AI Policy Wiki
Dashboard

NIST AI Risk Management Framework (AI RMF 1.0)

medium confidence · updated 2026-07-14

Federal voluntary framework for managing AI risks organized around four functions — Govern, Map, Measure, Manage — providing a common vocabulary and structured approach to AI trustworthiness and risk management.

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework for managing risks associated with artificial intelligence, published by the U.S. National Institute of Standards and Technology (NIST) on January 26, 2023 as NIST AI 100-1 (DOI 10.6028/NIST.AI.100-1; canonical text at nvlpubs.nist.gov) (Source: nist.gov). It provides a common vocabulary and a structured approach to AI trustworthiness and risk management, and is treated as a living document with the next review expected by 2028. NIST's framework page states, as of its June 2026 update, that "the AI RMF 1.0 is being revised" (Source: nist.gov).

Development and companion resources

The framework was developed by NIST's Information Technology Laboratory AI program through a consensus-driven, open process that included a Request for Information (July 29, 2021), a concept paper (December 2021), initial and second public drafts (March 17 and August 18, 2022), public comment rounds, and multiple workshops (Source: nist.gov). NIST publishes companion resources alongside the framework: the AI RMF Playbook, an AI RMF Roadmap, crosswalks to other frameworks, and a Perspectives collection. On March 30, 2023, NIST launched the Trustworthy and Responsible AI Resource Center (AIRC) to facilitate implementation of, and international alignment with, the AI RMF. Official Arabic and Japanese translations of the framework have been published (Source: nist.gov).

Structure

The framework is divided into two parts. Part 1 (Foundational Information) covers framing risk, understanding harms, and the challenges of AI risk measurement, and sets out a set of AI trustworthiness characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair (with managed harmful bias).

Part 2 (the AI RMF Core) is organized around four functions:

FunctionPurpose
GovernCultivate organizational risk culture; establish policies, processes, accountability
MapContextualize AI risks — understand the AI system, its context, and potential impacts
MeasureEmploy quantitative and qualitative methods to assess AI risks
ManageAllocate resources and respond to mapped and measured risks on a regular basis

Role in U.S. AI governance

The AI RMF is the closest the United States has to a federal AI governance standard, providing a common vocabulary and structured approach that several state laws and attorney-general guidances reference. Both SB 53 and the Colorado AI Act incorporate NIST standards by reference, and multiple state laws cite the framework as a safe harbor or best-practice benchmark.

The AI RMF is voluntary, positioning it as a complement to rather than a substitute for mandatory approaches such as transparency legislation, product liability, and anti-discrimination requirements. The relationship between voluntary and mandatory governance is contested: Amodei argues that voluntary practices are insufficient because not all companies follow them.

The framework also supplies the technical risk-management vocabulary that underpins risk categories including AI Autonomy Risk and AI Biosecurity. Its Govern–Map–Measure–Manage structure reflects a transparency-first sequencing in which risks are mapped and measured before being managed.

Post-RMF-1.0 developments

NIST's AI guidance line continued after RMF 1.0. The NIST AI 600-1 — Generative AI Profile (July 26, 2024) is an RMF profile for generative AI with 12 risk categories and more than 200 suggested actions; it applies the four Core functions to generative-AI-specific risks. SP 800-53 Release 5.2.0 (August 27, 2025) adds controls SA-24 (Design for Cyber Resiliency), SI-02(07) (Root Cause Analysis), and SA-15(13) (Logging Syntax); these are not AI-specific but are inherited by federal AI systems. The NIST AI Agent Standards Initiative (February 17, 2026) is a CAISI-led umbrella initiative extending the NIST line into the agent era, organized around industry standards, open-source protocols, and agent security and identity research, and continuing the work begun with AI 600-1. A parallel sector track is the AI RMF Profile on Trustworthy AI in Critical Infrastructure, issued as a concept note on April 7, 2026.

Provenance

This page summarizes NIST AI 100-1 (January 2023), authored by the National Institute of Standards and Technology. Related NIST documents are covered on separate pages: NIST AI 600-1 — Generative AI Profile, the Generative AI Profile (July 2024) that applies the four Core functions to generative-AI-specific risks, and NIST AI Agent Standards Initiative (Feb 2026), the NIST AI Agent Standards Initiative (February 2026) extending the framework into the agent era.