What did NIST say about managing artificial intelligence risk?
Reviewed by Jason Burns, Editorial Steward · Last updated
The National Institute of Standards and Technology's AI Risk Management Framework 1.0, released in January 2023, tells organizations to govern, map, measure, and manage the risks of AI systems throughout their lifecycle, and defines what a trustworthy AI system looks like. As National Institute of Standards and Technology, National Institute of Standards and Technology (U.S. Department of Commerce), put it on the record before the NIST AI Risk Management Framework 1.0 (AI RMF 1.0) (January 26, 2023): "AI risk management offers a path to minimize potential negative impacts of AI systems, such as threats to civil liberties and rights, while also providing opportunities to maximize positive impacts."
Editor's note: NIST has since published the Generative AI Profile (NIST AI 600-1, July 2024) as a companion to AI RMF 1.0. When applying the framework today, read both together.
What this means in plain English
The framework defines AI trustworthiness across seven characteristics: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair — with harmful bias managed. It then organizes practice into four functions: Govern (policies and culture), Map (context and risks), Measure (assessment methods), and Manage (allocation of resources and mitigations).
What this does not mean
The AI RMF is voluntary guidance, not a regulation. It does not by itself impose legal obligations, and complying with it does not confer any legal safe harbor.
How to use this information
Use the framework as an internal governance blueprint. Map your AI systems into the four functions, document your context and risk assessments, and pair the core RMF with the Generative AI Profile if you build or deploy generative systems.
Risks and limitations
The framework is high-level; specific technical controls, metrics, and thresholds are left to the implementer. Do not treat NIST language as a substitute for domain-specific risk assessment (e.g. medical, financial, or safety-critical systems).
Sources
- NIST AI Risk Management Framework 1.0 (PDF) (retrieved 2026-07-19)
- NIST AI RMF program page (retrieved 2026-07-19)
- NIST Generative AI Profile (AI 600-1) (retrieved 2026-07-19)
Also asked as
- What is the NIST AI Risk Management Framework?
- What does NIST recommend for AI safety?