AI now affects cybersecurity in three directions at once. Organisations need to secure the AI they deploy, use AI responsibly in defence and prepare for attackers using the same technology.
NIST's preliminary Cybersecurity Framework Profile for Artificial Intelligence organises this challenge into three focus areas: Secure, Defend and Thwart. It applies the familiar Cybersecurity Framework 2.0 structure to AI-related risks and opportunities. The profile was released as a preliminary draft in December 2025, so organisations should treat it as current direction rather than a final compliance standard.
Secure the AI system and its surrounding components
An AI application includes more than a model. It may include prompts, retrieval data, vector stores, APIs, tools, identities, orchestration code and human review. Inventory these components, classify their data and define who can change them. Monitor dependencies and third-party models because a change outside your organisation can alter risk inside it.
Use AI in cyber defence with accountable oversight
AI can support alert correlation, malware analysis, threat intelligence enrichment and investigation. Set boundaries around the decisions it can make. Analysts should be able to inspect the evidence behind a recommendation, override it and recognise when model behaviour has changed. Measure whether the capability improves accuracy and response, not simply whether it produces output faster.
Prepare for AI-enabled attacks
Attackers can use AI to scale social engineering, reconnaissance and content generation. The response is stronger identity verification, resilient business processes and controls that do not depend on a message looking authentic. Rehearse scenarios involving convincing impersonation, automated probing and manipulation of AI-enabled workflows.
Connect the three views through governance
A single steering group should understand where AI is deployed, where it supports security operations and how it changes the threat model. Use a shared risk register and clear control owners. This avoids separate programmes that leave gaps between AI governance and cybersecurity.
Ask three questions: Are our AI systems secure? Are we using AI safely to improve defence? Are our people and processes resilient to attackers using AI?