This week I had the opportunity to review and provide feedback to National Institute of Standards and Technology (NIST) on NIST IR 8596 irpd: Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile).

AI is forcing cybersecurity frameworks to confront issues they were never designed for. Model behavior changes over time. Decisions are automated. Trust and accountability become part of the security conversation, not an afterthought.

My comments focused on practical gaps I see repeatedly in the field:
• How organizations sequence AI security maturity
• Where governance breaks down when AI decisions cause harm
• The need for continuous assurance, not point-in-time controls
• How CSF outcomes can address AI behavior without becoming prescriptive

NIST’s willingness to open this work for public comment matters. Frameworks only stay relevant when they reflect how technology actually behaves in production.

If you’re working through AI security, governance, or risk right now, this draft is worth reading and commenting on before it closes. https://www.nccoe.nist.gov/projects/cyber-ai-profile