Jump to content

NIST AI Risk Management Framework: Difference between revisions

From AI Law Wiki
Expand NIST framework: legal status, trustworthiness, core functions, implementation and generative AI guidance
Remove redundant top-of-page navigation row at Craig’s request
 
(One intermediate revision by the same user not shown)
Line 1: Line 1:
<div class="ailaw-legislation-nav" style="font-size:0.92em; margin-bottom:1.2em;">[[Legislation and Regulation|Legislation & Regulation]] · [[United States Federal Authorities|Federal]] · [[AI Law by Topic|Browse by topic]]</div>
<!-- AILAW-LEGISLATION-START -->
<!-- AILAW-LEGISLATION-START -->
<div class="ailaw-legislation-layout" style="display:flex; flex-wrap:wrap; gap:1.5em; align-items:flex-start;">
<div class="ailaw-legislation-layout" style="display:flex; flex-wrap:wrap; gap:1.5em; align-items:flex-start;">
Line 80: Line 78:


== Related articles ==
== Related articles ==
* [[AI Policy]]
* [[Policy]]
* [[United States Federal Authorities]]
* [[United States Federal Authorities]]
* [[National Artificial Intelligence Initiative Act of 2020]]
* [[National Artificial Intelligence Initiative Act of 2020]]

Latest revision as of 21:33, 12 September 2026

Law & policy information
Name
NIST AI Risk Management Framework (AI RMF 1.0)[1]
Jurisdiction
United States — federal guidance; designed for use across sectors[2]
Instrument type
Voluntary risk-management framework[2]
Bill / legal citation
NIST AI 100-1[1]
Legislative or adoption status
Version 1.0 released January 26, 2023; NIST reports revision work underway.[3]
Effective dates
Voluntary guidance; publication is not a statutory commencement date.[2]
Last source verification
September 11, 2026 — framework, companion resources, and NIST revision notice.[3]

Overview

The NIST AI Risk Management Framework (AI RMF) is voluntary guidance from the U.S. National Institute of Standards and Technology for organizations that design, develop, acquire, deploy, or use artificial intelligence. Version 1.0 organizes risk management around four functions—Govern, Map, Measure, and Manage—and addresses harms to individuals, organizations, communities, and society. It is intended to be rights-preserving, usable across sectors, and adaptable to different applications and organizational resources.[2]

Its central premise is that AI risk depends on the entire system and the context in which people use it. A technically accurate model can still cause harm through unsuitable deployment, inadequate oversight, or effects on people outside its immediate user base. NIST therefore treats AI as a socio-technical system and calls for risk management throughout its lifecycle.[4]

NIST developed the framework pursuant to the National Artificial Intelligence Initiative Act of 2020. The AI RMF itself is voluntary guidance, rather than a statute or binding regulation. It does not prescribe a universal acceptable level of risk: users must take account of applicable laws, sector requirements, and the particular deployment context when determining risk tolerance.[5]

The framework connects technical work to legal and organizational governance. Govern 1.1 calls for legal and regulatory requirements to be understood, managed, and documented; Govern 2.3 assigns executive leadership responsibility for AI development and deployment risk decisions. Map 4.1 addresses legal risks from system components, including third-party data, software, and possible infringement of intellectual property or other rights. These are framework outcomes; applying them does not replace compliance with the underlying legal obligations.[6]

The intended audience extends beyond developers to deployers, evaluators, managers, procurement personnel, and other participants in the AI lifecycle. NIST emphasizes multidisciplinary input and engagement with affected people. Responsibility is distributed across actors whose visibility into the system may differ: a model developer may not know the circumstances in which a customer will deploy it.[7]

What counts as AI risk?

The framework considers both the likelihood of an event and the magnitude of its consequences. It recognizes that harms may emerge immediately or over time, affect particular people or wider systems, and arise through interactions among models, data, users, and institutions. Risk assessment consequently includes the setting of use and downstream effects, as well as technical performance.[8]

NIST distinguishes risk measurement from risk tolerance and prioritization. Difficulty measuring a risk is not evidence that the risk is small—or large. Organizations should identify uncertainties, prioritize their most consequential risks, and document residual risks after mitigation. Where negative risks are unacceptable, NIST recommends safely stopping development or deployment until those risks can be sufficiently managed.[9]

Characteristics of trustworthy AI

The framework identifies seven connected characteristics. Their relative importance and the tradeoffs between them depend on context; satisfying one characteristic does not establish overall trustworthiness.[10]

  • Valid and reliable: The system performs its intended function under relevant conditions, supported by suitable testing and continued monitoring. Accuracy measures should reflect realistic deployment conditions.[11]
  • Safe: Design, testing, monitoring, and intervention arrangements address dangers to life, health, property, and the environment, with particular urgency for serious injury or death risks.[12]
  • Secure and resilient: The system resists unauthorized access and attacks and can withstand, recover from, or safely degrade under adverse events and unexpected changes.[13]
  • Accountable and transparent: Appropriate information about development, deployment, decisions, and responsibility is available to relevant audiences. Transparency supports oversight and redress but does not by itself establish accuracy or fairness.[14]
  • Explainable and interpretable: People can understand relevant aspects of how a system operates and what its outputs mean in context. Explanations should suit the audience and use.[15]
  • Privacy-enhanced: Design and use address autonomy, identity, confidentiality, and control over information, including risks from inferring previously private information.[16]
  • Fair, with harmful bias managed: Evaluation considers discrimination, accessibility, and systemic, statistical, and human cognitive bias. Demographic balance alone does not settle whether a system is fair.[17]

The four core functions

The Core divides each function into categories and subcategories describing risk-management outcomes. The functions are iterative, not four mandatory stages completed once in sequence. Govern operates across the other functions; findings from measurement or live operation can require revisiting earlier assumptions and decisions.[18]

Govern

Govern establishes the policies, responsibilities, resources, and organizational culture needed to manage AI risk. It includes documenting accountability, training personnel, maintaining an AI-system inventory, defining human oversight, collecting external feedback, and preparing for third-party failures and safe decommissioning. Governance continues throughout the system's life.[19]

Map

Map establishes what the system is meant to do, who will use it, who could be affected, and which benefits and harms are plausible. It includes documenting capabilities and knowledge limits, intended use, human oversight, component risks, and the likely magnitude of impacts. The resulting context informs whether development or deployment should proceed and what needs evaluation.[20]

Measure

Measure uses quantitative, qualitative, or mixed methods to evaluate and monitor the risks identified through Map. NIST calls for testing before deployment and during operation, realistic benchmarks, documentation of uncertainty and limitations, and consideration of independent review. Evaluation covers trustworthiness and impacts, rather than a single model accuracy score.[21]

The framework also addresses measurement gaps. Measure 3.2 calls for considering ways to track risks that available techniques cannot readily assess. Feedback and appeal mechanisms for users and affected communities can contribute to evaluation, alongside technical tests.[22]

Manage

Manage turns assessment results into prioritized decisions, resources, and responses. Options include mitigating, transferring, avoiding, or accepting risk, with residual risks documented. It covers ongoing third-party and pretrained-model monitoring, incident response and recovery, communication with affected people, and mechanisms to override, disengage, or deactivate systems when necessary.[23]

Implementation, profiles, and documentation

AI RMF profiles tailor the Core to a particular application, sector, technology, or organizational setting. A Current Profile describes existing outcomes; a Target Profile describes desired outcomes. Comparing them helps identify gaps, prioritize action, and estimate staffing and funding needs. NIST does not mandate a profile template.[24]

The companion AI RMF Playbook offers suggested actions and supporting resources for the Core's subcategories. NIST expressly describes it as neither a checklist nor a sequence to follow in full. Organizations can select suggestions appropriate to their circumstances.[25]

Documentation connects the functions. Examples of records contemplated by the Core include assigned roles and escalation responsibilities; system purposes and limits; component and third-party risks; test methods, results, and uncertainties; residual-risk decisions; and monitoring, incident-response, and decommissioning plans. These records make decisions more traceable and support review as systems and uses change.[26]

NIST recommends integrating AI risk management into broader enterprise risk processes, including cybersecurity and privacy. It also cautions that adopting the framework alone will not create effective accountability or incentives: leadership commitment, resources, and organizational practices matter. Users are encouraged to evaluate periodically whether their implementation actually improves risk management.[27]

Generative AI companion profile

The NIST Generative AI Profile (NIST AI 600-1) applies the framework to risks that are new or intensified in generative AI. It supplements the general Core with risk descriptions and suggested actions; it does not replace AI RMF 1.0. Its principal action areas include governance, content provenance, pre-deployment testing, and incident disclosure.[28]

The profile addresses matters such as fabricated outputs (confabulation), privacy, harmful bias, information integrity and security, intellectual property, and dependence on components across the AI value chain. It distinguishes model, application, and wider ecosystem risks, and explains that mitigations may differ at each level. It also identifies uncertainty and limitations in the evidence available when the profile was written.[28]

Publication record

  • January 26, 2023: NIST released AI RMF 1.0 following public consultation and draft development.[3]
  • July 26, 2024: NIST released the Generative Artificial Intelligence Profile as a companion resource.[3]

As checked on September 11, 2026, NIST's program page states that AI RMF 1.0 is being revised as part of America's AI Action Plan. The Playbook page states that it will be updated after the framework revision. The explanations above describe the published version 1.0 and its 2024 generative-AI companion, rather than an assumed future revision.[3][25]

References

  1. 1.0 1.1 NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023).
  2. 2.0 2.1 2.2 2.3 NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); Executive Summary.
  3. 3.0 3.1 3.2 3.3 3.4 NIST, AI Risk Management Framework, program page (accessed September 11, 2026).
  4. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); sections 1–2.
  5. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); Executive Summary and section 1.2.2.
  6. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); sections 1.2.2, 5.1 and 5.2.
  7. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); sections 1.2.4 and 2; Appendix A.
  8. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); sections 1.1–1.2.
  9. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); sections 1.2.1–1.2.3.
  10. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 3.
  11. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 3.1.
  12. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 3.2.
  13. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 3.3.
  14. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 3.4.
  15. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 3.5.
  16. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 3.6.
  17. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 3.7.
  18. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 5.
  19. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 5.1 and Table 1.
  20. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 5.2 and Table 2.
  21. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 5.3 and Table 3.
  22. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); Table 3, MEASURE 3.2–3.3.
  23. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 5.4 and Table 4.
  24. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); section 6.
  25. 25.0 25.1 NIST AI Resource Center, AI RMF Playbook (accessed September 11, 2026).
  26. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); Tables 1–4.
  27. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (January 2023); sections 1.2.4 and 4.
  28. 28.0 28.1 NIST, Generative Artificial Intelligence Profile, NIST AI 600-1 (July 2024), sections 1–3.