST Cybersecurity Framework 2.0 framework, while complementing existing structures such as the AI Risk Management Framework.

Known as the Cyber AI Profile, the guidelines focuses on three key areas: Securing AI System Components (Secure), Conducting AI-Enabled Cyber Defense (Defend), and Thwarting AI-Enabled Cyberattacks (Thwart).

With the NIST context, Secure manages cybersecurity challenges which occur with AI integration within enterprise ecosystems and infrastructure, while Defend examines AI can enhance current security processes.

The Thwart tackles resilience operations against the increasing number of bad actors employing AI in their attacks. As explored in SDxCentral’s new cybersecurity supplement, nation-state adversaries such as Iran’s Islamic Revolutionary Guard are already using AI tools to create phishing emails; North Korean hacking groups meanwhile have used OpenAI software to identify potential defense targets. Another example in the form of the Russia-affiliated Fancy Bear has been creating malicious prompts targeting HuggingBear API.

NIST’s recommendations revolved around The Cybersecurity Framework Core Functions of Govern, Identify, Protect, Detect, Respond, and Recover, applied to a taxonomy of high-level cybersecurity outcomes to help organizations manage their cybersecurity risks.

The Cyber AI Profile draft results from a year-long collaborative effort, incorporating input from over 6,500 contributors within NIST's Cyber AI Community of Interest, alongside findings from various workshops and public draft reviews.

The draft is open for comments from the security community through January 30, 2026.