Skip to main content

NIST AI RMF

NIST AI Risk Management Framework

Dominant voluntary AI governance framework in the US. Four functions (Govern, Map, Measure, Manage) operationalize what regulators expect. Not legally binding but heavily referenced.

Jurisdiction

United States

Enacted

Pending

Effective

Jan 26, 2023

Enforcement

None (voluntary framework)

NIST

Why It Matters

Colorado AI Act provides affirmative defense for NIST RMF compliance. Referenced by federal agencies and increasingly in procurement requirements.

Who Must Comply

  • Organizations developing or deploying AI (voluntary)

Safety Provisions

  • Govern: organizational policies and culture
  • Map: context and risk understanding
  • Measure: risk assessment methods
  • Manage: response and mitigation strategies
  • Generative AI Profile (NIST AI 600-1) addresses GAI-specific risks

View on map

United States

Focus Areas

Algorithmic accountability

Cite This

APA

United States. (2023). NIST AI Risk Management Framework.

Related Regulations

In Effect US

EO 14409

US executive order directing federal cyber-defense upgrades and establishing a voluntary framework under which advanced-AI developers may submit 'covered frontier models' for classified national-security benchmarking up to 30 days before release. Expressly prohibits any mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of AI models.

In Effect US

State AG AI Warning

Coordinated state AG warnings: 44 AGs (Aug 25, 2025, led by TN, IL, NC, and SC AGs) and 42 AGs (Dec 2025, led by PA AG) to OpenAI, Meta, and others citing chatbots "flirting with children, encouraging self-harm, and engaging in sexual conversations."

In Effect DE

Germany KI-MIG

German national law implementing the EU AI Act, designating the Bundesnetzagentur (BNetzA) as the lead market surveillance authority under a centralized hybrid model.

Enacted US-IL

IL HB 5511

Requires covered operators of online platforms to apply protective default settings to users they know to be minors, including limits on algorithmic feeds, a 10 p.m. to 7 a.m. notification curfew and no autoplay by default on addictive social media platforms, and establishes a device-level age-bracket signal that Internet-enabled device manufacturers must provide and operators must request. Announced by the Governor as the Children's Social Media Safety Act, the title of the bill as introduced. Enforced by the Attorney General.

Enacted US-NJ

NJ Kids Code

Codifies a New Jersey Age-Appropriate Design Code requiring covered online service providers to design services likely to be accessed by minors around minors' safety and wellbeing, including high-privacy defaults, limits on engagement-maximising design features, and data protection impact assessments. Enforced by the Attorney General with a private right of action for minors and their parents.

In Effect CN

China Minor Content Classification Measures

Establishes a four-category classification framework for online content that may harm minors' physical and mental health. Prohibits platforms from displaying classified harmful content in prominent positions (homepage, pop-ups, trending, recommendations). Requires preventive measures against content risks from algorithmic recommendations and generative AI.

Last updated January 23, 2026. Verify against primary sources before relying on this information.