AI Policy Wiki
Dashboard

National Institute of Standards and Technology (NIST)

medium confidence · updated 2026-08-12

Federal agency within the U.S. Department of Commerce that develops measurements, standards, and technology guidance. Publisher of the AI Risk Management Framework (AI RMF 1.0) and NIST AI 600-1 Generative AI Profile; host of the U.S. AI Safety Institute.

The National Institute of Standards and Technology (NIST) is a non-regulatory federal agency within the U.S. Department of Commerce that develops measurements, standards, and technology guidance. In AI policy it is the publisher of the AI Risk Management Framework (AI RMF 1.0) and the NIST AI 600-1 Generative AI Profile, and the host of the U.S. AI Safety Institute. Its publications are voluntary standards unless incorporated into law or regulation by another authority.

TypeNon-regulatory federal agency within the U.S. Department of Commerce
HeadquartersGaithersburg, Maryland (with Boulder, CO campus)
Founded1901 (as the National Bureau of Standards)
Director (2024)Laurie E. Locascio (at publication of NIST AI 600-1)
Director (2026)Arvind Raman, Under Secretary of Commerce for Standards and Technology and NIST Director (Source: nist.gov)

Mandate

NIST develops measurements, standards, and technology to advance innovation and competitiveness. It is non-regulatory: its publications are voluntary standards unless incorporated into law or regulation by another authority.

AI frameworks and profiles

AI Risk Management Framework (AI 100-1)

Published January 26, 2023, the AI RMF 1.0 is among the closest things to a federal AI governance baseline in the US. It organizes AI risk management around four functions: Govern, Map, Measure, and Manage. State laws including SB 53 and the Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) incorporate NIST standards by reference, and private-sector responsible-scaling policies (Anthropic's Responsible Scaling Policy (Version 3.1), OpenAI Preparedness Framework V.2) map onto its vocabulary.

NIST AI 600-1 — Generative AI Profile

The Generative AI Profile was published July 26, 2024 pursuant to Executive Order 14110 — Safe, Secure, and Trustworthy AI § 4.1(a)(i)(A). A cross-sectoral profile of the AI RMF for generative AI, it defines 12 GAI risk categories and more than 200 suggested actions across the RMF functions. It was not withdrawn after EO 14110 was rescinded in January 2025.

Critical-infrastructure profile

A concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure was released April 7, 2026, forming a parallel sector-profile track alongside the agent initiative.

U.S. AI Safety Institute and consortium

The U.S. AI Safety Institute (US AISI) was established within NIST under EO 14110 as the US counterpart to the UK AI Safety Institute. It conducts evaluations of frontier models, including capability evaluations, red-teaming, and safety testing, and publishes technical reports. It was restructured under the Trump administration in 2025 but functionally persists.

NIST also convenes the AI Safety Institute Consortium (AISIC), a public-private consortium including frontier AI labs, civil-society organizations, and government partners.

Center for AI Standards and Innovation (CAISI)

CAISI is the NIST sub-entity that hosts the AI Agent Standards Initiative launched February 17, 2026. It coordinates with NSF and interagency partners on industry-led agent standards, open-source agent protocols (via NSF's POSE program), and research on agent security and identity. As of April 2026, active CAISI workstreams include the RFI on AI Agent Security (closed March 9), the NCCoE concept paper on Software and AI Agent Identity and Authorization (closed April 2), sector listening sessions in healthcare, finance, and education, and a planned Q4 2026 AI Agent Test Suite.

On April 27, 2026, the Commerce Department confirmed selection of Chris Fall, a veteran of the first Trump administration, to lead CAISI (Source: insideaipolicy.com).

Evaluation programs

NIST states its AI role as promoting innovation and cultivating trust in the design, development, use, and governance of AI technologies and systems (Source: nist.gov). Its standing measurement programs include the Face Recognition Technology Evaluation (FRTE) for face-recognition systems and the NIST GenAI evaluation program for generative AI, alongside work on bias in automated decision-making and related technical guidance (Source: nist.gov).

Artificial Intelligence Technology Evaluation (AITE)

NIST is rolling out an Artificial Intelligence Technology Evaluation initiative offering volunteer, first-come first-served testing of AI models on blind data in a sequestered environment, with results to be published. NIST states the sequestered design "mitigates the risk of train/test data contamination" — the failure mode that has made public benchmark scores hard to interpret as capability measurements. The initiative was reported on July 29, 2026; only the lede of the trade-press account was retrievable, so eligibility criteria, the model categories covered, and the publication schedule are not recorded here (Source: insideaipolicy.com). See AI Benchmarks and Evaluation.

Other AI-relevant publications and activity

NIST issued a draft publication on the AI data center threat landscape for public comment, reported July 28, 2026, stating that "there is a lack of established standards, guidelines, and best practices specifically for AI data center security." Only the lede of the trade-press account was retrievable, so the draft's publication number, scope, and comment deadline are not recorded here (Source: insideaipolicy.com). See AI and Cybersecurity, Data Center Siting / AI Power Politics.

AI Standards Zero Drafts pilot and NIST AI 300-1

NIST announced the AI Standards Zero Drafts project in March 2025. Under the pilot, NIST collects input on "topics with a science-backed body of work," develops a preliminary stakeholder-driven draft standard, and then submits it "via the private sector–led standardization process as proposals for voluntary consensus standards" — routing U.S. input into private-sector bodies rather than producing another NIST-maintained framework. Two topics were selected from community input.

The first published output is NIST AI 300-1, Guidance and Templates for Public-Facing AI Documentation, released as an initial public draft in July 2026 and authored by Razvan Amironesei and Jesse Dunietz (NIST AI 300-1 ipd — Guidance and Templates for Public-Facing AI Documentation (initial public draft, July 2026); topic page NIST AI 300-1 — Guidance and Templates for Public-Facing AI Documentation). The 54-page draft covers documentation of AI datasets and models intended for public release, and supplies process guidance, a seven-field dataset template and an eight-field model template against which conformity can be assessed, and a mechanism for extending them via profiles. It is written in ISO/IEC drafting conventions for submission to INCITS/AI, the private-sector-led committee representing the United States in ISO/IEC JTC 1/SC 42, and NIST states it "does not expect to maintain the document further" once it enters that process, expecting to be "just one voice among many." Comments are invited to ai-standards+doczd@nist.gov; NIST states it "will consider input received by September 16, 2026."

The document's scope excludes documentation of whole AI systems and of components shipped alongside a model, such as guardrail classifiers. Its foreword states that NIST "will publish a final and complete version of this document based on feedback received"; a trade-press account of August 3 characterised the draft as "an initial and potentially final version," a phrase that does not appear in the document, whose only statement in that direction is that NIST will not maintain it after handoff (Source: insideaipolicy.com). NIST's own AI Standards page dates the release to July 29, 2026; the same trade-press item gives July 30, and the PDF cover carries only "July 2026." See ISO/IEC 42001 — AI Management System, NIST AI Risk Management Framework 1.0, AI Transparency.

Proposed AI evaluation guidelines (August 2026)

NIST proposed guidelines on August 7, 2026 for evaluating AI systems and opened them for public comment, saying the guidelines are for organizations that want to "measure the impact of their AI systems." Ike Harris, executive director of the Washington-based Frontier Security Institute, called them "the first step in standardizing the way the federal government evaluates AI systems both for itself and for its contractors." The proposal arrived the same day President Trump said Congress wants to regulate the AI industry "out of business," a juxtaposition the reporting draws directly (Source: yahoo.com).

The instrument is NIST AI 200-2, "The TEVV-Athlon Framework for Evaluating AI Systems," issued as an initial public draft. It sets out a four-stage method for developing customised assessments of AI systems from an organisation's test, evaluation, verification and validation objectives, covering statistical machine learning models, large language models, multi-modal models and agentic systems, and invites input on six questions. The 60-day comment period opened August 7, 2026 and closes October 6, 2026, with comments directed to TEVV-Athlon@nist.gov under the subject line "NIST AI 200-2" (NIST AI 200-2 ipd — The TEVV-Athlon Framework for Evaluating AI Systems (initial public draft, August 2026)). See AI Benchmarks and Evaluation, Government AI Procurement.

NIST SP 800-53 Release 5.2.0, published August 27, 2025, is not AI-specific but adds controls (SA-24 Design for Cyber Resiliency, SI-02(07) Root Cause Analysis, SA-15(13) Logging Syntax) that federal AI systems, including agent systems, inherit. The release responds to EO 14306 on software resiliency.

A workshop on "Securing AI Data Center: Architecture, Security Posture, and Emerging Standards" is scheduled for July 22, 2026, extending NIST's AI security work to data-center infrastructure (Source: nist.gov). NIST's semiconductor programs also intersect with AI: in June 2026 the Commerce Department announced a definitive agreement with SandboxAQ for a $500 million CHIPS R&D award to accelerate AI-driven semiconductor materials discovery (Source: nist.gov).

NIST published a request for information on modernizing the National Vulnerability Database by integrating artificial intelligence capabilities, set for publication in the Federal Register on August 12, 2026. NIST states it "seeks stakeholder input on opportunities, challenges, and priorities for modernizing the NVD in an evolving cybersecurity landscape increasingly shaped by artificial intelligence and machine-consumable security data," as the program continues to face increased demand for enrichment (Source: insideaipolicy.com). See AI and Cybersecurity.

Relationship to other agencies and frameworks

Within Commerce, NIST is non-regulatory; regulatory authority on compute exports sits with BIS. OMB AI policy (M-24-10, M-24-18) builds on NIST frameworks for federal agency adoption, and sector regulators including the FDA, FAA, EEOC, and CFPB reference NIST frameworks in domain-specific guidance.

At the state level, California SB 53 — Transparency in Frontier AI Act, Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment), and State AG AI Guidances (CA, NJ, MA, OR) reference NIST standards. Internationally, NIST coordinates with ISO/IEC standards bodies on AI management (for example, ISO/IEC 42001).

Relationships

Sources