← Back to list

The Framework That Cannot Save Itself

Five Failure Modes Inside the NIST Cyber AI Profile and the Operating Model Redesign the Industry Refuses to Have

Jose Spena in Harmonious Pinnacle · 2026-04-25 00:31 · 0 claps · 12.8 min read paywalled
#agentic-ai #cybersecurity #nist-csf #shadow-ai #it-governance
Open on Medium ↗
Wiki topics: AGT · AI Agents 🔒 · Cybersecurity

The Framework That Cannot Save Itself

Five Failure Modes Inside the NIST Cyber AI Profile and the Operating Model Redesign the Industry Refuses to Have

The agenda promised a tidy ninety minutes. The reality was a three-hour descent into the diagnostic silence that follows a failed autopsy. That February morning, the enterprise security team sat before a growing pile of annotated pages. These were the preliminary drafts of NIST IR 8596, known in the trade as the Cyber AI Profile. It was an artifact of ambition, a 2025 attempt to map the sprawling volatility of machine learning onto the rigid geometry of the Cybersecurity Framework. On the whiteboard, shapes were drawn and redrawn, but the connectors between desired outcomes and current reality remained stubbornly absent.

The inventory was a ledger of tactical defeat. Of the forty-seven AI systems identified, only twelve had survived the sanitizing light of formal procurement. The rest, the twenty-four shadow deployments, were ghosts in the machine. They had been connected to sensitive data pipelines with the same casual recklessness one might use to download a weather app for a personal phone. The Cyber AI Profile offers a three-level priority schema, a triage for the digital age, yet it remains a useless map if the territory itself is unobserved. You cannot prioritize the risks of a model you have not yet admitted exists.

Somewhere in the deep architecture of the building, a model trained on customer interactions was generating recommendations without a single audit trail to witness its errors. In a separate silo, a generative tool was summarizing privileged contracts and leaking the remains into a cloud environment that had never seen a security assessment. The Profile names these as risks to be governed. What it lacks the language to describe is the paralysis of the governed. This is the gap between a framework that identifies the rot and an operating model that is too fractured to cut it out. This essay is an examination of that gap. It is the space where the framework ends and the actual work of survival begins.

The Framework That Was Not Enough

NIST possesses a long and distinguished history of translating complex technical challenges into frameworks that the enterprise world can actually inhabit. The Cybersecurity Framework remains arguably the most widely referenced voluntary governance document in the world. It provides a common language and a set of organized functions that security teams use to navigate a landscape of perpetual crisis. Its influence on how organizations think about risk is difficult to overstate.

The Cyber AI Profile, released in preliminary draft form on December 16, 2025, represents the most serious federal effort to extend this architecture into the terrain of artificial intelligence. The project was not a perfunctory exercise. It involved over 6,500 participants and generated more than 1,400 individual responses during its comment period. The authors, led by Katerina Megas and Barbara Cuthill, are serious professionals producing serious work. The technical input phase was equally rigorous. Between the April 2025 workshop and the December release, NIST conducted three dedicated virtual sessions. Each was scoped to a specific Focus Area: Securing AI System Components on August 26, Conducting AI-enabled Cyber Defense on August 19, and Thwarting AI-enabled Cyber Attacks on September 2. These sessions translated conceptual discussions into the specific considerations that now form the backbone of the draft.

None of what follows is an argument against the quality of that work. It is an argument about what the debates surfacing within it reveal. The two central questions currently before the Spring 2026 working sessions, namely, whether to retain the prioritization schema and what to do with the recurring phrase “standard cybersecurity practices apply,” are not merely technical editorial choices. They are symptoms of a deeper problem. These debates reveal a structural assumption embedded in the architecture of the Profile itself. The assumption is that organizations deploying AI already possess the governance maturity and the operating model clarity to apply this guidance in practice. For the vast majority of the organizations the Profile is intended to serve, that assumption is false.

What the Threat Environment Is Already Doing

Before diagnosing the failure cascade within the framework debate, it is worth pausing on what the threat environment has already produced. The stakes of governance failure are not theoretical. IBM’s 2025 Cost of a Data Breach Report, which examined breaches occurring between March 2024 and February 2025, documented that one in six breaches now involves attackers using AI tools. Most commonly, these were AI-generated phishing campaigns, which accounted for 37% of attacker AI usage, and deepfake impersonation attacks, which accounted for 35%. This was the first year the research population documented significant AI involvement in attacks. The finding appears as a measured datum rather than a projection.

The same study produced a finding that should arrest any governance conversation in its tracks. Among organizations that experienced an AI-related security incident, 97% were found to lack proper AI access controls. Among the full study population, 63% had no AI governance policies in place to manage models or to prevent the proliferation of shadow AI. The average enterprise operating without those controls is not merely exposed to a higher risk of breach. According to the data, the presence of high-level shadow AI added an additional $670,000 to the global average breach cost. Conversely, organizations that deployed AI security and automation extensively shortened their breach lifecycle by 80 days and saved an average of $1.9 million per incident. The financial argument for governance is unambiguous. The governance itself is almost entirely absent.

This is the environment into which the Cyber AI Profile has arrived. It is also the environment that makes the framework’s two contested structural questions so consequential. Whether to include a prioritization schema and what language to use when no AI-specific considerations have been identified are not abstract editorial questions. They are, in the context of that 63% governance absence figure, the difference between a framework that helps organizations build something and one that helps them produce the appearance of having built something.

Five Failure Modes Inside the Framework

The Cyber AI Profile’s community working sessions are a genuinely unusual exercise in open governance. NIST is asking for help to resolve questions that the preliminary draft could not. What this openness inadvertently reveals, however, is a set of structural tensions. These compose a five-stage failure cascade that will reproduce itself in organizations that adopt the Profile without attending to the underlying operating model.

Stage One: The Governance Architecture Illusion

Every framework arrives with an implicit promise. It assumes that organizations prepared to adopt it are also prepared to execute it. The Cyber AI Profile inherits the architecture of CSF 2.0, mapping AI-specific considerations onto six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. The assumption is that the organization already knows what it is running. The IBM data suggests otherwise. An organization that has not inventoried its assets cannot meaningfully apply a priority schema. This is not a failure of the framework; it is a failure of the operating model that the framework cannot see.

Stage Two: The Prioritization Trap

The feedback documented in NIST’s Spring 2026 discussion reveals a fundamental struggle. Participants found the three-level priority schema unclear and inconsistently applied. The community has proposed four paths: refine the schema, add a fourth level for prerequisites, replace it with an indicator of AI difference, or eliminate it altogether. NIST currently prefers the fourth. This debate is a reflection of a deeper truth. Prioritization is an organizational capability before it is a framework feature. Organizations without AI maturity lack the internal knowledge to map their situation onto any schema.

Stage Three: The Language Escape Hatch

The working sessions are also debating the phrase “standard cybersecurity practices apply.” The community flags this as ambiguous. It inadvertently suggests that no additional attention is needed. NIST’s preferred replacement, “No AI-specific cybersecurity program considerations were identified,” is cleaner but does not solve the structural problem. This phrase remains an invitation to stop looking. For a resource-constrained organization, it is a path of least resistance. It provides permission to apply legacy practices to a new category of asset and move on.

Stage Four: The Agentic Blind Spot

No feedback theme was more consistent in the March 23, 2026 workshop summary than the concern about agentic AI. Participants flagged that the preliminary draft lacked guidance for systems where AI agents orchestrate other tools. This is the multiplicative problem. As Paddy Harrington of Forrester predicted, agentic AI will likely cause a public breach in 2026 because security leaders have not rethought governance for autonomous entities. The Profile can name the problem, but it cannot provide the real-time governance that agents require.

Stage Five: The Security Debt Cascade

When the first four stages run their course, the consequences accumulate. Shadow AI deployments continue operating in the dark. Prioritization decisions produce documentation that does not reflect actual exposure. The escape-hatch language provides cover for unexamined risks. By the time this security debt materializes as an incident, the question of which priority schema was chosen is no longer meaningful. The cascade has run its sequence. The framework did what frameworks do. The organization did what organizations without adequate operating models do. And the gap between the two produced the outcome both were intended to prevent.

The Cost That Does Not Appear in the Subcategory Table

There is a human dimension to this cascade. When a security team spends three hours mapping a framework to an ungoverned AI estate, they are paying for organizational choices made upstream. These are the procurement decisions that bypassed review and the leadership that celebrated adoption without funding governance. Security practitioners are already overextended. The expectation that they absorb new framework requirements without new resources creates a new form of organizational debt. Naming this is not a digression. The operating model redesign must include a realistic account of human capacity.

What Actually Works: Operating Model Before Framework Application

The argument that frameworks fail without operating model foundations is not an argument against frameworks. It is an argument for sequencing. The organizations that will extract genuine value from the Cyber AI Profile are not those that begin by downloading the document and mapping their subcategories. They are those that complete a prior set of organizational investments that make the framework applicable.

The first of these investments is an AI system inventory conducted with the same rigor that mature organizations apply to software asset management. This means not only cataloging approved AI deployments but actively identifying shadow AI through network analysis, procurement review, and employee disclosure programs. An organization that does not know what AI it is running cannot prioritize its governance of that AI, regardless of which schema a framework provides. The IBM data makes this concrete. The organizations that detected breaches internally rather than through attacker disclosure or third-party discovery saved an average of $900,000 per incident. Internal detection requires internal visibility. Internal visibility begins with inventory.

The second investment is the separation of AI adoption governance from AI cybersecurity governance, without allowing them to operate independently. Most organizations approaching the Cyber AI Profile for the first time are attempting to solve both problems simultaneously. They are using a cybersecurity framework as a substitute for the AI governance infrastructure they have not yet built. This produces the governance architecture illusion. The organizations that avoid this trap treat AI adoption governance as a prerequisite for meaningful cybersecurity framework application. Adoption governance addresses which AI tools are permitted, for what purposes, and under what oversight conditions. You cannot secure a system whose scope and purpose your organization has not yet defined.

The third investment is the development of internal risk characterization capability. This is the organizational capacity to assess the specific risk context that determines which cybersecurity outcomes are most urgent for each AI deployment. This is the capability that makes any prioritization schema useful. Without it, the schema is an external imposition that cannot connect to internal reality. With it, even a framework that removes its prioritization schema entirely, as NIST is currently considering, can be applied with genuine rigor. The organization brings its own prioritization logic to the exercise.

For the agentic AI challenge in particular, the organizations closest to managing it effectively are those that have treated AI agents as first-class identities in their identity and access management programs. They apply the same rigor as they would to human users. This means assigning agents explicit permissions, audit trails, and behavioral constraints rather than treating them as background services exempt from access governance. It means defining conditions under which agent autonomy can be reduced or suspended during incident response. This is a specific guidance point that the Cyber AI Profile’s Defend Focus Area does include. It means testing those conditions before an incident rather than discovering during one that the controls do not function as designed.

A Different Question for Different Roles

For the CISO

The Cyber AI Profile gives you a vocabulary and a structure. What it cannot give you is the AI system inventory, the shadow AI visibility, or the organizational authority to enforce governance across business units that adopted AI before you had a framework to offer them. Before you build a compliance map against the Profile’s subcategories, audit what your organization actually knows about its AI estate. The gap between that knowledge and what the framework assumes is the risk your team will actually carry. The Profile’s eventual guidance on agentic AI will not substitute for an access governance program that treats AI agents as identities. Begin building that program now, before the next draft appears.

For the AI Program Manager

You are closest to the deployment decisions that create the governance conditions the CISO must then manage. Every AI tool adopted without a security review, every business unit that connected a generative AI application to sensitive data without coordinating with the security office, every pilot that became a production system before its risk profile was assessed, represents a contribution to the security debt that the Cyber AI Profile is designed to address. The most useful thing you can do with the Profile at this stage is use its three Focus Areas, Secure, Defend, and Thwart, as a structured conversation framework with your security counterparts. Do not use them to assign compliance levels. Use them to identify which of your current AI deployments have never been reviewed through any of the three lenses. Start there.

For the Board and C-Suite

The IBM 2025 data offers a number that belongs in board-level risk conversations. Among organizations that experienced AI-related security incidents, 97% lacked proper AI access controls. Among the full study population, 63% had no AI governance policies in place. Your organization may be among the minority with governance policies in place. If it is, the question worth asking is whether those policies have been tested against the shadow AI exposure that your security team may not have been asked to investigate. The $670,000 breach cost premium associated with shadow AI is not a technology cost. It is a governance cost. It is one your organization can choose to pay proactively or reactively.

For the Policy and Standards Professional

The NIST Cyber AI Profile working sessions represent exactly the kind of deliberate, community-informed standards development that produces durable guidance. Three dedicated technical sessions in the summer of 2025, each exploring a single Focus Area in depth with practitioners, followed by a public comment period that drew more than 1,400 responses, followed by a January 2026 workshop on the resulting draft: this is a consultation sequence that the field should recognize as genuinely serious. The two questions on the table for Working Session One are both resolvable at the framework level. What this essay argues is that resolving them well, while necessary, will not be sufficient to prevent the five-stage failure cascade in the organizations that most need the guidance. The more important question, which the working sessions could usefully surface even if it cannot be answered within a standards document, is what organizational prerequisites must exist before the Profile’s guidance becomes actionable. Making that question explicit in the Profile’s framing, even without prescribing the answer, would represent a significant contribution to the field.

Conclusion: The Map and the Territory

Silicon Valley has a saying that has traveled well beyond its origin: the map is not the territory. Applied to cybersecurity governance, its implications are more consequential than its casual use in strategy discussions acknowledges. A framework is a map. It describes a territory, organizes its features into recognizable categories, and provides a language for navigation. What it cannot do is alter the terrain. It cannot build the roads that do not yet exist, staff the checkpoints that have never been established, or clear the paths that organizational inertia has blocked.

The NIST Cyber AI Profile is among the most carefully constructed maps the cybersecurity field has produced for the AI terrain. Three dedicated Focus Area working sessions with technical practitioners, a community of more than 6,500 participants, more than 1,400 written comments, and a full workshop on the resulting draft: this process reflects a seriousness about standards development that the field needs and too rarely receives.

But the five-stage failure cascade described in this essay does not begin with the wrong priority schema. It begins with organizations that deploy AI without inventorying it, govern AI without structures that are built for it, and apply frameworks to problems they have not yet defined with enough precision to solve. The cascade proceeds through prioritization traps, language escape hatches, agentic blind spots, and compounding security debt. It ends with breach costs that the IBM data has now quantified with uncomfortable precision: $670,000 in additional exposure per incident for organizations with high shadow AI, and 97% of AI-related breach victims found to have lacked the access controls they should have had.

The framework debates taking place in NIST’s working sessions are the right debates for a standards body to have. What the industry refuses to have, and what this essay argues must be added to the conversation, is the operating model debate. This is the discussion of what organizational redesign must precede framework application for the framework to produce anything other than a compliance artifact. True AI cybersecurity governance is not a document adoption. It is an operating model transformation that begins with knowing what AI you have, continues through building the structures to govern it, and arrives at framework application only after those foundations are in place.

The team in that February conference room will meet again. The Cyber AI Profile will be refined. A new draft will appear, better than the preliminary draft in the ways that the community has asked it to be. The thirty-six AI deployments that were never reviewed will still be running. The question of whether the next working session will surface that problem is, at this moment, unanswered. The question of whether it must is not.

Note on analytical framework: The five-stage failure cascade described in this essay is original analytical work by Jose Spena. It does not derive from any cited study and should not be attributed to NIST or any other source organization.

This article reflects conditions as of April 2026. The NIST Cyber AI Profile remains in active development. Readers are encouraged to engage directly with the Spring 2026 Community of Interest working sessions and to provide feedback at cyberaiprofile@nist.gov.

AI #Cybersecurity #NIST #CyberAIProfile #AIGovernance #CyberRisk #EnterpriseAI #CSF #AIRisk #SecurityLeadership #AgenticAI #ShadowAI #ITLeadership


메타데이터
post_id
eb8ea24e4102
slug
the-framework-that-cannot-save-itself-eb8ea24e4102
url
https://medium.com/harmonious-pinnacle/the-framework-that-cannot-save-itself-eb8ea24e4102
canonical_url
https://medium.com/harmonious-pinnacle/the-framework-that-cannot-save-itself-eb8ea24e4102
author_url
https://medium.com/@josespena
status
ok
fetched_at
2026-06-14 11:28:49