Skip to content

AI Outlooks

News and viewpoints on the latest in AI security

Primary Menu
  • Home
  • What’s new in AI
    • AI Security News
    • Agentic AI News
    • AI Regulation News
    • AI Research News
    • AI Model News
  • Solutions
  • Cybersecurity
    • AI security
    • OWASP
    • Ransomware
    • Shadow AI
  • Learn
    • AI security
    • LLM security
    • AI governance
    • AI compliance
    • Agentic AI
    • AI infrastructure
    • AI data security
  • Home
  • Glossary
  • What is the NIST AI Risk Management Framework?
  • Glossary

What is the NIST AI Risk Management Framework?

Staff May 19, 2026

TL;DR

  • The NIST AI RMF is voluntary guidance, published January 26, 2023, for managing AI risks.
  • Govern, Map, Measure, and Manage are four interconnected functions that loop rather than run as sequential checkpoints.
  • More than 240 organizations built the framework over 18 months, with no commercial agenda.
  • Seven trustworthiness characteristics trade off against each other, so the framework demands documented reasoning.
  • No enforcement mechanism exists, and a team of 20 people cannot stand up a cross-functional risk committee.

The NIST AI Risk Management Framework (AI RMF) is a voluntary guidance document released by the National Institute of Standards and Technology that helps organizations identify, assess, and manage the risks created by artificial intelligence systems.

Published on January 26, 2023. First of its kind from the U.S. government. Now the most widely referenced AI governance standard in the country.

The framework was built over 18 months through a consensus-driven process that involved more than 240 organizations, from private companies to academic institutions to civil society groups. Multiple drafts. Public comment. Workshops. The result is a framework that reflects real operational concerns, not just theoretical ideals. Unlike vendor-authored governance frameworks that inevitably steer toward a product, the AI RMF has no commercial agenda.

At its core, the AI RMF operates through four interconnected functions. They are not sequential checkpoints. They loop.

FunctionCore questionWhat you produce
GovernWho is accountable?Policies, roles, culture, board-level ownership
MapWhat AI do we have and who does it affect?System inventory, stakeholder impact maps, dependency records
MeasureHow risky is it, by what metrics?Risk scores, test results, audit artifacts, red-team findings
ManageWhat do we do about it?Treatment plans, mitigation actions, deploy/remediate/retire decisions

Each pass through the cycle deepens your ability to handle AI risk. The framework is sector-agnostic by design. A three-person startup and a 50,000-employee financial institution can both use it, though their implementations will look nothing alike.

Why the NIST AI RMF matters right now

Global legislative mentions of AI rose 21.3% across 75 countries in a single year, according to Stanford’s 2025 AI Index Report.

The EU AI Act is now law. Japan passed its AI Promotion Bill in February 2025. Australia published mandatory guardrails for high-risk AI in September 2024. President Biden signed Executive Order 14110 on AI safety in October 2023, which explicitly calls out risk management and responsible AI development.

If your organization uses AI and you have no governance framework, you are already behind. The AI RMF gives you a starting point that regulators recognize. PwC put it bluntly: “Federal policies often shape corporate norms, especially in an area such as AI risk management, where many organizations have been seeking clarification on expectations at the federal level while sorting through a patchwork of state AI laws.”

The framework is voluntary.

But voluntary does not mean optional when every major regulation maps to the same principles.

The four functions

Think of Govern, Map, Measure, and Manage as a continuous improvement loop, not a checklist.

Govern asks: who is accountable for AI risk in your organization? This function establishes policies, assigns roles, and builds the organizational culture that makes everything else possible. Without governance, the other three functions sit in a drawer somewhere. A governance charter should define scope, objectives, and guiding principles for trustworthy AI. It should name a board-level champion with budget authority. NIST emphasizes that governance is not a compliance checkbox. It is the foundation. Many organizations skip this step and go straight to technical controls. That is why AI governance often fails.

Map asks: what AI systems do you have, what do they do, and who do they affect? This is contextual analysis. You build an inventory of AI systems with documented purposes, training data sources, dependencies on third-party APIs, and the stakeholders each system touches, both directly and indirectly. A radiology model does not just affect patients. It affects clinicians’ workflows, billing processes, and downstream diagnostic decisions. Mapping captures this web of impact. If you cannot see all your AI systems, you cannot secure them. That shadow AI problem is where data security and governance intersect.

Measure asks: how risky are these systems, and by what metrics?

This function moves from narrative to quantification. You select metrics that track specific harms. Accuracy for safety-critical tasks. Demographic parity for fairness. Resilience scores for security.

You run baseline tests on clean data, then progress to stress tests, red-team exercises, and adversarial scenarios. Every evaluation artifact gets stored in a central repository for auditability. Quantitative scores need qualitative validation from domain experts and affected users. A model that looks fine on paper can still fail in the wild, which is why security best practices emphasize continuous monitoring over point-in-time audits.

Manage asks: given what you know, what do you do about it? Treatment plans. Mitigation strategies. Post-deployment monitoring. Vendor oversight. The Manage function determines whether you deploy, remediate, or retire a system. It closes the loop by feeding findings back into Govern and Map. This is where frameworks stop being theory and start affecting real deployments and, sometimes, real people.

What makes an AI system trustworthy?

The AI RMF defines seven characteristics of trustworthy AI. Every other section of the framework orbits around them.

CharacteristicWhat it meansTrades off against
Valid and reliablePerforms consistently under expected conditionsExplainability, fairness
SafeDoes not cause harm to humans, property, or environmentSpeed, autonomy
Secure and resilientWithstands adversarial attacks, data poisoning, model theftCost, latency
Accountable and transparentSomeone can explain decisions; responsibility is assignedPrivacy (more transparency can expose data)
Explainable and interpretableOutputs can be understood by the people who depend on themAccuracy in complex models
Privacy-enhancedPersonal data protected through design, not afterthought. See our AI privacy risks guide.Accuracy, auditability
Fair, with harmful bias managedDoes not systematically disadvantage protected groupsAccuracy on majority groups

These characteristics are not independent. Privacy and fairness tend to pull in opposite directions from accuracy. Security and explainability trade off. The framework does not pretend otherwise. It asks organizations to make those tradeoffs explicit and document their reasoning.

How the AI RMF was built (and why that matters)

Most frameworks drop into the world fully formed. Or so it seems.

The AI RMF took the opposite approach. NIST published a Request for Information in July 2021. Responses came from across industry, academia, and civil society. Then a concept paper in December 2021. A first draft in March 2022. A second draft in August 2022. Each round included public workshops and open comment periods. All feedback is publicly archived.

MilestoneDate
Request for InformationJuly 2021
Concept paperDecember 2021
First draftMarch 2022
Second draftAugust 2022
AI RMF 1.0 finalJanuary 26, 2023

The final framework cites input from more than 240 contributing organizations. That number matters. It means the framework was not written by three people in a conference room. It was stress-tested by practitioners who build, deploy, audit, and regulate AI systems.

This development process also explains why the framework is deliberately technology-neutral. It does not prescribe specific tools, models, or architectures. It works whether you are using a logistic regression model or a 400-billion-parameter language model. Technology changes. Governance principles should not need to.

AI RMF profiles: Generative AI and critical infrastructure

The core framework is broad by design. Profiles make it specific.

In July 2024, NIST published NIST-AI-600-1, the Generative Artificial Intelligence Profile. This companion document maps the AI RMF’s functions, categories, and subcategories onto the unique risks of generative AI. Hallucinations. Toxicity. Prompt injection. Data leakage from training corpora. Copyright issues in generated outputs. It does not replace the core framework. It adapts it.

In April 2026, NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure. Power grids. Water systems. Transportation networks. Essential services where AI failures cascade. The concept note is public now. A full profile follows.

Beyond these, organizations create their own profiles. A hospital system layers on HIPAA. A bank adds FFIEC guidance. Profiles are what make the AI RMF practical rather than abstract.

AI RMF and the broader regulatory picture

The AI RMF is not a regulation. It was built with an eye on the direction of travel. And it aligns with most major AI laws.

Here is how the framework maps to the regulatory field:

RegulationStatusHow AI RMF aligns
EU AI ActLaw, effective August 2024Four-function structure maps to transparency, risk management, human oversight requirements
U.S. Executive Order 14110Signed October 2023Names NIST specifically; references AI RMF as key resource for federal AI safety
Japan AI Promotion BillPassed February 2025Light on prescription, strong on accountability; Govern function maps naturally
Australia AI Safety StandardsVoluntary 2019, mandatory guardrails Sep 2024Guardrails require risk management, performance testing, human oversight

The pattern is consistent. Every major regulation converges on the same core ideas. Know what your AI does. Measure its risks. Manage them. Prove you did. The AI RMF gives you the structure to do that.

Where the AI RMF falls short

No framework is perfect. The AI RMF has real limitations.

It is voluntary. No enforcement mechanism. No certification body. No audit process that carries legal weight. Organizations that treat the framework as window dressing can do so without consequence. NIST wanted adoption, not resistance. But effectiveness depends entirely on organizational commitment, and commitment is not distributed evenly.

It is high-level. It tells you what to do but not how. An organization new to AI governance may find the gap between “establish a risk-aware culture” and concrete steps to be frustratingly wide. The companion Playbook helps, but it is also deliberately non-prescriptive. NIST expects the AI RMF to be a living document, with the next major update informed by community input no later than 2028.

Then there is the overlap question. NIST also maintains the Cybersecurity Framework and SP 800-53, the canonical catalog of security controls. Organizations already operating under these standards now have to layer the AI RMF on top. Practitioners who have done both mapping exercises report that SP 800-53 mentions AI only twice in Revision 5. NIST is working on COSAiS (Control Overlays for Securing AI Systems) to bridge this gap, releasing a draft outline in January 2026. Until those overlays are finalized, security teams improvise the connection between traditional infosec controls and AI-specific risks. That improvisation is where production AI security risks tend to emerge.

And the framework asks a lot of smaller organizations. A team of 20 people cannot stand up a cross-functional AI risk committee, run quarterly model audits, and maintain a central evidence repository. NIST acknowledges this and encourages scaling. The “scale it down” guidance is thin.

What the framework gets right

Despite those limitations, the AI RMF has earned its position as the reference standard.

The socio-technical approach is its strongest feature. It treats AI risk as something that emerges from the interaction between technical systems and the people, processes, and institutions around them. A biased model is not just an algorithm problem. It is an organizational problem. A data problem. A problem of who was in the room when requirements were written. The four functions force you to look at all of it.

The framework also avoids the trap of treating fairness, security, and accuracy as separate problems solved by separate teams. It bundles them under trustworthiness and demands that tradeoffs be surfaced. Not buried. A model that is 99% accurate but discriminates against Black applicants cannot pass a serious AI RMF review just because its accuracy number is high. You must document the bias. Explain what you did about it. Decide whether to deploy anyway, and on what basis.

These are uncomfortable conversations. The framework forces you to have them.

And unlike vendor-authored frameworks, the AI RMF has no commercial agenda. It does not recommend specific tools. It does not create a market for certification or licensing. It is free to download, free to adopt, free to adapt. That independence gives it credibility no vendor framework can match.

What other frameworks assess and manage AI security risk?

The AI RMF is the governance layer. It is not the only layer, and it was never meant to be the whole stack. Most mature programs run it alongside two or three others, each covering something the RMF deliberately leaves abstract.

FrameworkWhat it coversHow it fits with the AI RMF
ISO/IEC 42001Certifiable AI management system, published December 2023Adds the audit trail and certificate the RMF has no mechanism to issue
OWASP Top 10 for LLM ApplicationsApplication-layer risks: prompt injection, improper output handling, excessive agencyFills the technical “how” beneath the Measure function
MITRE ATLASAdversarial tactics and techniques against ML systems, modeled on ATT&CKGives red teams a shared vocabulary for threats the RMF only names in the abstract
NIST CSF 2.0 and SP 800-53Traditional cybersecurity controls and governanceWhere AI risk connects to the security program you already run. NIST’s COSAiS overlays are extending SP 800-53 to cover AI-specific risk
EU AI ActBinding obligations tiered by risk classTurns voluntary practice into legal requirement for anyone serving the EU market
Google SAIFLifecycle controls spanning data, infrastructure, model, and application, including practices for securing AI pipelinesUseful implementation detail, though it reflects one vendor’s architecture

The overlap is real, and it is mostly redundant rather than contradictory. The governance frameworks among them converge on the same four questions the RMF asks. Know what you have. Know what can go wrong. Do something about it. Prove you did.

A workable default: run the AI RMF as your governance spine, certify against ISO/IEC 42001 if procurement demands it, and use OWASP and ATLAS as the technical checklists your engineers actually test against. Add the EU AI Act as a compliance overlay if it applies to you. Layering all six from day one is how governance programs stall before they produce anything.


How to get started

If your organization has not begun implementing the AI RMF, here is a practical starting sequence. Do not try to do all of it at once.

  • Inventory your AI systems. You cannot manage risk you have not identified. List every model, dataset, and API integration along with its purpose, owner, and deployment status. A rough inventory is infinitely better than none.
  • Designate one AI risk steward. In a small organization this might be the CTO or general counsel. In a larger one, a dedicated role. What matters: someone owns the question “are our AI systems trustworthy?” and has the authority to act on the answer.
  • Start with one high-impact system. Pick the AI system that could cause the most harm if it failed. Whether harm to customers, employees, or the business itself. Run it through Govern, Map, Measure, Manage. Learn what works. Then expand.
  • Read the Playbook. NIST’s AI RMF Playbook provides suggested actions for each subcategory in the framework. It is updated roughly twice a year based on community feedback. It is the closest thing to an implementation manual.
  • Align with existing compliance work. The AI RMF is designed to integrate with enterprise risk management, cybersecurity programs, and regulatory compliance. Do not build a parallel structure. Map AI risks into your existing risk register. Use the same escalation paths. The framework works best when it extends what you already do.
  • Document everything. Model cards. Impact assessments. Test results. Governance decisions. It is not bureaucracy for its own sake. It is your defense when a regulator asks what you knew about your AI systems and when you knew it.

Next steps

The AI RMF is a framework, not a destination. NIST expects a 2.0 version informed by community feedback, with input expected no later than 2028. The Generative AI Profile and Critical Infrastructure Profile are expanding the framework’s scope. The COSAiS overlays will bridge the gap between AI risk management and traditional security controls.

If you are just starting, download the framework from the NIST AI Resource Center and read the Executive Summary. It is 10 pages. For most organizations using AI in any substantive way, it is worth the time.

When you are ready to go deeper, comparing AI security solutions is the natural next step once your governance framework is in place.

Continue Reading

Previous: What is the EU AI Act?
Next: The OWASP Top 10 for LLM Applications: Secure against the latest risks

More in AI security

  • Guide

The agentic AI security checklist: 12 controls to verify before you deploy

Staff September 4, 2026
Twelve controls to verify before you deploy an AI agent, each mapped to an OWASP ASI risk...
Read more Read more about The agentic AI security checklist: 12 controls to verify before you deploy
LLM jailbreak defense: techniques that actually stop attacks Jailbreak defense
  • Cybersecurity

LLM jailbreak defense: techniques that actually stop attacks

Staff July 28, 2026
How do enterprises secure AI data pipelines at production scale? safety
  • Cybersecurity

How do enterprises secure AI data pipelines at production scale?

Staff July 28, 2026
How companies can defend against AI model extraction attacks
  • Guide

How companies can defend against AI model extraction attacks

Staff July 23, 2026
What is a model inversion attack?
  • Glossary

What is a model inversion attack?

Staff July 22, 2026

Glossary

model router
  • LLMs

What is a model router for AI? A plain-English guide

Staff July 30, 2026
A model router for AI is a decision layer that picks which large language model answers each...
Read more Read more about What is a model router for AI? A plain-English guide
What is agentic SDLC?
  • Glossary

What is agentic SDLC?

Staff July 22, 2026
What is a model inversion attack?
  • Glossary

What is a model inversion attack?

Staff July 22, 2026
LLM system prompt leakage: what it is, how it works, and how to stop it agentic ai
  • Glossary

LLM system prompt leakage: what it is, how it works, and how to stop it

Staff July 15, 2026
What is LLM supply chain security? (OWASP LLM03:2025 explained) llm supply chain
  • Glossary

What is LLM supply chain security? (OWASP LLM03:2025 explained)

Staff July 14, 2026

Guides

The agentic AI security checklist: 12 controls to verify before you deploy
  • Guide

The agentic AI security checklist: 12 controls to verify before you deploy

Staff September 4, 2026
LLM jailbreak defense: techniques that actually stop attacks Jailbreak defense
  • Cybersecurity

LLM jailbreak defense: techniques that actually stop attacks

Staff July 28, 2026
How do enterprises secure AI data pipelines at production scale? safety
  • Cybersecurity

How do enterprises secure AI data pipelines at production scale?

Staff July 28, 2026
How companies can defend against AI model extraction attacks
  • Guide

How companies can defend against AI model extraction attacks

Staff July 23, 2026
What is a model inversion attack?
  • Glossary

What is a model inversion attack?

Staff July 22, 2026
How to prevent adversarial attacks on AI models
  • Guide

How to prevent adversarial attacks on AI models

Staff July 22, 2026
  • Home
  • What’s new in AI
  • Solutions
  • Cybersecurity
  • Learn
Copyright © All rights reserved. | by AF themes.