A foundation model is a large AI model trained on broad data so it can be adapted to many downstream tasks. It serves as a reusable base for applications such as chat, image generation, summarisation, and classification. The same general capability also creates governance risk because one model can influence many systems at once.
Expanded Definition
A foundation model is not just a large model, but a general-purpose model that can be adapted through prompting, fine-tuning, retrieval, or tool use to support multiple downstream applications. That flexibility is what makes it powerful in enterprise environments and also harder to govern than a single-purpose model. In practice, the model may be used directly by end users, embedded into other systems, or exposed through APIs that other teams depend on. Definitions vary across vendors on where "foundation model" ends and "large language model" or "general-purpose model" begins, so NHIMG treats the term as a capability class rather than a product category.
For governance and assurance, the most useful lens is whether the model can influence many workflows, data paths, and decisions from one shared base. The NIST AI 600-1 Generative AI Profile is useful here because it frames generative AI risk in operational terms, including lifecycle controls, testing, and monitoring. The most common misapplication is treating a foundation model like an ordinary application component, which occurs when teams ignore shared downstream impact and reuse the model without change control.
Examples and Use Cases
Implementing foundation models rigorously often introduces governance overhead, requiring organisations to weigh speed of reuse against control over model behaviour, data exposure, and drift.
- A customer support assistant built on a shared model is fine-tuned for brand tone, but still inherits the base model's weaknesses and must be monitored for unsafe or incorrect outputs.
- An internal search assistant uses retrieval-augmented generation to answer policy questions, where the foundation model interprets content but does not replace source-of-truth documents.
- A development team uses the same model behind code generation, ticket summarisation, and release-note drafting, creating a single point of governance for multiple workflows.
- A security operations team connects the model to investigation tools, which improves triage speed but increases the need for strict tool permissions and logging.
- A regulated organisation reviews whether a vendor-hosted model is a foundation model under its AI governance policy before allowing business units to deploy it at scale.
These scenarios are consistent with the broader risk-management approach in the NIST AI 600-1 Generative AI Profile, especially where the same model influences multiple services. The key question is not whether the model is impressive, but how many decisions it can affect from one shared dependency.
Why It Matters for Security Teams
Foundation models matter because they concentrate operational risk. A weakness in the base model can propagate into chatbots, copilots, classification services, and agentic workflows that rely on the same underlying weights or API. That creates governance requirements around model provenance, access control, prompt handling, evaluation, and change management. Security teams also need to distinguish between model capability and system trustworthiness: a model may be broadly useful while still being unsuitable for high-impact decisions without guardrails.
This term also intersects with identity and NHI governance when foundation models are used inside autonomous agents or exposed to tool-using workflows. In those cases, the model is not just generating text, but helping determine which actions an agent takes, which secrets it requests, and which resources it can reach. That makes model governance inseparable from privilege boundaries and auditability. Organisations typically encounter the consequences only after a model update, unsafe output, or unintended tool invocation affects production systems, at which point foundation model governance becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST AI 600-1 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI RMF | AI RMF defines risk governance practices for models used across many downstream tasks. | |
| NIST AI 600-1 | The GenAI Profile addresses lifecycle risks for generative foundation models. | |
| OWASP Agentic AI Top 10 | Agentic AI guidance is relevant when foundation models drive tool-using autonomous systems. | |
| CSA MAESTRO | MAESTRO covers security concerns for agentic AI systems built on reusable model foundations. | |
| NIST CSF 2.0 | GV.RM-01 | CSF risk management supports oversight of shared AI dependencies and governance decisions. |
Apply profile guidance to testing, monitoring, and change control for generative model deployments.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org