NIST AI 600-1 Profile Mapping for Federal Deployment
NIST AI 600-1 provides a profile of the NIST AI Risk Management Framework (AI RMF 1.0) tailored to generative AI systems. For a provider targeting US federal deployment, the AI 600-1 profile maps onto the FedRAMP OSCAL Sept-30 mandate along three axes: (1) GOVERN — the profile governance functions (GOVERN 1-5) align with FedRAMP security assessment framework requirements for AI system documentation, making the Council of AI verified measurement credential a direct input to the OSCAL control-implementation narrative. (2) MAP — the profile mapping of AI risks to organisational context overlaps with FedRAMP system security plan (SSP) requirements; a signed model card with provenance chain satisfies both. (3) MEASURE — the profile measurement methodology maps to continuous monitoring requirements under FedRAMP; the Council boundary-instrumentation baseline (monitored containment) provides the evidence stream. Practical first steps: (a) generate an AI system inventory mapped to NIST SP 800-53 controls. (b) Conduct a gap analysis between ISO/IEC 42001 AIMS and AI 600-1 profile requirements. (c) Prepare a crosswalk document showing how each AI RMF subcategory is addressed. (d) Integrate the Council of AI containment index as an autonomous evidence source for the MEASURE function.
The posture is monitored containment — 600-1 does not require proving safety, it requires proving you are watching systematically.
Standards and sources referenced
- NIST AI 100-1 (AI RMF 1.0)
- NIST AI 600-1 (Generative AI Profile, draft)
- FedRAMP OSCAL Mandate Sept-30 2026
- Council of AI Containment Incident Index