REGULATORY INTELLIGENCE · ODA3 INSIGHTS

NIST Cyber AI Profile Working Session: What the Next Draft Will Include

On April 28, 2026, NIST’s NCCoE is hosting the rst of a virtual working session series to update the Cybersecurity Framework (CSF) Cyber AI Pro le ..

Editorial header for NIST Cyber AI Profile Working Session: What the Next Draft Will Include
CATEGORYRegulatory Intelligence
EVIDENCE BASISSource publication
PUBLISHEDApril 23, 2026
READING TIME4 min

Article

Target Audience: CISOs, Compliance Officers, Standards Body Participants
Category: Standards Development / Regulatory

Executive Summary:
On April 28, 2026, NIST’s NCCoE is hosting the first of a virtual working session series to update the Cybersecurity Framework (CSF) Cyber AI Profile . Following the January 2026 workshop, community feedback called for clearer description of the approaches used to develop Profile elements, including priorities and considerations. This post summarizes what changed, what’s being workshopped, and how organizations can participate or track updates.

Evidence Tier: Primary Verified (NIST .gov official event announcement)

The Context

The NIST NCCoE Cyber AI Profile is intended to help organizations “strategically adopt AI while addressing and prioritizing cybersecurity risks stemming from its advancements” .

In January 2026, NIST hosted a workshop to obtain feedback on the Preliminary Draft. The takeaways were recently shared in a blog post and have been “instrumental” in creating the next draft .

What’s Being Workshopped April 28

The April 28, 2026, virtual working session (1:00 PM – 4:00 PM ET) focuses on :

Topic: Updates to Profile Elements and Contents

Specific community feedback being addressed:

  • Need for clearer description of approaches used to develop Profile elements
  • Clarification of what “priorities” and “considerations” mean in the Profile context
  • Proposed approaches for incorporating this feedback in the next version

What the Cyber AI Profile Covers

The Profile sits within the NIST CSF framework and is designed to help organizations manage AI-specific cybersecurity risks across:

  • AI adoption lifecycle
  • Integration with existing cybersecurity programs
  • Prioritization of AI security investments

Why This Matters to Your Company

Your company is positioned at the intersection of AI security and standards development, with active engagement in NIST, ISO/IEC JTC 1/SC 42, OWASP, and IETF (Section 2 of your profile).

The NIST Cyber AI Profile will become a foundational reference for:

  • US government AI security requirements (via Executive Order implementation)
  • Cross-industry AI security benchmarking
  • Procurement standards for AI systems

How to Engage

Organizations and individuals can :

  1. Register for the April 28 virtual working session
  2. Review the January 2026 workshop takeaways (published as NIST blog post)
  3. Track the next draft release (date TBD following working sessions)
  4. Submit formal comments when the next draft is released for public comment

📌 Notably Absent

The event announcement does not specify how many working sessions will follow or a release timeline for the next draft. The April 28 session is described as “Session #1” of a series.

Anticipated Profile Structure

Based on community feedback described, the next draft is expected to include:

ElementExpected Content
PrioritiesSpecific, ranked AI security actions mapped to CSF functions
ConsiderationsImplementation factors including organizational context, threat environment, and resource constraints
ApproachesMethodological transparency about how elements were derived (addressing direct community feedback)

Recommended Action

For the company’s standards development practice:

  • Assign a team member to attend the April 28 session
  • Track whether the Profile aligns with your AI Control Plane framework
  • Prepare a formal comment response when the next draft releases (opportunity to cite your incident research corpus as evidence for specific controls)

The Bottom Line

NIST is actively refining the Cyber AI Profile with direct community input. The April 28 session will determine how priorities and considerations are structured in the next draft. Organizations that engage now shape the standard; organizations that wait inherit it.



Framework context

This article supports operational interpretation across the GAISSF Ecosystem. Use GAISSF for governance and assurance context, UAIF for incident classification, and AI-IRF for incident-response architecture. These links describe relationships; they do not assert certification, regulatory approval, or legal compliance.

Tags

AI SecurityRegulatory IntelligenceODA3 InsightsNIST AI RMF

Continue reading