# NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0)

- **Jurisdiction:** United States (federal) (US)
- **Type:** Standard · **Status:** In force · **Binding:** no
- **Issued by:** National Institute of Standards and Technology (NIST)
- **Proposed:** — · **Adopted:** 26 Jan 2023 · **Effective:** 26 Jan 2023
- **Obligations:** Risk classification, Impact assessment, Data governance, Human oversight
- **Sectors:** All sectors

## Summary
Voluntary framework (Govern, Map, Measure, Manage) for managing AI risks across the lifecycle, with a Generative AI Profile and, since 7 Apr 2026, a concept note for a critical-infrastructure profile. NIST states the AI RMF 1.0 'is being revised as part of the White House AI Action Plan', which calls for removing references to misinformation, DEI and climate change.

## Why it matters
It remains the reference framework many state laws, contracts and audits point to (e.g. as a safe-harbour benchmark), so revisions will ripple into compliance programmes.

## Source
[NIST](https://www.nist.gov/itl/ai-risk-management-framework) · [secondary](https://www.nist.gov/caisi)
Checked against the source on 4 Oct 2026. Related: NIST's Center for AI Standards and Innovation (CAISI, renamed from the AI Safety Institute in 2025 and now styled 'CAISSI' on NIST's site after EO 14434) runs voluntary agreements with developers and published evaluations of PRC models (DeepSeek V4 Pro, May 2026; GLM-5.2, Jul 2026; GLM-5.3, Sep 2026). Revised AI RMF not yet published as of 2026-10-04.

## Cite
NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0). National Institute of Standards and Technology (NIST). Status: In force. wheresthe.ai, https://wheresthe.ai/rule/us-nist-ai-rmf/ (verified 4 Oct 2026).

---
Canonical page: https://wheresthe.ai/rule/us-nist-ai-rmf/ · Not legal advice.
