
A framework published without regulatory force
On 26 January 2023, the US National Institute of Standards and Technology released the first version of the AI Risk Management Framework. The announcement is explicit that the document is 'for voluntary use by organizations designing, developing, deploying or using AI systems,' and it carries no penalty for non-adoption and no accreditation scheme attached to it. NIST describes the document, as retrieved on 16 September 2026 from its living framework page, as intended to help organisations 'incorporate trustworthiness considerations into the design, development, use, and evaluation' of AI systems, a description of intent rather than of enforceable obligation.
Four functions, not a scorecard
The framework is organised around four functions, described on NIST's AI Resource Center as Govern, Map, Measure and Manage. Govern covers the policies, roles and culture an organisation puts around AI risk before any system is built. Map covers identifying the context and likely impacts of a specific AI use case. Measure covers the analytical and testing methods used to assess identified risks. Manage covers the actions taken in response to measured risk, including deciding whether to proceed, mitigate or stop. None of the four functions specifies a pass or fail threshold; each is a category of activity an organisation is meant to carry out and document, with the specific metrics and tolerances left to the organisation and sector.
What the framework does not do
The framework does not test, certify or grade any AI system, and it does not itself resolve what counts as an acceptable level of risk in a given deployment. Because it is deliberately generic across sectors and system types, an organisation that adopts it still has to build or borrow the specific evaluation methods that fill in the Measure function; the framework describes the activity of measuring, not a fixed test suite. NIST's own materials note the document is subject to revision, and a companion resource specific to generative systems followed in July 2024, extending rather than replacing the original four-function structure. A claim that a product is 'NIST AI RMF compliant' is therefore a claim about following a voluntary process, not a claim verified by NIST or backed by any published conformity assessment.
- Which of the four functions has an organisation actually documented, as opposed to referenced in marketing language?
- What specific measurement methods fill the Measure function for this system, and who defined the acceptance threshold?
- Has the organisation revisited its Map and Measure work since the system's last material change, or is the assessment now stale?
The framework's contribution was to give organisations a common structure for AI risk conversations that previously had none; it does not substitute for the sector-specific testing and evidence that a safety claim still requires.
Sources & reading trail
Announces the AI RMF's release date and states the framework is for voluntary use.
Source published: 26 January 2023 · Retrieved: 16 September 2026
Living overview page describing the framework's purpose and noting the later Generative AI Profile.
Source published: Not established · Retrieved: 16 September 2026
Describes the four core functions, Govern, Map, Measure and Manage, that structure the framework.
Source published: Not established · Retrieved: 16 September 2026
Papers and official documents establish the record; the reading and the questions are Model Field Guide editorial analysis. This retrospective draft does not imply the site published on the event date.