Generative AI refers to AI systems that produce new content, text, images, audio, video, code, or structured data, rather than simply classifying, scoring, or analyzing information that already exists. Instead of predicting a label (fraud/not fraud, cat/dog), a generative model predicts the next plausible piece of content given a prompt, drawing on patterns learned from massive training datasets. Large language models (ChatGPT, Claude, Gemini), image diffusion models (Midjourney, Stable Diffusion), and code assistants (GitHub Copilot) are all generative AI. It matters for governance because generative systems introduce risks that traditional predictive AI mostly didn't: they can confidently state falsehoods ("hallucinate"), they raise unresolved questions about the copyright status of training data and outputs, they make deepfakes and synthetic media trivially cheap to produce, and employees adopt them informally faster than IT and compliance teams can track ("shadow AI"). In July 2024, the U.S. National Institute of Standards and Technology (NIST) published a dedicated companion profile, NIST AI 600-1, specifically to extend its AI Risk Management Framework to cover these generative-AI-specific risks.
Run the free AI Health CheckGenerative AI, AI systems that produce new content, text, image, audio, video, code, or structured data, rather than only classifying or analysing existing inputs.
Generative AI is the broader category that includes large language models, image generators, video models, and code-generation systems. The governance challenges are distinct from traditional ML: hallucination, training data IP exposure, output authenticity, deepfake risk, and shadow use are all amplified. NIST published a Generative AI Profile (NIST AI 600-1) specifically to extend the AI RMF for this category.
Source: NIST AI 600-1 Generative AI Profile (July 26, 2024)
Most AI systems built before the 2020s were discriminative or predictive: given an input, they output a classification, score, ranking, or forecast (this transaction is fraudulent, this loan applicant is high-risk, this image contains a face). The model's job is to draw a boundary between existing categories in the data.
Generative AI instead learns the underlying statistical structure of its training data well enough to produce new, original examples that plausibly belong to it. A large language model doesn't retrieve a stored answer to a question, it predicts, one token at a time, the most statistically likely continuation of the prompt, informed by patterns absorbed from its training corpus. The same mechanism, applied to pixels, audio waveforms, or code tokens, produces images, speech, or software.
This shift changes the risk profile. A generative system can be fluent and confident while being factually wrong, can reproduce copyrighted or personal data it saw during training, and can be used to create fake but highly convincing content, problems that barely existed for a model that only outputs a probability score.
Large language models (LLMs)
Generate and manipulate text, chat assistants, summarization, drafting, translation, and code generation. Examples include GPT, Claude, and Gemini.
Image diffusion models
Generate or edit images from text prompts by iteratively refining noise into a picture. Examples include Stable Diffusion, Midjourney, and DALL-E.
Video generation models
Produce short video clips from text or image prompts, an area of rapid recent progress with its own deepfake and consent implications.
Audio and voice synthesis
Generate speech, music, or clone a specific person's voice from a short sample, raising authentication and impersonation risks.
Code-generation assistants
Suggest, complete, or write software code inline in a developer's editor, trained on public and licensed code repositories.
Multimodal models
Accept and generate combinations of text, image, audio, and video within a single system, increasingly the default architecture for frontier models.
NIST AI 600-1, the Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, was published July 26, 2024, as a companion to the core NIST AI Risk Management Framework (AI RMF 1.0). It was developed in response to a 2023 presidential executive order directing NIST to produce generative-AI-specific guidance; that executive order was later rescinded in January 2025, but the NIST profile itself remains a standing, actively referenced publication. The profile lists twelve risks that are either novel to generative AI or significantly exacerbated by it, alongside more than 200 suggested management actions.
CBRN Information or Capabilities
Lowering the barrier to accessing chemical, biological, radiological, or nuclear weapons information.
Confabulation ("hallucination")
Confidently producing false, fabricated, or nonsensical content presented as fact.
Dangerous, Violent, or Hateful Content
Generating content that incites violence, self-harm, or hateful conduct.
Data Privacy
Leaking, inferring, or reconstructing sensitive personal data memorized during training.
Environmental Impacts
Energy and water consumption from training and running large generative models.
Harmful Bias and Homogenization
Amplifying discriminatory bias or narrowing the diversity of outputs and viewpoints at scale.
Human-AI Configuration
Risks from how people interact with and over-trust or misuse generative systems.
Information Integrity
Generating and spreading mis- and disinformation at low cost and high volume.
Information Security
Lowering the barrier for cyberattacks, malicious code, or prompt-injection exploits.
Intellectual Property
Producing outputs that infringe copyright or reproduce protected training material.
Obscene, Degrading, and/or Abusive Content
Generating non-consensual intimate imagery, CSAM-adjacent content, or degrading material.
Value Chain and Component Integration
Risks inherited from third-party foundation models, plugins, or data sources in the supply chain.
Shadow AI is the most immediate exposure for most organizations: employees paste confidential or personal data into free consumer chatbots long before procurement or security teams have approved, inventoried, or risk-assessed the tool. Unlike a purchased predictive-analytics platform, a generative chat interface can be adopted by any individual employee in minutes.
Regulators have started treating generative AI as a distinct category rather than folding it into general AI rules. The EU AI Act imposes dedicated transparency and technical-documentation obligations on providers of "general-purpose AI models", the category that covers most generative foundation models, which took effect on 2 August 2025, with additional obligations for models posing "systemic risk." Separately, the Act's Article 50 transparency obligations, requiring chatbots to disclose that users are interacting with AI and requiring deepfakes and other AI-generated or manipulated content to be labeled, apply from 2 August 2026, a distinct deadline from the general-purpose-AI provider obligations described above. Output authenticity, training-data provenance, and content-labeling requirements are now recurring themes across jurisdictions.
Because a single generative model can be repurposed for drafting, coding, image creation, and customer-facing chat simultaneously, governance programs increasingly need to assess generative AI use case-by-use-case rather than tool-by-tool, the same underlying model can carry low risk in one deployment and high risk in another.
What is generative AI in simple terms?
It is AI that creates new content, writing, pictures, sound, video, or software code, instead of just labeling or analyzing content that already exists. You give it a prompt and it generates an original response based on patterns it learned from huge amounts of training data.
How is generative AI different from machine learning generally?
Generative AI is a subset of machine learning. Traditional machine learning models are usually predictive, they classify, score, or forecast (e.g., is this email spam?). Generative models produce new outputs (e.g., write this email) rather than a label or a number.
What is NIST AI 600-1 and is it mandatory?
NIST AI 600-1 is the Generative AI Profile, published July 26, 2024, as a voluntary companion to the NIST AI Risk Management Framework. It is not a binding law, but it is widely used by U.S. federal agencies, vendors, and auditors as a reference checklist of the 12 risk categories generative AI introduces.
What are the biggest risks of using generative AI in a business?
The most common practical risks are: confabulation (confidently wrong outputs), leakage of confidential or personal data typed into public tools, unresolved copyright exposure from training data and outputs, deepfake/impersonation misuse, and "shadow AI", unapproved employee use that bypasses security review.
Is generative AI regulated under the EU AI Act?
Yes. The EU AI Act treats most generative foundation models as "general-purpose AI models" (Article 53) and requires providers to maintain technical documentation, supply information to downstream deployers, and publish a summary of training content; these obligations took effect on 2 August 2025, with extra rules for models deemed to carry systemic risk.
What's the difference between generative AI and agentic AI?
Generative AI produces content in response to a prompt and stops. Agentic AI uses generative models as a reasoning engine inside a system that can also plan multi-step tasks, call tools or APIs, and take actions in the world with limited human intervention between steps.
Last reviewed July 2026
This page is general information about What Is Generative AI?, not legal, regulatory, or professional advice, and does not capture every nuance or exception. Requirements change and can be fact-specific. Always verify against primary sources and your own qualified legal counsel before relying on it.