Article reader Listen + reading controls
Article reader
Preparing the reader…
Reading settings
Generative AI guidance should be built in public¶
The National Institute of Standards and Technology (NIST) has formed a public working group to help develop guidance for generative artificial intelligence. The group will begin by considering how the Artificial Intelligence Risk Management Framework (AI RMF) applies to these systems and will draw input from industry, academia, government, and civil society.
That open process is not a detour on the way to a standard. It is part of how a credible standard is made.
The risks cross professional boundaries¶
Generative artificial intelligence (AI) can produce text, code, images, audio, and other content. Its risks do not belong to one technical discipline. Security specialists see prompt injection and data exposure. Human-factors researchers see automation bias and unclear reliance. Lawyers see intellectual-property and accountability questions. Domain experts see errors that general evaluators miss. Operators see the workarounds that emerge after deployment.
No one group has the complete problem definition.
Public development creates a structured way to combine those partial views. It also exposes vocabulary conflicts early. Terms such as “hallucination,” “grounding,” “red teaming,” and “human oversight” can sound shared while meaning different things across communities.
Consensus should not erase uncertainty¶
Standards work often seeks language broad enough to travel across sectors. The risk is producing statements everyone can accept because they specify little.
Useful guidance should distinguish several layers:
- common outcomes that apply widely;
- context questions every organization should answer;
- controls that fit particular risk patterns;
- test methods with stated limitations; and
- open research questions for which no mature practice exists.
The last category is essential. Declaring a practice “best” before enough operational evidence exists can freeze an early convention into an authority it has not earned.
NIST's AI RMF is strong precisely because it treats risk management as contextual and iterative. A generative-AI profile should preserve that quality rather than become a universal checklist for a rapidly changing capability.
Contribute cases, not only opinions¶
Organizations participating in the working group can improve the conversation by bringing structured experience. A useful case describes:
- the intended use and affected people;
- the model and application boundary;
- the observed failure or concern;
- the control attempted;
- the evidence used to judge that control;
- unintended effects or workarounds; and
- what remains unresolved.
An anonymized near miss may teach more than a polished principle statement. It reveals how risk emerges through interactions among technology, workflow, and incentives.
This is consistent with Argyris and Schön's work on organizational learning: mature learning does not only correct an error within existing rules. It also questions the assumptions and governing values that produced the rule. Public guidance should be able to evolve when implementation reveals that a favored control does not work as expected.
Build a two-way channel inside the organization¶
External participation has little value if it is disconnected from internal delivery. Organizations should appoint representatives who can move in both directions: bring real implementation questions to the group and return emerging practices to product, security, legal, and mission teams.
A small internal forum can review public drafts against live systems, document conflicts, and submit evidence. That turns standards engagement into capability building rather than public affairs.
The artifacts created for participation—a use-case map, failure taxonomy, evaluation protocol, or control crosswalk—can also strengthen the organization's own governance. Even a disagreement with proposed guidance becomes useful if the rationale is preserved.
Openness is a form of infrastructure¶
Generative AI is moving too quickly for every organization to learn alone. A public working group can create shared language, reusable methods, and a record of where confidence is justified. It will work only if participants contribute the difficult parts: failed tests, contested definitions, and cases that do not fit the draft.
Good guidance should be technically informed, operationally grounded, and open to revision. Building it in public is how the field can see not only the answer, but the evidence and disagreement from which the answer emerged.
Sources and research trail¶
- National Institute of Standards and Technology, “New NIST Public Working Group on AI” (June 22, 2023).
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework.
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (2023).
- Argyris and Schön, Organizational Learning: A Theory of Action Perspective (1978).
- Wenger, Communities of Practice: Learning, Meaning, and Identity (1998).