NIST AI Risk Management Framework
The NIST AI Risk Management Framework is a voluntary set of guidance developed by the U.S. National Institute of Standards and Technology to help organizations identify and manage risks that arise when designing, building, and using artificial intelligence systems. It is not a law, and organizations cannot be formally certified against it; instead, it offers a structured way to think through AI risks and to work toward more trustworthy AI. Because it is voluntary, it carries no legal force in itself unless an organization is required to follow it by contract or by another rule.
The AI RMF (published as AI RMF 1.0 in 2023) is a voluntary, non-certifiable framework issued by NIST to support the management of risks across the AI lifecycle, from design and development through implementation and use. Its Core provides outcomes and actions intended to enable dialogue, understanding, and activities that help organizations manage AI risks and develop trustworthy AI. It is a framework rather than a binding regulation, and it should not be conflated with statutory obligations such as the EU AI Act; adherence is voluntary unless incorporated by contract or referenced by another legal instrument. NIST supplements the framework with an AI RMF Playbook, which NIST plans to update frequently, and has continued to develop related resources, including a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure. Practitioners should note that the framework and its associated resources are periodically updated and should be verified against the current authoritative NIST text.
Why it matters
As organizations increasingly embed artificial intelligence into products, services, and internal operations, they face risks that traditional risk management approaches were not designed to address—including risks tied to model behavior, data quality, and the ways AI systems affect the people and communities they touch. The AI RMF matters because it gives organizations a common, structured vocabulary and a set of outcomes for reasoning about these risks across the full AI lifecycle, from design and development through implementation and use. It fills a gap for teams that need a credible reference point but are not yet subject to binding AI-specific law, or that operate across jurisdictions with differing requirements.
It is important to keep the framework's status in perspective. The AI RMF is voluntary and non-certifiable: an organization cannot obtain a formal certification against it, and it carries no legal force on its own. That distinguishes it sharply from statutory instruments such as the EU AI Act, which impose binding obligations within their jurisdictional scope. The AI RMF becomes obligatory for a given organization only when it is incorporated by contract or referenced by another legal instrument. Readers should not treat use of the framework as evidence of legal compliance, nor assume that following it satisfies any specific regulatory duty.
Because the framework and its supporting materials continue to evolve—NIST plans to update the AI RMF Playbook frequently and has continued developing related resources—its practical value depends on working from the current authoritative version. Application to any particular AI system requires professional judgment about the organization's risk tolerance, sector, and applicable legal environment, and this entry is informational rather than guidance for a specific situation.
Who it's relevant to
Inside AI RMF
Common questions
Answers to the questions practitioners most commonly ask about AI RMF.
