Generated by GPT-5.6 Medium
NIST recently joined the Gen AI bandwagon - Gen AI can compress the first draft of a cybersecurity assessment “from weeks to hours.”
Speed is seductive AND deceptive.
It’s seductive because most CEOs wait until the last minute to make a risk management decision.
In clinical trials - many life science companies make decisions on CROs a month before the first patient is recruited. And that’s for $10-100M bets.
In my cyber and privacy practice - my life science clients start working on FDA cyber and HIPAA compliance during a sales process with a customer or strategic partner.
It’s deceptive because you can quickly end up with security theater - feeling secure instead of being secure.
You can move so fast with Gen AI on the security assessment that your CFO and CEO are out of the loop.
Precisely the people who need to know how your enterprise value will be impacted by cyber events.
NIST’s draft SP 1353, published on August 19, describes using AI to review governance documents, map organizational evidence to Cybersecurity Framework outcomes, identify gaps and generate current- and target-state profiles.
The source material may include policies, risk registers, penetration-test reports, vulnerability scans and interview notes. CSRC
When speed works
A medtech company can use AI to scan a document set that previously required days of expensive specialist work. AI can then connect a company privacy policy statement to a vulnerability scan and an audit finding.
It can find contradictions, normalize terminology and help the team not start a risk assessment from scratch.
The RA/QA and product teams can work faster with FDA cybersecurity guidance, NIST frameworks and the HIPAA Security Rule—and make better use of external security expertise.
Faster iterations on the risk model deepen the company’s understanding of plausible threat scenarios and their financial impact.
It might speed up a regulatory submission.
I would use it.
But I would not confuse a fast answer that makes sense with being secure.
When speed creates security theater
FDA’s February 2026 cybersecurity guidance requires traceability between the threat model, cybersecurity risk assessment, software bill of materials and testing documentation. fda.gov
Traceability is not text generated by an LLM.
Traceability is a structured and defensible relationship between a claim, the system under review, a testable control and evidence that the control actually works.
A language model can produce the appearance of that relationship remarkably well.
Gen AI creates two new threats to the evidence itself: disclosure of confidential information and false confidence in unsupported conclusions.
Breach of confidentiality
The documents most useful to the model are also among the company’s most sensitive: architecture, vulnerabilities, supplier weaknesses, risk tolerances and unremediated findings. NIST explicitly warns users to check retention, training, access and confidentiality settings before uploading sensitive information. nvlpubs.nist.gov
False confidence
Suppose the model maps an authentication policy to a CSF outcome, links it to a penetration-test result and labels the outcome “aligned.”
The mapping may sound reasonable while missing that the test covered the web portal, not the USB port used for software updates. Or that the tested software version is no longer deployed. Or that the policy says what should happen but the product does something else.
The model might make up evidence or miss an important detail (like the type of connection used to update the device software).
Now the company has a risk assessment, management approves the wrong remediation priorities, and the bugs go into a submission or a product.
Being wrong by being fast
The impact of being wrong by being fast will be a delayed submission, an avoidable security defect, a rejected customer assessment or a postmarket incident supported by documentation that looked a lot stronger than the underlying control.
Polished, consistent AI output makes this worse.
Write for human reviewers
Human reviewers like structured, comprehensive output. A beautifully completed framework can conceal weak evidence more effectively than a visibly incomplete one.
NIST understands part of the problem. Its draft repeatedly calls the outputs drafts, says qualified personnel must review them and requires preservation of identifiers, context, provenance and mapping status. It also suggests comparing results from multiple models. NIST Cybersecurity Framework 2.0
I think that NIST is right to suggest multiple models but model agreement is not enough.
Two models agreeing does not turn an unsupported claim into evidence.
Human review struggles when the reviewer is checking hundreds of plausible mappings in a document without access to the underlying technical facts.
A better design is to put what the AI claims into a structured data model of threats, vulnerabilities, assets and controls.
Every entity has a source, version, system boundary and verification result.
A structured data model enables programmatic checks for completeness and consistency before a human judges whether the countermeasure is technically adequate.
Automate for consistency
Recent work on the Secuman ontology proposes machine-readable representations and programmatic constraint checking for medical-device cybersecurity risk files, covering threat scenarios, assets, attacker profiles, controls and residual risk.
The authors explicitly state that their system performs first-pass validation; it does not determine whether a control is technically adequate. arxiv.org
You can use AI to find missing relationships (for example - threats without countermeasures) and save drudge work of reporting and compiling data.
You need a deep understanding of threat scenarios and clarity on how your enterprise value behaves when your systems are attacked in the field.
You need to write submission documentation in language FDA reviewers accept.
Should I use AI in cyber and regulatory work?
That train already left the station.
The tradeoff is speed to security theater or speed to security.
Worth reading
NIST SP 1353 initial public draft, Using Artificial Intelligence for CSF Analysis and Reporting, August 19, 2026. Comments close October 15. CSRC
FDA, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions, February 2026. FDA
Diller et al., Supporting Cybersecurity Risk Management for Medical Devices via the Secuman Ontology and Shapes, August 1, 2026. arxiv.org


