NIST CSF 2.0 and the Cyber AI Profile (NIST IR 8596) for Healthcare AI in 2026
By Sagar Shankaran, Founder of CallSphere
NIST CSF 2.0 added the Govern function in 2024. The draft Cyber AI Profile (NIST IR 8596) maps AI-specific risk to CSF outcomes. Here is how healthcare AI voice and chat align in 2026.
Key takeaways
NIST CSF 2.0 added a new Govern function. The draft Cyber AI Profile (NIST IR 8596) extends CSF outcomes to AI-specific risk. Together they form the cybersecurity backbone healthcare AI vendors are graded against in 2026.
What the rule says
NIST released the Cybersecurity Framework 2.0 (NIST CSF 2.0) in February 2024. It restructures the framework around six functions — Govern (new), Identify, Protect, Detect, Respond, and Recover — each broken into categories and subcategories. Govern adds explicit organizational, supply-chain, and policy outcomes that reach AI risk directly.
The draft Cybersecurity Framework Profile for Artificial Intelligence (NIST IR 8596) was published December 2025 with a comment period running through January 30, 2026 and an initial public draft expected later in 2026. The Cyber AI Profile maps AI-specific risks and controls to CSF 2.0 outcomes across three lenses: securing AI systems, defending with AI, and thwarting AI-enabled attacks. It pulls in NIST AI Risk Management Framework (AI RMF 1.0, January 2023) controls and Generative AI Profile (NIST AI 600-1, July 2024) overlays.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent for healthcare in your browser — 60 seconds, no signup.
The Health Sector Coordinating Council (HSCC) announced a 2026 sector-wide initiative aligned to CSF 2.0, HITRUST, and ISO 27001 to deliver healthcare-specific maturity models and checklists.
What AI voice/chat must do
Concretely, an AI voice or chat vendor in healthcare maps every operational control to CSF 2.0 subcategories. Govern: GV.OC (organizational context), GV.SC (cybersecurity supply chain risk management) covering model providers, GV.RR (roles and responsibilities) including AI-system owners. Identify: ID.AM-7 (data identification including training data) and ID.RA (risk assessments with AI-specific threats). Protect: PR.DS (data security including embeddings and prompts), PR.IR (technology infrastructure resilience). Detect: DE.AE (adverse event analysis covering prompt-injection and jailbreak), DE.CM (continuous monitoring including model drift). Respond and Recover: RS.MA (incident management with model-specific runbooks) and RC.RP (recovery plan execution) for model rollback.
The Cyber AI Profile adds outcomes around training-data integrity, model-output validation, prompt safety, and supply-chain provenance for foundation models.
CallSphere compliance posture
Explore a live demo and compare current plans to find the right fit for your business.
Still reading? Stop comparing — try CallSphere live.
See the healthcare AI agent handle a real call — complete, industry-specific, and live in your browser. No signup.
flowchart LR
A[CSF 2.0 Govern] --> B[BAA + SBOM]
B --> C[Identify Assets]
C --> D[Protect Encrypt + IAM]
D --> E[Detect SIEM\nAI Threats]
E --> F[Respond Rollback]
F --> G[Recover DR]
G --> H[Cyber AI Profile\nIR 8596]
Compliance checklist
- Map every AI control to a CSF 2.0 subcategory; do not leave AI in a vague "Protect" bucket.
- Stand up GV.SC for supply-chain — model providers, vector stores, prompt-cache vendors.
- Inventory data assets including embeddings, prompts, completions, fine-tune sets.
- Run AI RMF 1.0 risk assessments and feed the output into ID.RA artifacts.
- Implement prompt-injection, jailbreak, and model-extraction detection signatures.
- Monitor model drift on production metrics; alert when distributions shift past thresholds.
- Build an AI-specific incident runbook with rollback, retraining, and disclosure paths.
- Track HSCC sector guidance updates quarterly.
- Track NIST IR 8596 from draft to public draft and adjust controls accordingly.
- Cross-walk to HITRUST, and ISO 27001 to avoid duplicate evidence collection.
FAQ
Is CSF 2.0 mandatory for healthcare? Not on its own. It is the de facto baseline that customers and auditors expect.
Where does AI RMF fit? AI RMF is the AI risk management overlay; the Cyber AI Profile bridges it to CSF outcomes.
Is the Cyber AI Profile final? Not yet. Initial public draft expected later in 2026.
Does HSCC guidance replace NIST? No. It is sector-specific operationalization built on NIST.
Sources
- NIST CSF 2.0: https://www.nist.gov/cyberframework
- NIST AI RMF 1.0: https://www.nist.gov/itl/ai-risk-management-framework
- NIST AI 600-1 Generative AI Profile: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
- NIST IR 8596 (Draft) Cyber AI Profile: https://csrc.nist.gov/pubs/ir/8596/iprd
- HSCC 405(d) Health Sector Coordinating Council: https://405d.hhs.gov/

Written by
Sagar Shankaran· Founder, CallSphere
LinkedInSagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
Try CallSphere AI Voice Agents
See how AI voice agents work for your industry. Live demo available -- no signup required.