United States · Guidance
United States — NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting (NIST SP 1353, Initial Public Draft)
Issued by National Institute of Standards and Technology (NIST), Department of Commerce.
Summary
NIST SP 1353 explores how generative AI can support organisations using the NIST Cybersecurity Framework 2.0. It provides structured prompts and practical use cases for activities including reviewing organisational cybersecurity governance, analysing evidence against CSF outcomes, producing current-state and target-state profiles, identifying gaps, and generating CSF-related governance artefacts.
Why it matters
Structured prompts and practical use cases for using AI in Cybersecurity Framework 2.0 work; reviewing organisational cybersecurity governance; analysing evidence against CSF outcomes; producing current-state and target-state profiles; identifying gaps; generating CSF-related governance artefacts; human review of model output; voluntary guidance issued as an initial public draft, with public comments closing on 15 October 2026.
Governance themes
Topics
Record metadata
- Country
- United States
- Region
- Americas
- Governance themes
- AI governance, Risk management, Standards
- Document type
- Guidance
- Status
- Published
- Publication date
- 19 August 2026
- Added to archive
- 25 August 2026
- Archive record last updated
- 25 August 2026
- Language
- English
- Original source
- View original source
Citation export
Plain citation
National Institute of Standards and Technology, NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting (NIST SP 1353), Initial Public Draft, 19 August 2026. Global AI Governance Archive. https://archive.reitaw.com/documents/us-nist-sp-1353-csf-2-0-ai-analysis-reporting-quick-start-guide-ipd-2026.
BibTeX
@misc{us_nist_sp_1353_csf_2_0_ai_analysis_reporting_quick_start_guide_ipd_2026,
title = {United States — NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting (NIST SP 1353, Initial Public Draft)},
author = {National Institute of Standards and Technology (NIST), Department of Commerce},
year = {2026},
howpublished = {Global AI Governance Archive},
url = {https://csrc.nist.gov/pubs/sp/1353/ipd},
note = {Archive record: https://archive.reitaw.com/documents/us-nist-sp-1353-csf-2-0-ai-analysis-reporting-quick-start-guide-ipd-2026},
}See the citation guide for style-specific examples.
Reita's Notes
NIST's draft demonstrates something genuinely useful: AI can reduce some of the administrative burden involved in formal governance. It can organise evidence, compare documentation against a framework, identify gaps and help produce reports and other governance artefacts. But producing the artefacts of governance is not quite the same as governing. An AI system can determine whether a policy contains appropriate language without establishing whether an organisation behaves accordingly. It can organise evidence without knowing whether that evidence accurately represents organisational reality, and it can produce a sophisticated risk register without deciding which risks an organisation should ultimately accept. The concern is therefore not simply that AI might produce poor governance documentation. AI increasingly makes it possible to produce the appearance of mature governance: policies, assessments, registers, reports and organised evidence, without necessarily changing how decisions are made. For organisations with limited governance capacity, AI could genuinely make frameworks such as CSF 2.0 more accessible. The unresolved question is where automation of governance work should stop, and where judgement, accountability and external assurance still need to come from.
Recorded cross-references
- United States — U.S. AI Safety Institute Consortium
Related Entries
- United StatesFramework8 February 2024
United States — U.S. AI Safety Institute Consortium
The U.S. AI Safety Institute Consortium was established by NIST in February 2024 to operationalise work flowing from Executive Order 14110. It convened more than 200 organisations, including AI companies, academic instit…
- United StatesGuidance1 January 2026
United States — FTC Enforcement Actions on Algorithmic Disgorgement
The Federal Trade Commission’s 2026 enforcement focus on algorithmic disgorgement used consumer protection powers to address models trained on illegally obtained, deceptive, or non-consensual data. In such cases, compani…
- CanadaBill / ProposalUndated
Canada — Proposed Amendments to the Artificial Intelligence and Data Act
Canada’s 2024 proposed amendments to the Artificial Intelligence and Data Act refined the pending Bill C-27 framework. The amendments focused on defining classes of high-impact AI systems, including biometric identificat…
- ChileGuidance11 December 2023
Chile — Circular 17 ai tools public sector
Chile’s Circular No. 17 provided public-sector guidance on the use of artificial intelligence tools. The circular framed AI adoption as part of state modernisation and encouraged public bodies to use AI intentionally and…
- CanadaGuidance27 September 2023
Canada — Voluntary Code of Conduct on Advanced Generative AI Systems
Canada’s Voluntary Code of Conduct provided an interim governance framework for organisations developing and managing advanced generative AI systems while the Artificial Intelligence and Data Act proceeded through the le…
This archive is provided for research and informational purposes. It should not be interpreted as legal or regulatory advice.