Free Consultation
Home Regulations AI Risk Management Framework 1.0
Regulation

AI Risk Management Framework 1.0

NIST (USA, used globally) · International (voluntary) · Framework

This page is a plain-English summary written by us, not legal advice — the official text is linked above. Our catalogue was last reviewed 2026-08-15; that is a review of the whole catalogue, not an independent legal verification of this entry.

Authority
NIST (USA, used globally)
Jurisdiction
International (voluntary)
Type
Framework
Status
Guidance
Maximum penalty
Voluntary — no penalties
Catalogue reviewed
2026-08-15
Official source checked
2026-08-23 — unchanged since our last read
Official text

Status

Published 2023 (v1.0); Generative AI Profile (NIST AI 600-1) 2024; extended since via profiles/addenda (e.g. the draft Cyber AI Profile, 2025) rather than a formal 1.1 revision

Requirements (4)

GOVERN recommended

Govern: culture & accountability

Cultivate a risk-management culture: policies, roles, accountability and oversight across the organisation.

MAP recommended

Map: context & risks

Establish the context and identify risks for the AI system and its intended/foreseeable uses.

MEASURE recommended

Measure: analyse & track

Use quantitative/qualitative methods to assess trustworthiness — bias, robustness, security, drift — continuously.

Dates that matter

Guidance 2024-07-26 · in force

NIST AI RMF — Generative AI Profile published

Companion profile mapping GenAI-specific risks to the Govern/Map/Measure/Manage functions.

Action: Map your GenAI risks against the profile’s suggested actions.

Get told when this changes

Our agents re-read the official source every few hours and republish this page when it moves. Leave an email and you will hear about it — only when something actually changed.

Double opt-in. One confirmation email, then nothing until this regulation moves. Unsubscribe in one click.

Compare it with another regulation

The same obligation themes side by side — what both demand, what only one does, and which deadline lands first.

Real incidents citing this regulation

Editorial cross-reference: these are the curated case studies whose prevention note names this regulation. It is not a finding of legal breach.

critical 2021

Zillow Offers iBuying model drift

Zillow

Concept drift

Prevention: Post-market drift monitoring + human gatekeeping on price thresholds

critical 2012

Knight Capital runaway trading algorithm

Knight Capital

Runaway autonomous action

Prevention: Kill switch + blast-radius limits + staged rollout

critical 2025

Coding agent deleted a production database

Reported (AI coding agent)

Unauthorized tool use

Prevention: Approval gates + least-privilege + backups + kill switch

critical 2024

$25M lost to a deepfake video-call CEO

Arup

Deepfake social engineering

Prevention: Out-of-band verification + approval controls on payments