← All laws
NIST AI RMFVoluntaryInternational standard

NIST AI Risk Management Framework 1.0 and Generative AI Profile (NIST AI 600-1)

Last reviewed Sep 25, 2026.

In short

The NIST AI RMF is a free, voluntary US framework for managing AI risk across the lifecycle, built on four functions: Govern (policies and accountability), Map (context and risks), Measure (testing and metrics) and Manage (prioritising and responding). The 2024 Generative AI Profile adds about 200 suggested actions for twelve generative-AI risks such as confabulation, data privacy, provenance, bias and harmful content. It is the most common reference point in US state laws and contracts, and a practical starting point for SMBs that need a defensible programme.

Who it applies to

  • Organisations that build or use AI systems in International standard.
  • Any use case — it is not limited to specific applications.
  • Size: everyone, including solo operators.
  • Voluntary, but referenced by US laws: Texas TRAIGA treats compliance with it as an affirmative defence, and regulators cite it as the expected baseline.

Key dates

  1. Jan 26, 2023✓AI RMF 1.0 released
  2. Jul 26, 2024✓Generative AI Profile (NIST AI 600-1) released
  3. Apr 7, 2026✓Concept note for a Critical Infrastructure profile released; AI RMF revision under way

What you have to do

  • Assign clear ownership and policies for AI (Govern).
  • Document each system's context, intended use and who could be harmed (Map).
  • Test and measure for accuracy, bias, security and robustness before and after deployment (Measure).
  • Prioritise risks, decide what to fix, monitor and respond to incidents (Manage).
  • For generative AI, apply the AI 600-1 profile actions on provenance, confabulation and harmful content.

Penalties

None; voluntary. Following it can reduce liability (for example, it is an affirmative defence under Texas TRAIGA).

Related lessons

Real cases

  • Ban2023 · US-federal
    FTC v. Rite Aid — five-year ban on facial recognition surveillance

    Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.

Industries where it matters

Sources

Last reviewed Sep 25, 2026.

Educational information, not legal advice. Laws change and details depend on your situation — check the linked sources and talk to a qualified lawyer before acting. Last content review: 2026-09-25.

Spotted an error? Ask the tutor or email hello@myaiguide.pro.