Editor’s Note: NIST published a nine-page draft this month showing how a generative AI model can turn policy documents and personnel interview notes into a draft profile of an organization’s cybersecurity posture.

Nowhere in those nine pages does the word authentication appear.

The National Institute of Standards and Technology released the initial public draft of Special Publication 1353, “NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting,” on Aug. 19. Comments are open through Oct. 15 at 11:59 p.m. and go to csf@nist.gov. NIST states no time zone. The guide is the 10th in a series the CSF 2.0 project team has been issuing since Feb. 26, 2024, and the only one of the 10 devoted entirely to using AI. The use case examples “illustrate a possible approach and are not prescriptive assessment or assurance methodologies,” NIST said. That is as far as the draft goes on its own standing: the words legal, binding and obligation appear nowhere in it.

That status matters, because this document is built to be run rather than read. Appendix A supplies a step-by-step workflow, from opening the AI tool to generating output for review.


Content Assessment: NIST wants comment on AI-drafted CSF profiles, and its guide never says authentication

Information - 93%
Insight - 93%
Relevance - 92%
Objectivity - 93%
Authority - 91%

92%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "NIST wants comment on AI-drafted CSF profiles, and its guide never says authentication."


News Analysis – Cybersecurity Beat

NIST wants comment on AI-drafted CSF profiles, and its guide never says authentication

ComplexDiscovery Staff

NIST published a nine-page draft this month showing how a generative AI model can turn policy documents and personnel interview notes into a draft profile of an organization’s cybersecurity posture.

Nowhere in those nine pages does the word authentication appear.

The National Institute of Standards and Technology released the initial public draft of Special Publication 1353, “NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting,” on Aug. 19. Comments are open through Oct. 15 at 11:59 p.m. and go to csf@nist.gov. NIST states no time zone. The guide is the 10th in a series the CSF 2.0 project team has been issuing since Feb. 26, 2024, and the only one of the 10 devoted entirely to using AI. The use case examples “illustrate a possible approach and are not prescriptive assessment or assurance methodologies,” NIST said. That is as far as the draft goes on its own standing: the words legal, binding and obligation appear nowhere in it.

That status matters, because this document is built to be run rather than read. Appendix A supplies a step-by-step workflow, from opening the AI tool to generating output for review.



What the guide actually asks the model to do

The draft carries three notional use cases built on the CO-STAR prompt framework, which specifies context, objective, style, tone, audience and response format. Use Case 1 runs an AI-assisted review of cybersecurity policy, strategy and risk governance against the CSF 2.0 Govern function. Use Case 3 drafts a target state profile from internal and industry references.

Use Case 2 is the one that should stop an eDiscovery reader cold. It builds a draft Organization Current State Profile out of two input classes, the organization’s artifacts and what NIST calls personnel interview notes, mapping both onto CSF 2.0 outcomes and logging whatever the sources fail to cover. The sample prompt tells the model to fill two columns of a profile template for every outcome in the CSF core, and to prefix the practices column, column H, with Strength, Partial or Gap “wherever the interviews provided a read.” The payoff NIST advertises is speed, “compressing the initial drafting from weeks to hours” while “rapidly ingesting and correlating large document sets.”

The interview notes NIST ships are invented. Its supplemental portfolio models a fictitious bank, Halverston Community Bank, whose simulated records were themselves “created with generative AI for illustrative purposes,” and the draft states that every individual, organization and record across the guide and its supplements is a product of fiction. NIST also fenced off what it wants to hear about, saying it seeks comment on the quick-start guide and the supplied prompts, not on the fictional organizational documents.

NIST built in more control than a quick read suggests

It would be easy, and wrong, to say the agency shipped a prompt library with nothing attached to it.

The guide asks twice for source-grounded and traceable output, instructs the model not to fabricate, and tells it to say so plainly when an outcome is not addressed in the sources. Both profile prompts require the model to map each CSF outcome to the requirements or risk responses that drive it and cite them, and both require a closing “Assumptions & Evidence Gaps” note, though each asks for a different accounting. The Use Case 2 note must list “any outcomes where the sources were silent or thin” and “any places where column H rests on documented process rather than observed practice.” Three separate passages say “AI-generated content should always be reviewed by qualified personnel.” Two of the three go further and put the burden of validating applicability, scope, inputs, assumptions and outputs on the user.

The guide even reaches for the word practitioners will want. AI-assisted mappings and crosswalks, it says, should “retain identifiers, source context, provenance, and statuses,” so that unsupported mappings do not get used without review by a subject-matter expert. Its glossary defines hallucination as plausible but inaccurate output requiring expert review, and defines status labels for AI-assisted mappings pending expert validation.

That is a validation layer, and it is aimed squarely at analytic quality.

Where the vocabulary runs out

Analytic quality and evidentiary foundation are different problems, and the draft solves only the first.

A word search of the full nine pages returns no instance of authentication, admissibility, litigation, subpoena, custodian, work product, attorney, deposition, exhibit or chain of custody. Privilege appears twice, both times as access privileges in a list of AI tool settings to review, never as attorney-client privilege or work product protection. The provenance the guide asks practitioners to retain is provenance of the mapping, meaning which reference supported which outcome. It is not provenance of the record, meaning who created the artifact, when, from what inputs, under whose supervision, and whether a witness can establish that account.

Record provenance is what can help build that foundation, and the guide leaves that side of the ledger empty.

The rules ask two different questions

Consider what happens after a breach. A current state profile assembled this way describes the organization’s self-assessed security posture at a moment in time, and if it is sought in litigation, a regulatory inquiry or diligence, someone has to establish what it is.

Federal Rule of Evidence 901(a) sets that bar: the proponent “must produce evidence sufficient to support a finding that the item is what the proponent claims it is.” Rule 901(b) then offers a list of examples, and says on its face that the list is illustrative rather than complete. Two entries matter here. Rule 901(b)(1) is the familiar route, testimony from a witness with knowledge. Rule 901(b)(9) is the one built for machines, “evidence describing a process or system and showing that it produces an accurate result.” Rule 902(13) goes further, treating as self-authenticating “a record generated by an electronic process or system that produces an accurate result,” shown by a certification from a qualified person, with written notice to the opposing party. Rule 902(14) does the same for data copied from an electronic device, provided it is “authenticated by a process of digital identification.”

Authentication is only the first gate, and the gates are worth keeping separate. Admitting a profile for the truth of what it asserts is a different question, and the business-records exception in Rule 803(6) is one route to it, though not the only one. That exception reaches a record “made at or near the time by, or from information transmitted by, someone with knowledge.” It must also have been kept in the course of a regularly conducted activity, and making it must have been a regular practice of that activity. Those conditions are shown by a custodian or another qualified witness, or by a certification complying with Rule 902(11) or (12). Even then the opponent can defeat the exception by showing that the source, method or circumstances of preparation indicate a lack of trustworthiness.

Read those elements against the workflow and the live questions come into focus. A profile drafted by a model from staff interview notes may be a record made from information transmitted by people with knowledge, which is the structure the rule already contemplates; the recorder need not be the person who knows. What an opponent would press instead is whether the sources behind a given mapping were knowledgeable, whether producing such a profile is a regular practice of the business or a one-time exercise, and whether the method of preparation indicates a lack of trustworthiness. Those questions are open, and a model in the middle of the process is what makes them worth asking.

A second layer sits underneath that one. A profile repeating statements drawn from staff interviews may present a hearsay-within-hearsay problem, since each embedded statement would have to be nonhearsay or fall within an exception of its own. Rule 805 provides that combined statements are not excluded by the hearsay rule when each part qualifies, which is not the same as making the profile admissible. Clearing the profile as a business record would not, by itself, clear the statements inside it.

On the two routes this article traces, testimony and certification, both gates run through a person who can answer for the process. If the notes fed into the tool were gathered by counsel, a privilege question arrives ahead of either, and the guide’s advice to review a vendor’s data retention and confidentiality terms does not reach it. Direction by counsel does not settle privilege on its own, but it is the point at which someone should be asking.

The obvious rejoinder is that none of this is NIST’s job. Evidence rules are made by the rules committees, the Judicial Conference, the Supreme Court that promulgates them and Congress, which reviews them, and a quick-start guide is not the place to litigate Rule 902. That is fair, and it goes less far than it looks. NIST has already stepped into the adjacent territory, telling readers to check data retention, access privileges and confidentiality terms and to follow company privacy and data-management policy before entering sensitive information. Having gone that distance, leaving out a sentence about material collected at the direction of counsel is a line drawn in an odd place.

A rule for machine evidence is still unfinished

The Rule 707 proposal has been moving in one direction, and it is not toward a lighter reliability showing.

On the Standing Committee’s approval, a proposed new Rule 707 on machine-generated evidence went out for public comment in August 2025, with comments due Feb. 16, 2026. As published it would reach machine-generated evidence offered without an expert witness, in circumstances where Rule 702 would have applied had a witness testified to it, and would require the court to find that the evidence satisfies Rule 702(a) through (d). It would not reach the output of simple scientific instruments.

Anyone reading that and concluding that a human reviewer solves the problem should read the committee note, which forecloses the point directly. The rule applies when machine output is entered directly, the note says, and also when it arrives accompanied by lay testimony. Its example is a technician who enters a question, prints the answer, and has no expertise about whether the answer is any good. In that situation the proponent would still owe the same reliability showing an expert would have to make.

That matters here because NIST’s instruction is to have output reviewed by qualified personnel, and qualified personnel is not a term of evidence law. The employee who reviews a model-drafted profile may know the organization’s controls cold and still be unable to speak to whether the system that produced the mapping returns an accurate result. Those are different competences, and the proposal is drafted around the gap between them.

The direction of travel since the comment period closed reinforces the point. At its May 7, 2026, meeting the Advisory Committee took up a revised draft that retitles the rule’s scope from machine-generated evidence to artificial intelligence, adds a notice provision, and carves out facts subject to judicial notice. Under the revision the agenda materials describe as the likely leading contender for republication, a proponent would normally have to produce an expert, with other kinds of proof left for exceptional cases.

The committee did not send that revision out. It declined to open another round of public comment on Rule 707 at the May meeting and agreed to keep working on the revised version, alongside its parallel work on deepfakes, when it next convenes. Rule 707 is not among the amendments currently out for public comment, and nothing has been sent forward for adoption.

That deepfake track has a history of its own. The committee’s April 2024 agenda book carries a proposed new Rule 901(c) from Paul W. Grimm and Maura R. Grossman, which would make computer-generated or other electronic evidence a challenger shows is more likely than not fabricated or altered, in whole or in part, admissible only if the proponent shows its probative value outweighs its prejudicial effect on the challenging party. The reporter recommended waiting for courts to gain experience under the existing rules before acting. No Rule 901(c) amendment is out for public comment now.

A trap waits for anyone tracking rulemaking dockets this autumn. Evidence Rules 104 and 902 are out for public comment from Aug. 14, 2026, through Feb. 15, 2027, which looks like the fix and is not. The proposed Rule 902 amendment reaches a different subdivision than the ones above, adding federally recognized Indian Tribes and Nations to the Rule 902(1) list of entities whose sealed public documents are self-authenticating. The Rule 104 amendment writes the preponderance standard into the text and reworks how relevance questions are handled. The committee connects neither to artificial intelligence.

The committee’s next meeting is scheduled for Oct. 15, 2026, in Boston, the same day NIST’s comment window closes. The committee said it would carry Rule 707 into that fall session, and the Federal Register notice says an agenda will be posted at least seven days beforehand. Two federal bodies working opposite ends of one problem, the committee drafting the rule that would govern machine-generated evidence and the agency publishing prompts to generate it, arrive at the same date.

How to spend the comment window

The comment window is the near-term lever, and it closes Oct. 15.

Practitioners who want this on the record should write to csf@nist.gov before the deadline and aim at the guide and its prompts, which is the scope NIST says it is soliciting. Useful comments will be concrete. Ask that the Use Case 2 prompt require a source manifest naming each input document, its custodian and its date. Ask that the “Assumptions & Evidence Gaps” note record which human reviewed which mapping and when, which would not by itself establish that the system returns accurate results but would give a later certification something to build on. Ask NIST to say directly what the guide now leaves to inference, that notes collected at the direction of counsel may carry privilege and warrant review before anyone pastes them into a general-purpose tool.

The scholarship on AI evidence is worth reading before writing, and several works cited here come from a recurring collaboration between Grimm and Grossman. Grossman is a research professor at the University of Waterloo’s Cheriton School of Computer Science who serves frequently as a court-appointed special master in complex federal litigation involving advanced technologies. Grimm is the retired U.S. district judge who directed Duke Law’s Bolch Judicial Institute through the end of 2025. They have written together since 2021, when they and Gordon V. Cormack published “Artificial Intelligence as Evidence” in the Northwestern Journal of Technology and Intellectual Property, and again in 2023 on “The GPTJudge: Justice in a Generative AI World” with Daniel G. Brown and Molly Xu for the Duke Law & Technology Review. In May 2025 they published “Judicial Approaches to Acknowledged and Unacknowledged AI-Generated Evidence” in the Columbia Science and Technology Law Review, separating evidence a party admits an AI produced from evidence whose authenticity is disputed. Grimm has more recently distinguished AI-generated evidence from AI-enhanced evidence, treating both as raising authentication and reliability problems and both as carrying a risk of prejudice at trial, according to the Bolch Judicial Institute’s summary of a Reuters Practical Law Journal Q&A published in October 2025. With Kevin F. Brady, Grimm and Grossman have since built a decision tree for evaluating AI-generated evidence, posted as a Sedona Conference Journal preprint in April 2026, that walks the authentication question through Rule 901(a) and the Rule 901(b) routes and accounts for proposed Rule 707.

Information governance teams have work that does not wait on NIST. The workflow directs users to upload the files in the Organizational Documents folder into the AI tool, and the guide names five: bank security requirements, staff interview notes, a security policy handbook, a risk register and an organizational profile template. NIST’s copies are fiction, but the categories are not, and in a real organization those five may sit at different sensitivity levels under different retention duties. Nothing in the workflow asks anyone to sort them before they go in.

Classify the profile, its drafts and its supporting materials under your retention schedule before anyone runs the prompt, remembering that a draft can itself be a record. That classification drives retention and disposition. It does not decide discoverability, which under Rule 26(b)(1) turns on relevance to a claim or defense, proportionality and privilege, while Rule 34 reaches what is in your possession, custody or control. A litigation hold suspends scheduled disposition for information within the hold’s scope. Keep the prompt, the input set and the model identifier with the output, since a profile separated from its inputs is an assertion nobody can check. Have the reviewing analyst attest to what they verified rather than that they read it.

Buyers have a window of their own. Executable prompts, a sample workflow and a ready-made fictitious dataset add up to something close to a product specification, and part of that specification is already advertised. Complyance markets an AI agent that, in the company’s words, “audits your cybersecurity evidence against NIST CSF criteria, surfacing gaps as actionable findings.” Vanta says its agent “uses AI to map controls, identify gaps, and prioritize remediation.” That is the ingestion-and-mapping half of what Use Case 2 describes. The guide supplies the drafting half. As those converge, the certification burden moves. An analyst running a prompt by hand can keep the prompt and the inputs, and can record whatever model identifier the tool displays, which is not always the same thing as an exact build. A customer of a packaged feature may not be able to do even that, if the prompt is proprietary, the model changes without notice, or the retrieval step that assembled the inputs is not exposed. Buyers can settle that now by asking for those artifacts as a contractual deliverable, while the category is young enough that the asking shapes the roadmap.

Another document is already behind this one. NIST’s Cyber AI Profile, issued as NIST IR 8596 in initial preliminary draft, has closed its comment period and sits in review.

NIST has made a careful case for a workflow it says can compress weeks of drafting into hours, and the draft is more disciplined than its summaries suggest. The unresolved question is not whether the output is useful. It is who answers for it when someone asks where the profile came from, and whether that person can speak to the system as well as to the subject matter. Which of your compliance artifacts could survive that question today?



News sources



Assisted by GAI and LLM technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).