The National Institute of Standards and Technology (NIST) has unveiled a concept paper outlining a potential new framework—referred to as “Securing AI“—aimed at enhancing cybersecurity measures throughout the AI lifecycle. The August 2025 paper proposes the use of “NIST Overlays” to integrate tailored AI-specific protections into existing cybersecurity and privacy frameworks.
NIST Overlays are an established mechanism within the NIST Risk Management Framework, traditionally used to apply specialized security requirements in high-risk contexts like healthcare and government systems. The new concept reimagines Overlays for AI, focusing on areas such as model robustness, secure data pipelines, threat modeling, model release protocols, and protections against emerging risks like training data poisoning or model exfiltration.
The proposed framework would apply to a broad spectrum of stakeholders—including developers, deployers, evaluators, and acquirers of AI systems—encouraging shared responsibility across the AI lifecycle. While voluntary, the guidance is designed to be widely adaptable across sectors and levels of AI maturity.
Key areas identified for future overlay development include high-risk use cases such as biometric recognition, edge AI, and AI integrated into industrial control systems. Each would receive overlays with customized threat models and safeguards, helping organizations make risk-informed decisions when building or deploying AI.
The “Securing AI” initiative builds on earlier NIST efforts, including the AI Risk Management Framework (AI RMF 1.0), and is part of a broader federal push to ensure trustworthy and secure AI adoption. NIST is currently seeking public feedback on the concept paper, which will inform the development of a full Securing AI framework. The agency expects to hold workshops later this year.
Need Help?
If you’re concerned or have questions about how to navigate the global AI regulatory landscape, don’t hesitate to reach out to BABL AI. Their Audit Experts can offer valuable insight and ensure you’re informed and compliant.