The National Institute of Standards and Technology (NIST) – the organization known in the cybersecurity world for maintaining resources like the National Vulnerability Database (NVD) and the NIST Cybersecurity Framework – has become a prominent source of guidance in the realm of AI security, too, thanks to the NIST AI Risk Management Framework (AI RMF).
As the first major standard to offer a structured guide to securing AI systems, NIST AI RMF can be a valuable resource for organizations seeking to develop a comprehensive AI security strategy.
Read on to learn whether NIST AI RMF is the best AI risk management framework for your business’s needs as we explain what the AI RMF is, compare it to other major AI security standards (including ISO 42001), discuss its limitations, and offer tips on deriving the greatest value from AI RMF as a way to bolster AI security.
What is NIST AI RMF?
The NIST AI Risk Management Framework is a voluntary framework designed to help organizations identify, assess, manage, and monitor risks associated with AI systems. Released in January 2023 by the National Institute of Standards and Technology, a US federal agency, the framework provides a flexible approach for improving the trustworthiness, safety, security, and reliability of AI applications and services.
Like most cybersecurity frameworks, NIST AI RMF doesn’t prescribe highly specific technical controls. Instead, it offers high-level guidance for integrating AI risk management into organizational processes and decision-making. The framework aims to be applicable across industries, organization sizes, and AI use cases, and to remain relevant as AI evolves.
A core objective of AI RMF is helping organizations balance innovation with responsible AI development and deployment. The framework encourages organizations to evaluate risks related to security, privacy, fairness, explainability, resilience, and accountability throughout the AI lifecycle.
NIST AI RMF vs. ISO 42001
To date, one other major AI risk management framework has emerged beyond NIST AI RMF: ISO 42001, which debuted in December 2023. Although NIST AI RMF and ISO 42001 both focus on AI governance and risk management and are broadly similar, they differ in key respects.
NIST AI RMF is a voluntary framework that provides guidance for identifying and managing AI risks. Organizations can adopt the framework flexibly and tailor its recommendations to their specific needs. The framework emphasizes risk assessment, governance, and continuous improvement but does not define formal certification requirements.
ISO 42001, by contrast, is an international management system standard for AI. It establishes formal requirements for creating, implementing, maintaining, and improving an Artificial Intelligence Management System (AIMS). Organizations can pursue third-party certification to demonstrate compliance with the standard, but this is not possible using NIST AI RMF.
In practice, many organizations use the two frameworks together. NIST AI RMF provides practical guidance for AI risk management, while ISO 42001 offers a structured compliance framework that organizations can certify against.
NIST AI RMF vs. EU AI Act
The NIST AI RMF also differs significantly from the EU AI Act.
The EU AI Act is a regulatory framework that establishes legally binding requirements for organizations operating certain AI systems within the European Union. It categorizes AI systems according to risk levels and imposes compliance obligations on providers and deployers of high-risk AI systems.
NIST AI RMF, in contrast, is not a regulation. It does not create legal obligations or define penalties for noncompliance. Instead, it provides guidance that organizations can use to improve AI governance and risk management practices.
It’s possible to use NIST AI RMF to support EU AI Act compliance because the framework’s governance, risk assessment, and documentation practices align with many of the operational requirements imposed by the regulation. However, implementing NIST AI RMF alone does not guarantee compliance with the EU AI Act.
It’s also worth noting that the NIST AI RMF was developed by a US-based government agency that operates independently of European Union agencies, which created the AI Act; thus, there is no formal or official connection between NIST AI RMF and the EU AI Act.
Operationalizing CTEM Through External Exposure Management
CTEM breaks when it turns into vulnerability chasing. Too many issues, weak proof, and constant escalation…
This whitepaper offers a practical starting point for operationalizing CTEM, covering what to measure, where to start, and what “good” looks like across the core steps.
Key components of NIST AI RMF
NIST AI RMF is organized around four core functions: Govern, Map, Measure, and Manage. Together, these functions provide a lifecycle-oriented approach to AI risk management.
Governance
The NIST AI RMF Govern function establishes the organizational structures, policies, processes, and accountability mechanisms needed to manage AI risks throughout the AI lifecycle. The framework identifies governance as a cross-cutting function that should be “infused throughout the other three functions” so that it informs all risk management activities. It emphasizes leadership oversight, risk management policies, organizational culture, and roles and responsibilities for trustworthy AI. The framework also highlights the importance of integrating AI risk management into broader enterprise governance and risk management programs.
AI system mapping
The Map function focuses on understanding AI systems within their intended context, including their purpose, stakeholders, operating environment, and potential impacts. According to the AI RMF’s MAP function, organizations should document system capabilities, data sources, assumptions, limitations, and affected parties to create a comprehensive picture of how AI systems are used and where risks may emerge. This contextual understanding provides the foundation for meaningful risk identification and evaluation.
Risk assessment
The Measure function serves as the framework’s primary capability for analyzing, benchmarking, and monitoring AI-related risks. To help organizations achieve this goal, NIST AI RMF emphasizes the use of qualitative and quantitative methods to assess characteristics such as AI accuracy, reliability, robustness, security, privacy, fairness, and explainability. The framework also stresses that AI risk measurement should be “continuous, timely, and performed throughout the AI system lifecycle dimensions” because risks can evolve as models, data, and operating conditions change over time.
Risk management and mitigation
The Manage function focuses on prioritizing, responding to, and monitoring AI risks based on organizational objectives and risk tolerance. The framework recommends implementing controls, mitigation strategies, incident response procedures, and ongoing monitoring processes to reduce the likelihood or impact of identified risks. The function also emphasizes continuous improvement, ensuring that organizations regularly reassess risks and adapt mitigation measures as AI systems and threat landscapes evolve.
Tips from the Expert
Rob Gurzeev, CEO and Co-Founder of CyCognito, has led the development of offensive security solutions for both the private sector and intelligence agencies.
- Continuously monitor and manage AI exposures: The constantly changing nature of AI systems makes it essential to detect new risks as they emerge. Practices like Continuous Threat Exposure Management (CTEM) play a vital role in this area by allowing businesses to monitor for new AI threats on an ongoing basis.
- Validate AI systems through ongoing testing: One-off tests or validations aren’t sufficient to ensure full AI risk coverage. Instead, strive for continuous tests that constantly validate and revalidate AI systems, making it possible to detect new vulnerabilities as they emerge.
- Measure AI risk using consistent metrics and reporting: Quantifying the level of risk that AI vulnerabilities pose, helps businesses track their overall AI security hygiene, while also providing clarity into which risks to prioritize. For this reason, consider tracking metrics like Attack Success Rate (ASR) and flag rate and reporting on them regularly.
- Adapt AI risk management practices based on emerging threats: As AI technology evolves, new security risks and challenges are likely to emerge, and security strategies must evolve with them.
Limitations of NIST AI RMF
While NIST AI RMF provides valuable guidance, organizations should recognize its limitations and supplement it with additional frameworks, controls, and security practices when necessary.
Limited specificity for AI security controls
One of the framework’s primary limitations is its intentionally high-level nature.
NIST AI RMF focuses on principles, processes, and risk management concepts rather than prescribing detailed technical security controls. While this flexibility makes the framework broadly applicable to different types of AI systems and helps ensure its relevance as AI evolves, it can leave organizations uncertain about exactly which controls they should implement to address specific AI threats.
For this reason, businesses may need to supplement AI RMF with additional guidance from cybersecurity frameworks, AI security standards, and industry-specific best practices to build comprehensive AI security programs.
Limited coverage of agentic AI security (vs. generative)
The framework was developed shortly after the emergence of production-ready generative AI technologies, and it predates more recent advances in autonomous and agentic AI systems. For example, the Model Context Protocol, an important standard for creating AI agents, did not exist when NIST AI RMF appeared.
As a result, AI RMF provides limited guidance for managing MCP security risks and other challenges associated with protecting AI agents that can autonomously make decisions, interact with external systems, execute workflows, or perform actions without continuous human oversight.
Organizations deploying agentic AI may therefore need additional governance and security measures to address risks such as excessive autonomy, tool misuse, unauthorized actions, and complex decision chains that extend beyond traditional generative AI use cases.
Lack of formal enforcement
Unlike regulatory frameworks and certifiable standards, NIST AI RMF lacks formal enforcement mechanisms. Organizations are free to adopt the framework in whole, in part, or not at all. There are no audits, penalties, certifications, or legal consequences associated with noncompliance.
While this flexibility encourages broad adoption, it can also create inconsistencies in implementation. Different organizations may interpret and apply the framework in significantly different ways, leading to varying levels of risk management maturity.
Is NIST AI RMF compliance mandatory?
Compliance with NIST AI RMF is not mandatory in any way.
The framework is voluntary and does not carry the force of law. Organizations are not legally required to implement its recommendations unless specific contractual, regulatory, or organizational requirements reference the framework.
However, organizations may voluntarily adopt AI RMF because it provides a widely recognized foundation for AI governance and risk management. Government agencies, regulated industries, and organizations pursuing responsible AI initiatives increasingly use the framework as a benchmark for establishing AI risk management programs.
In practice, implementing AI RMF can also support compliance with emerging AI regulations and standards by helping organizations establish governance, documentation, and risk assessment processes that regulators increasingly expect to see.
How NIST AI RMF supports exposure management
As organizations deploy more AI systems, they face growing challenges related to visibility, attack surface management, and risk prioritization. Traditional exposure management practices aren’t always able to identify these risks due to the unique character of AI security threats. However, NIST AI RMF helps close this gap by reinforcing principles that extend threat exposure management processes into the realm of AI.
Specifically, the framework emphasizes understanding and documenting AI assets, data sources, third-party dependencies, and operational contexts (these actions are covered in the section Govern 1.6, which addresses the inventorying of AI systems). These activities help organizations build comprehensive inventories of AI-related exposures and identify previously unknown or unmanaged risks.
NIST AI RMF also encourages (in sections Measure 2.4 and 3.1) continuous monitoring and ongoing risk assessment, which align closely with modern exposure management practices. Section Manage 3.1 extends continuous monitoring to third-party assets. Rather than relying on periodic assessments alone, organizations are encouraged to maintain ongoing visibility into AI systems and emerging threats.
Exposure management is an important component of NIST AI RMF no matter which types of AI system an organization uses, but it becomes particularly important for businesses that adopt externally hosted AI services, foundation models, and agentic AI platforms. These technologies often introduce new attack surfaces that traditional security programs may not adequately address. By incorporating AI risk management into broader exposure management initiatives, organizations can improve their ability to identify, validate, prioritize, and remediate AI-related security risks before they lead to exploitation.
Best practices for achieving AI RMF compliance
Organizations seeking to align with NIST AI RMF can strengthen their AI risk management programs by following several key best practices.
Align controls with risk tolerance
AI risks vary significantly across use cases, industries, and deployment environments. Organizations should align AI security controls, governance processes, and oversight mechanisms with their specific risk tolerance and business objectives.
Risk-based implementation helps ensure that resources are focused on the most significant threats while avoiding unnecessary complexity for lower-risk AI applications.
Document AI security risks and processes
Comprehensive documentation is essential for effective AI risk management.
Businesses should maintain inventories of AI systems, document risk assessments, track mitigation activities, and establish clear records of governance decisions. Documentation improves accountability, supports audits and regulatory reviews, and enables more effective risk management over time.
Make AI security a cultural (not just technical) priority
Successful AI risk management requires participation from stakeholders across the organization.
Security teams, data scientists, legal departments, compliance personnel, and executive leadership all play important roles in managing AI risks. Building a culture of responsible AI use helps ensure that risk management considerations are integrated into everyday decision-making rather than treated as an isolated technical function.
Understand and address the limits of AI RMF
Organizations should recognize that AI RMF is a foundation rather than a complete solution to AI security risks.
While the framework provides valuable guidance, it should be supplemented with technical security controls, AI-specific testing methodologies, threat modeling practices, exposure management programs, and regulatory compliance efforts. Understanding the framework’s limitations enables organizations to build more comprehensive and resilient AI governance programs.
As AI technologies continue to evolve, organizations that combine NIST AI RMF with continuous exposure management and robust security practices will be better positioned to manage emerging risks while maintaining trust, compliance, and operational resilience.
Boosting AI security with CyCognito
NIST AI RMF tells you to inventory your AI systems and monitor them continuously. As a high-level framework, it does not tell you how to find the AI assets you don’t already know about, or how to confirm which of them an attacker could exploit. CyCognito is a leading external attack surface management platform that operationalizes those functions, continuously discovering and validating every internet-facing AI asset you run, starting from nothing more than your organization’s name.
- Builds the AI asset inventory the Govern function calls for, discovering model endpoints, APIs, MCP servers, and shadow AI without seeds or a prior list
- Extends discovery to the agentic and MCP exposures the framework barely addresses, covering the gap it left by predating autonomous AI
- Continuously validates whether discovered AI exposures are actually exploitable, replacing periodic assessment with the always-on measurement the framework calls for
- Prioritizes findings by attacker reachability and business context, matching the Manage function’s emphasis on acting according to risk tolerance
- Routes validated findings to the right owners and tracks remediation through to verified closure
Organizations using CyCognito typically uncover an attack surface up to 20x larger than previously inventoried, then continuous validation narrows it to the 0.1% of findings confirmed exploitable, giving Govern, Measure, and Manage the live data the framework assumes but does not provide.
If you want to see CyCognito in action, click here to schedule a 1:1 demo.