NIST AI Risk Management Framework
The NIST AI Risk Management Framework provides a voluntary, flexible framework for managing risks associated with AI systems throughout their lifecycle. It is structured around four core functions: Govern, Map, Measure, and Manage.
Who Needs to Comply?
US federal agencies (mandated), and any organization worldwide that develops or deploys AI systems (voluntary adoption). Widely referenced by US state AI legislation and international standards bodies.
Key Dates & Timeline
Version 1.0 published January 2023. NIST AI RMF Playbook and Generative AI Profile released throughout 2023-2024. Crosswalk with EU AI Act published 2024.
Latest NIST AI RMF Updates
NIST AI Resource Center operationalization support
NIST’s AI Resource Center is an implementation hub for operationalizing the AI RMF, so compliance teams should use it as a support source rather than a source of new obligations.
NIST AI RMF 1.0 overview and playbook update signal
NIST’s AI RMF overview confirms the framework remains AI RMF 1.0 and says the Playbook will be enhanced, so the current change is to supporting materials rather than the base framework.
NIST AI RMF critical infrastructure profile concept note
On 2026-04-07 NIST released a concept note for a trustworthy AI in critical infrastructure profile, indicating active profile development that regulated operators should monitor now.
White House AI Action Plan reference in NIST AI materials
NIST’s AI hub notes it was named in the White House’s July 23, 2025 AI Action Plan, signaling policy direction rather than a direct legal change to the AI RMF itself.
NIST draft misuse-risk guidance targets dual-use foundation models
NIST’s draft guidance on dual-use foundation models may affect model governance and testing workflows, so teams should treat it as an emerging reference for misuse-risk management even though it is not itself an AI RMF update.
NIST generative AI profile remains a key AI RMF companion resource
NIST’s July 26, 2024 Generative AI Profile remains a key companion to AI RMF 1.0, so organizations using GenAI should continue to map controls to the profile’s risk scenarios and governance themes.
NIST AI RMF development hub remains the authoritative framework source
NIST’s development page serves as the official baseline for AI RMF 1.0 and related resources, so teams should use it as the authoritative source for the framework’s scope and companion materials.
NIST ITL AI Program confirms concept note and agentic AI evaluation work
NIST’s ITL AI Program page reiterates the April 7, 2026 concept note and a related webinar on agentic AI evaluation probes, indicating the next wave of AI RMF work is focused on testing and evaluation infrastructure.
NIST releases concept note for AI RMF Profile on Trustworthy AI in Critical Infrastructure
On April 7, 2026, NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, which means critical-infrastructure AI programs should start aligning risk assessments and evaluation workflows to the emerging profile now.
NIST updated guidelines for managing misuse risk for dual-use foundation models
NIST’s second public draft on dual-use foundation-model misuse risk closed for comments on March 15, 2025, making it an important adjacent reference for foundation-model governance even though it is not the AI RMF itself.
Jurisdiction Coverage
Related Frameworks
Key Topics
Frequently Asked Questions
What is the NIST AI RMF?
The NIST AI Risk Management Framework is a voluntary framework developed by the US National Institute of Standards and Technology for managing risks in AI systems. It provides a structured approach organized around four functions: Govern, Map, Measure, and Manage.
Is the NIST AI RMF mandatory?
For US federal agencies, adherence to NIST AI RMF is mandated by executive orders. For private sector organizations, it is voluntary but increasingly referenced in US state AI legislation and industry standards as a best-practice benchmark.
How does NIST AI RMF compare to ISO 42001?
NIST AI RMF is a risk management framework focused on AI-specific risks, while ISO 42001 is a management system standard. NIST AI RMF is more prescriptive about risk categories and measurement, while ISO 42001 is more focused on organizational processes. They are complementary — many organizations adopt both.
Weekly digest
Leave your email to get each issue in your inbox. Free, no account required.
We use your email only for the digest. Privacy policy