NIST AI Risk Management Framework

The NIST AI Risk Management Framework is voluntary for all organizations and organized around four functions: Govern, Map, Measure, and Manage. No law or certification requires adopting it, though several US state AI laws cite it as a compliance benchmark. Organizations use it to structure AI risk programs.

Updated 2026-09-06 · 408 tracked updates

The NIST AI Risk Management Framework provides a voluntary, flexible framework for managing risks associated with AI systems throughout their lifecycle. It is structured around four core functions: Govern, Map, Measure, and Manage.

408
Regulations Tracked
15
Jurisdictions
10
Upcoming Milestones
2026-09-06
Last Updated

Who Needs to Comply?

Any organization worldwide that develops or deploys AI systems — adoption is voluntary for every organization, public or private, with no certification requirement. Several US state AI laws cite it as a benchmark, and international standards bodies reference it.

Key Dates & Timeline

Version 1.0 published January 2023. NIST AI RMF Playbook and Generative AI Profile released throughout 2023-2024. Crosswalk with EU AI Act published 2024.

Upcoming Milestones

2026-10-19

Deadline for public feedback on generative AI-enabled medical devices

FDA continues AI-enabled medical device guidance and submissions workflow updates
2026-10-31

ECB-requested comprehensive action plan for significant institutions

ESRB Warning on systemic cyber risks from frontier AI models
2026-11-01

Singapore AI Safety Red Teaming Challenge 2026 conducted

Artificial Intelligence in Singapore
2026-12-02

Article 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply

Digital Omnibus on AI amends the EU AI Act

Latest NIST AI RMF Updates

guidancehigh2026-09-06

Singapore updates agentic AI governance framework and PDPC personal-data guidance

Singapore has updated its model AI governance framework for agentic AI and already has advisory guidelines for personal-data use in AI recommendation and decision systems, so organizations should refresh governance, human oversight, and data-use controls now.

guidancemedium2026-09-06

FCA confirms no new AI-specific rules for financial services

The FCA says it is not planning AI-specific regulation and will rely on existing frameworks such as Consumer Duty and SM&CR, so firms should focus on fitting AI governance into current control regimes rather than waiting for a new rulebook.

bill-advancedmedium2026-09-06

California AI bills advancing on healthcare and employment automation

California’s 2026 AI bills on healthcare services and automated decision systems advanced late in session, so employers and health providers should continue tracking whether they become enacted obligations.

guidancelow2026-09-06

SEC announces internal AI task force

The SEC announced an internal AI task force on 1 August 2025 to coordinate responsible AI adoption across the agency; the announcement does not introduce a new external compliance obligation.

enforcementhigh2026-09-06

FTC AI enforcement actions on deceptive claims and substantiation

These records cover separate FTC proceedings concerning AI claims, an AI companion chatbot inquiry, and the later setting aside of the Rytr order; they do not establish a common new compliance deadline.

guidancehigh2026-09-06

NIST AI RMF revision and critical-infrastructure profile development

NIST says the AI RMF is being revised and that a new trustworthy-use profile for critical infrastructure is under development, while the baseline AI RMF 1.0 remains voluntary and headed for review no later than 2028.

guidancehigh2026-09-06

ISO/IEC 42006:2025 defines requirements for AI management system certification bodies

ISO/IEC 42006:2025 supplements the requirements for bodies auditing and certifying AI management systems against ISO/IEC 42001; the ISO catalog records its publication in July 2025.

consultationhigh2026-09-06

AI Act consultations and implementation guidance for GPAI, sandboxes, and transparency

The Commission has opened or advanced multiple AI Act implementation workstreams for GPAI, high-risk classification, transparency, and regulatory sandboxes, meaning providers and deployers must now align their implementation plans to the emerging guidance rather than wait for finalised national practice.

bill-introducedmedium2026-08-30

California AI health-care bills and transparency bill advance in the 2026 session

Several California AI bills were active in late August 2026, including health-care AI and transparency measures moving through amendments and enrollment, meaning California-facing AI teams should monitor final text closely for new obligations.

consultationmedium2026-08-30

EU AI Act implementation consultations advance on GPAI, transparency, high-risk classification and sandboxes

The Commission’s AI Act consultations on GPAI, transparency obligations, high-risk classification, sandboxes, and the scientific panel show that the operational rulebook is still being finalized, so affected providers should engage now to shape interpretation.

Jurisdiction Coverage

Related Frameworks

Key Topics

Frequently Asked Questions

Is the NIST AI RMF mandatory and how is it used?

The NIST AI Risk Management Framework is voluntary for all organizations and organized around four functions: Govern, Map, Measure, and Manage. No law or certification requires adopting it, though several US state AI laws cite it as a compliance benchmark. Organizations use it to structure AI risk programs.

What is the NIST AI RMF?

The NIST AI Risk Management Framework is a voluntary framework developed by the US National Institute of Standards and Technology for managing risks in AI systems. It provides a structured approach organized around four functions: Govern, Map, Measure, and Manage.

Is the NIST AI RMF mandatory?

No — the NIST AI RMF is voluntary for all organizations, public and private; no law or certification requires adopting it. Several US state AI laws cite it as a compliance benchmark, and organizations worldwide use it to structure AI risk programs.

How does NIST AI RMF compare to ISO 42001?

NIST AI RMF is a risk management framework focused on AI-specific risks, while ISO 42001 is a management system standard. NIST AI RMF is more prescriptive about risk categories and measurement, while ISO 42001 is more focused on organizational processes. They are complementary — many organizations adopt both.

Keep exploring

This hub tracks published actions referencing the NIST AI RMF; the framework itself is voluntary, and this page is not legal or accreditation advice.