Bern, Lisbon, New York info@ai-ei.org +351 93 832 8533
Assessment Platform

NIST Generative AI Profile Assessment

Confabulation, harmful content, data leakage, content provenance and third-party generative AI in your value chain.

NIST Generative AI 30 questions About 15 minutes Free, no account
Step 1 of 2 Organisation context
Organisation context

This shapes the recommendations you get at the end. Nothing here changes your score.

Please enter your organisation name.

Please enter a valid email address.

Please choose an option.

Please choose an option.

Please choose an option.

Please choose an option.

Choose another framework

Self-assessment only. Not legal advice, not an audit opinion, and not certification.

Readiness questions

Answer all 30 questions as honestly as you can. There are no right or wrong answers; an honest picture produces a useful action plan.

01

GenAI Governance and Policy

01 Is there an acceptable-use policy governing generative AI use by employees and in products?

Critical requirement, weight 3

02 Do you maintain an inventory of generative AI systems, models, and use cases (including shadow/unofficial use)?

Critical requirement, weight 3

03 Are approval processes in place before new GenAI use cases go live?

Critical requirement, weight 3

04 Are staff trained on GenAI limitations, risks, and safe usage practices?

Important requirement, weight 2

02

Pre-Deployment Testing and Red-Teaming

05 Are GenAI applications tested against defined criteria before deployment (quality, safety, robustness)?

Critical requirement, weight 3

06 Is structured red-teaming or adversarial testing performed (prompt injection, jailbreaks, misuse scenarios)?

Critical requirement, weight 3

07 Are evaluations repeated after model, prompt, or configuration changes?

Important requirement, weight 2

08 Are safeguards tested for high-risk outputs (dangerous, violent, or CBRN-related content)?

Critical requirement, weight 3

03

Confabulation and Output Quality

09 Are measures in place to reduce and detect confabulated (hallucinated) outputs, e.g., grounding or retrieval?

Critical requirement, weight 3

10 Are factual accuracy and output quality measured for key GenAI use cases?

Important requirement, weight 2

11 Are users clearly warned that GenAI outputs may be inaccurate and require verification?

Important requirement, weight 2

04

Content Provenance and Information Integrity

12 Is AI-generated content labelled or disclosed to users where appropriate?

Critical requirement, weight 3

13 Are provenance techniques (watermarking, metadata, C2PA-style credentials) used or planned for generated content?

Important requirement, weight 2

14 Are controls in place to prevent your GenAI systems being used for disinformation or impersonation?

Important requirement, weight 2

05

Data Privacy and Intellectual Property

15 Are controls in place to prevent sensitive or personal data leaking into prompts, training data, or outputs?

Critical requirement, weight 3

16 Are retention and usage terms of GenAI vendors reviewed (e.g., whether your data is used for training)?

Critical requirement, weight 3

17 Are intellectual property risks of generated content assessed (copyright, licensing of training data and outputs)?

Important requirement, weight 2

18 Is there guidance on what data classes may and may not be used with GenAI tools?

Critical requirement, weight 3

06

Harmful Content and Bias

19 Are content filters or moderation controls in place for obscene, degrading, or abusive outputs?

Critical requirement, weight 3

20 Is harmful bias in GenAI outputs assessed and mitigated for your use cases?

Important requirement, weight 2

21 Are there mechanisms for users to report harmful or incorrect outputs?

Important requirement, weight 2

07

Human-AI Configuration and Oversight

22 Is human review required for consequential decisions or externally published GenAI content?

Critical requirement, weight 3

23 Are roles defined for who may deploy, configure, and operate GenAI systems?

Important requirement, weight 2

24 Are measures in place to prevent over-reliance on GenAI (automation bias) in critical workflows?

Important requirement, weight 2

08

Value Chain and Third Parties

25 Are third-party GenAI models, APIs, and plugins risk-assessed before integration?

Critical requirement, weight 3

26 Are contractual and security requirements defined for GenAI vendors (SLAs, incident notification, data handling)?

Important requirement, weight 2

27 Do you track model/version changes by vendors and re-test when they occur?

Important requirement, weight 2

09

Monitoring, Incidents and Decommissioning

28 Are GenAI systems monitored in production (misuse patterns, drift, degraded output quality)?

Critical requirement, weight 3

29 Is there an incident response process covering GenAI-specific incidents (leakage, harmful output, jailbreak)?

Critical requirement, weight 3

30 Are processes in place to disable, roll back, or decommission GenAI features when risks exceed tolerance?

Important requirement, weight 2

Results are generated instantly. Self-assessment only, not an audit.