AI Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)
A companion profile to NIST’s AI RMF 1.0, mapping that framework’s four functions onto twelve risks specific to generative AI, including human-AI-interaction and content-provenance risks.
License: Public domain — U.S. federal government work (17 U.S.C. § 105).
Key points
- Human-AI Configuration names four distinct psychological risk patterns: inappropriately anthropomorphizing a generative AI system, algorithmic aversion (avoiding or underusing a system even where it would help, typically from unfamiliarity rather than actual unreliability), automation bias/over-reliance, and emotional entanglement with negative psychological effects. See Human-AI Interaction.
- Disclosing AI involvement to end users should weigh five factors rather than follow one fixed rule: the disclosure’s own objective, the context of use, the likelihood and magnitude of the risk if a user misses it, the audience receiving it, and how often it needs to repeat. See AI Content Marking.
- Content provenance metadata can record the model developer or content creator, creation date/time, location, modifications, and sources — tracked via techniques including digital watermarking, metadata recording, digital fingerprinting, and human authentication.