A small business can ask an AI tool to draft a cybersecurity profile in minutes. The speed is useful. The resulting document can also look more complete than the underlying security program actually is.

NIST released a draft quick-start guide on August 19 showing how artificial intelligence can support Cybersecurity Framework 2.0 analysis and reporting. The guide includes structured prompts for governance review, current-state profiles, target-state profiles, and related artifacts.

The important word is support. AI can organize source material, identify gaps, and accelerate a first draft. It cannot verify that an undocumented control exists, decide how much risk the owner will accept, or make an employee responsible for closing the gap.

A polished answer becomes dangerous when it is mistaken for evidence. The model may describe the control a well-run company should have. An operator still needs to determine whether that control is working in this company, on this network, with these vendors and people.

The workflow should preserve that distinction. Give the tool specific organizational documents. Require citations back to those inputs. Mark assumptions. Separate observed current state from proposed target state. Assign every unresolved item to a person who can verify or change it.

Review also needs domain judgment. A general manager may understand business consequence while a technology provider understands configuration. Neither perspective alone proves that the risk is controlled.

AI is valuable here because cybersecurity planning often stalls under the weight of terminology, documentation, and blank-page work. Removing that friction can help a small team begin. The organization still owns the truth of the profile and the decisions that follow.

The draft can arrive quickly. Accountability cannot be generated with it.