It describes a set of capabilities and uses, not an assurance level, autonomous defender, or replacement for security engineering and human accountability.
AI can help defenders process large or complex datasets, but the same technology can assist attackers or introduce new vulnerable components. NIST’s Initial Preliminary Draft Cyber AI Profile separates securing AI system components, conducting AI-enabled cyber defense, and thwarting AI-enabled cyberattacks; as of August 2026, it is not final guidance.
Key points
Define the decisionSpecify the user, task, inputs, permitted outputs, confidence needs, response time, and whether AI advises, proposes, or is authorized to act.
Evaluate in contextTest representative and adversarial cases, rare but costly failures, data drift, evasion, bias, latency, provenance, and comparisons with simpler rules or expert baselines.
Constrain operationsApply least privilege, human approval for consequential actions, protected logs, output validation, fallback procedures, monitoring, and rapid disablement or rollback.
Important limitationAI output is probabilistic and can be wrong, manipulated, stale, or unsupported. High alert-reduction or benchmark accuracy does not establish that attacks will be found, root causes are correct, or automated actions are safe.