Big Story: How NIST Is Updating Cybersecurity Guidance for AI
Key Takeaways
NIST is developing a Cyber AI Profile that applies the Cybersecurity Framework 2.0 to risks created by the development, deployment, and malicious use of artificial intelligence.
The profile is organized around three areas: protecting AI systems, defending against AI-enabled attacks, and using AI to improve cybersecurity operations.
Feedback from NIST workshops has focused on agentic AI, testing, accountability, human oversight, AI supply chains, and the need for practical guidance that smaller organizations can implement.
NIST received more than 1,400 comments on the preliminary profile and is reviewing them as it prepares the next draft.
Artificial intelligence is changing cybersecurity on both sides of the operating model. Organizations are integrating AI into software, business processes, and security tools, while attackers are using the same technology to identify vulnerabilities, craft exploits, and automate parts of attacks.
The National Institute of Standards and Technology is addressing that gap through a Cyber AI Profile built on the NIST Cybersecurity Framework 2.0. The aim is to help organizations apply familiar risk-management practices to AI without creating a separate cybersecurity system for every new model or application. The profile is currently under development, with NIST reviewing public comments on its preliminary draft.
The work begins with three distinct sources of risk. The first is the cybersecurity of AI systems themselves, including the models, data, infrastructure, applications, and components used to operate them. The second is AI-enabled cyberattacks, where adversaries use AI to increase the speed or scale of malicious activity. The third is AI-enabled cyberdefense, where organizations use AI to detect threats, analyze incidents, prioritize vulnerabilities, or automate parts of security operations.
Separating those areas matters because each creates a different problem. Protecting an AI application may require securing training data, model access, integrations, and software dependencies. Responding to AI-enabled attacks may require faster vulnerability management and improved detection. Using AI in defense raises a separate question: how much authority should a system be granted to block traffic, isolate devices, change permissions, or take other actions that affect production environments?
Agentic AI adds further complexity. An AI assistant that only produces text creates a different level of risk from an agent that can access databases, execute code, communicate with external systems, or make changes without waiting for approval. Identity and authorization are central to that work. Organizations also need ways to determine whether an AI system performs reliably under normal conditions, how it behaves when manipulated, and whether its security controls remain effective after models, prompts, data sources, or connected tools change.
The profile must also remain useful as the technology changes. Participants cautioned against guidance that is tied too closely to current model types or products, since such details can quickly become outdated. Organizations are distributing responsibility among security teams, technology leaders, business units, legal departments, risk functions, and newly appointed AI officers. The profile will need to clarify how these groups share accountability when an AI system produces an insecure result, takes an unauthorized action, or relies on models and data supplied by an outside vendor.
Participants discussed cryptographic signing, certification systems, and AI Bills of Materials as possible ways to document the models, data, software, and services inside an AI system. That information could help organizations identify which systems are affected when a model, component, or provider is found to contain a vulnerability.
NIST received more than 1,400 comments through its second workshop and public-comment process. It also held three virtual working sessions in April and May 2026 covering profile content, technical detail, and usability. NIST’s approach is to extend an existing risk framework so organizations can identify what the AI system can access, how it can fail, who is accountable, what evidence is required, and when a person must remain in control.

Build the right capabilities for what’s coming. Book a quick call with the Fractional Source team.
Quick Hit News:
Eleven Western governors signed a letter endorsing a new multi-state task force to study and modernize the region's aging electric grid. The effort creates the Western Transmission Expansion Coalition to assess transmission needs across the region and build a roadmap for expanding infrastructure. Governors from Colorado, Wyoming, Nevada, Idaho, Oregon, Montana, North Dakota, Arizona, New Mexico and Washington joined Utah Republican Gov. Spencer Cox, with the group also aiming to coordinate more closely with federal agencies to speed up permitting and construction timelines.
The Orlando Police Department launched a Drone as First Responder program, deploying eleven drones across nine docking sites so officers can view a scene within seconds of a 911 call. The city joins a growing list of departments, including Chula Vista, Miami Beach, and Oklahoma City, that credit the approach with faster response and fewer unnecessary deployments.
Alberto Gonzalez, Idaho's chief information officer and administrator of its Office of Information Technology Services for nearly four years, has been appointed director of the Idaho Transportation Department. He starts the new role taking over from Scott Stokes, who retired after a 35-year career at the agency. Gonzalez led Idaho's IT consolidation efforts and previously served as administrator for the Division of Motor Vehicles. Idaho Department of Commerce Administrator Jake Reynolds will serve as interim head of the technology office in his place.
Idaho school districts are updating policies to comply with new laws that took effect on July 1. Districts without an artificial intelligence policy must create one that governs how students and teachers use the technology on school devices, and the State Department of Education must develop its own framework focused on responsible use, instructional integration, and academic integrity. A separate law adds accountability measures for virtual schools, requiring that curricular materials meet state content standards and that teachers be certified, following a report that found gaps in oversight that allowed public funds to cover expenses such as streaming subscriptions and trampoline park visits.
For the Commute:
For Digital Government, Trust Is Essential (Priorities Podcast)
Estonia's minister of justice and digital affairs, Liisa-Ly Pakosta, talks about how the country built one of the most connected digital governments in the world after regaining independence in 1991. She says officials chose the cheapest and most effective path to digital services, drawing lessons from private industry such as banking. Pakosta points to public trust as the single factor the entire system depends on, noting that confidence in Estonia's digital services stays high even when trust in government itself runs lower, aided by transparency that lets residents see who accesses their data.
Resources & Events:
📅 The State of AI in Government (Virtual - July 29, 2026)
This webinar draws on research from IBM's Institute for Business Value, along with perspectives from public sector leaders, to examine where artificial intelligence delivers value in government and the risks organizations need to manage. The session offers a framework for building an AI strategy, shares government use cases, and explains why agencies are drawn to AI capabilities that are built into systems employees already use. Details →
📅 Michigan High School Cyber Summit 2026 (Novi, MI - October 14, 2026)
This event at the Vibe Credit Union Showplace introduces high school students across Michigan to cybersecurity careers and digital defense challenges. Organized with the Michigan Department of Technology, Management and Budget, the summit pairs students with public- and private-sector experts through discussions and hands-on activities focused on protecting critical infrastructure and building the state's future cybersecurity workforce. Details →
📊Report Spotlight: The Future of Finance for Government (KPMG)
This report from KPMG argues that government finance organizations are running outdated operating models that were not built for today's pace and complexity, leaving many still stuck reconciling numbers and chasing fragmented data. KPMG calls for a shift toward what it terms Intelligent Finance, a connected, AI-enabled framework that ties people, data, and technology together across processing, closing, and planning. The report projects that within three years, finance will shrink as a standalone department while its influence spreads across the wider organization, with AI agents handling transactional work and human staff moving into oversight, governance and strategic roles. Read →
Insight of the Week:
The 2026 NASCIO-Deloitte Cybersecurity Study found that state chief information security officer confidence in protecting public data has fallen sharply, dropping from 48% in 2022 to just 22% in 2026. 16% of state CISOs reported outright budget cuts this year, a first for the survey, while only 22% received budget increases of 6% or more, down from 40% in 2024. Most CISOs report low confidence in the cybersecurity readiness of local governments and public higher education, and only 2% feel very confident in the practices of their contractors and business partners.
Was this email forwarded to you? Subscribe here to get Fractional Leader delivered to your inbox every Tuesday & Thursday.


