Home / Resources / Compliance

Compliance · 6 min read · Updated 2026-07-06

NIST AI RMF: the playbook US enterprises are measured against — and how to pass it

The NIST AI Risk Management Framework is voluntary on paper and mandatory in practice — here is how US enterprises turn Govern, Map, Measure and Manage into evidence a regulator, court or customer will accept.

The United States has no single AI law — it has a center of gravity. NIST published the AI Risk Management Framework (AI RMF 1.0) on January 26, 2023, and followed it on July 26, 2024 with the Generative AI Profile (NIST-AI-600-1), which catalogs 12 risk categories unique to or amplified by generative AI. In parallel, CISA and the UK's NCSC released joint Guidelines for Secure AI System Development in November 2023, co-sealed by 23 domestic and international cybersecurity agencies. Industry bodies — ITI, CompTIA, TechNet — point their members to the same documents. And the states are moving on their own clock: Colorado's pioneering AI Act (SB 24-205) was delayed from February 1, 2026 to June 30, 2026, then rewritten before it ever took effect. The framework is voluntary; being able to show your work is not.

Why has a voluntary framework become the de-facto standard?

Because everyone downstream borrowed it. Regulators cite it, insurers underwrite against it, procurement teams paste it into RFPs, and plaintiffs' lawyers ask why you ignored it. The AI RMF organizes trustworthy AI into four functions:

  • Govern — accountability, policies, roles and an auditable record of AI decisions.
  • Map — know where AI touches your data, people and consequential decisions.
  • Measure — test the risks you mapped, with repeatable metrics, not vibes.
  • Manage — act on findings: controls, human oversight, incident response.

An enterprise that can produce evidence for all four functions is defensible under almost any US regime that follows.

What does the Generative AI Profile add?

NIST-AI-600-1 turns abstract risk into a named catalog: information security (including direct and indirect prompt injection and data poisoning), data privacy and leakage, information integrity and content provenance, confabulation, and value-chain and component integration — the risk hiding in the models, connectors and plugins you didn't build. If your AI platform cannot demonstrate controls against these named risks, you are carrying them unmeasured.

CISA's secure-by-design expectation

The joint CISA/NCSC guidelines shift security left onto the vendor: secure design, secure development, secure deployment, secure operation. The practical translation for buyers — demand AI systems that are hardened by default, scan what enters the pipeline, fail closed, and log what they did. "The model provider handles it" is not a control.

The state patchwork makes evidence the safe harbor

Colorado's reversal is the lesson, not the exception: sector regulators (SEC and FINRA cautions on AI use, HIPAA's rules reaching health AI) and dozens of state bills will keep shifting. The only durable posture is evidence-based governance — controls you can measure and records you can produce, whatever the statute of the month says. What a US enterprise should demand of an AI platform:

  • Measurable controls: guardrails with real-time status, including prompt-injection defense and malware scanning of ingested content.
  • Audit evidence: an append-only ledger of every AI action, per request.
  • Human oversight: approval gates on consequential, agent-driven actions.
  • Deployment freedom: on-premises or air-gapped, so data-privacy risk is closed by architecture, not by contract.

Sources: NIST AI 100-1 (Jan 2023) and NIST-AI-600-1 (Jul 2024), nist.gov; CISA/NCSC Guidelines for Secure AI System Development (Nov 2023), cisa.gov; Colorado SB 24-205 timeline as reported by the Colorado General Assembly and legal trackers.

Related guides

Compliance

The EU AI Act Article 12 readiness guide

What record-keeping and human-oversight obligations actually require operationally from August 2026 — and the evidence an auditor will ask you to produce.

9 min read

Read the guide

Procurement

The sovereign AI buyer's checklist

Twelve concrete questions that separate verifiable sovereignty from a configuration checkbox — ask them of every vendor, including us.

8 min read

Read the guide

Risk

Shadow AI: your biggest leak is a paste-⁠box

Why employees pasting contracts into public chatbots is a legal exposure, not an IT nuisance — and why bans fail where better tools succeed.

7 min read

Read the guide
COMING SOONAANCER launches shortly.Register for prelaunch events & demos →