Article
Target Audience: CISOs, Compliance Officers, Standards Body Participants
Category: Standards Development / Regulatory
Executive Summary:
On April 28, 2026, NIST’s NCCoE is hosting the first of a virtual working session series to update the Cybersecurity Framework (CSF) Cyber AI Profile . Following the January 2026 workshop, community feedback called for clearer description of the approaches used to develop Profile elements, including priorities and considerations. This post summarizes what changed, what’s being workshopped, and how organizations can participate or track updates.
Evidence Tier: Primary Verified (NIST .gov official event announcement)
The Context
The NIST NCCoE Cyber AI Profile is intended to help organizations “strategically adopt AI while addressing and prioritizing cybersecurity risks stemming from its advancements” .
In January 2026, NIST hosted a workshop to obtain feedback on the Preliminary Draft. The takeaways were recently shared in a blog post and have been “instrumental” in creating the next draft .
What’s Being Workshopped April 28
The April 28, 2026, virtual working session (1:00 PM – 4:00 PM ET) focuses on :
Topic: Updates to Profile Elements and Contents
Specific community feedback being addressed:
- Need for clearer description of approaches used to develop Profile elements
- Clarification of what “priorities” and “considerations” mean in the Profile context
- Proposed approaches for incorporating this feedback in the next version
What the Cyber AI Profile Covers
The Profile sits within the NIST CSF framework and is designed to help organizations manage AI-specific cybersecurity risks across:
- AI adoption lifecycle
- Integration with existing cybersecurity programs
- Prioritization of AI security investments
Why This Matters to Your Company
Your company is positioned at the intersection of AI security and standards development, with active engagement in NIST, ISO/IEC JTC 1/SC 42, OWASP, and IETF (Section 2 of your profile).
The NIST Cyber AI Profile will become a foundational reference for:
- US government AI security requirements (via Executive Order implementation)
- Cross-industry AI security benchmarking
- Procurement standards for AI systems
How to Engage
Organizations and individuals can :
- Register for the April 28 virtual working session
- Review the January 2026 workshop takeaways (published as NIST blog post)
- Track the next draft release (date TBD following working sessions)
- Submit formal comments when the next draft is released for public comment
📌 Notably Absent
The event announcement does not specify how many working sessions will follow or a release timeline for the next draft. The April 28 session is described as “Session #1” of a series.
Anticipated Profile Structure
Based on community feedback described, the next draft is expected to include:
| Element | Expected Content |
|---|---|
| Priorities | Specific, ranked AI security actions mapped to CSF functions |
| Considerations | Implementation factors including organizational context, threat environment, and resource constraints |
| Approaches | Methodological transparency about how elements were derived (addressing direct community feedback) |
Recommended Action
For the company’s standards development practice:
- Assign a team member to attend the April 28 session
- Track whether the Profile aligns with your AI Control Plane framework
- Prepare a formal comment response when the next draft releases (opportunity to cite your incident research corpus as evidence for specific controls)
The Bottom Line
NIST is actively refining the Cyber AI Profile with direct community input. The April 28 session will determine how priorities and considerations are structured in the next draft. Organizations that engage now shape the standard; organizations that wait inherit it.
