NIST AI Risk Management Framework 1.0
Citation
Elham Tabassi. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1, 26 January 2023. NIST. Accessed 2026-08-14.
Source type: voluntary government framework
Evidence quality: primary framework, not binding law
Review status: checked
What it says
The AI RMF organizes work into Govern, Map, Measure, and Manage. It treats trustworthiness as contextual and multi-dimensional: validity, reliability, safety, security, resilience, accountability, transparency, explainability, privacy, and fairness with harmful bias managed. NIST cautions that optimizing characteristics separately does not ensure a trustworthy system and that tradeoffs depend on affected actors and context.
Assumptions and weaknesses
The framework is use-case agnostic and voluntary. It does not prescribe enforcement thresholds, platform-specific harm definitions, or legal compliance. AI RMF 1.0 is under revision as of 2026.
Implications for platform defense
Evaluate the entire decision system throughout its lifecycle, not only model accuracy. Document purpose, affected populations, validity conditions, monitoring, override, and decommissioning.
Chapters this affects
Chapters 6, 7, 11, 12, 15, 17, 19, and 21.