AIORG-W022 Standards & frameworks AI × management and organizations

Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile

Also recorded as: GenAI Profile · NIST AI 600-1

official profile publication

Recorded claims
2
coded from the inspected source
Evidence classes
1
normative-authority
Recorded limitations
4
stated, never hidden

From the hash-bound evidence releases

Recorded claims

Each claim states what the inspected source says, at the recorded location—bounded by its scope and graded by its confidence. Nothing here is a synthesis across works.

The GenAI Profile identifies cross-sector risks including confabulation, data privacy, harmful bias/homogenization, human-AI configuration, information integrity and security, intellectual property, harmful content, environmental impacts, and value-chain/component integration.

confidence: high for taxonomy normative-authority apw-r0-seed

Scope: Cross-sector generative-AI risks; relevance and severity vary by use case.

The profile maps suggested actions to Govern, Map, Measure, and Manage across the lifecycle, making predeployment evaluation, provenance, monitoring, incident response, and supplier/value-chain review recurring operating processes rather than a one-time model approval.

confidence: high for profile content normative-authority apw-r0-seed

Scope: Recommended risk-management actions, not legal requirements or certification.

Structured relationships

In-corpus citations

Only source-supplied cites relationships whose two endpoints are admitted are shown. Invocation evidence remains a separate relationship.

Cites (0)

No in-corpus outgoing citation is available in the current enrichment coverage.

Cited by (0)

No in-corpus incoming citation is available in the current enrichment coverage.

Boundaries

Limitations & independence

Recorded at coding time, carried with the work forever. A claim without its limits is not evidence.

Recorded limitations

  • Voluntary companion profile
  • Risk categories are broad and context-dependent
  • No control-effectiveness estimates
  • Technology and threat environment evolve

Source independence

US government cross-sector profile; normative risk taxonomy and actions, not an audit of deployments.