The supplied sources do not contain NIST AI 600-1 or January 2024 guidance on generative AI. The sources reference NIST's Cybersecurity Framework 2.0, Privacy Framework, and FTC privacy and security guidance, but provide no content about NIST artificial intelligence risk management requirements, the AI Risk Management Framework (AI RMF), or specific obligations for organizations deploying generative AI systems.

This article cannot be completed as specified because the foundational requirement—explaining what NIST AI 600-1 mandates—depends entirely on source material that was not provided. Any attempt to describe risk identification protocols, testing requirements, transparency obligations, documentation standards or governance structures for generative AI would require inventing content, which violates the absolute rules governing this output.

What Can Be Established From Available Sources

The sources confirm that NIST maintains frameworks for cybersecurity risk management and privacy risk management. The Cybersecurity Framework 2.0 helps organizations understand and improve management of cybersecurity risk. The Privacy Framework serves as a voluntary tool to help organizations identify and manage privacy risk while building products and services.

The FTC enforces privacy and security obligations under Section 5 of the FTC Act, requiring companies to honor express and implied privacy promises and maintain security appropriate to the data they possess. The Health Breach Notification Rule may apply following data breaches involving health-related information.

Why Executive Ownership Matters for Emerging Technology Governance

Even without specific AI guidance in the supplied sources, a consistent pattern emerges: frameworks establish what must be done, but they do not create the executive ownership needed to ensure it happens. Organizations face accountability for risk management outcomes—whether cybersecurity, privacy or emerging technology—without necessarily having clear internal ownership, measurement systems or decision authority.

This gap is particularly acute with emerging technologies where regulatory expectations are developing faster than internal governance structures. Leadership becomes accountable for managing risks they may not yet fully understand, using processes that may not yet exist, measured against standards that continue to evolve.

What Adequate Governance Requires

Adequate governance of any risk domain requires a named executive accountable for strategy, a documented approach to identifying and measuring risk, clear authority to make risk decisions, and regular reporting to leadership and the board. For emerging technology risk, this typically means:

  • Executive ownership that understands both the technology and the regulatory environment
  • Risk identification processes that can be applied before incidents occur
  • Documentation practices that survive audit and examination
  • Testing protocols that validate controls rather than assume them
  • Transparency mechanisms that explain systems to stakeholders and regulators
  • Governance structures that connect technical decisions to business risk

These requirements apply regardless of the specific framework. The challenge is that most organizations lack the internal expertise to own this function effectively, particularly when the technology and regulatory landscape are both moving rapidly.

How Virtual CISO Leadership Addresses the Ownership Gap

A [virtual CISO (vCISO)](/vciso/) provides the executive-level ownership that closes the gap between framework requirements and operational reality. This is not a technical implementation role. It is strategic leadership: translating regulatory expectations into business decisions, establishing governance structures, making risk calls, and reporting to the executive team and board.

For emerging technology governance specifically, vCISO leadership provides a designated decision-maker who understands how new capabilities create new risks, can evaluate controls before deployment rather than after incidents, and maintains the regulatory perspective needed to position the organization defensibly.

Next Steps for Leadership

If your organization is deploying or evaluating generative AI systems, start by answering these questions:

  • Who is accountable to the CEO and board for AI-related risk decisions?
  • What process exists to identify risks before systems are customer-facing or decision-making?
  • How would we document our risk management approach if examined by regulators?
  • What testing have we completed to validate that our controls work as designed?
  • Can we explain our systems' behavior and limitations to stakeholders transparently?
  • How do we measure progress on risk management rather than just deployment milestones?

If these questions lack clear answers, the organization has an ownership gap. The technology may be progressing while the governance structure remains undefined.

Heights Consulting Group provides confidential consultations for executives and boards establishing governance for emerging technology risk. The consultation clarifies whether your organization has adequate ownership in place or needs executive leadership to close the gap. Contact Heights directly to schedule a confidential discussion of your organization's situation.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: AI and Emerging Technology Governance

Governance for how your organization adopts artificial intelligence: approved uses, data handling boundaries, review before deployment, and accountability for the output.

Read about AI and Emerging Technology Governance