GovernanceCore
Voluntary frameworkUnited States

NIST AI Risk Management Framework 1.0

A voluntary, widely adopted framework organised around four functions (Govern, Map, Measure and Manage) that has become the de facto reference for building trustworthy AI programmes in the US and beyond.

Status
Voluntary framework
Jurisdiction
United States · Standard
Adopted
Jan 26, 2023
In force
Jan 26, 2023
Enforcement date
Regulator / body
National Institute of Standards and Technology (non-binding)
Sectors
Cross-sector
Extraterritorial
No

Key dates

  • Jan 26, 2023
    AI RMF 1.0 released
  • Jul 26, 2024
    Generative AI Profile (NIST-AI-600-1) released

Risk areas addressed

Safety & robustnessBias & discriminationTransparencyGovernance & accountability

Who it applies to

Any organisation designing, developing, deploying or using AI systems that wants a structured, voluntary approach to managing AI risk.

Penalties & enforcement

None (voluntary framework).

Enforced by: National Institute of Standards and Technology (non-binding)

Getting ready

NIST AI RMF carries no direct penalty today, so its value is evidential: teams adopt it to show a named standard behind their controls for safety & robustness, bias & discrimination and transparency. Mapping an existing AI inventory against it is usually enough to surface the gaps, and that same evidence tends to carry over to the binding regimes that follow.

Official source

NIST AI Risk Management Framework

Related regulations

← All regulations