AI Policy Wiki
Dashboard

NIST AI Risk Management Framework 1.0

high confidence · updated 2026-07-26

US federal voluntary AI risk-management framework (January 2023). Four core functions — Govern, Map, Measure, Manage. The most-cited domestic AI governance baseline: anchors OMB M-24-10 federal procurement, threads through Colorado AI Act 'reasonable care,' Trump-era EO 14110 and its 2025 rescission, the lab-side RSP / Preparedness frameworks, and the Anthropic / OpenAI Illinois SB 315 endorsements. Updated by the Generative AI Profile (NIST AI 600-1, July 2024) and the previewed Generative-AI-with-agent-guidance profile (April 2026).

The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary, non-regulatory framework for managing risks across the AI lifecycle, published by the National Institute of Standards and Technology on January 26, 2023. It organizes AI risk-management activity around four core functions — Govern, Map, Measure, and Manage — and carries no certification or enforcement mechanism. It is widely referenced across U.S. federal procurement, state legislation, and corporate governance programs.

Published: January 26, 2023 Publisher: National Institute of Standards and Technology (NIST), U.S. Department of Commerce Authorizing statute: National AI Initiative Act of 2020 (Section 5301; 15 U.S.C. § 9401 et seq.), which directed NIST to develop a voluntary AI risk-management framework Type: Voluntary framework (non-regulatory; no certification, no enforcement) Document ID: NIST AI 100-1 Direct citation: Tabassi, Elham. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.100-1

Scope

The AI RMF provides organizations with a voluntary, rights-preserving, non-sector-specific framework to manage AI risks. It is designed for use by AI developers, deployers, and users across public and private sectors. The framework takes no position on individual risk thresholds: it provides the process by which risks are governed, mapped, measured, and managed, leaving the substance of acceptable-risk thresholds to the implementing organization. It tells organizations how to manage AI risk but does not tell them which risks to accept; the threshold-setting is delegated to the organization (in voluntary use), to procurement officials (in OMB context), to courts (in Colorado AI Act "reasonable care" context), or to legislatures (in EU AI Act context).

The drafting process was statutorily required to be open and consensus-based. The published version followed two public drafts (March 2022, August 2022), more than 240 individual and organizational comments, and a series of public workshops. NIST and outside commentators have cited this open process as a basis for treating the RMF as a legitimate U.S. federal AI-governance reference despite its lack of enforcement provisions.

Four core functions

The RMF organizes AI risk-management activity around four functions, each with categories and subcategories. The functions are presented as an iterative loop, not a sequence.

FunctionPurposeRepresentative activities
GovernCultivate AI risk-management culture; policies, accountability, workforce; cross-cutting.Set risk-tolerance policy; assign roles; embed AI risk in enterprise risk management; oversight of third-party AI.
MapEstablish context, scope, categorize AI risks; understand stakeholders and use cases.Document the AI use case; classify the system; identify affected groups; identify the data lineage; identify the assumptions and limitations.
MeasureAssess, analyze, track AI risks using metrics and evaluation tools.Run pre-deployment evaluations; ongoing monitoring; bias and fairness testing; robustness testing; benchmark against test sets.
ManagePrioritize and act on risks; plan responses; communicate residual risks.Prioritize identified risks; respond (mitigate / transfer / accept); document residual risk; plan incident response; communicate trade-offs to stakeholders.

Each function has subcategories with specific activities and outcomes documented in the AI RMF Playbook, an online companion. The RMF resembles the NIST Cybersecurity Framework (CSF) structurally — Govern, Identify, Protect, Detect, Respond, Recover — the most widely adopted voluntary U.S. cyber-governance framework. NIST has described the choice as deliberate: the CSF showed that a non-regulatory NIST framework can become a de facto standard through private-sector and procurement-side adoption. The CSF became the de facto U.S. cyber baseline despite being voluntary, and NIST has published a CSF-to-AI-RMF crosswalk that reinforces the structural parallel. The Govern function added to CSF 2.0 in 2024 mirrors the AI RMF's Govern function.

Companion documents and updates

The first companion profile, NIST AI 600-1 — Generative AI Profile (July 2024), extends the AI RMF specifically to generative AI risks, including confabulation, hallucination, dangerous-uplift, IP and copyright, malicious-actor abuse, and environmental impact. It is the most-referenced sub-framework for U.S. frontier-model governance discussions.

NIST previewed an AI RMF Profile for Generative AI v2 on April 22, 2026, adding agent-specific guidance in line with the NIST CAISI agent standards initiative. The v2 update is the first NIST-side profile to incorporate agent architecture concepts such as agent identity, multi-agent orchestration risks, and tool-use safety (Source: nist.gov). The underlying NIST AI Agent Standards Initiative (2026) (Agent Standards Initiative, February 2026) is the CAISI-led NIST initiative on agent security and identity that the v2 GenAI Profile incorporates.

On April 7, 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, intended to "guide critical infrastructure operators towards specific risk management practices to consider when engaging AI-enabled capabilities" — extending the profile mechanism from a technology class (generative AI, agents) to a deployment sector for the first time. NIST's framework page also states that "the AI RMF 1.0 is being revised," so the January 2023 core document is itself under revision alongside the profile work (Source: nist.gov).

NIST also maintains supplementary materials — the AI RMF Roadmap, Crosswalks, and Playbook — including crosswalks to ISO/IEC standards (notably ISO/IEC 42001) and to the OECD AI Principles. The framework has been translated into Arabic and Japanese, and the Trustworthy and Responsible AI Resource Center launched March 30, 2023 to "facilitate implementation of, and international alignment with, the AI RMF" (Source: nist.gov).

NIST AI Consortium relaunch

Inside AI Policy reported on May 29, 2026 that NIST relaunched its voluntary AI industry consortium under a "measurement science" mandate aligned with the Trump administration's accelerated-deployment agenda, recasting a body originally chartered under the Biden-era AI Safety Institute (Source: insideaipolicy.com). The relaunch reframes the consortium's official mission away from the AISI-era "safety" framing toward "measurement science," a NIST-native vocabulary aligned with the agency's statutory measurement-and-standards remit. The Inside AI Policy reporting noted that the shift bears on what the consortium publishes (eval methodology and measurement protocols rather than safety guidance) and who joins (a broader industry tent rather than the original AISI safety-and-evaluation-firm set).

Inside AI Policy paired the relaunch with the administration's broader pro-deployment posture, including the America's AI Action Plan and the draft preemption EO. Whether the consortium retains the original AISI's evaluation depth or shifts to a lighter-touch industry forum was not resolved in the reporting. The relaunch interacts with the Illinois SB 315 third-party-audit requirement passed the same week: if the NIST consortium publishes operational measurement protocols that lab third-party auditors adopt, the federal-side "measurement science" frame and the state-side audit framework would converge; otherwise, Illinois would rely on private audit firms developing the methodology independently. The CCIA's May 28 letter stated that "no credible or standardized ecosystem currently exists to conduct the type of independent audits envisioned."

Relation to other frameworks

FrameworkRelationship
ISO/IEC 42001 — AI Management SystemComplementary; ISO 42001 is certifiable, AI RMF is voluntary. Both organize AI governance systematically. NIST publishes a crosswalk.
ISO/IEC 42005 — AI Impact AssessmentThe ISO AI-impact-assessment standard complements AI RMF's Map and Measure functions.
EU AI Act (Regulation 2024/1689)AI RMF compliance may partially satisfy some EU AI Act requirements but is not recognized as a formal compliance pathway. The EU AI Act's risk-tiered structure is more prescriptive than the RMF's process-based structure.
OMB M-24-10The Biden-era OMB memo on federal AI use explicitly anchors risk management on the AI RMF. The Trump-era OMB M-25-21 / M-25-22 memos (issued April 2025) reshape but do not displace this anchor.
Colorado AI Act (SB 24-205)References "reasonable care" — AI RMF adherence is widely treated as evidence of reasonable care under the Act's anti-discrimination provisions.
Illinois SB 315 (frontier safety framework with mandatory third-party audits)The first state-level bill (signed pending in May 2026) to require third-party audits of frontier-model safety frameworks; the audit standard is widely expected to map to the AI RMF's Manage / Measure functions plus the NIST AI 600-1 GenAI Profile.
**[[concepts/responsible-scaling-policyAnthropic RSP]] / [[sources/openai-preparedness-frameworkOpenAI Preparedness Framework]]**Lab-specific frameworks that map to a subset of the AI RMF (primarily Map and Measure for catastrophic risks).
**[[sources/frontier-compliance-frameworkFrontier compliance frameworks]]**The structural pattern of voluntary U.S. frontier-AI governance — RSP, Preparedness, the lab-side safety-frameworks — broadly inherits from the AI RMF's process orientation.

The AI RMF's voluntary status carries both advantages and limits frequently noted in commentary: it is flexible, non-burdensome, and adoptable globally without statutory authority, but provides no enforcement, no certification, and no legal safe harbor. The voluntary posture has been associated with NIST's apolitical reputation; the framework survived the Biden-to-Trump transition with EO 14110 rescinded but the AI RMF intact and its updates continuing.

Adoption and use

Federal procurement (OMB M-24-10), Trump-era EO references, state legislation including the Colorado AI Act and Illinois SB 315, and corporate governance programs anchor on AI RMF terminology and structure.

At the federal level, OMB M-24-10 (Biden) and the Trump-era OMB M-25-21 and M-25-22 (April 2025) both treat the AI RMF as the operative federal AI risk-management vocabulary. At the state level, Colorado, California, New York, Illinois, and Texas AI bills reference the AI RMF either explicitly or via "reasonable care" or "industry standard" terminology that practitioners read as AI RMF-shaped.

Among AI labs, Anthropic and OpenAI both cite AI RMF terminology in their safety frameworks and in public testimony, including in their May 14–15, 2026 endorsements of Illinois SB 315 (frontier safety framework with mandatory third-party audits), the first state-level bill to require mandatory third-party audits, which are expected to operationalize against the AI RMF and the GenAI Profile.

Internationally, the OECD has cross-walked the AI RMF against the OECD AI Principles. The UK AISI references the AI RMF in its safety-case framework. The EU AI Act's "harmonized standards" track is expected to incorporate AI-RMF-influenced provisions via ISO/IEC.

Relationships

Sources

  • NIST — "AI Risk Management Framework 1.0" (NIST AI 100-1), January 26, 2023 (Source: doi.org)
  • NIST — "AI Risk Management Framework: Generative AI Profile" (NIST AI 600-1), July 26, 2024 (Source: nvlpubs.nist.gov)
  • NIST — AI RMF Profile for Generative AI v2 (preview), April 22, 2026 (Source: nist.gov)
  • National AI Initiative Act of 2020 (15 U.S.C. § 9401 et seq.) — statutory authority for AI RMF (Source: congress.gov)
  • NIST AI RMF Crosswalks page (against ISO/IEC, OECD, and CSF) (Source: nist.gov)