NIST AI Risk Management Framework (AI RMF) and AI Resource Center
- Type
- Standards body
- Place
- United States — United States (federal, non-regulatory)
- Last checked
- 2026-09-22
- Next check due
- 2027-03-21
Ways to reach them
- AI RMF team inbox — reads and logs external comments
- Formal Requests for Information / public comment dockets
- Mailing list for NIST AI activity announcements (catches new comment windows)
- AI Resource Center
- Homepage
What it does
AI RMF 1.0 (Jan 2023) — a voluntary framework structured around Govern, Map, Measure, Manage — plus the Generative AI Profile (NIST AI 600-1), crosswalks to other frameworks, the AI RMF Roadmap, and the AI Resource Center (AIRC) with the Trustworthy & Responsible AI playbooks. The RMF is being revised under the White House AI Action Plan.
Honest assessment
Genuinely responsive by government standards: a real published inbox, real published comment dockets, and a track record of incorporating external crosswalks. A substantive, well-structured comment submitted during an open RFI is one of the highest-yield low-cost actions available anywhere in this list for a US-relevant concern. Note that NIST's AI safety posture shifted substantially with the 2025 AI Action Plan and the CAISI reorganisation — the framing is now innovation-and-security rather than safety.
Concerns it covers
Sociotechnical risk across the board: validity, safety, security/resilience, accountability/transparency, explainability, privacy, and bias. The GenAI Profile explicitly covers CBRN information access, confabulation, dangerous/violent content and harmful bias — so it does reach misuse risk, but not loss of control.
Government channel
Direct — NIST is a US federal agency; the AI RMF is referenced in federal procurement, state legislation and international crosswalks.