NIST AI RMF anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Primary documents, operating bodies, related frameworks, named contributors, reference resources for the NIST AI RMF cluster.

Primary documents

  • NIST AI 100-1: AI Risk Management Framework 1.0 (January 2023). Foundational framework document. Free PDF from NIST.
  • NIST AI 100-1 Playbook โ€” actionable suggestions per function and sub-category. Living document; updates published periodically. Free.
  • NIST AI 100-1 Roadmap โ€” NIST's planned future AI work. Updated periodically.
  • NIST AI 100-1 Crosswalks โ€” published mappings to ISO 27001, ISO 42001, EU AI Act, NIST Privacy Framework, NIST CSF, OECD AI Principles, others. Updated through 2024-2025.
  • NIST AI 600-1: Generative AI Profile (July 2024). 200+ suggested actions across 12 GenAI risk categories.
  • NIST AI 100-4: Reducing Risks Posed by Synthetic Content โ€” supplementary guidance on synthetic-content risks.

Companion NIST publications

  • NIST SP 1270: A Proposal for Identifying and Managing Bias in AI (2022). Bias-specific work that informs AI RMF.
  • NIST IR 8312: Four Principles of Explainable AI (2021).
  • NIST SP 800-218: Secure Software Development Framework (SSDF) (2022). Bridges to secure AI development.
  • NIST Cybersecurity Framework 2.0 (February 2024). Voluntary cybersecurity framework. NIST AI RMF and CSF use similar function-based structures.
  • NIST Privacy Framework 1.1 (2024 update). Companion to NIST CSF on the privacy axis.

Operating bodies

  • NIST โ€” National Institute of Standards and Technology, US Department of Commerce. Publisher of voluntary frameworks across cybersecurity, privacy, AI, cryptography, software security, IoT, more.
  • NIST AI Safety Institute (AISI) โ€” established within NIST in 2024. Operationalizes AI safety work, particularly for frontier models. Conducts pre-deployment evaluations through voluntary commitments with major AI developers.
  • NIST AI Resource Center (AIRC) โ€” central NIST AI content hub at airc.nist.gov.

Adjacent and competing frameworks

  • ISO/IEC 42001:2023 โ€” sibling certifiable AI management system standard.
  • ISO/IEC 23894:2023 โ€” AI risk management guidance (similar scope to NIST AI RMF but ISO format).
  • OECD AI Principles (2019, updated 2024) โ€” international voluntary principles. NIST AI RMF and ISO 42001 both consistent with OECD principles.
  • UNESCO Recommendation on the Ethics of AI (2021) โ€” international voluntary recommendation.
  • Singapore Model AI Governance Framework (2020, GenAI extension 2024) + AI Verify open-source testing toolkit.
  • EU AI Act (Reg 2024/1689) โ€” regulatory; NIST AI RMF informs but does not satisfy AI Act compliance.
  • UK AI Action Plan / DSIT AI guidance โ€” voluntary; pro-innovation framing.
  • OWASP LLM Top 10 (2023, 2025 publication Nov 2024) โ€” operational application-security taxonomy.
  • MITRE ATLAS โ€” adversarial threat landscape for AI systems.
  • MITRE AI Maturity Model โ€” emerging maturity framing.

Named contributors and voices

NIST AI team

  • Reva Schwartz โ€” co-led AI RMF development; published widely on bias and trustworthy AI.
  • Apostol Vassilev โ€” NIST AI Safety Institute leadership; AISI's evaluation work.
  • Elham Tabassi โ€” long-standing NIST AI lead; AI standards work.
  • Various NIST authors โ€” co-authors on AI RMF 1.0, Playbook, GenAI Profile, supplementary publications.

AISI

  • AISI staff (post-2024 establishment) โ€” public statements on frontier-model evaluation methodology.
  • AISI Director rotates with administration; structural continuity through 2026 maintained.

External contributors (cited in framework development)

  • AI Verify Foundation (Singapore) โ€” referenced in international harmonization discussions.
  • Various academic AI safety / AI ethics researchers โ€” comments on draft framework iterations.
  • Industry contributors โ€” Anthropic, OpenAI, Google, Microsoft, Meta safety teams via voluntary-commitment processes.

Critical voices

  • Various AI safety researchers arguing NIST AI RMF is insufficiently rigorous for frontier-model risks.
  • Industry voices arguing NIST AI RMF GenAI Profile (200+ actions) is operationally burdensome.
  • Cross-jurisdictional voices noting US-centric framing in some categories.

Reference resources

  • airc.nist.gov โ€” NIST AI Resource Center. Central hub for AI RMF, Playbook, crosswalks, supplementary publications.
  • nist.gov/itl/ai-risk-management-framework โ€” AI RMF official page.
  • nist.gov/aisi โ€” AI Safety Institute page.
  • OECD AI Policy Observatory (oecd.ai) โ€” international AI policy tracking, including NIST AI RMF references.

Regulatory and policy context

  • Executive Order 13859 (February 2019) โ€” initial NIST AI standards direction.
  • Executive Order 14110 (October 2023) โ€” broader AI safety direction; rescinded January 2025.
  • Subsequent administration AI policy through 2025-2026 โ€” varies; NIST work continues with shifting policy emphasis.
  • NDAA provisions โ€” annual defense authorization acts have included AI safety / NIST AI work funding provisions.
  • State-level AI legislation (Colorado AI Act 2024, others 2024-2026) often reference NIST AI RMF as preferred framework.
  • Federal agency AI guidance (Treasury, FTC, FDA, others) increasingly references NIST AI RMF.

See also