Rules / United States (federal)
NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0)
Voluntary framework (Govern, Map, Measure, Manage) for managing AI risks across the lifecycle, with a Generative AI Profile and, since 7 Apr 2026, a concept note for a critical-infrastructure profile. NIST states the AI RMF 1.0 'is being revised as part of the White House AI Action Plan', which calls for removing references to misinformation, DEI and climate change.
Why it matters
It remains the reference framework many state laws, contracts and audits point to (e.g. as a safe-harbour benchmark), so revisions will ripple into compliance programmes.
What it requires
Cite this record
NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0). National Institute of Standards and Technology (NIST). Status: In force. wheresthe.ai, https://wheresthe.ai/rule/us-nist-ai-rmf/ (verified 4 Oct 2026).
Line of Thought
Developments connected to this rule
What has happened that this rule shapes, or that shapes it. Pick one to keep following the thread.
- DevelopmentUS Treasury releases AI lexicon and finance-specific AI risk framework19 Feb 2026 · Policy · US
- DevelopmentFTC begins enforcing TAKE IT DOWN Act's 48-hour removal duty for intimate deepfakes19 May 2026 · Enforcement or ruling · US
- DevelopmentAnthropic launches Claude for Healthcare with HIPAA-ready tools for providers and payers11 Jan 2026 · Launch · US
- DevelopmentOpenAI launches ChatGPT Health, linking medical records and wellness apps7 Jan 2026 · Launch · US
- DevelopmentMicrosoft cuts an Israeli defence unit's access to Azure storage and AI services25 Sep 2025 · Enforcement or ruling · IL, US
- DevelopmentFTC orders seven firms to explain how AI companion chatbots protect children11 Sep 2025 · Enforcement or ruling · US
More from United States (federal)
-
In forceEffective 23 Jan 2025
-
In forceEffective 23 Jul 2025
-
In forceEffective 11 Dec 2025
-
ProposedProposed 20 Mar 2026
-
ProposedProposed 4 Jun 2026
-
In forceEffective 2 Jun 2026