Home / Knowledge Base / NIST AI RMF
NIST AI 100-1 · AI 600-1

The NIST AI Risk Management Framework, explained.

Where the EU AI Act is law, the NIST AI RMF is a voluntary framework — but it has become the de-facto US baseline for building trustworthy AI. It organises AI risk work into four functions — Govern, Map, Measure, Manage — and its Generative AI Profile (NIST AI 600-1) adapts them to foundation models and agents.

Publisher: NIST (US Dept. of Commerce) Core: AI 100-1 (Jan 2023) GenAI Profile: AI 600-1 (Jul 2024) Status: Voluntary
Overview

What the AI RMF is, and why it exists

The NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0, publication NIST AI 100-1) was released in January 2023 in response to a Congressional direction to help organisations manage the risks of AI. Unlike the EU AI Act, it is voluntary, non-sector-specific, and rights-preserving — a resource, not a regulation. It has nonetheless become the reference baseline that US federal agencies, procurement teams, and enterprises point to when they ask a vendor to "manage AI risk."

Its purpose is to help organisations incorporate trustworthiness into the design, development, use, and evaluation of AI. It is designed to be practical, adaptable to any organisation's size and sector, and to be used across the full AI lifecycle by everyone from data scientists to executives.

Foundations

The characteristics of trustworthy AI

The framework centres on seven characteristics that make an AI system trustworthy. Managing risk means balancing these — they can be in tension, and the right trade-off is context-dependent:

  • Valid & reliable — accurate and robust across expected conditions (the foundation).
  • Safe — does not endanger human life, health, property, or the environment.
  • Secure & resilient — withstands adversarial attack and recovers from adverse events.
  • Accountable & transparent — information is available across the lifecycle to appropriate actors.
  • Explainable & interpretable — the "how" and the "meaning" of outputs can be understood.
  • Privacy-enhanced — safeguards anonymity, confidentiality, and control over data.
  • Fair, with harmful bias managed — addresses systemic, computational, and human-cognitive bias.
The core

The four functions

The RMF Core organises the work into four functions. Govern is a cross-cutting culture-and-process function that runs through the other three; Map, Measure, and Manage form an iterative loop applied throughout the AI lifecycle. Each function breaks into categories and subcategories of concrete outcomes.

Function 1 · cross-cutting

Govern

Cultivate a culture of risk management — the policies, accountability, and structures that make the other three functions work.

  • Policies & processes for mapping, measuring, and managing AI risk.
  • Accountability structures and clear roles/responsibilities.
  • Workforce diversity, competence, and AI literacy.
  • Third-party / supply-chain risk policies.
Function 2

Map

Establish the context and frame the risks — you cannot manage what you have not identified.

  • Context, intended purpose, and setting established.
  • Capabilities, and the AI system inventory, catalogued.
  • Risks and benefits mapped for all components, including third-party.
  • Impacts to individuals, groups, and society characterised.
Function 3

Measure

Analyse, assess, benchmark, and monitor AI risk using quantitative and qualitative methods.

  • Appropriate metrics & methods identified and applied.
  • Trustworthiness characteristics evaluated (safety, security, bias, etc.).
  • Mechanisms for tracking risks over time.
  • Feedback on measurement effectiveness gathered.
Function 4

Manage

Prioritise and act on risks — allocate resources to treat, monitor, and respond.

  • Risks prioritised and treated based on impact.
  • Strategies to maximise benefit, minimise harm planned.
  • Third-party risks managed; incidents responded to and recovered from.
  • Ongoing monitoring & documented response.
The companion Playbook. NIST publishes an AI RMF Playbook with suggested actions, references, and documentation for each subcategory — the practical "how" behind each outcome. It is voluntary and can be adapted to an organisation's needs.
Generative AI

The Generative AI Profile — NIST AI 600-1

In July 2024, in response to the US Executive Order on AI, NIST published a Generative AI Profile (NIST AI 600-1) — a cross-sectoral profile that applies the four functions specifically to generative AI. It identifies 12 risks that are unique to, or amplified by, generative AI, and then lists concrete actions aligned to the Govern/Map/Measure/Manage subcategories to address them.

The twelve risk categories include:

  • CBRN information or capabilities — lowered barriers to chemical, biological, radiological, or nuclear weapons.
  • Confabulation — confidently produced false or misleading "hallucinated" content.
  • Dangerous, violent, or hateful content.
  • Data privacy — leakage or inference of sensitive/personal data.
  • Environmental impacts of training and operating large models.
  • Harmful bias & homogenisation.
  • Human-AI configuration — over-reliance, automation bias, misuse.
  • Information integrity — disinformation, deepfakes at scale.
  • Information security — expanded attack surface, prompt injection, model/​data poisoning, exfiltration.
  • Intellectual property — training-data and output IP exposure.
  • Obscene, degrading, or abusive content (incl. CSAM/NCII).
  • Value chain & component integration — third-party model and data supply-chain risk.
Where Shadow AI Discovery fits. The GenAI Profile's information-security and value-chain risks map directly onto what the sensor discovers — prompt-injection and exfiltration telemetry, unverified MCP/agent provenance, and exposed API keys — providing measurable evidence for the Measure and Manage functions.
Crosswalk

How the RMF maps to the EU AI Act

The frameworks are complementary: the RMF gives you the process to produce much of the evidence the EU AI Act legally requires. A single control effort can satisfy both.

NIST AI RMFAnalogous EU AI Act obligation
Govern — policies, accountability, rolesQuality management system (Art. 17); AI literacy (Art. 4)
Map — context, inventory, impactsRisk identification (Art. 9); classification & intended purpose
Measure — metrics, evaluation, testingTesting & accuracy (Art. 9/15); data governance (Art. 10)
Manage — treat, monitor, respondRisk controls (Art. 9); post-market monitoring (Art. 72)
GenAI Profile — adversarial testing, info-secGPAI evaluation & red-teaming (Art. 55)
Sources

References

Not legal advice. The NIST AI RMF is a voluntary framework; adopting it does not by itself satisfy any statutory obligation. This explainer summarises publicly available NIST materials as of 2025–2026.