Summary NIST released a preliminary draft of its Cybersecurity Framework Profile for Artificial Intelligence, organising AI security into three areas: securing AI system components, using AI for cyber defence, and defending against AI-enabled attacks. A full draft is expected during 2026.
Source: American Banker · 17 December 2025 · read the original article
Three domains, three different owners The value of the three-part split is that it separates concerns that are routinely conflated. Securing AI system components is an infrastructure and supply chain problem: model weights, training pipelines, vector stores, inference endpoints and the credentials that reach them. Using AI for cyber defence is a security operations question about detection quality and false positive cost. Defending against AI-enabled attacks is a threat model update, principally around social engineering, synthetic identity and automated reconnaissance.
In most banks these three sit with different teams. Mapping them to one profile is what allows a single answer to the question of how AI is secured.
Why the vocabulary matters The profile complements NIST's AI risk management framework and is likely to become the reference language examiners and internal audit use. That is a practical reason to adopt it early even where existing controls are adequate: control effectiveness is judged partly on whether the firm can demonstrate coverage against a recognised map.
Adoption does not require re-engineering. It requires mapping existing controls to profile categories, identifying the categories with no owner, and reporting coverage in that structure.
Immediate actions - Map current AI-related security controls to the three profile domains and record gaps - Treat model artefacts and retrieval corpora as protected assets with access control and integrity monitoring - Update the threat model for AI-enabled social engineering and synthetic identity in onboarding and payment authorisation - Set expectations with model vendors on security disclosure and incident notification
Methodology and limitations This summarises trade reporting on a preliminary draft as at the date shown and links to the original. Draft content is subject to change before final publication, and the profile is voluntary rather than a supervisory requirement.
Related reading See [Banking Risk](/expertise/banking-risk), [Enterprise Risk](/expertise/enterprise-risk), [Model Risk](/expertise/model-risk) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).
Frequently asked questions
What should risk leaders know about three domains, three different owners?
The value of the three-part split is that it separates concerns that are routinely conflated. Securing AI system components is an infrastructure and supply chain problem: model weights, training pipelines, vector stores, inference endpoints and the credentials that reach them. Using AI for cyber defence is a security operations question about detection quality and false positive cost. Defending against AI-enabled attacks is a threat model update, principally around social engineering, synthet...
Why the vocabulary matters?
The profile complements NIST's AI risk management framework and is likely to become the reference language examiners and internal audit use. That is a practical reason to adopt it early even where existing controls are adequate: control effectiveness is judged partly on whether the firm can demonstrate coverage against a recognised map.
What should risk leaders know about methodology and limitations?
This summarises trade reporting on a preliminary draft as at the date shown and links to the original. Draft content is subject to change before final publication, and the profile is voluntary rather than a supervisory requirement.
What should risk leaders know about related reading?
See [Banking Risk](/expertise/banking-risk), [Enterprise Risk](/expertise/enterprise-risk), [Model Risk](/expertise/model-risk) and the overview in [AI governance in insurance and banking](/insights/ai-governance-insurance-banking-2026).