← Blog
ai-agentscompliancegovernance

A 12-Risk Go-Live Worksheet for an AI Agent

NIST AI 600-1 names twelve risks unique to or worsened by generative AI. File one owner-and-evidence block per risk, with residual-risk acceptance, before a tool-calling agent goes into production.

MightyBot ·
Twelve blank frosted navy tiles in two rows of six on a wide tray, one tile glowing amber.

Summary: Before a tool-calling agent goes into production, complete one stacked block for each of the twelve risks NIST AI 600-1 names as unique to or worsened by generative AI. Each block records the risk, a single owner, and an evidence pointer a reviewer can pull. Start from AI governance vocabulary, then fill each stacked block on the sheet before production.

The twelve risks, each with an owner and an evidence pointer

The profile, published 26 July 2024, names twelve risks unique to or exacerbated by generative AI. Fill one stacked block per risk.

Risk: quote or one-line restatement from the profile. Owner: one named role who can accept or escalate residual risk. Evidence: artifact path, date, and residual-risk note a reviewer can pull.

Risk: CBRN Information or Capabilities. Owner: safety or prohibited-use owner. Evidence: refuse-list and red-team prompts for dual-use queries the agent’s tools could assist.

Risk: Dangerous, Violent, or Hateful Content. Owner: content-safety owner. Evidence: policy plus sample blocked outputs.

Risk: Data Privacy. Owner: privacy owner. Evidence: data-flow map for prompts, logs, and retrieval, plus a minimization rule.

Risk: Environmental Impacts. Owner: platform or FinOps owner. Evidence: training or inference cost or energy note for the chosen runtime.

Risk: Harmful Bias or Homogenization. Owner: fairness or evaluation owner. Evidence: subgroup or language slice on the live task set.

Risk: Information Integrity. Owner: communications or content-provenance owner. Evidence: source-link or watermark policy for agent-published text.

Risk: Intellectual Property. Owner: legal or IP owner. Evidence: licensed-corpus note and output-similarity review on the production corpus.

Risk: Obscene, Degrading, and/or Abusive Content. Owner: trust-and-safety owner. Evidence: blocked-output sample and reporter path.

The remaining four risks are worked in the go-live section below.

How GOVERN, MAP, MEASURE, and MANAGE sit under every block

The parent AI RMF 1.0 is voluntary and organizes work into GOVERN, MAP, MEASURE, and MANAGE. GOVERN is a cross-cutting function. 600-1 Section 3 maps suggested actions to those functions.

Keep the four functions as columns of thought inside each stacked block, never as a wide table. GOVERN names who may accept the residual. MAP scopes the agent, its tools, and upstream components. MEASURE points at the test or metric. MANAGE points at the monitor, rollback, or incident file.

Four agent rows that usually stall go-live

Work these four on the live agent: false tool results, review gates, tool permissions, and upstream components.

Risk: Confabulation. Confidently stated but erroneous or false content, including invented tool results or citations. Owner: evaluation lead or product-risk owner. Evidence: pre-production false-statement rate on the live prompt set, an output-validation rule, and a sample of blocked or corrected traces. Bound this cell with execution limits that keep agents from inventing answers.

Risk: Human-AI Configuration. Interactions that can produce anthropomorphizing, algorithmic aversion, automation bias, over-reliance, or emotional entanglement. Owner: operations or control owner who designs the review gates. Evidence: written review points, UI copy that does not present the agent as a person, and an override log showing humans still reject bad outputs. Pair the gates with agent guardrails.

Risk: Information Security. Lowered barriers for offensive cyber capabilities, plus a larger attack surface on tools, prompts, training data, code, or model weights. Owner: security owner for the agent identity and tool permissions. Evidence: tool-permission matrix, prompt-injection and tool-abuse test pack, and access logs for prompts, retrieval stores, and model artifacts.

Risk: Value Chain and Component Integration. Non-transparent or untraceable integration of upstream third-party components, including procured datasets, pre-trained models, plugins, and tool SDKs. Owner: vendor-risk or platform owner. Evidence: inventory of foundation model, version, plugins, datasets, and tool SDKs, plus the supplier-vetting file and a pin or allow-list for each component.

What done looks like before production

The AI RMF can prioritize risk. Organizations define their own readiness to bear residual risk. A block is done when it has a named owner, a dated evidence pointer, and a written residual-risk acceptance inside that tolerance. Empty cells are a no-go.

File the sheet against AI RMF 1.0 and 600-1 as published. The AI RMF 1.0 is being revised. Do not hold production for an unpublished 2.0.

FAQ

Frequently Asked Questions

Is the NIST AI RMF mandatory?

The AI RMF is intended for voluntary use. NIST published 600-1 as a companion profile of that parent framework. Organizations use it to govern, map, measure, and manage generative-AI risks.

Which of the twelve 600-1 risks apply to an agent that can call tools?

All twelve stay on the worksheet. Confabulation, human-AI configuration, information security, and value-chain integration are the four that usually stall a tool-calling agent.

What evidence counts as done on this sheet?

A block is done when it has a named owner, a dated evidence pointer, and a written residual-risk acceptance. Empty cells are a no-go.

Does 600-1 apply if the organization only consumes a vendor agent?

The value-chain risk still belongs on the sheet. 600-1 describes GAI value chains as involving procured datasets, pre-trained models, and software libraries.

How does this NIST sheet relate to the financial-services control cut before you scale a pilot?

This sheet is the cross-sector 600-1 file for an agent go-live. The sector overlay for which controls apply first is in financial-services AI controls before an agent pilot.