GLACIS·AI security frameworks·NIST AI RMF·Updated August 2026
NIST AI RMF, function by function.
Implementing NIST AI RMF means choosing the subcategories that fit a stated context, carrying out the work, and preserving evidence of it. This voluntary framework is not a certification or legal-compliance status. The guide maps GOVERN, MAP, MEASURE and MANAGE across AI RMF 1.0 and the NIST AI 600-1 generative AI profile, and covers profiles, intellectual-property risk, and the SP 800-53 AI control-overlay work tracking through 2026.
By Joe Braidwood, CEO GLACIS·31 min read·Published 20 December 2025·Updated 13 August 2026
Jan 2023
NIST AI RMF 1.0 published: voluntary, sector-agnostic
Jul 2024
NIST AI 600-1 GenAI Profile: 12 risks across GOVERN/MAP/MEASURE/MANAGE
The NIST AI Risk Management Framework (AI RMF 1.0), released January 2023, is voluntary guidance for managing AI risks. It organizes outcomes across 4 core functions, 19 categories, and 72 subcategories; NIST’s July 2024 Generative AI Profile provides a companion risk-management profile for generative AI.[1]
NIST describes AI RMF as voluntary for public- and private-sector use and states that AI RMF 1.0 is being revised. Colorado’s original 2024 AI Act tied a safe harbor to it, but that statute was repealed and replaced before taking effect and the safe harbor did not survive. H.R. 6936 was a proposal in the expired 118th Congress and did not become law. Contracts and procurement processes may still incorporate framework terms.[2][3][4]
This guide explains the framework’s functions and offers implementation questions. It is not a NIST-endorsed implementation, certification path, or substitute for the framework text.
This guide does not treat a draft profile, third-party crosswalk, consortium membership or implementation pattern as final NIST guidance or as a universal requirement. Verify newer NIST publications directly before updating a control baseline.
Reported AI harm has climbed steeply. According to the Stanford AI Index, 233 AI-related incidents were reported in 2024, a 56.4% increase over 2023 and a 26-fold increase since 2012.[5] Those incidents included deepfake intimate images, chatbots implicated in self-harm, and false identification by anti-theft AI systems. That is the class of event an AI incident response plan has to be ready for.
AI risk claims are difficult to compare when incident taxonomies, evaluation datasets, and deployment boundaries differ. NIST AI RMF provides a common structure for describing risk work, but adoption of the framework does not itself establish that a system is safe, compliant, or effectively controlled.
Where the law landed: Colorado’s original 2024 AI Act offered a NIST AI RMF / ISO 42001 safe-harbor affirmative defense, but it was repealed and replaced by SB 26-189 (Automated Decision-Making Technology) before taking effect, and that safe harbor was not carried forward. NIST AI RMF stays valuable as the backbone for the documentation, disclosure, and human-review duties that commence January 1, 2027, even though it is no longer a codified defense.[2]
Under SB 26-189, the Colorado Attorney General enforces violations as deceptive trade practices under the Colorado Consumer Protection Act, with civil penalties up to $20,000 per violation. These obligations are enacted but not operative until January 1, 2027.
Enterprise adoption
Major enterprises have publicly embraced NIST AI RMF:
Workday describes NIST AI RMF as “a concrete benchmark for mapping, measuring, and managing our approach to AI governance” that helps “maintain customer trust and stay true to company core values.”[4]
Google has built an AI governance program “aligned with the AI RMF approach and underpinned by industry-leading research.”[4]
The Workday and Google statements above are examples of public alignment claims. Reviewers still need to inspect the organization’s actual scope, implementation, evidence, and exceptions rather than infer assurance from framework alignment alone.
Framework structure
The NIST AI RMF is organized around four core functions, 19 categories, and 72 subcategories. The companion Playbook provides suggested actions for each subcategory, while remaining voluntary and adaptable to organizational context.[1]
Function
Purpose
Categories
Subcategories
GOVERN
Establish organizational culture and structures
6
~20
MAP
Understand context and identify risks
5
18
MEASURE
Assess and analyze identified risks
5
22
MANAGE
Prioritize and address risks
3
~12
TOTAL
19
72
G
GOVERN
Foundational: enables and informs all other functions
The framework defines seven characteristics that AI systems should exhibit to be considered trustworthy:[1]
Valid and Reliable
Consistent, accurate performance
Safe
No harm to people or environment
Secure and Resilient
Protected, recoverable from disruptions
Accountable and Transparent
Clear ownership and visibility
Explainable and Interpretable
Decisions can be understood
Privacy-Enhanced
Individual privacy protected
Fair with Harmful Bias Managed
Regular auditing for biases with corrective actions
GOVERN: establishing AI governance
The GOVERN function is foundational. It enables and informs the other three functions. Without effective governance structures, technical controls lack context and accountability. NIST emphasizes that governance should be established first and maintained throughout the AI lifecycle.[1]
Primary ownership typically sits with General Counsel, CISOs, Head of Risk, or Chief Risk Officer, the leaders positioned to operationalize AI risk management as part of broader enterprise risk strategy.[9]
GV.1
Organizational Policies
Establish policies that define acceptable AI uses, risk thresholds, and accountability structures.
Document AI use policies aligned with organizational values and legal obligations
Define risk tolerance thresholds by use case category
Establish approval workflows for high-risk AI applications
Create incident response procedures specific to AI failures
Evidence Required:Policy documents, approval records, version history
GV.2
Roles and Responsibilities
Define clear accountability for AI risk management across the organization.
Assign executive sponsorship for AI governance program
Define RACI matrix for AI risk assessment, approval, and monitoring
Establish cross-functional AI governance committee
Evidence Required:Org charts, role descriptions, committee charters, meeting minutes
GV.3
Workforce and Culture
Build organizational capability and culture for responsible AI development and deployment.
Provide AI risk awareness training for relevant staff
Create channels for reporting AI concerns without retaliation
Build a culture that values AI safety alongside innovation
The MAP function focuses on understanding the context in which AI systems operate and identifying potential risks before deployment. It comprises 5 categories and 18 subcategories.[10]
Effective mapping covers foreseeable misuse as well as intended use. The framework asks teams to consider every stakeholder who might be affected by an AI decision, including the people who never touch the system themselves.
MP.1
Context and Use Case Analysis
Document the intended purpose, users, and operating environment for each AI system.
Define intended use cases with specific user populations
Identify foreseeable misuses and off-label applications
Assess deployment environment and integration points
Document data sources, quality, and provenance
Evidence Required:Use case documentation, data lineage records, architecture diagrams
MP.2
Stakeholder Impact Assessment
Identify who is affected by AI decisions and how they might be harmed.
Map all stakeholders affected by AI outputs (direct and indirect)
Engage affected communities in risk identification
Evidence Required:Impact assessments, stakeholder maps, engagement records
MP.3
Risk Identification
Systematically identify risks across the AI lifecycle and risk categories.
Catalog risks to each trustworthy AI characteristic
Consider risks from training data, model architecture, deployment
Document known limitations and failure modes
Evidence Required:Risk registers, model cards, limitation documentation
MEASURE: assessing AI risks
The MEASURE function involves quantifying and analyzing identified risks through testing, metrics, and ongoing monitoring. It comprises 5 categories and 22 subcategories.[10]
Measurement results depend on the task, dataset, model version, prompt and system configuration, grader, and test date. Record those boundaries so that reviewers do not mistake one benchmark result for a durable, model-wide performance claim.
MS.1
AI Testing and Evaluation
Establish rigorous testing protocols for AI systems before and after deployment.
Conduct performance testing across diverse conditions and edge cases
Test for adversarial robustness and prompt injection vulnerabilities
Establish ongoing monitoring to detect performance degradation, drift, and emerging risks.
Monitor model performance metrics in production
Detect data drift and distribution shifts
Set up alerting for anomalous outputs or behaviors
Evidence Required:Monitoring dashboards, alert logs, drift reports, incident records
MANAGE: treating AI risks
The MANAGE function covers the prioritization and treatment of identified risks, including mitigation strategies and response planning. It translates measurement into action.
Risk treatment can include human review, use restrictions, technical controls, monitoring, incident response, fallback paths, and acceptance of documented residual risk. Each treatment needs an owner, trigger, coverage boundary, and evidence that can be reviewed.
MG.1
Risk Prioritization
Prioritize risks based on likelihood, impact, and organizational risk tolerance.
Score risks using consistent criteria aligned with enterprise risk
Factor in reversibility and remediation difficulty
Consider regulatory and reputational implications
Evidence Required:Risk scoring matrices, prioritization decisions, review records
MG.2
Risk Treatment Options
Select and implement appropriate risk treatment strategies.
Avoid
Don’t deploy the AI system or use case
Mitigate
Implement controls to reduce risk to acceptable levels
Transfer
Share risk via contracts, insurance, or partnerships
Accept
Document with appropriate executive approval
Evidence Required:Treatment decisions, control implementation records, acceptance documentation
MG.3
Incident Response
Prepare for and respond to AI failures, incidents, and unintended outcomes.
The framework is not meant to be applied 72 subcategories at a time, uniformly, to everything an organization builds. The mechanism that makes it tractable is the profile: a selection and prioritization of subcategories for a stated context. Implementation becomes confused when this step is skipped and the catalog is treated as a flat checklist.
Three kinds of profile do different jobs, and a working program usually runs more than one at a time.
Profile type
What it scopes
Worked example
What it produces
Use-case
One application or deployment setting
NIST AI 600-1, the generative AI profile
Extra actions against subcategories that already exist
Cross-sectoral
A risk that recurs across industries
The Critical-Infrastructure profile concept note, 7 April 2026
Shared treatment for a common risk
Temporal: current
What the organization does today
Baseline assessment of an existing model estate
An honest description of present practice
Temporal: target
Where the organization intends to be
The state a customer contract or a statute requires
A gap list, which becomes the work plan
The current-and-target pair is the one auditors and enterprise buyers ask to see, because the gap between them is the part of the framework that describes intent. A current profile identical to the target is either finished or unexamined, and reviewers tend to assume the second.
Two practical notes. A profile is a scoping decision, not a maturity score: NIST does not certify AI RMF adoption and publishes no conformity grade, so a vendor offering a certified AI RMF level is describing a scheme of its own making. And because AI 600-1 is itself a use-case profile, adopting it adds no subcategories. It tells you which of the 72 carry more weight when a system is generative, and what to do about them.
NIST AI 600-1
Generative AI profile
Released July 26, 2024, per Executive Order 14110, the Generative AI Profile identifies 12 risks unique to or exacerbated by generative AI and provides over 200 suggested actions for risk management.[11]
The 12 GenAI risk categories
1. CBRN Information
Access to chemical, biological, radiological, nuclear weapons information
2. Confabulation
Production of false or misleading content (“hallucinations”)
3. Dangerous Content
Creation of violent, hateful, or inciting content
4. Data Privacy
Leakage, unauthorized use, or de-anonymization of personal data
5. Environmental Impacts
High energy consumption and carbon emissions
6. Harmful Bias
Reinforcement of stereotypes and discriminatory outputs
7. Homogenization
Reduction in content diversity and perspective
8. Information Integrity
Mis/disinformation and manipulation of information
9. Information Security
Lowered barrier to cybersecurity attacks
10. Intellectual Property
Training data and output copyright concerns
11. Obscene Content
Generation of sexual, violent, or illegal content
12. Value Chain
Risks from third-party components and integrations
Integration with AI RMF 1.0: The GenAI Profile maps each of the 12 risks to the core GOVERN, MAP, MEASURE, and MANAGE functions, providing specific actions for generative AI contexts. Organizations implementing AI RMF should layer the GenAI Profile for LLM and generative AI deployments.
Intellectual property risk under the generative AI profile
Risk 10 of NIST AI 600-1 gets one line in most summaries and rather more attention in a security review, because it is the generative-AI risk most likely to arrive as a contract question rather than a technical one. It has two halves that are easy to conflate and need separating before either can be managed.
The input half concerns what the model was trained or grounded on: whether training data was licensed, whether retrieval is pulling copyrighted or third-party confidential material into a prompt, and whether an employee pasted something into a general-purpose assistant that the organization had no right to disclose. The output half concerns what the model produces: substantially similar generations, memorized passages reproduced verbatim, and the open question of what rights attach to generated material at all.
The four questions a reviewer actually asks, and the record that answers each:
What went into this system? Provenance for training and fine-tuning data, and the license terms attached to each source.
What is being retrieved at run time? The corpora a retrieval step can reach, and the rule that decides whether a given document is allowed into a prompt.
What is the model provider permitted to do with our inputs? The commercial terms covering training on customer data, retention, and any indemnity offered against third-party claims.
What did we check before the output was used? What the configured system reported about a similarity or leakage check for this generation, and what outcome it recorded.
The first three are documentation questions and most organizations can answer them, slowly, from contracts and data inventories. The fourth is the one that fails in a review. Asserting that a similarity check exists is a policy claim. Showing that it ran on the generation now under dispute, on the date in question, and what it decided, is an evidence claim, and the two are not interchangeable when a rights-holder is asking.
NIST AI 600-1 places the treatment across all four functions rather than in one place. GOVERN carries the policy and the third-party terms. MAP identifies where copyrighted or licensed material can enter. MEASURE covers the similarity and memorization testing. MANAGE covers takedown, retraining, and the response when a claim arrives. A profile that addresses only the GOVERN half is the common failure, and it is visible from outside: the organization can produce the policy and cannot produce a single record of it being applied.
Regulatory signals
NIST AI RMF has transitioned from voluntary guidance to a widely used regulatory reference point. Frameworks and statutes increasingly cite it as a benchmark, though its status as a codified legal defense varies and, in Colorado, no longer applies.
Regulation
NIST AI RMF Reference
Effective Date
Penalties
Colorado SB 26-189 (ADMT)
Recommended practice; no codified safe harbor[2]
Jan 1, 2027 (compliance)
Up to $20,000/violation
H.R. 6936 (118th Congress)
Historical proposal; did not become law[3]
Expired
None from this bill
Executive Order 14110
Historical directive; revoked in January 2025[12]
Revoked
No current mandate from this order
EU AI Act
Compatible risk-based approach
August 2025+
Up to 7% revenue
Colorado: from safe harbor to a transparency regime
Colorado’s original 2024 AI Act (SB 24-205) offered an affirmative defense for organizations that could demonstrate compliance with NIST AI RMF or ISO 42001. That law was repealed and replaced by SB 26-189 (Automated Decision-Making Technology), signed May 14, 2026, before it ever took effect, and the framework safe harbor did not survive into the new statute. NIST AI RMF is therefore no longer a codified legal defense in Colorado, though it remains a strong backbone for the documentation and disclosure duties the new law introduces.[2]
SB 26-189 regulates covered automated decision-making technology (ADMT) used to materially influence a consequential decision, rather than the old “high-risk AI system” category. Its core duties, none of which are operative until January 1, 2027, center on transparency rather than mandatory impact assessments:
Pre-use notice before a covered ADMT materially influences a consequential decision
Post-adverse-outcome disclosure within 30 days, plus consumer rights to data correction and meaningful human review on request
Developer documentation to deployers, with records retained at least three years
The 2024 Act’s reasonable-care duty against algorithmic discrimination, mandatory risk-management programs, and annual impact assessments were eliminated; discrimination is now handled under existing Colorado anti-discrimination law.
Crosswalk to other frameworks
Organizations implementing NIST AI RMF build a strong foundation for compliance with multiple regulatory frameworks:
NIST AI RMF Function
EU AI Act
ISO 42001
Colorado SB 26-189 (ADMT)
GOVERN
Quality Management (Art. 17)
Clauses 5-7 (Leadership, Planning)
Governance Policy
MAP
Risk Classification (Art. 6)
Clause 6.1 (Risk Assessment)
Covered-ADMT scoping
MEASURE
Testing & Monitoring (Art. 9)
Clauses 9-10 (Evaluation)
Ongoing Assessment
MANAGE
Risk Management (Art. 9)
Clause 8 (Operation)
Risk Mitigation
SP 800-53 control overlays for AI, and what to do before they land
AI RMF is a risk framework, not a control catalog. It tells an organization what to reason about and leaves the specific controls open, which is why two teams can both claim NIST AI RMF alignment and have almost nothing in common. The work now tracking through 2026 to produce control overlays for AI against NIST SP 800-53 is aimed squarely at that gap: overlays express AI-specific controls in the vocabulary federal systems already use for everything else.
For anyone already inside a federal or FedRAMP boundary this matters more than the framework itself, because 800-53 is the language of the authorization package. An overlay turns AI RMF from a parallel exercise into a set of controls that sit in the same baseline, get assessed by the same assessor, and appear in the same system security plan.
The overlays are not final, and building a program around unpublished control identifiers would be a mistake. Three things are safe to do now because they hold regardless of the final numbering:
Record AI control outcomes in a form that can be re-labeled later. A record carrying a configured control identifier, reported outcome, reported event time, and covered fields can be mapped to a new identifier more readily than a screenshot or quarterly summary. Its signature protects the covered fields; it does not by itself establish execution, timing, or event truth.
Keep the AI system inventory in the same place as the rest of the estate. Overlays apply to systems already enumerated in a boundary; an AI inventory maintained in a separate spreadsheet has to be reconciled before it can be overlaid.
Treat the existing 800-53 families as the default and note only the genuine deltas. Access control, audit and accountability, and system and information integrity already cover most of what an AI system needs. The AI-specific additions cluster around provenance, model change, and output validation.
The order matters. Organizations that wait for the overlays and then start recording have no history to assess against them on day one. Organizations that record control outcomes now arrive with a back catalog that can be relabeled in an afternoon.
NIST AI RMF describes risk-management outcomes. Auditors and other reviewers may also request scoped operational records showing what configured controls reported, together with testing and coverage evidence. Whether that evidence demonstrates diligence or satisfies a legal duty depends on the applicable criteria and review.
These layers have different evidentiary properties and should be used together. A signed operational record can support integrity and provenance for a covered event; it does not replace policy, risk assessment, independent testing, validation, or coverage analysis.
1
Policy Documentation
Written AI policies and procedures
Intent
2
Process Records
Risk assessments, impact documentation
Process
3
Execution Logs
Automated monitoring, test results, audit trails
Operational
4
Cryptographic Attestation
Signed, timestamped records of configured control outcomes
Integrity
Moving beyond policy and dashboard evidence can make specific operational events easier to review. Signed records strengthen integrity and provenance for covered events, while effectiveness and coverage still require separate evidence. Read more about the Proof Gap.
Frequently asked questions
What is the NIST AI RMF?
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework published by the National Institute of Standards and Technology in January 2023. It provides 72 subcategories across 19 categories and 4 core functions (GOVERN, MAP, MEASURE and MANAGE) to help organizations design, develop, deploy and use AI systems responsibly.[1]
Is NIST AI RMF mandatory?
NIST describes AI RMF as voluntary for public- and private-sector use and states that AI RMF 1.0 is being revised. H.R. 6936 was a proposal in the expired 118th Congress and did not become law. Contracts or procurement processes may incorporate framework terms, but that is not a general statutory mandate.[3]
What is NIST AI 600-1?
NIST AI 600-1 is the voluntary Generative AI Profile released in July 2024. It was developed pursuant to Executive Order 14110, which was revoked in January 2025; the NIST publication remains available as a companion resource to AI RMF 1.0.[11][12]
How does NIST AI RMF relate to the Colorado AI Act?
Colorado’s original 2024 AI Act (SB 24-205) cited NIST AI RMF and ISO 42001 as the basis for a safe-harbor affirmative defense, but that law was repealed and replaced before it ever took effect. The successor statute, SB 26-189 (Automated Decision-Making Technology), signed May 14, 2026 with substantive obligations commencing January 1, 2027, does not carry over the NIST/ISO safe harbor. Aligning with NIST AI RMF remains strong recommended practice and supports documentation and disclosure duties, but it is no longer a codified legal defense in Colorado.[2]
What is a NIST AI RMF profile?
A profile is the AI RMF’s tailoring mechanism. Rather than applying all 72 subcategories uniformly, an organization selects and prioritizes them for a specific context. A use-case profile scopes the framework to one application, such as generative AI or a hiring system. A cross-sectoral profile addresses a risk that cuts across industries. A temporal profile is the pair you actually manage against: a current profile describing what you do today and a target profile describing where you intend to be, with the gap between them forming the work plan. NIST AI 600-1 is itself a use-case profile, which is why it adds actions rather than new subcategories.
How does NIST AI RMF differ from NIST CSF?
The NIST Cybersecurity Framework addresses cybersecurity risks broadly. NIST AI RMF specifically addresses AI-related risks such as bias, explainability, confabulation, and AI-specific security concerns such as prompt injection. Most organizations need both frameworks to cover the full range of risk.
What is the difference between NIST AI RMF and ISO 42001?
NIST AI RMF is a risk management framework focused on AI-specific risks: it tells you what to address. ISO 42001 is a certifiable management system standard that provides the how of organizational implementation. They are complementary: use NIST AI RMF for risk identification and ISO 42001 for management system certification.
Can small organizations implement NIST AI RMF?
Yes. The framework is designed to be scalable and risk-proportionate. Small organizations can implement a simplified version focused on their highest-priority AI systems. Start with governance foundations (GOVERN), identify the critical use cases (MAP), and expand measurement and management based on risk levels.
Who should own NIST AI RMF implementation?
Primary ownership typically sits with General Counsel, the CISO, the Head of Risk, or the Chief Risk Officer, the leaders positioned to operationalize AI risk management as part of broader enterprise risk strategy.[9] Implementation requires a cross-functional team including legal, compliance, engineering, and business stakeholders.
References
[1]NIST. ”AI Risk Management Framework 1.0.” NIST AI 100-1, January 2023. nvlpubs.nist.gov
[2]Colorado General Assembly. SB 24-205 (Colorado AI Act, signed May 17, 2024) was repealed and replaced by SB 26-189 (“Automated Decision-Making Technology”), signed May 14, 2026, with substantive compliance commencing Jan 1, 2027. leg.colorado.gov/bills/sb26-189
[3]U.S. Congress. H.R. 6936, 118th Congress (introduced Jan. 10, 2024; expired without enactment at the end of that Congress). Historical proposal only.
[4]NIST. ”Perspectives about the NIST AI Risk Management Framework.” 2023. nist.gov
[5]Stanford HAI. ”AI Index 2025: State of AI in 10 Charts.” April 2025. hai.stanford.edu
[9]Net Solutions. ”How to Implement NIST AI RMF for Enterprises.” 2024. netsolutions.com
[10]Ankura. ”Implementing the NIST AI Risk Management Framework.” 2024. ankura.com
[11]NIST. ”Generative Artificial Intelligence Profile (NIST AI 600-1).” July 2024. nvlpubs.nist.gov
[12]White House. ”Executive Order 14110 on Safe, Secure, and Trustworthy AI.” October 2023. federalregister.gov
[13]Forrester. ”AI Governance Software Spend Will See 30% CAGR From 2024 To 2030.” 2024. forrester.com
Scoped operational records mapped to the AI RMF and the GenAI Profile (NIST AI 600-1), with crosswalks to ISO/IEC 42001 and EU AI Act review questions. The records show what configured controls reported; framework conformance, effectiveness, coverage, and compliance require separate assessment.