The Challenge
NIST faces a problem familiar to every CISO dealing with AI adoption: how to create practical security guidance for rapidly evolving technology. On April 3, 2025, at the National Cybersecurity Center of Excellence, NIST held a workshop to address this issue. Feedback highlighted a gap you might recognize: organizations need specific guidance that doesn't require overhauling their entire security program with each new AI deployment.
The NIST Cybersecurity Framework and AI Risk Management Framework offer strategic direction, but translating them into actionable controls for specific AI implementations has left security teams improvising. Your organization is likely deploying AI across various functions, each with unique risk profiles that existing controls weren't designed to handle.
The Environment and Constraints
NIST operates under constraints similar to those in your organization:
Don't reinvent the wheel. Both federal and private sector stakeholders emphasized this. Organizations have invested heavily in NIST SP 800-53 controls. Adopting a separate framework for AI systems would create unnecessary overhead and confusion.
Serve different audiences. Not all organizations develop AI systems. Many are consumers of AI services or integrate third-party AI capabilities. A universal control catalog would impose developer-specific requirements on AI users who can't implement them.
Address actual AI-specific risks. Early AI security efforts often treated AI systems as generic software, applying standard controls without modification. While many controls apply, some risks need unique considerations. The challenge is identifying which controls require AI-specific tailoring.
NIST's portfolio includes SP 800-53, SP 800-218A on secure software development for generative AI, and the AI-100-2e2025 taxonomy of adversarial machine learning attacks. The task is to connect these into actionable guidance.
The Approach Taken
NIST's solution involves use-case-focused, threat-informed control overlays built on SP 800-53. This approach is replicable in your environment.
Control overlays are tailored SP 800-53 controls for specific requirements or technologies. The focus here is on modularity and specificity.
The strategy includes:
Use case specificity. NIST plans multiple overlays for different AI system types, components, and user roles. Controls for an AI model development pipeline differ from those for AI service consumption.
Threat-informed tailoring. Overlays will use the adversarial machine learning taxonomy to address actual attack patterns. Generic "secure the model" guidance isn't helpful when facing prompt injection or data poisoning attacks.
Focus on delta controls. Overlays will emphasize controls needing unique AI implementation, not standard software security controls. This helps security teams focus on where AI systems need different treatment.
NIST will establish a Community of Interest for AI Control Overlays to maintain engagement and incorporate feedback as technologies evolve.
Results and Implications
Though still in development, the control overlays offer immediate value. They show how to integrate AI security into existing governance without creating parallel structures.
For your organization, start mapping AI use cases to control requirements now, before NIST publishes formal overlays. The SP 800-53 catalog already contains applicable controls. You need a systematic way to identify which require AI-specific guidance.
In practice, your standard access control requirements (AC family in SP 800-53) apply to AI systems, but implementing least privilege for a large language model API needs different controls than traditional application access. The principle remains; the implementation changes. That's what the overlay approach addresses.
The modular structure also solves governance issues. Deploy an AI-powered tool, and apply the relevant overlay without imposing unnecessary controls on your AI development team. Later, add a developer-focused overlay for custom models. The overlays stack rather than conflict.
What They Would Do Differently
NIST's workshop revealed that early AI security efforts tried to create comprehensive frameworks before understanding implementation patterns. The shift to use-case-specific overlays reflects a lesson learned: detailed controls require knowledge of how AI systems are deployed and operated in production.
If starting fresh, NIST might begin with the overlay approach rather than high-level frameworks. However, those frameworks provide necessary context. The real lesson is about sequencing: establish principles, then move quickly to implementation guidance informed by real-world usage.
Takeaways for Your Team
Map your AI use cases now. Don't wait for NIST overlays. Inventory your AI systems: Are you developing models? Consuming AI services? Embedding AI in products? Each category needs different control emphasis.
Identify your delta controls. Review your existing SP 800-53 implementation. For each AI system, document which controls need AI-specific guidance versus which apply as-is. This becomes your internal overlay.
Engage with NIST's Community of Interest. Participate when it launches. Organizations shaping these overlays will have guidance reflecting their constraints. Waiting for final publication may result in generic guidance that doesn't fit your environment.
Don't rebuild from scratch. The biggest risk in AI security isn't missing a control; it's creating a separate AI security program that doesn't integrate with your existing governance. Use your current framework as the foundation and layer AI-specific requirements on top.
Focus on threat-informed controls. Generic "secure the AI" requirements don't help. Use resources like NIST's adversarial ML taxonomy to ensure your controls address specific attack patterns: prompt injection, model inversion, data poisoning, adversarial examples. Controls that don't map to actual threats are overhead.
The control overlay approach won't solve every AI security challenge, but it offers a practical path forward that builds on your existing investments. That's more valuable than another framework to implement.



