Free Consultation
#AI
#nist

NIST AI Risk Management Framework 1.0: A Practical Roadmap Before AI Regulation Catches Up

August 7, 2026

California already regulates automated decision-making in ways that touch AI tools used in hiring, healthcare, and financial services. The state's automated decisionmaking technology rules took effect on October 1, 2025. Covered businesses must reach full compliance by January 1, 2027, for automated decisionmaking technology already in use before that date.

There is no single federal law that mandates how a company must manage AI risk. The Biden-era executive order on AI safety was rescinded by the current administration in January 2025, leaving a policy gap at the federal level. That gap is closing fast at the state level, and organizations still need a defensible way to show responsible AI use.

This article breaks down the National Institute of Standards and Technology's Artificial Intelligence Risk Management Framework 1.0, known as the NIST AI RMF. It covers the four core functions of Govern, Map, Measure, and Manage, identifies who the framework targets, and makes the case for adopting it now, before state mandates or contract requirements force the issue. Organizations deploying AI tools in healthcare, software as a service, or government contracting all have a stake in this conversation.

What Is NIST, and Why Did It Build an AI Framework?

The National Institute of Standards and Technology (NIST) is a non-regulatory federal agency housed inside the U.S. Department of Commerce. It has long produced widely adopted technical standards. Congress directed NIST to build the AI Risk Management Framework through the National Artificial Intelligence Initiative Act of 2020, instructing the agency to develop a voluntary framework that could balance innovation with accountability. NIST built the document over roughly a year and a half of public workshops and comment periods rather than issuing it unilaterally.

NIST is not an enforcement body. It publishes guidance and standards that other regulators, procurement offices, and courts frequently reference, which is exactly what has happened with the AI RMF since its release.

What Is the NIST AI Risk Management Framework 1.0?

NIST released the AI RMF 1.0 on January 26, 2023. The framework is voluntary, sector-neutral, and use-case agnostic, and it applies to traditional machine learning, generative AI, and AI features embedded in larger products. It gives organizations a common vocabulary for identifying, evaluating, and responding to AI-related risk across the full system lifecycle, from design through retirement.

Unlike a certification scheme, the AI RMF does not produce a pass or fail result. No auditor issues a certificate against it. Instead, it functions as a structured method that an organization can apply, document, and reference when regulators, customers, or insurers ask how AI risk gets managed internally.

The Four Core Functions: Govern, Map, Measure, Manage

The AI RMF Core is composed of four functions: Govern, Map, Measure, and Manage. Each of these high-level functions breaks down into categories and subcategories, and the four functions work together rather than as isolated checkboxes.

Measure tends to carry the most technical detail of the four, since it covers testing methods that verify whether a system behaves as intended before and after deployment.

Who Needs to Care About the NIST AI RMF?

The NIST AI Risk Management Framework applies to any organization that designs, builds, procures, or operates an AI system, regardless of size or industry. That description covers a wide range of California businesses already using AI features without necessarily labeling them that way.

Three groups tend to have the most direct stake in adopting the framework:

A healthcare technology company using an AI diagnostic aid, a software as a service provider embedding a large language model into a product, and a defense contractor evaluating AI-assisted logistics tools all fall within the framework's intended reach.

Where the AI RMF Fits Among Other IT and Compliance Frameworks

Organizations juggling multiple compliance obligations often need a mental map of how the major frameworks relate. A short list of IT frameworks commonly cited by small and midsize businesses (SMBs) in regulated industries includes:

NIST alone publishes two common cybersecurity frameworks that organizations frequently confuse. The Cybersecurity Framework (CSF) addresses general information security risk across an organization's systems. The AI RMF applies that same risk-based thinking specifically to artificial intelligence systems. Both are voluntary, and both have become reference points that regulators build requirements around.

Why Adopt It Voluntarily, Before Regulators Mandate Compliance?

Adopting the AI RMF now, ahead of a binding mandate, gives an organization a documented, defensible risk management posture before one becomes legally required. The federal executive order on safe, secure, and trustworthy AI, issued in October 2023, was rescinded on January 20, 2025. Its replacement order focused on removing barriers to AI development rather than imposing new risk requirements. That leaves a policy vacuum at the federal level, but states have moved to fill it.

Colorado passed the clearest example. Developers and deployers under Colorado's AI Act have an affirmative defense if they discover and cure violations and are otherwise in compliance with the AI RMF published by NIST or another designated framework. California has followed a related path through privacy regulation rather than a standalone AI statute. Its automated decisionmaking technology rules took effect on October 1, 2025, with compliance required by January 1, 2027, for covered businesses using the technology in significant decisions before that date. California also enacted broader AI-specific statutes: the AI Transparency Act and the Transparency in Frontier Artificial Intelligence Act create statewide standards for transparency, labeling, provenance tracking, and risk governance for generative and frontier AI systems.

An organization that already runs AI systems through Govern, Map, Measure, and Manage has most of the documentation a regulator, insurer, or enterprise customer will eventually ask for. Retrofitting that documentation after an incident or an audit request costs considerably more time and money than building it into an existing security program from the start.

How Organizations Can Start Implementing the AI RMF

Implementation does not require adopting every subcategory of the framework at once. A phased approach tends to work better for smaller teams.

Moving From Awareness to a Documented AI Risk Program

The NIST AI RMF 1.0 gives organizations a structured, defensible way to manage AI risk before a patchwork of state laws forces the issue. Waiting for a mandate to arrive means starting governance work under deadline pressure rather than on a manageable timeline. Building the Govern, Map, Measure, and Manage functions into an existing security and compliance program now positions an organization to meet whatever comes next, whether that is a state disclosure law, a customer security questionnaire, or a future federal standard.

Planet 9 is a Bay Area cybersecurity consulting firm specializing in SOC 2 and HIPAA readiness for SMBs in healthcare, SaaS, and technology. Our vCISOs and compliance managers help organizations build AI risk governance into existing security programs, configure GRC tools if needed, and get audit-ready without wasted time.

Book a Free Consultation

Schedule a free consultation today to explore how Planet 9 can help you achieve your security and compliance goals.
Book Free Consultation

FAQs

How does a vCISO service differ from hiring a full-time CISO?
A part-time CISO offers the same strategic oversight and expertise as a full-time CISO but on a flexible, cost-effective basis. It’s ideal for small to mid-sized businesses that need executive-level guidance without the overhead.
Is a virtual CISO service suitable for regulated industries like healthcare or finance?
Yes, virtual CISOs (or fractional CISOs) are especially valuable for industries with strict compliance requirements such as HIPAA, PCI DSS, or GLBA. They help ensure your organization meets regulatory standards and is prepared for audits.
What can I expect during a vCISO engagement?
Our vCISO service typically includes cybersecurity assessments, program development, compliance planning, incident response strategy, vendor risk management, and ongoing executive reporting tailored to your business.
How do I know if my business needs a CISO-as-a-Service?
If you lack in-house security leadership, struggle with compliance, or face growing cyber risks, a vCISO can fill that gap, providing strategic direction, improving resilience, and helping you make smarter security investments.

FAQs

What is the NIST AI Risk Management Framework 1.0?
The NIST AI RMF 1.0 is voluntary guidance published by the National Institute of Standards and Technology in January 2023 for managing risk across the AI lifecycle. It organizes risk management into four functions: Govern, Map, Measure, and Manage, and it applies across industries and AI use cases.
Is the NIST AI RMF mandatory?
No federal law currently requires adoption of the NIST AI RMF, and NIST itself describes the framework as voluntary. Some state laws, including Colorado's AI Act, reference compliance with the framework as a factor in legal defenses, which gives it practical weight even without a federal mandate.
What is NIST?
NIST stands for the National Institute of Standards and Technology, a non-regulatory agency within the U.S. Department of Commerce. NIST develops technical standards and frameworks, including the Cybersecurity Framework and the AI Risk Management Framework, that organizations across industries widely reference.
How does the NIST AI RMF differ from the NIST Cybersecurity Framework?
The NIST Cybersecurity Framework addresses general information security risk across an organization's systems and data. The AI RMF applies that same structured, risk-based approach specifically to artificial intelligence systems, covering concerns unique to AI such as model drift and algorithmic bias.
Which businesses in California should pay attention to the NIST AI RMF?
Any California business using AI in hiring, healthcare, financial decisions, or customer-facing products has reason to pay attention, given the state's expanding automated decisionmaking rules. Healthcare technology firms, software as a service companies, and defense contractors face the most direct exposure since their AI use cases often touch regulated data or consequential decisions.

Related blog posts