Back to Learning Center

The Role of NIST AI RMF in AI Security Strategies

The National Institute of Standards and Technology (NIST) – the organization known in the cybersecurity world for maintaining resources like the National Vulnerability Database (NVD) and the NIST Cybersecurity Framework – has become a prominent source of guidance in the realm of AI security, too, thanks to the NIST AI Risk Management Framework (AI RMF).

As the first major standard to offer a structured guide to securing AI systems, NIST AI RMF can be a valuable resource for organizations seeking to develop a comprehensive AI security strategy.

Read on to learn whether NIST AI RMF is the best AI risk management framework for your business’s needs as we explain what the AI RMF is, compare it to other major AI security standards (including ISO 42001), discuss its limitations, and offer tips on deriving the greatest value from AI RMF as a way to bolster AI security.

What is NIST AI RMF?

The NIST AI Risk Management Framework is a voluntary framework designed to help organizations identify, assess, manage, and monitor risks associated with AI systems. Released in January 2023 by the National Institute of Standards and Technology, a US federal agency, the framework provides a flexible approach for improving the trustworthiness, safety, security, and reliability of AI applications and services.

Like most cybersecurity frameworks, NIST AI RMF doesn’t prescribe highly specific technical controls. Instead, it offers high-level guidance for integrating AI risk management into organizational processes and decision-making. The framework aims to be applicable across industries, organization sizes, and AI use cases, and to remain relevant as AI evolves.

A core objective of AI RMF is helping organizations balance innovation with responsible AI development and deployment. The framework encourages organizations to evaluate risks related to security, privacy, fairness, explainability, resilience, and accountability throughout the AI lifecycle.

NIST AI RMF vs. ISO 42001

To date, one other major AI risk management framework has emerged beyond NIST AI RMF: ISO 42001, which debuted in December 2023. Although NIST AI RMF and ISO 42001 both focus on AI governance and risk management and are broadly similar, they differ in key respects.

NIST AI RMF is a voluntary framework that provides guidance for identifying and managing AI risks. Organizations can adopt the framework flexibly and tailor its recommendations to their specific needs. The framework emphasizes risk assessment, governance, and continuous improvement but does not define formal certification requirements.

ISO 42001, by contrast, is an international management system standard for AI. It establishes formal requirements for creating, implementing, maintaining, and improving an Artificial Intelligence Management System (AIMS). Organizations can pursue third-party certification to demonstrate compliance with the standard, but this is not possible using NIST AI RMF.

In practice, many organizations use the two frameworks together. NIST AI RMF provides practical guidance for AI risk management, while ISO 42001 offers a structured compliance framework that organizations can certify against.

NIST AI RMF vs. EU AI Act

The NIST AI RMF also differs significantly from the EU AI Act.

The EU AI Act is a regulatory framework that establishes legally binding requirements for organizations operating certain AI systems within the European Union. It categorizes AI systems according to risk levels and imposes compliance obligations on providers and deployers of high-risk AI systems.

NIST AI RMF, in contrast, is not a regulation. It does not create legal obligations or define penalties for noncompliance. Instead, it provides guidance that organizations can use to improve AI governance and risk management practices.

It’s possible to use NIST AI RMF to support EU AI Act compliance because the framework’s governance, risk assessment, and documentation practices align with many of the operational requirements imposed by the regulation. However, implementing NIST AI RMF alone does not guarantee compliance with the EU AI Act.

It’s also worth noting that the NIST AI RMF was developed by a US-based government agency that operates independently of European Union agencies, which created the AI Act; thus, there is no formal or official connection between NIST AI RMF and the EU AI Act.

White Paper

Operationalizing CTEM Through External Exposure Management

CTEM breaks when it turns into vulnerability chasing. Too many issues, weak proof, and constant escalation…

This whitepaper offers a practical starting point for operationalizing CTEM, covering what to measure, where to start, and what “good” looks like across the core steps.

Get the White Paper

Key components of NIST AI RMF

NIST AI RMF is organized around four core functions: Govern, Map, Measure, and Manage. Together, these functions provide a lifecycle-oriented approach to AI risk management.

Governance

The NIST AI RMF Govern function establishes the organizational structures, policies, processes, and accountability mechanisms needed to manage AI risks throughout the AI lifecycle. The framework identifies governance as a cross-cutting function that should be “infused throughout the other three functions” so that it informs all risk management activities. It emphasizes leadership oversight, risk management policies, organizational culture, and roles and responsibilities for trustworthy AI. The framework also highlights the importance of integrating AI risk management into broader enterprise governance and risk management programs.

AI system mapping

The Map function focuses on understanding AI systems within their intended context, including their purpose, stakeholders, operating environment, and potential impacts. According to the AI RMF’s MAP function, organizations should document system capabilities, data sources, assumptions, limitations, and affected parties to create a comprehensive picture of how AI systems are used and where risks may emerge. This contextual understanding provides the foundation for meaningful risk identification and evaluation.

Risk assessment

The Measure function serves as the framework’s primary capability for analyzing, benchmarking, and monitoring AI-related risks. To help organizations achieve this goal, NIST AI RMF emphasizes the use of qualitative and quantitative methods to assess characteristics such as AI accuracy, reliability, robustness, security, privacy, fairness, and explainability. The framework also stresses that AI risk measurement should be “continuous, timely, and performed throughout the AI system lifecycle dimensions” because risks can evolve as models, data, and operating conditions change over time.

Risk management and mitigation

The Manage function focuses on prioritizing, responding to, and monitoring AI risks based on organizational objectives and risk tolerance. The framework recommends implementing controls, mitigation strategies, incident response procedures, and ongoing monitoring processes to reduce the likelihood or impact of identified risks. The function also emphasizes continuous improvement, ensuring that organizations regularly reassess risks and adapt mitigation measures as AI systems and threat landscapes evolve.

Tips from the Expert

Rob Gurzeev CEO and Co-Founder

Rob Gurzeev, CEO and Co-Founder of CyCognito, has led the development of offensive security solutions for both the private sector and intelligence agencies.

  • Continuously monitor and manage AI exposures: The constantly changing nature of AI systems makes it essential to detect new risks as they emerge. Practices like Continuous Threat Exposure Management (CTEM) play a vital role in this area by allowing businesses to monitor for new AI threats on an ongoing basis.
  • Validate AI systems through ongoing testing: One-off tests or validations aren’t sufficient to ensure full AI risk coverage. Instead, strive for continuous tests that constantly validate and revalidate AI systems, making it possible to detect new vulnerabilities as they emerge.
  • Measure AI risk using consistent metrics and reporting: Quantifying the level of risk that AI vulnerabilities pose, helps businesses track their overall AI security hygiene, while also providing clarity into which risks to prioritize. For this reason, consider tracking metrics like Attack Success Rate (ASR) and flag rate and reporting on them regularly.
  • Adapt AI risk management practices based on emerging threats: As AI technology evolves, new security risks and challenges are likely to emerge, and security strategies must evolve with them.

Limitations of NIST AI RMF

While NIST AI RMF provides valuable guidance, organizations should recognize its limitations and supplement it with additional frameworks, controls, and security practices when necessary.

Limited specificity for AI security controls

One of the framework’s primary limitations is its intentionally high-level nature.

NIST AI RMF focuses on principles, processes, and risk management concepts rather than prescribing detailed technical security controls. While this flexibility makes the framework broadly applicable to different types of AI systems and helps ensure its relevance as AI evolves, it can leave organizations uncertain about exactly which controls they should implement to address specific AI threats.

For this reason, businesses may need to supplement AI RMF with additional guidance from cybersecurity frameworks, AI security standards, and industry-specific best practices to build comprehensive AI security programs.

Limited coverage of agentic AI security (vs. generative)

The framework was developed shortly after the emergence of production-ready generative AI technologies, and it predates more recent advances in autonomous and agentic AI systems. For example, the Model Context Protocol, an important standard for creating AI agents, did not exist when NIST AI RMF appeared.

As a result, AI RMF provides limited guidance for managing MCP security risks and other challenges associated with protecting AI agents that can autonomously make decisions, interact with external systems, execute workflows, or perform actions without continuous human oversight.

Organizations deploying agentic AI may therefore need additional governance and security measures to address risks such as excessive autonomy, tool misuse, unauthorized actions, and complex decision chains that extend beyond traditional generative AI use cases.

Lack of formal enforcement

Unlike regulatory frameworks and certifiable standards, NIST AI RMF lacks formal enforcement mechanisms. Organizations are free to adopt the framework in whole, in part, or not at all. There are no audits, penalties, certifications, or legal consequences associated with noncompliance.

While this flexibility encourages broad adoption, it can also create inconsistencies in implementation. Different organizations may interpret and apply the framework in significantly different ways, leading to varying levels of risk management maturity.

Is NIST AI RMF compliance mandatory?

Compliance with NIST AI RMF is not mandatory in any way.

The framework is voluntary and does not carry the force of law. Organizations are not legally required to implement its recommendations unless specific contractual, regulatory, or organizational requirements reference the framework.

However, organizations may voluntarily adopt AI RMF because it provides a widely recognized foundation for AI governance and risk management. Government agencies, regulated industries, and organizations pursuing responsible AI initiatives increasingly use the framework as a benchmark for establishing AI risk management programs.

In practice, implementing AI RMF can also support compliance with emerging AI regulations and standards by helping organizations establish governance, documentation, and risk assessment processes that regulators increasingly expect to see.

How NIST AI RMF supports exposure management

As organizations deploy more AI systems, they face growing challenges related to visibility, attack surface management, and risk prioritization. Traditional exposure management practices aren’t always able to identify these risks due to the unique character of AI security threats. However, NIST AI RMF helps close this gap by reinforcing principles that extend threat exposure management processes into the realm of AI.

Specifically, the framework emphasizes understanding and documenting AI assets, data sources, third-party dependencies, and operational contexts (these actions are covered in the section Govern 1.6, which addresses the inventorying of AI systems). These activities help organizations build comprehensive inventories of AI-related exposures and identify previously unknown or unmanaged risks.

NIST AI RMF also encourages (in sections Measure 2.4 and 3.1) continuous monitoring and ongoing risk assessment, which align closely with modern exposure management practices. Section Manage 3.1 extends continuous monitoring to third-party assets. Rather than relying on periodic assessments alone, organizations are encouraged to maintain ongoing visibility into AI systems and emerging threats.

Exposure management is an important component of NIST AI RMF no matter which types of AI system an organization uses, but it becomes particularly important for businesses that adopt externally hosted AI services, foundation models, and agentic AI platforms. These technologies often introduce new attack surfaces that traditional security programs may not adequately address. By incorporating AI risk management into broader exposure management initiatives, organizations can improve their ability to identify, validate, prioritize, and remediate AI-related security risks before they lead to exploitation.

Best practices for achieving AI RMF compliance

Organizations seeking to align with NIST AI RMF can strengthen their AI risk management programs by following several key best practices.

Align controls with risk tolerance

AI risks vary significantly across use cases, industries, and deployment environments. Organizations should align AI security controls, governance processes, and oversight mechanisms with their specific risk tolerance and business objectives.

Risk-based implementation helps ensure that resources are focused on the most significant threats while avoiding unnecessary complexity for lower-risk AI applications.

Document AI security risks and processes

Comprehensive documentation is essential for effective AI risk management.

Businesses should maintain inventories of AI systems, document risk assessments, track mitigation activities, and establish clear records of governance decisions. Documentation improves accountability, supports audits and regulatory reviews, and enables more effective risk management over time.

Make AI security a cultural (not just technical) priority

Successful AI risk management requires participation from stakeholders across the organization.

Security teams, data scientists, legal departments, compliance personnel, and executive leadership all play important roles in managing AI risks. Building a culture of responsible AI use helps ensure that risk management considerations are integrated into everyday decision-making rather than treated as an isolated technical function.

Understand and address the limits of AI RMF

Organizations should recognize that AI RMF is a foundation rather than a complete solution to AI security risks.

While the framework provides valuable guidance, it should be supplemented with technical security controls, AI-specific testing methodologies, threat modeling practices, exposure management programs, and regulatory compliance efforts. Understanding the framework’s limitations enables organizations to build more comprehensive and resilient AI governance programs.

As AI technologies continue to evolve, organizations that combine NIST AI RMF with continuous exposure management and robust security practices will be better positioned to manage emerging risks while maintaining trust, compliance, and operational resilience.

Boosting AI security with CyCognito

NIST AI RMF tells you to inventory your AI systems and monitor them continuously. As a high-level framework, it does not tell you how to find the AI assets you don’t already know about, or how to confirm which of them an attacker could exploit. CyCognito is a leading external attack surface management platform that operationalizes those functions, continuously discovering and validating every internet-facing AI asset you run, starting from nothing more than your organization’s name.

  • Builds the AI asset inventory the Govern function calls for, discovering model endpoints, APIs, MCP servers, and shadow AI without seeds or a prior list
  • Extends discovery to the agentic and MCP exposures the framework barely addresses, covering the gap it left by predating autonomous AI
  • Continuously validates whether discovered AI exposures are actually exploitable, replacing periodic assessment with the always-on measurement the framework calls for
  • Prioritizes findings by attacker reachability and business context, matching the Manage function’s emphasis on acting according to risk tolerance
  • Routes validated findings to the right owners and tracks remediation through to verified closure

Organizations using CyCognito typically uncover an attack surface up to 20x larger than previously inventoried, then continuous validation narrows it to the 0.1% of findings confirmed exploitable, giving Govern, Measure, and Manage the live data the framework assumes but does not provide.

If you want to see CyCognito in action, click here to schedule a 1:1 demo.

Explore all guides

AI Security

AI Security

AI security covers prompt injection, model poisoning, insecure agents, MCP servers, shadow AI, and more. Learn the key risks and best practices for securing AI systems and infrastructure.

Learn More about AI Security
API Security

API Security

APIs, the unseen connections powering modern apps, can be vulnerable entry points for attackers. Weak API security exposes sensitive data and critical functions, potentially leading to breaches and disruptions.

Learn More about API Security
Application Security

Application Security

Application security (AppSec) involves safeguarding applications against threats throughout their lifecycle. This encompasses the entire process from design to deployment, ensuring that applications remain resilient against cyber threats.

Learn More about Application Security
Attack Surface Management

Attack Surface Management

Attack surface management is the continuous process of identifying and reducing an organization’s exposed assets and vulnerabilities before attackers can exploit them.

Learn More about Attack Surface Management
Cloud Security

Cloud Security

Cloud security refers to the discipline of protecting cloud-based infrastructure, applications, and data from internal and external threats.

Learn More about Cloud Security
Cyber Attack

Cyber Attack

A cyber attack is an attempt by hackers to damage or disrupt a computer network or system.

Learn More about Cyber Attack
DRPS

DRPS

A digital risk protection service (DRPS) offers visibility and defense against cybersecurity threats to an organization’s digital attack surfaces.

Learn More about DRPS
Exposure Management

Exposure Management

Exposure management is a set of processes which allow organizations to assess the visibility, accessibility, and risk factors of their digital assets.

Learn More about Exposure Management
Penetration Testing

Penetration Testing

Penetration testing, often called pentesting, is a simulated cyberattack on a computer system, network, or application to identify vulnerabilities.

Learn More about Penetration Testing
Red Teaming

Red Teaming

Red teaming is a security assessment method where a team simulates a real-world cyberattack on an organization to identify vulnerabilities and weaknesses in their defenses. This helps organizations improve their security posture by revealing potential attack vectors and response inefficiencies.

Learn More about Red Teaming
Threat Hunting

Threat Hunting

Threat hunting is a proactive cybersecurity practice where security teams search for and isolate advanced threats that have bypassed traditional security measures. It involves actively searching for malicious activity within a network, rather than just responding to alerts from security systems.

Learn More about Threat Hunting
Threat Intelligence

Threat Intelligence

Threat intelligence is the process of gathering, analyzing, and interpreting information about potential or actual cyber threats to an organization. It’s a proactive approach that helps organizations understand the threat landscape, identify risks, and implement effective security measures.

Learn More about Threat Intelligence
Vulnerability Assessment

Vulnerability Assessment

Vulnerability assessment is the process of identifying, quantifying, and prioritizing vulnerabilities in a system.

Learn More about Vulnerability Assessment
Vulnerability Management

Vulnerability Management

Vulnerability management is a comprehensive approach to identifying and reporting on security vulnerabilities in systems and the software they run.

Learn More about Vulnerability Management

By clicking submit, I acknowledge receipt of the CyCognito Privacy Policy.

Thank you! Here is the report you requested.

Click below to access your copy of the "Operationalizing CTEM With External Exposure Management" white paper.

Read the White Paper
Cycognito White Paper

Operationalizing CTEM With External Exposure Management

Operationalizing CTEM With External Exposure Management

CTEM breaks when it turns into vulnerability chasing. This whitepaper gives a practical starting point to operationalize CTEM through exposure management, with requirements, KPIs, and where to start.