AI risk
Capability, governance, and accident pathways. Items, when present, carry a label: official data, interpretation, or hypothesis. This is not a forecast of a specific date.
Snapshot
- Item
- NIST Artificial Intelligence Risk Management Framework
- Date
- Concept note Apr 7, 2026; AI RMF 1.0 issued Jan 26, 2023
- What
- NIST AI RMF 1.0 is voluntary. NIST states it is being revised as part of the White House AI Action Plan. On Apr 7, 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure.
- Source
- NIST AI Risk Management Framework
Watching official feeds: NIST AI RMF page, NIST AI Resource Center, White House AI Action Plan. No model-benchmark or accident count is frozen here.
Notes
official data
CISA OT drop: Ignition CVSS 8.8 plus Rockwell ENBT DoS — Sep 3 ICS batch
Washington, District of Columbia, USA
CISA published multiple ICS advisories dated 3 Sep 2026, including ICSA-26-246-06 (Inductive Automation Ignition ≤8.1.53, CVE-2026-77393 Incorrect Default Permissions, CVSS v3 8.8 HIGH) and ICSA-26-246-05 (Rockwell 1756-ENBT all versions, CVE-2025-10478 crafted CIP DoS, CVSS v3 7.5). No known public exploitation specifically targeting these vulnerabilities reported to CISA at this time. Distinct from Sep 2 KEV and OT playbook notes.
official data
CISA KEV: seven actively exploited CVEs include LiteLLM AI gateway and SonicWall SMA1000
Washington, District of Columbia, USA
CISA alert 2 Sep 2026 added seven Known Exploited Vulnerabilities based on evidence of active exploitation, including CVE-2026-59822 BerriAI LiteLLM Improper Authentication and SonicWall SMA1000 CVE-2026-83548 (SSRF) / CVE-2026-83549 (OS command injection). BOD 26-04 risk-based remediation and pre-patch compromise checks apply for FCEB.
official data
CISA and FBI: OT/IT outage playbook for communicating under pressure
Washington, District of Columbia, USA
CISA publication dated September 2, 2026 — Communicating Under Pressure: Best Practices for Service Providers — developed with the FBI and international partners. Guidance for clear, timely, accurate, audience-appropriate communications during IT and OT outages from cyber actors, human error, equipment failure, or natural hazards; ties to CI Fortify backup-comms assumptions.
official data
NIST AI ‘zero draft’ docs open — comment window runs to Sep 16
Gaithersburg, Maryland, United States
NIST AI Standards page: on July 29, 2026 NIST released an initial public draft of Guidance and Templates for Public-Facing AI Documentation: An AI Standards ‘Zero Draft.’ NIST will consider input received by September 16, 2026. Distinct from the April AI RMF note.
official data
CISA adds PaperCut NG/MF flaws to KEV — federal fix by Sep 14
United States
CISA alert Aug 31, 2026 adds CVE-2026-81578 and CVE-2026-82078 (PaperCut NG/MF) to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. KEV due date 2026-09-14 under BOD 26-04 for FCEB agencies.
official data
House bill would task NIST’s CAISI with tracking self-improving AI
U.S. Capitol, Washington, D.C.
Reps. George Whitesides (D-CA) and Pat Harrigan (R-NC) introduced the Self-Improving AI Monitoring Act on 29 Aug 2026. House office release: NIST’s CAISI would monitor systems that autonomously research and develop subsequent AI models. Introduced, not enacted.
official data
CISA warns of active AI-assisted attacks on Siemens industrial controllers
CISA, Arlington, Virginia
CISA Cybersecurity Advisory AA26-231A, 19 Aug 2026, co-sealed NSA, FBI, DOE, and EPA: active threat to Siemens S7-series PLCs using AI-generated exploitation scripts disguised as monitoring tools. No victim counts on the page.
official data
NIST overhauls AI RMF 1.0 for critical infrastructure — still voluntary, still not an accident clock
NIST, Gaithersburg, Maryland
NIST’s AI RMF 1.0 remains the voluntary Artificial Intelligence Risk Management Framework. NIST says it is being revised as part of the White House AI Action Plan. On 7 April 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure.