Summary: Before a tool-calling agent goes into production, complete one stacked block for each of the twelve risks NIST AI 600-1 names as unique to or worsened by generative AI. Each block records the risk, a single owner, and an evidence pointer a reviewer can pull. Start from AI governance vocabulary, then fill each stacked block on the sheet before production.
The twelve risks, each with an owner and an evidence pointer
The profile, published 26 July 2024, names twelve risks unique to or exacerbated by generative AI. Fill one stacked block per risk.
Risk: quote or one-line restatement from the profile. Owner: one named role who can accept or escalate residual risk. Evidence: artifact path, date, and residual-risk note a reviewer can pull.
Risk: CBRN Information or Capabilities. Owner: safety or prohibited-use owner. Evidence: refuse-list and red-team prompts for dual-use queries the agent’s tools could assist.
Risk: Dangerous, Violent, or Hateful Content. Owner: content-safety owner. Evidence: policy plus sample blocked outputs.
Risk: Data Privacy. Owner: privacy owner. Evidence: data-flow map for prompts, logs, and retrieval, plus a minimization rule.
Risk: Environmental Impacts. Owner: platform or FinOps owner. Evidence: training or inference cost or energy note for the chosen runtime.
Risk: Harmful Bias or Homogenization. Owner: fairness or evaluation owner. Evidence: subgroup or language slice on the live task set.
Risk: Information Integrity. Owner: communications or content-provenance owner. Evidence: source-link or watermark policy for agent-published text.
Risk: Intellectual Property. Owner: legal or IP owner. Evidence: licensed-corpus note and output-similarity review on the production corpus.
Risk: Obscene, Degrading, and/or Abusive Content. Owner: trust-and-safety owner. Evidence: blocked-output sample and reporter path.
The remaining four risks are worked in the go-live section below.
How GOVERN, MAP, MEASURE, and MANAGE sit under every block
The parent AI RMF 1.0 is voluntary and organizes work into GOVERN, MAP, MEASURE, and MANAGE. GOVERN is a cross-cutting function. 600-1 Section 3 maps suggested actions to those functions.
Keep the four functions as columns of thought inside each stacked block, never as a wide table. GOVERN names who may accept the residual. MAP scopes the agent, its tools, and upstream components. MEASURE points at the test or metric. MANAGE points at the monitor, rollback, or incident file.
Four agent rows that usually stall go-live
Work these four on the live agent: false tool results, review gates, tool permissions, and upstream components.
Risk: Confabulation. Confidently stated but erroneous or false content, including invented tool results or citations. Owner: evaluation lead or product-risk owner. Evidence: pre-production false-statement rate on the live prompt set, an output-validation rule, and a sample of blocked or corrected traces. Bound this cell with execution limits that keep agents from inventing answers.
Risk: Human-AI Configuration. Interactions that can produce anthropomorphizing, algorithmic aversion, automation bias, over-reliance, or emotional entanglement. Owner: operations or control owner who designs the review gates. Evidence: written review points, UI copy that does not present the agent as a person, and an override log showing humans still reject bad outputs. Pair the gates with agent guardrails.
Risk: Information Security. Lowered barriers for offensive cyber capabilities, plus a larger attack surface on tools, prompts, training data, code, or model weights. Owner: security owner for the agent identity and tool permissions. Evidence: tool-permission matrix, prompt-injection and tool-abuse test pack, and access logs for prompts, retrieval stores, and model artifacts.
Risk: Value Chain and Component Integration. Non-transparent or untraceable integration of upstream third-party components, including procured datasets, pre-trained models, plugins, and tool SDKs. Owner: vendor-risk or platform owner. Evidence: inventory of foundation model, version, plugins, datasets, and tool SDKs, plus the supplier-vetting file and a pin or allow-list for each component.
What done looks like before production
The AI RMF can prioritize risk. Organizations define their own readiness to bear residual risk. A block is done when it has a named owner, a dated evidence pointer, and a written residual-risk acceptance inside that tolerance. Empty cells are a no-go.
File the sheet against AI RMF 1.0 and 600-1 as published. The AI RMF 1.0 is being revised. Do not hold production for an unpublished 2.0.