California already regulates automated decision-making in ways that touch AI tools used in hiring, healthcare, and financial services. The state's automated decisionmaking technology rules took effect on October 1, 2025. Covered businesses must reach full compliance by January 1, 2027, for automated decisionmaking technology already in use before that date.
There is no single federal law that mandates how a company must manage AI risk. The Biden-era executive order on AI safety was rescinded by the current administration in January 2025, leaving a policy gap at the federal level. That gap is closing fast at the state level, and organizations still need a defensible way to show responsible AI use.
This article breaks down the National Institute of Standards and Technology's Artificial Intelligence Risk Management Framework 1.0, known as the NIST AI RMF. It covers the four core functions of Govern, Map, Measure, and Manage, identifies who the framework targets, and makes the case for adopting it now, before state mandates or contract requirements force the issue. Organizations deploying AI tools in healthcare, software as a service, or government contracting all have a stake in this conversation.
What Is NIST, and Why Did It Build an AI Framework?
The National Institute of Standards and Technology (NIST) is a non-regulatory federal agency housed inside the U.S. Department of Commerce. It has long produced widely adopted technical standards. Congress directed NIST to build the AI Risk Management Framework through the National Artificial Intelligence Initiative Act of 2020, instructing the agency to develop a voluntary framework that could balance innovation with accountability. NIST built the document over roughly a year and a half of public workshops and comment periods rather than issuing it unilaterally.
NIST is not an enforcement body. It publishes guidance and standards that other regulators, procurement offices, and courts frequently reference, which is exactly what has happened with the AI RMF since its release.
What Is the NIST AI Risk Management Framework 1.0?
NIST released the AI RMF 1.0 on January 26, 2023. The framework is voluntary, sector-neutral, and use-case agnostic, and it applies to traditional machine learning, generative AI, and AI features embedded in larger products. It gives organizations a common vocabulary for identifying, evaluating, and responding to AI-related risk across the full system lifecycle, from design through retirement.
Unlike a certification scheme, the AI RMF does not produce a pass or fail result. No auditor issues a certificate against it. Instead, it functions as a structured method that an organization can apply, document, and reference when regulators, customers, or insurers ask how AI risk gets managed internally.
The Four Core Functions: Govern, Map, Measure, Manage
The AI RMF Core is composed of four functions: Govern, Map, Measure, and Manage. Each of these high-level functions breaks down into categories and subcategories, and the four functions work together rather than as isolated checkboxes.
- Govern: Establishes organizational culture, policies, and accountability for AI risk, and this function cuts across the other three.
- Map: Frames the context of a specific AI system, including its intended use, stakeholders, and foreseeable risks.
- Measure: Analyzes and tracks identified risks using qualitative and quantitative testing, evaluation, and validation methods.
- Manage: Allocates resources to treat prioritized risks, respond to incidents, and feed lessons learned back into governance.
Measure tends to carry the most technical detail of the four, since it covers testing methods that verify whether a system behaves as intended before and after deployment.
Who Needs to Care About the NIST AI RMF?
The NIST AI Risk Management Framework applies to any organization that designs, builds, procures, or operates an AI system, regardless of size or industry. That description covers a wide range of California businesses already using AI features without necessarily labeling them that way.
Three groups tend to have the most direct stake in adopting the framework:
- Executives and boards who bear ultimate accountability for how AI tools affect customers, patients, or employees.
- Compliance and risk managers responsible for demonstrating due diligence to regulators, auditors, and business partners.
- Engineering and IT teams that select, configure, and monitor AI models and vendor tools day to day.
A healthcare technology company using an AI diagnostic aid, a software as a service provider embedding a large language model into a product, and a defense contractor evaluating AI-assisted logistics tools all fall within the framework's intended reach.
Where the AI RMF Fits Among Other IT and Compliance Frameworks
Organizations juggling multiple compliance obligations often need a mental map of how the major frameworks relate. A short list of IT frameworks commonly cited by small and midsize businesses (SMBs) in regulated industries includes:
- SOC 2 (System and Organization Controls 2), focused on data security and availability for service providers
- HIPAA (Health Insurance Portability and Accountability Act), governing protected health information
- CMMC (Cybersecurity Maturity Model Certification), required for Department of Defense contractors handling Controlled Unclassified Information
- ISO 27001 (International Organization for Standardization standard), an internationally recognized information security management system
- PCI DSS (Payment Card Industry Data Security Standard), covering payment card data
- NIST AI RMF, addressing AI-specific risk rather than general information security
NIST alone publishes two common cybersecurity frameworks that organizations frequently confuse. The Cybersecurity Framework (CSF) addresses general information security risk across an organization's systems. The AI RMF applies that same risk-based thinking specifically to artificial intelligence systems. Both are voluntary, and both have become reference points that regulators build requirements around.
Why Adopt It Voluntarily, Before Regulators Mandate Compliance?
Adopting the AI RMF now, ahead of a binding mandate, gives an organization a documented, defensible risk management posture before one becomes legally required. The federal executive order on safe, secure, and trustworthy AI, issued in October 2023, was rescinded on January 20, 2025. Its replacement order focused on removing barriers to AI development rather than imposing new risk requirements. That leaves a policy vacuum at the federal level, but states have moved to fill it.
Colorado passed the clearest example. Developers and deployers under Colorado's AI Act have an affirmative defense if they discover and cure violations and are otherwise in compliance with the AI RMF published by NIST or another designated framework. California has followed a related path through privacy regulation rather than a standalone AI statute. Its automated decisionmaking technology rules took effect on October 1, 2025, with compliance required by January 1, 2027, for covered businesses using the technology in significant decisions before that date. California also enacted broader AI-specific statutes: the AI Transparency Act and the Transparency in Frontier Artificial Intelligence Act create statewide standards for transparency, labeling, provenance tracking, and risk governance for generative and frontier AI systems.
An organization that already runs AI systems through Govern, Map, Measure, and Manage has most of the documentation a regulator, insurer, or enterprise customer will eventually ask for. Retrofitting that documentation after an incident or an audit request costs considerably more time and money than building it into an existing security program from the start.
How Organizations Can Start Implementing the AI RMF
Implementation does not require adopting every subcategory of the framework at once. A phased approach tends to work better for smaller teams.
- Build an inventory of every AI system in use, including vendor tools with embedded AI features.
- Assign clear ownership for AI governance, often extending an existing security or compliance role.
- Map risks and intended use for each system before expanding deployment.
- Define measurement methods appropriate to each system's risk level, from basic testing to formal validation.
- Fold AI risk management into an existing Governance, Risk, and Compliance (GRC) program rather than building a separate silo.
Moving From Awareness to a Documented AI Risk Program
The NIST AI RMF 1.0 gives organizations a structured, defensible way to manage AI risk before a patchwork of state laws forces the issue. Waiting for a mandate to arrive means starting governance work under deadline pressure rather than on a manageable timeline. Building the Govern, Map, Measure, and Manage functions into an existing security and compliance program now positions an organization to meet whatever comes next, whether that is a state disclosure law, a customer security questionnaire, or a future federal standard.
Planet 9 is a Bay Area cybersecurity consulting firm specializing in SOC 2 and HIPAA readiness for SMBs in healthcare, SaaS, and technology. Our vCISOs and compliance managers help organizations build AI risk governance into existing security programs, configure GRC tools if needed, and get audit-ready without wasted time.





