NIST AI Risk Management Framework 1.0 and Generative AI Profile (NIST AI 600-1)
Last reviewed Sep 25, 2026.
In short
The NIST AI RMF is a free, voluntary US framework for managing AI risk across the lifecycle, built on four functions: Govern (policies and accountability), Map (context and risks), Measure (testing and metrics) and Manage (prioritising and responding). The 2024 Generative AI Profile adds about 200 suggested actions for twelve generative-AI risks such as confabulation, data privacy, provenance, bias and harmful content. It is the most common reference point in US state laws and contracts, and a practical starting point for SMBs that need a defensible programme.
Who it applies to
- Organisations that build or use AI systems in International standard.
- Any use case — it is not limited to specific applications.
- Size: everyone, including solo operators.
- Voluntary, but referenced by US laws: Texas TRAIGA treats compliance with it as an affirmative defence, and regulators cite it as the expected baseline.
Key dates
- Jan 26, 2023✓AI RMF 1.0 released
- Jul 26, 2024✓Generative AI Profile (NIST AI 600-1) released
- Apr 7, 2026✓Concept note for a Critical Infrastructure profile released; AI RMF revision under way
What you have to do
- Assign clear ownership and policies for AI (Govern).
- Document each system's context, intended use and who could be harmed (Map).
- Test and measure for accuracy, bias, security and robustness before and after deployment (Measure).
- Prioritise risks, decide what to fix, monitor and respond to incidents (Manage).
- For generative AI, apply the AI 600-1 profile actions on provenance, confabulation and harmful content.
Penalties
None; voluntary. Following it can reduce liability (for example, it is an affirmative defence under Texas TRAIGA).
Related lessons
- Level 1What AI compliance is (and who the rules target)6 min
- Level 1The world map of AI rules: EU, US patchwork, Canada, standards8 min
- Level 2Build your AI inventory6 min
- Level 4Governance structure and roles6 min
- Level 4Incident response and monitoring7 min
- Level 4Security and robustness7 min
- Level 5Management systems in practice: ISO 42001, NIST AI RMF and continuous assurance8 min
- Level 5Staying current: key dates ahead and how to track change6 min
Real cases
- Ban2023 · US-federalFTC v. Rite Aid — five-year ban on facial recognition surveillance
Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.
Industries where it matters
Sources
- AI Risk Management Framework — NIST ↗
- NIST AI 600-1: Generative Artificial Intelligence Profile (PDF) ↗
- NIST AI RMF 1.0 (PDF) ↗
Last reviewed Sep 25, 2026.