Standard / soft law
GenAI in consequential decisions should have confabulation/output-validation controls (NIST GenAI Profile)
Per NIST AI 600-1 §2.2 (Confabulation) and suggested actions MS-2.5-003 / MS-2.6-005, GenAI integrated into consequential decision-making should review and verify sources and citations in outputs, and have architecture that monitors outputs and can recover from errors — because confidently-stated false content ('hallucinations') can mislead users in high-stakes contexts. Detect a GenAI consequential-decision path (healthcare, legal, financial) with no output-validation, source-verification, or confabulation-monitoring control.
nist-genai-profile.confabulation-controls · NIST AI 600-1 §2.2 (Confabulation) + MS-2.5-003 / MS-2.6-005 · official source · jurisdictions: *
Standard / soft law
GenAI systems should employ content-provenance methods and measure their effectiveness (NIST GenAI Profile)
Per NIST AI 600-1 §2.8 (Information Integrity) and actions GV-4.3-001 / MS-1.1-001 / MS-2.7-005, GAI systems should employ content-provenance methodologies (cryptography, watermarking, digital signatures), trace the origin and modifications of digital content, and measure the reliability of these authentication methods. Detect a synthetic-content generation path with no provenance/watermarking mechanism. Converges with the binding synthetic-content-marking laws (CA SB942/AB853, EU Art.50, China, CT).
nist-genai-profile.content-provenance · NIST AI 600-1 §2.8 (Information Integrity) + GV-4.3-001 / MS-1.1-001 / MS-2.7-005 · official source · jurisdictions: *
Standard / soft law
GenAI outputs should be screened for PII/sensitive-data leakage (NIST GenAI Profile)
Per NIST AI 600-1 §2.4 (Data Privacy) and action MP-4.1-009, GAI systems should leverage approaches to detect the presence of PII or sensitive data in generated output (text, image, video, audio), because models can leak memorized training data or infer sensitive information. Detect a GAI output path with no PII/sensitive-data leakage screening.
nist-genai-profile.output-pii-leakage-detection · NIST AI 600-1 §2.4 (Data Privacy) + MP-4.1-009 · official source · jurisdictions: *
Standard / soft law
GenAI systems should inventory and vet third-party components (NIST GenAI Profile)
Per NIST AI 600-1 §2.12 (Value Chain and Component Integration) and actions GV-6.1-007 / MG-3.1-005, GAI systems should inventory all third-party entities/components (pre-trained models, procured datasets, libraries) and review their transparency artifacts (system cards, model cards) — because opaque third-party integration diminishes transparency and accountability for downstream users. Detect a GAI system integrating third-party models/datasets with no component inventory or model-card review.
nist-genai-profile.value-chain-provenance · NIST AI 600-1 §2.12 (Value Chain and Component Integration) + GV-6.1-007 / MG-3.1-005 · official source · jurisdictions: *