This report summarizes the discussion at the second “Cyber AI Profile Workshop,” in January 2026 during which focused on the Preliminary Draft of the NIST Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile). The workshop gathered input across government, industry, and academia to provide guidance for managing cybersecurity risks associated with AI systems and for leveraging AI to enhance cybersecurity capabilities to inform the next draft of the NIST Cyber AI Profile. NIST also provided an update on its work to develop the Special Publication (SP) 800-53 Control Overlays for Securing AI Systems (COSAiS). The report highlights key themes raised during the discussions, including governance challenges, stability of the Profile over time, AI attack surfaces, the need for consistent AI taxonomy, ideas for specific risk-based guidance and resources to support usability (e.g., use cases), and AI-enabled cyber defense opportunities.
This report summarizes the discussion at the second “Cyber AI Profile Workshop,” in January 2026 during which focused on the Preliminary Draft of the NIST Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile). The workshop gathered input across government, industry, and...
See full abstract
This report summarizes the discussion at the second “Cyber AI Profile Workshop,” in January 2026 during which focused on the Preliminary Draft of the NIST Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile). The workshop gathered input across government, industry, and academia to provide guidance for managing cybersecurity risks associated with AI systems and for leveraging AI to enhance cybersecurity capabilities to inform the next draft of the NIST Cyber AI Profile. NIST also provided an update on its work to develop the Special Publication (SP) 800-53 Control Overlays for Securing AI Systems (COSAiS). The report highlights key themes raised during the discussions, including governance challenges, stability of the Profile over time, AI attack surfaces, the need for consistent AI taxonomy, ideas for specific risk-based guidance and resources to support usability (e.g., use cases), and AI-enabled cyber defense opportunities.
Hide full abstract