Skip to content

NIST AI 600-1: register the framework and transcribe its 211 suggested actions - #187

Merged
emmanuelgjr merged 13 commits into
GenAI-Security-Project:mainfrom
Prasad-desh:nist-ai-600-1
Oct 4, 2026
Merged

emmanuelgjr merged 13 commits into
GenAI-Security-Project:mainfrom
Prasad-desh:nist-ai-600-1

Conversation

@Prasad-desh

@Prasad-desh Prasad-desh commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

What this PR changes

Adds NIST AI 600-1 (the AI RMF Generative AI Profile) as a framework registry. Refs #119 — the agent-safe half of that ticket: registration and transcription only. No mapping rows are asserted, and no vulnerability IDs are affected. Which suggested action addresses which entry is security judgment (C4) and belongs to a framework-owner reviewer per STRAT-04.

  • data/frameworks/nist-ai-600-1.json — 211 suggested actions across 49 AI RMF subcategories. control_id is the document's own Action ID, description the Suggested Action verbatim, title derived mechanically from it, gai_risks the document's own GAI Risks column. inventory_completeness: complete, 211 of 211
  • data/framework-sources.json — registered, current_version: "2024-07"
  • scripts/control-ids.js — id grammar ^(?:GV|MP|MS|MG)-\d{1,2}\.\d{1,2}-\d{3}$, so checkControlIdShapes() covers it from day one
  • scripts/control-ids.test.mjs — four tests: the grammar, all 211 ids against it, and every gai_risks value against the document's twelve risks
  • scripts/exports.test.mjs — see Notes for reviewers
  • Regenerated: data/stats.json, docs/frameworks-registry.js, README markers

On parent: it is the AI RMF subcategory the action is filed under. 45 of the 49 resolve against data/frameworks/nist-ai-rmf.json; MG-4.3, MP-3.4, MS-2.12 and MS-2.13 do not, because that registry holds only the subcategories existing mappings cite. The $comment says so.

Type of change

  • New mapping file
  • Update to existing mapping (content, controls, CVE refs)
  • Bug fix (broken link, typo, incorrect cross-ref)
  • New recipe (shared/RECIPES.md)
  • New tool (shared/TOOLS.md)
  • Infrastructure (scripts, CI, templates)
  • Translation (i18n/)

Source / evidence

NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, July 2024 — https://doi.org/10.6028/NIST.AI.600-1

Every control id, description and risk tag is transcribed from the suggested-action tables of that document.

Checklist

Content

  • Follows the file template structure — N/A, no mapping file is added
  • Severity ratings consistent with AIVSS / OWASP definitions — N/A, none assigned
  • Cross-references bidirectional — N/A, no mapping file
  • All referenced vulnerability IDs are valid — this PR references none
  • License header present — N/A for JSON registries; shape matches the other data/frameworks/*.json

Links & data

  • All internal .md links resolve — no .md files changed
  • All external URLs return 200 — the one URL added is the NIST DOI above
  • data/schema.json compatible — the registry validates against data/framework-schema.json; gai_risks is an extra property, which that schema permits

Project hygiene

  • Changelog entry added — the registry carries its own changelog block; no mapping file was modified
  • CHANGELOG.md updated — conditional on a new mapping file, which this isn't. Happy to add an [Unreleased] note if you'd prefer
  • README.md counts updated — file count unchanged; the freshness marker moved 4 current → 5 via npm run stats
  • Ran validation locally — see below

For new mapping files only

N/A — no mapping file is added.

Notes for reviewers

Verification, rebased onto main at 633c59a. npm test 93/93. A clean clone of that base is 89/89, so the four added tests pass and nothing regresses. validate.js reports 0 errors and 91 warnings, identical to that clean clone. npm run build is deterministic across two runs, and git status shows only the intended files.

Changes made in response to review.

  1. The 13 hyphen line-break artifacts are fixed, along with the 6 titles derived from them. The cause was the extraction joining a compound broken across a line without rejoining it at the hyphen; the parser now does, and a /\w- \w/ search over the file returns nothing.
  2. The parent claim is corrected in both the $comment and the description above, naming the four subcategories that are not in nist-ai-rmf.json. Rewording rather than adding them, so the AI RMF control count is untouched.
  3. gai_risks added for all 211 actions, transcribed from the GAI Risks column, with a test asserting every value is one of the twelve and that all twelve are exercised.

Two things found while transcribing the risk column, both worth a decision.

The tables spell four risks differently from the enumeration in section 2: Harmful Bias and Homogenization (57 rows), Environmental (4), CBRN Information and Capability (2) and Human AI Configuration (1). The registry normalises to the section 2 names, since those define the twelve and the test checks against them. The variants are recorded in the $comment. Say the word if you would rather keep the table spellings and widen the test.

GV-1.4-002 carries a fifth tag, Civil Rights violations, which is not one of the twelve and appears nowhere else in the document. It is not recorded in gai_risks and is noted in the $comment instead of being silently dropped or silently admitted.

Why exports.test.mjs changed. prose-shaped control ids do not spread beyond the known set runs an OSCAL export for every file in data/frameworks/, but compliance-report.js resolves --framework from the names the mappings cite, so a registry nothing maps is not found. The fix skips those, exempting nothing that does produce a prose id.

One transcription detail. A pattern match over the PDF finds 212 ids, but GV-1.1-002 appears only in the explanation of the Action ID scheme. GOVERN 1.1 has exactly one action; the tables define 211. Recorded in inventory_completeness.

Merge conflict resolved. data/stats.json conflicted with #184 as you predicted. The branch now merges main and the file is regenerated, so the control total is 1184 (973 after #184, plus these 211).

Transcription and verification done with AI assistance; I reviewed the diff and ran the build, validators and test suite locally.

…gistry (refs GenAI-Security-Project#119)

Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 13:08

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@emmanuelgjr

Copy link
Copy Markdown
Contributor

Thanks, @Prasad-desh. This is careful work, and the notes for reviewers made it quick to check.

Verification of this branch (2559544), local runs:

  • Against current main: validate 0 errors (93 warnings, same as main), stats:check current, 92/92 unit tests, and a second generate.js + stats + render-stats produces no drift.
  • Ids: checked against the published PDF (NIST.AI.600-1.pdf from nvlpubs). It has 212 distinct id-shaped strings, and the only one missing from the registry is GV-1.1-002, which appears only in the Action ID explanation. That confirms your reading. 211 ids, no duplicates.
  • Descriptions: all 211 match the PDF word for word, checked as an in-order word match near each id so the GAI-risk column can't interfere. The only differences are the ones below.

One fix needed: 13 descriptions keep a line-break artifact. Where a hyphenated compound wrapped at the hyphen, the line break became a space, so the text reads non- systematic instead of non-systematic:

GV-6.2-002 open- data · MS-1.1-006 red- teaming · MS-2.2-004 privacy- enhancing · MS-2.5-001 non- systematic · MS-2.5-002 retrieval- augmented · MS-2.5-003 pre- deployment · MS-2.8-003 tamper- proof · MS-2.11-002 sub- sampling · MS-3.3-003 AI- generated · MG-2.2-002 AI- generated · MG-2.2-008 AI- generated · MG-3.1-001 third- party · MG-3.2-002 pre- trained

Six of the derived titles carry it too (GV-6.2-002, MS-2.5-001, MS-2.5-003, MS-3.3-003, MG-2.2-002, MG-2.2-008). Each one is a genuine compound in the PDF, so the fix is to drop the space and keep the hyphen. A /\w- \w/ search over the file finds exactly these.

One claim to correct: 14 parent values don't resolve against nist-ai-rmf.json. The description says every parent resolves there, but four subcategories aren't in that registry: MP-3.4 (6 actions), MS-2.12 (4), MG-4.3 (3) and MS-2.13 (1). nist-ai-rmf.json only holds the subcategories that existing mappings cite. Nothing validates this today, so the branch is green either way. Two ways to fix it: add the four subcategories to nist-ai-rmf.json as curated parents, transcribed from AI RMF 1.0, or reword the claim and the $comment. Adding them changes the AI RMF control count, so the maintainer should choose.

The exports.test.mjs change looks right to me. A registry nothing cites can't emit OSCAL, and the skip exempts nothing that does.

Left for the maintainer (my view in brackets, not a ruling): the title-derivation rule (verbatim text stays in description, so nothing is lost), keeping the 49 subcategories out of this registry (agreed: it protects the denominator), dropping the stub mapping files (the REQUIRED_SECTIONS conflict you describe is real), and the branch name (harmless).

Merge-order note. This PR and #184 both change data/stats.json (the control total), so whichever merges second will show a conflict in that file. I simulated main + #184 + #185 + #186 + this PR: that file is the only conflict, and regenerating fixes it. After generate.js + stats + render-stats: 0 errors, 93/93, no drift.

CI hasn't run here. Workflows on fork PRs wait for a maintainer to approve them, so every result above is from a local run, not a GitHub check.

@emmanuelgjr

Copy link
Copy Markdown
Contributor

Following up with the maintainer's decisions, so you know exactly what's needed to merge.

The four calls you asked about are settled your way. The title-derivation rule stands, the 49 subcategories stay out of this registry, the stub mapping files stay out, and the branch name is fine.

Needed before merge:

  1. The 13 hyphenation fixes from my earlier comment (non- systematic → non-systematic, and so on, including the six titles derived from them).
  2. The 14 unresolved parent values (MP-3.4, MS-2.12, MG-4.3, MS-2.13). Simplest fix: reword the claim in the $comment and the PR description to say the parents are AI RMF subcategory ids, of which these four aren't in nist-ai-rmf.json yet. Adding them to nist-ai-rmf.json is also fine, provided they're transcribed verbatim from AI RMF 1.0.
  3. One addition: transcribe the GAI risk tags for each action. Every suggested action in the PDF carries a "GAI Risks" column, tagged with one or more of the document's 12 risks (Information Security, Confabulation, Data Privacy, …). That's NIST's own data, so copying it is transcription, not security judgment, and it's the most useful part of the document for this crosswalk. It turns the later human mapping job from 51 entries × 211 actions into 51 entries × 12 risks, followed by confirming candidate actions. Suggested shape, per control: "gai_risks": ["Information Security", "Confabulation"], using the risk names exactly as the document spells them. Add a test that every value is one of the 12. data/framework-schema.json doesn't forbid extra properties, so no schema change is needed.

Also landing separately: #188. The webapp home page counted every registry as a framework, so this PR would have shown 27 frameworks on the live site while the README says 26 mapped, and added 211 unmapped controls to the headline. #188 makes the home page count mapped frameworks only. It doesn't touch your files, and with it merged, this registry can land without changing any public number until the first rows map to it.

After merge, a framework-owner reviewer will author the mapping rows (per #119 and STRAT-04). Thanks again. The transcription itself checked out to the word.

@Prasad-desh

Copy link
Copy Markdown
Contributor Author

got it @emmanuelgjr , will do the changes. thanks for the updates

Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
…rent claim

Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
@Prasad-desh

Copy link
Copy Markdown
Contributor Author

@emmanuelgjr all three done, rebased onto main at 633c59a with the data/stats.json conflict resolved.

1. Hyphenation. Fixed, including the six derived titles, which are regenerated from the corrected text rather than patched. The cause was mine: the extraction joined words across a line break without rejoining compounds at the hyphen. The parser now does, and a /\w- \w/ search over the file returns nothing.

2. Parent claim. Reworded rather than adding the subcategories, so the AI RMF control count is untouched. The $comment and the PR description now name MG-4.3, MP-3.4, MS-2.12 and MS-2.13 as the four not in nist-ai-rmf.json, and say why.

3. gai_risks. Added for all 211 actions from the GAI Risks column, with a test asserting every value is one of the twelve and that all twelve are exercised, so a typo in the list can't pass unnoticed.

Two things the risk column turned up that need your call:

  • The tables spell four risks differently from the section 2 enumeration: Harmful Bias and Homogenization (57 rows), Environmental (4), CBRN Information and Capability (2) and Human AI Configuration (1). I normalised to the section 2 names, since those define the twelve and the test checks against them; the variants are recorded in the $comment. Happy to keep the table spellings and widen the test instead, if you would rather the field be literal.
  • GV-1.4-002 carries a fifth tag, Civil Rights violations, which is not one of the twelve and appears nowhere else in the document. I left it out of gai_risks and noted it in the $comment, rather than dropping it quietly or admitting a thirteenth value.

Verification on the rebased branch: npm test 93/93, where a clean clone of 633c59a is 89/89. validate.js 0 errors and 91 warnings, identical to that clean clone. npm run build deterministic across two runs, git status showing only the intended files. Control total is 1184, which is 973 after #184 plus these 211.

Understood on #188 landing first. Thanks for checking all 211 against the PDF; the two things you caught were both mine.

emmanuelgjr added a commit that referenced this pull request Oct 3, 2026
The home page added every registry to the framework list, mapped or not, and
summed every registry's controls into "Registry Controls". A registry that
lands before its rows (NIST AI 600-1 in #187) would have shown 27 frameworks
against the README's 26 mapped, and added 211 unmapped controls (+19%).

Frameworks now come from the mapping rows alone, and the controls total only
counts registries a row cites. No change to today's numbers: all 26 registries
are mapped. New webapp test pins the hero to stats.json's frameworks.mapped.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Prasad Deshpande <74897556+Prasad-desh@users.noreply.github.com>
@emmanuelgjr

Copy link
Copy Markdown
Contributor

Thanks, @Prasad-desh. All three changes check out, and I verified the new risk tags independently.

Verification of 6c2354f, local runs against main at cc0a735 (after #188 and #190):

  • validate 0 errors (92 warnings, same as main), stats:check current, 94/94 unit tests, and a second generate + stats + render-stats produces no drift.
  • Webapp: with this branch, the home page still shows 26 frameworks and the same Registry Controls total. The Webapp: count only mapped frameworks in the home-page headline #188 test passes on this head, so the registry lands without changing any public number.
  • Hyphenation: the /\w- \w/ search returns nothing, and all 211 descriptions still match the PDF word for word.
  • gai_risks: I read the GAI Risks cell of every action straight from the PDF's tables (pdfplumber, cell by cell, rather than from flattened text). The tags match on 211 of 211 actions, with no tag missing and none extra.
  • Parent wording: the $comment and the description now name the four subcategories that don't resolve, and why.

Your two calls: I'd keep both as you have them.

  1. Normalising to the section 2 names is right. The twelve are defined in section 2, which makes gai_risks a closed vocabulary that consumers can filter on, and your test enforces it. I confirmed the table variants exist (e.g. "Harmful Bias and Homogenization", "CBRN Information and Capability", "Human AI Configuration"), and recording them in the $comment keeps the transcription honest.
  2. "Civil Rights violations" on GV-1.4-002: confirmed in the PDF, where the cell reads "…Data Privacy; Civil Rights violations". Keeping it out of gai_risks and noting it in the $comment is the right handling. Admitting a thirteenth value would break the vocabulary, and dropping it silently would lose data.

From the review side this is ready. Next, the maintainer approves the fork CI run, and the PR merges once the checks are green.

@emmanuelgjr
emmanuelgjr merged commit 591b13b into GenAI-Security-Project:main Oct 4, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants