Primary documents, operating bodies, related frameworks, named contributors, reference resources for the NIST AI RMF cluster.
Primary documents
- NIST AI 100-1: AI Risk Management Framework 1.0 (January 2023). Foundational framework document. Free PDF from NIST.
- NIST AI 100-1 Playbook โ actionable suggestions per function and sub-category. Living document; updates published periodically. Free.
- NIST AI 100-1 Roadmap โ NIST's planned future AI work. Updated periodically.
- NIST AI 100-1 Crosswalks โ published mappings to ISO 27001, ISO 42001, EU AI Act, NIST Privacy Framework, NIST CSF, OECD AI Principles, others. Updated through 2024-2025.
- NIST AI 600-1: Generative AI Profile (July 2024). 200+ suggested actions across 12 GenAI risk categories.
- NIST AI 100-4: Reducing Risks Posed by Synthetic Content โ supplementary guidance on synthetic-content risks.
Companion NIST publications
- NIST SP 1270: A Proposal for Identifying and Managing Bias in AI (2022). Bias-specific work that informs AI RMF.
- NIST IR 8312: Four Principles of Explainable AI (2021).
- NIST SP 800-218: Secure Software Development Framework (SSDF) (2022). Bridges to secure AI development.
- NIST Cybersecurity Framework 2.0 (February 2024). Voluntary cybersecurity framework. NIST AI RMF and CSF use similar function-based structures.
- NIST Privacy Framework 1.1 (2024 update). Companion to NIST CSF on the privacy axis.
Operating bodies
- NIST โ National Institute of Standards and Technology, US Department of Commerce. Publisher of voluntary frameworks across cybersecurity, privacy, AI, cryptography, software security, IoT, more.
- NIST AI Safety Institute (AISI) โ established within NIST in 2024. Operationalizes AI safety work, particularly for frontier models. Conducts pre-deployment evaluations through voluntary commitments with major AI developers.
- NIST AI Resource Center (AIRC) โ central NIST AI content hub at airc.nist.gov.
Adjacent and competing frameworks
- ISO/IEC 42001:2023 โ sibling certifiable AI management system standard.
- ISO/IEC 23894:2023 โ AI risk management guidance (similar scope to NIST AI RMF but ISO format).
- OECD AI Principles (2019, updated 2024) โ international voluntary principles. NIST AI RMF and ISO 42001 both consistent with OECD principles.
- UNESCO Recommendation on the Ethics of AI (2021) โ international voluntary recommendation.
- Singapore Model AI Governance Framework (2020, GenAI extension 2024) + AI Verify open-source testing toolkit.
- EU AI Act (Reg 2024/1689) โ regulatory; NIST AI RMF informs but does not satisfy AI Act compliance.
- UK AI Action Plan / DSIT AI guidance โ voluntary; pro-innovation framing.
- OWASP LLM Top 10 (2023, 2025 publication Nov 2024) โ operational application-security taxonomy.
- MITRE ATLAS โ adversarial threat landscape for AI systems.
- MITRE AI Maturity Model โ emerging maturity framing.
Named contributors and voices
NIST AI team
- Reva Schwartz โ co-led AI RMF development; published widely on bias and trustworthy AI.
- Apostol Vassilev โ NIST AI Safety Institute leadership; AISI's evaluation work.
- Elham Tabassi โ long-standing NIST AI lead; AI standards work.
- Various NIST authors โ co-authors on AI RMF 1.0, Playbook, GenAI Profile, supplementary publications.
AISI
- AISI staff (post-2024 establishment) โ public statements on frontier-model evaluation methodology.
- AISI Director rotates with administration; structural continuity through 2026 maintained.
External contributors (cited in framework development)
- AI Verify Foundation (Singapore) โ referenced in international harmonization discussions.
- Various academic AI safety / AI ethics researchers โ comments on draft framework iterations.
- Industry contributors โ Anthropic, OpenAI, Google, Microsoft, Meta safety teams via voluntary-commitment processes.
Critical voices
- Various AI safety researchers arguing NIST AI RMF is insufficiently rigorous for frontier-model risks.
- Industry voices arguing NIST AI RMF GenAI Profile (200+ actions) is operationally burdensome.
- Cross-jurisdictional voices noting US-centric framing in some categories.
Reference resources
- airc.nist.gov โ NIST AI Resource Center. Central hub for AI RMF, Playbook, crosswalks, supplementary publications.
- nist.gov/itl/ai-risk-management-framework โ AI RMF official page.
- nist.gov/aisi โ AI Safety Institute page.
- OECD AI Policy Observatory (oecd.ai) โ international AI policy tracking, including NIST AI RMF references.
Regulatory and policy context
- Executive Order 13859 (February 2019) โ initial NIST AI standards direction.
- Executive Order 14110 (October 2023) โ broader AI safety direction; rescinded January 2025.
- Subsequent administration AI policy through 2025-2026 โ varies; NIST work continues with shifting policy emphasis.
- NDAA provisions โ annual defense authorization acts have included AI safety / NIST AI work funding provisions.
- State-level AI legislation (Colorado AI Act 2024, others 2024-2026) often reference NIST AI RMF as preferred framework.
- Federal agency AI guidance (Treasury, FTC, FDA, others) increasingly references NIST AI RMF.