Guide
AI Governance for CISOs: NIST's Framework, the 12 GenAI Risks and the New Agentic AI Rules
What a CISO needs to know about governing AI in 2026: NIST's AI Risk Management Framework (Govern, Map, Measure, Manage), the 12 risks in NIST's Generative AI Profile, and the May 2026 CISA-led joint guidance on agentic AI. Sourced to the primary documents.
TL;DR: NIST's AI Risk Management Framework (AI RMF 1.0, January 2023) is the reference point most AI governance programs build on, organized into four functions: Govern, Map, Measure and Manage. NIST's companion Generative AI Profile (NIST AI 600-1, July 2024) names 12 risks specific to or worsened by generative AI, from confabulation to data privacy to intellectual property exposure. The newest addition is agentic AI: a joint guidance published May 1, 2026 by CISA, the NSA and counterpart agencies in Australia, Canada, New Zealand and the UK tells organizations not to grant AI agents broad or unrestricted access, especially to sensitive data or critical systems, and to pair that restraint with continuous monitoring and layered defenses. None of these three documents is a law. All three are the primary reference set a CISO building or defending an AI governance program should be able to cite by name.
Why "AI governance" means something more specific now
Through most of 2024 and 2025, AI governance conversation for security leaders centered on "shadow AI": employees adopting generative AI tools without sanctioned review, creating data exposure and compliance risk the security program had no visibility into. That problem has not gone away. But the center of the conversation has shifted to a narrower, harder question: how much autonomy and access should an AI agent, one that can take actions on a system rather than just answer a prompt, actually be given. That is the exact question the May 2026 joint guidance from CISA and five partner agencies was written to answer, and it is why agentic AI governance now sits alongside, not underneath, the older "shadow AI" problem on a CISO's list.
The reference framework: NIST's AI RMF
NIST's AI Risk Management Framework, published January 2023 as NIST AI 100-1, is a voluntary framework intended to help organizations manage the risks AI poses "to individuals, organizations, and society" and to build trustworthiness into AI systems across their design, development, use and evaluation. NIST designed it as a living document; a formal community review is expected no later than 2028, and NIST maintains a companion overview page alongside the framework text itself.
The framework's Core is organized into four functions. Each breaks down into categories, subcategories and suggested actions, which NIST is explicit are "not a checklist" and "not necessarily an ordered set of steps":
Govern is the foundation the other three depend on. The framework describes it as the function that "cultivates and implements a culture of risk management" across an organization, sets "processes, documents, and organizational schemes that anticipate, identify, and manage" AI system risk, and connects the technical work of AI development to "organizational values and principles." Govern is explicitly cross-cutting: NIST says its outcomes "should be integrated into each of the other functions," and most organizations are expected to put Govern in place before starting Map.
Map establishes the context needed to make an initial decision about an AI system at all. Its outcomes give "sufficient contextual knowledge about AI system impacts to inform an initial go/no-go decision about whether to design, develop, or deploy" the system. That includes documenting intended purpose, likely users, risk tolerance and the business value the system is meant to deliver, before Measure or Manage can meaningfully begin.
Measure analyzes and tracks the risks Map identified, using "quantitative, qualitative, or mixed-method tools, techniques, and methodologies." NIST's framework calls for AI systems to be "tested before their deployment and regularly while in operation," with independent review where possible to reduce internal bias. Measure's outputs, including documented test, evaluation, verification and validation (TEVV) processes, feed directly into Manage.
Manage allocates resources to the risks Measure quantified. It covers prioritizing treatment "based on impact, likelihood, and available resources," choosing to mitigate, transfer, avoid or accept a given risk, and, notably, maintaining "mechanisms...to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use." That last point matters for agentic systems specifically: Manage is where a CISO's program needs an actual kill switch, not just a monitoring dashboard.
The 12 risks NIST says are unique to or worsened by generative AI
NIST's Generative AI Profile, approved July 25, 2024 as NIST AI 600-1, extends the AI RMF with risks specific to generative AI, each mapped back to the four functions above. NIST names 12:
- CBRN information or capabilities: easier access to or synthesis of information that could assist chemical, biological, radiological or nuclear weapons development.
- Confabulation: confidently stated but false output, commonly called hallucination, that can mislead a user who trusts it.
- Dangerous, violent or hateful content: easier production of or access to violent, radicalizing or self-harm-related content.
- Data privacy: leakage or unauthorized disclosure of biometric, health, location or other sensitive personal data.
- Environmental impacts: the resource cost of training and operating generative AI models.
- Harmful bias or homogenization: amplification of systemic or statistical bias, or output that becomes erroneously uniform across users and contexts.
- Human-AI configuration: risks from how people interact with a system, including over-reliance, automation bias or anthropomorphizing an AI tool.
- Information integrity: a lowered barrier to generating content that blurs fact, opinion and fiction, including at the scale needed for disinformation campaigns.
- Information security: lowered barriers to offensive cyber capability, including automated vulnerability discovery, phishing content and an expanded attack surface.
- Intellectual property: easier reproduction of copyrighted, trademarked or licensed material, or exposure of trade secrets.
- Obscene, degrading or abusive content: easier production of or access to abusive imagery, including synthetic child sexual abuse material.
- Value chain and component integration: risk from non-transparent or untraceable third-party components feeding into a generative AI system.
NIST's own framing is useful for scoping a program: these are risks the document found an existing empirical evidence base for at the time it was written, not speculative risks about future, more capable systems. A governance program built only against this list should expect it to be revised as NIST updates the profile.
The new layer: governing agentic AI
Agentic AI, AI systems that can take actions, call tools or access other systems rather than only generate text, is the subject of the newest primary document in this space: Careful Adoption of Agentic Artificial Intelligence (AI) Services, published May 1, 2026 by CISA together with the NSA and cyber agencies in Australia, Canada, New Zealand and the UK. The guidance's core recommendations are narrow and specific rather than a general framework:
- Agents should not be given "broad or unrestricted access, especially to sensitive data or critical systems."
- Organizations should conduct "comprehensive threat modeling, continuous monitoring, and regular security assessments" of agentic systems, not a one-time pre-deployment review.
- Programs should implement "layered defense strategies, strong identity management," and strong oversight mechanisms around agents, treating an agent's identity and permissions the way an organization would treat a privileged human account, not a static service credential.
Read against the AI RMF, this guidance is effectively a Map-and-Manage instruction for one specific, fast-moving category of AI system: scope an agent's access deliberately before deployment (Map), and keep tightening or revoking that access as its behavior is observed in production (Manage), rather than treating agent permissioning as a one-time configuration step.
What this means for a governance program, in practice
None of the three documents above requires a specific program structure, and this guide is not recommending one either; it is pointing at what each source actually instructs. Read together, they suggest three things worth checking against an existing program rather than building from scratch: whether Govern-level accountability for AI risk decisions is assigned to a named role rather than diffused across teams, as the AI RMF's Govern function calls for; whether the organization's generative AI risk register actually covers the 12 categories NIST's profile names, rather than only the two or three that get the most vendor attention (information security and data privacy); and whether any AI agent already in production has the kind of unrestricted access the May 2026 guidance specifically warns against, which is worth an inventory pass on its own given how quickly agentic tools have been adopted inside existing software.
What this guide does not cover
This page covers the content of three named primary documents: NIST's AI RMF, NIST's Generative AI Profile, and the May 2026 joint agentic AI guidance. It does not cover sector-specific AI regulation (the EU AI Act, state-level US AI laws) or contractual AI governance terms from specific vendors, which are outside what these three documents address and belong in a separate, jurisdiction-specific review. It also does not replace a security leader's own risk assessment; a CISO should cite the primary documents directly when building board or audit materials, rather than relying on secondary summaries, this one included.
For the regulatory side of a CISO's job more broadly, see CISO Tribune's guide to the SEC's cybersecurity disclosure rules and the SEC Item 1.05 materiality decision guide; for where AI governance sits inside the role overall, see What Does a CISO Do?
Frequently asked questions
- What is the NIST AI Risk Management Framework?
- A voluntary framework NIST published in January 2023 (NIST AI 100-1) to help organizations manage the risks AI poses to people, organizations and society, and to build trustworthiness into how AI is designed, developed, used and evaluated. It is organized into four functions: Govern, Map, Measure and Manage.
- What are the four AI RMF functions?
- Govern builds the organizational culture, policies and accountability structure that the other three functions depend on. Map establishes the context needed to decide whether an AI system should be built or used at all. Measure analyzes and tracks a system's risks with quantitative and qualitative tools. Manage allocates resources to the risks Map and Measure identified, including the decision to supersede, disengage or deactivate a system.
- What is the NIST Generative AI Profile?
- A companion document to the AI RMF, NIST AI 600-1, approved July 25, 2024. It names 12 risks unique to or worsened by generative AI, from confabulation and data privacy to CBRN information and intellectual property exposure, and maps suggested actions for each back to the AI RMF's four functions.
- What does the new agentic AI guidance say?
- "Careful Adoption of Agentic Artificial Intelligence (AI) Services," published May 1, 2026 by CISA, the NSA and cyber agencies in Australia, Canada, New Zealand and the UK, recommends that organizations not grant AI agents broad or unrestricted access, especially to sensitive data or critical systems, and that they run comprehensive threat modeling, continuous monitoring and regular security assessments alongside layered defenses, strong identity management and oversight mechanisms.
- Is a CISO required to follow NIST's AI RMF or the agentic AI guidance?
- No. The AI RMF is explicitly voluntary, and the joint agentic AI guidance is advisory, not a regulation. Neither carries the force of law on its own. A CISO's actual AI governance obligations come from whatever laws, sector rules or contracts apply to their organization; these documents are reference frameworks a CISO can govern against, not mandates.
Sources
- Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 · National Institute of Standards and Technology (NIST), January 26, 2023
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1 · National Institute of Standards and Technology (NIST), July 25, 2024
- Careful Adoption of Agentic Artificial Intelligence (AI) Services · Cybersecurity and Infrastructure Security Agency (CISA), with the NSA, Australia's ACSC, the Canadian Centre for Cyber Security, New Zealand's NCSC and the UK's NCSC, May 1, 2026
- AI Risk Management Framework (program overview) · National Institute of Standards and Technology (NIST), October 9, 2026
Hadass Liza Bitton
Writer
Hadass Liza Bitton is a writer at CISO Tribune covering security leadership: the people who take the top security seat, the ones who leave it, and what each move signals. Reach her at hadass@cisotribune.com.
The Briefing
Every verified CISO move of the week, in your inbox Friday.
Every verified CISO move and one piece of analysis, weekly.
Unsubscribe any time. See the privacy policy.