← AI Bill of Rights

NIST AI Risk Management Framework

The US government's voluntary framework for making AI systems valid, reliable, safe, and honest about their own limits.

Source: https://www.nist.gov/itl/ai-risk-management-framework

The NIST AI Risk Management Framework (AI RMF 1.0, released January 2023) is the closest thing the United States has to a shared definition of "tested." It organizes work into four functions — Govern, Map, Measure, Manage — and defines seven characteristics of a trustworthy AI system: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed.

Two ideas in it bear directly on a right to safe, tested systems. First, validity is contextual: NIST insists that a system be measured against its intended purpose and deployment context, not against a benchmark chosen by its builder. A model that scores well in the lab and was never evaluated for the use it actually sees in production is, in RMF terms, unmeasured. Second, the framework treats acknowledging limits as a requirement rather than a caveat — the Map function asks organizations to document what the system cannot do, where it degrades, and under what conditions its outputs should not be relied on.

The Generative AI Profile (NIST AI 600-1, July 2024) extends the RMF to foundation models, naming confabulation, information integrity, and human-AI configuration as risks that must be measured before deployment. The framework is voluntary and carries no penalties — which is exactly why a public commitment to it matters.