Guidance · United States

NIST AI Risk Management Framework

NIST’s AI RMF, released 26 January 2023, is a voluntary framework for incorporating trustworthiness considerations into the design, development, use and evaluation of AI products, services and systems. Later generative-AI and critical-infrastructure profiles extend the toolkit without converting the core text into a statute.

United StatesRecord updated 2023-01-26
Current standingPublished (voluntary)

Briefing follows NIST’s overview statement on voluntary use, plus the AI RMF 1.0 core-function structure (Govern, Map, Measure, Manage). Profile documents and playbooks are separate publications.

NIST AI RMF releasePublication date from the indexed event.
  1. AI RMF 1.0 released

What this instrument is

Fact

The AI Risk Management Framework is a NIST publication. Standing is “Published (voluntary).”

NIST’s overview states the framework is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into design, development, use and evaluation of AI products, services and systems.

The NIST AI Risk Management Framework (AI RMF) is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.

NIST AI RMF overview page · Overview of the AI RMF

How the instrument works

Mechanism

Under AI RMF 1.0, organisations structure work across four core functions: Govern (cross-cutting culture, roles and oversight), Map (context and risk identification), Measure (assessment and monitoring of identified risks), and Manage (prioritisation and response). Categories and subcategories under those functions supply the operational taxonomy.

Organisations may adopt that structure without a federal mandate from the framework text itself. Other laws, contracts or sector supervisors may still require RMF-aligned practices. That external mandate is separate from the voluntary character of the NIST publication.

  • Voluntary adoption path for trustworthiness risk management.
  • Core functions (AI RMF 1.0) · Govern, Map, Measure, Manage.
  • Applies across design, development, use and evaluation.
  • Later profiles (generative AI, critical infrastructure) specialise the core framework.

What the RMF is not

Analysis

The RMF is not a licensing regime and not a substitute for California SB 53 framework-publication duties or EU AI Act legal obligations. It is a measurement and management vocabulary federal and private actors often reference.

Limits of this record

Limits

The RMF text is voluntary; it does not create a federal licensing duty by itself. Generative-AI and critical-infrastructure profiles are separate NIST publications with specialised guidance that this briefing does not treat as part of the core 1.0 functions.

Who writes, enforces or is named

Fact

The following actors are linked to this vehicle in the graph. Their presence here records institutional role on the page, not an independent finding that each actor has completed a compliance duty.

  • National Institute of Standards and Technology (standards-body): The federal standards body that develops AI risk-management, measurement and evaluation resources.

Key passages on the record

Fact

Each block below is an explicit evidence row: a claim that points to one supporting passage. Read the quote and locator before treating the paraphrase as settled.

  • NIST states the AI RMF is intended for voluntary use. Voluntary status means organisations may adopt the RMF without a federal mandate from the framework itself. Operational note: It separates standards-based risk management from statutory evaluation or licensing duties.

The NIST AI Risk Management Framework (AI RMF) is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.

NIST AI RMF overview page · Overview of the AI RMF · NIST states the AI RMF is intended for voluntary use

Chronology of recorded changes

Fact

Dated events attached to this vehicle. Each entry is a graph event with its own update page when present.

  • 2023-01-26 · publication · NIST releases AI Risk Management Framework 1.0. Release established a federal voluntary reference for organisational AI risk management. Consequence recorded: Created the principal US federal voluntary AI risk-management baseline.

Policy asks this vehicle carries

Fact

A vehicle is an instrument. Asks are the outcomes the instrument is treated as advancing in the AI Tribune graph.

  • Use voluntary AI risk-management frameworks for organisational governance Status: adopted. Adopt voluntary frameworks such as the NIST AI RMF to manage trustworthiness risks without treating the framework text as a statute.

Primary documents indexed here

Fact

These documents are the originals behind the evidence rows. Prefer the document text over secondary paraphrase when the two diverge.

  • NIST AI Risk Management Framework (Voluntary framework, 2023-01-26). NIST page describing the voluntary AI RMF 1.0, Generative AI Profile and later critical-infrastructure concept note.

Updates and changes

Dated sub-pages
2023-01-26 · publicationNIST releases AI Risk Management Framework 1.0

NIST published the voluntary AI Risk Management Framework.

Policy asks

Outcomes on this vehicle

Primary documents

Original record

Evidence

Supporting passages

NIST states the AI RMF is intended for voluntary use

NIST’s AI RMF overview describes the framework as voluntary and designed to improve trustworthiness risk management.

The NIST AI Risk Management Framework (AI RMF) is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.
National Institute of Standards and Technology · NIST AI RMF overview page · Overview of the AI RMF