NIST AI Risk Management Framework

Also known as: NIST AI RMF

framework · cybersecurity · regulatory-standard

NIST's voluntary framework for managing AI risks across govern, map, measure, and manage functions, released January 2023 with a generative AI profile in 2024.

The NIST AI Risk Management Framework (AI RMF) is the voluntary risk-management framework for artificial intelligence systems published by the National Institute of Standards and Technology (NIST) in January 2023 as AI RMF 1.0, mandated by the National Artificial Intelligence Initiative Act of 2020 (Public Law 116-283). The framework provides guidance for organizations designing, developing, deploying, or using AI systems to identify and manage AI-specific risks while supporting trustworthy AI. The framework is structured around four core functions — Govern, Map, Measure, Manage — paralleling the structure of the NIST Cybersecurity Framework. NIST released the AI RMF Playbook providing practical guidance on function implementation, the AI RMF Crosswalk mapping the framework to other standards (ISO/IEC 42001, EU AI Act, OECD AI Principles), and subsequent generative-AI profile (July 2024) addressing generative AI specifically. The framework is voluntary rather than regulatory, providing consensus-based guidance rather than enforceable requirements, with implementation supported through the NIST Trustworthy and Responsible AI Resource Center.

Originators

National Institute of Standards and Technology (NIST), particularly NIST Information Technology Laboratory; Mandated by National Artificial Intelligence Initiative Act of 2020 (Public Law 116-283); AI RMF 1.0 released January 2023 after substantial public-comment process and multiple drafts (RFI 2021, concept paper 2021, initial draft 2022, second draft 2022, final RMF 2023); Subsequent: AI RMF Playbook, AI RMF Crosswalk, Generative AI Profile (NIST AI 600-1, July 2024), ongoing NIST Trustworthy and Responsible AI Resource Center (AIRC) development; intellectual antecedents in NIST Cybersecurity Framework (2014 onward), NIST Privacy Framework (2020), NIST Risk Management Framework (NIST SP 800-37), broader risk-management tradition, academic and industry trustworthy-AI literature (NIST AI 100 series special publications) high

Year / Decade

2023 (AI RMF 1.0 release in January 2023); 2024 (Generative AI Profile); ongoing development high

Primary sources

NIST (January 2023). AI Risk Management Framework (AI RMF 1.0), NIST AI 100-1, NIST (January 2023). AI RMF Playbook (companion implementation guidance), NIST (July 2024). Artificial Intelligence Risk Management Framework: Generative AI Profile, NIST AI 600-1, National Artificial Intelligence Initiative Act of 2020 (Public Law 116-283, foundational legislative mandate) high

Core components

Primary use case

Voluntary risk-management framework for AI system design, development, deployment, and use across industries; applied principally in: enterprise AI governance program design (substantial adoption since 2023 release across financial services, healthcare, technology, government); federal-government AI implementation supporting Executive Order 14110 (October 2023) AI safety and security mandate (though E.O. 14110 was rescinded January 2025, AI RMF continues as foundational framework); AI governance reference in state-level AI legislation (Colorado AI Act, California AI bills); third-party AI risk-management standards (ISO/IEC 42001 alignment); industry AI safety initiatives; academic and professional reference in AI ethics, AI governance, AI risk management, and AI policy literature; complementary to (and crosswalked with) NIST Cybersecurity Framework, NIST Privacy Framework, ISO/IEC 42001, EU AI Act, OECD AI Principles, Singapore Model AI Governance Framework, AI Bill of Rights; input to AI assurance and AI audit practices; NIST Trustworthy and Responsible AI Resource Center (AIRC) provides ongoing implementation support.

Common criticisms

Lineage

Siblings
NIST Cybersecurity Framework, NIST Privacy Framework, NIST Risk Management Framework, EU AI Act, OECD AI Principles, Singapore Model AI Governance Framework, AI Bill of Rights