AI Governance: Complete Guide to Responsible AI Governance
Learn what AI governance is, why it matters, how frameworks support it, who is responsible, and how to build an...
Organizations searching for “NIST AI guidelines” often expect one definitive rulebook, but NIST’s AI guidance is distributed across frameworks, profiles, technical publications, security resources, evaluation programs, and standards initiatives.
NIST AI guidelines are voluntary resources that help organizations govern artificial intelligence, evaluate trustworthiness, and manage AI risks throughout the system lifecycle.
The National Institute of Standards and Technology develops AI guidance, measurement methods, evaluation resources, and technical standards activities. Its work is relevant to organizations that develop, purchase, deploy, integrate, or use AI systems.
The AI Risk Management Framework is central to this ecosystem, but it is not the only relevant resource. NIST also provides an implementation Playbook, a Generative AI Profile, adversarial machine-learning guidance, standards resources, and emerging guidance for advanced models and AI agents.
The framework is voluntary. It is not an AI law, universal certification requirement, or automatic route to regulatory compliance. As of September 2026, AI RMF 1.0 remains the published framework, but NIST states that a revision is in progress.
For a comprehensive explanation of the framework itself, see our NIST AI Risk Management Framework guide.
“NIST AI guidelines” describes an ecosystem, not one universal publication.
AI RMF 1.0 is voluntary and organized around four functions.
NIST identifies seven characteristics of trustworthy and responsible AI.
The Playbook suggests implementation actions but is not a mandatory checklist.
NIST provides specialized guidance for generative AI and AI security.
NIST guidance can support compliance activities but does not replace legal analysis.
NIST AI guidelines are the combined frameworks, profiles, publications, technical resources, and standards-related initiatives NIST provides to support trustworthy and responsible AI.
Organizations can use these resources when developing AI systems, purchasing AI products, integrating third-party models, establishing governance processes, conducting risk assessments, evaluating system performance, or monitoring AI after deployment.
Different types of NIST resources serve different purposes.
A framework organizes risk-management activities and outcomes. The NIST AI RMF is the primary example for AI risk management.
A profile applies a framework to a particular technology, sector, or risk context. The Generative AI Profile adapts AI RMF concepts to risks that are distinctive to or intensified by generative AI.
A Playbook provides suggested actions that organizations can consider when working toward framework outcomes.
A technical publication may define terminology, categorize threats, or explain testing and measurement challenges.
NIST also contributes to voluntary consensus standards, international standards activities, technical evaluation methods, and measurement science. It serves as the U.S. federal government’s AI standards coordinator and participates in national and international discussions on AI governance.
Organizations do not need to apply every NIST resource to every system. Guidance should be selected and adapted according to the intended use, operating environment, affected stakeholders, technical dependencies, lifecycle role, and severity of potential harm.
NIST AI RMF is voluntary. The official AI RMF page describes it as a resource intended to improve organizations’ ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI systems.
The framework is not itself a law or regulation. It does not create a universal requirement to adopt particular controls or obtain NIST certification.
A separate obligation may still make NIST guidance relevant. A contract, procurement condition, organizational policy, customer requirement, or sector-specific rule may incorporate NIST practices. In that case, the obligation comes from that separate instrument, not directly from AI RMF.
This distinction matters when discussing NIST compliance. An organization may align its governance and risk-management processes with NIST guidance, but that alignment does not automatically prove compliance with every applicable AI, privacy, cybersecurity, employment, consumer-protection, or sector-specific law.
The appropriate resource depends on what the organization needs to accomplish.
|
Organizational need |
Relevant NIST resource |
How it can be used |
|
Establish enterprise AI risk management |
AI RMF 1.0 |
Structure governance, context analysis, measurement, and risk treatment |
|
Identify implementation actions |
AI RMF Playbook |
Select suggested actions based on risk and organizational maturity |
|
Assess generative AI |
Generative AI Profile |
Extend AI RMF analysis to GenAI-specific risks |
|
Understand AI security threats |
NIST AI 100-2e2025 |
Support threat modeling and security-testing scenarios |
|
Evaluate AI systems |
NIST measurement resources |
Develop context-appropriate testing and evaluation methods |
|
Track standards activity |
NIST AI Standards resources |
Identify relevant standards, crosswalks, and international initiatives |
|
Assess advanced models and agents |
CAISI guidance |
Monitor and apply relevant finalized evaluation guidance |
|
Address critical-infrastructure use |
Emerging AI RMF profile |
Follow development of context-specific risk-management practices |
This is not an exhaustive list. Organizations may need to combine several resources, particularly when a system presents security, privacy, fairness, safety, or sector-specific risks.
NIST AI RMF 1.0 identifies seven characteristics of trustworthy and responsible AI.
These characteristics are not the four framework functions. The functions organize risk-management activities, while the characteristics identify important dimensions for evaluating AI trustworthiness.

NIST explains that trustworthiness is contextual. Trade-offs can arise, and not every characteristic carries equal importance in every application.
A valid and reliable AI system performs consistently with its intended purpose and under the conditions in which it is expected to operate.
Organizations should define acceptable performance before deployment and evaluate relevant error types, operating boundaries, data quality, uncertainty, subgroup performance, and performance changes over time.
One aggregate accuracy score is rarely enough. A system can perform well overall while producing unacceptable errors for particular groups or failing under conditions common in real-world use.
Safety concerns protection from harmful outcomes affecting people, property, organizations, communities, or the environment.
The required level of safety assurance should reflect the consequences of failure. An AI system involved in medical decisions, industrial control, transportation, or critical infrastructure normally requires stronger safeguards than a low-impact administrative tool.
Relevant measures can include realistic testing, operating limits, fallback procedures, human intervention, incident response, and the ability to restrict or stop unsafe operation.
Secure and resilient AI systems should withstand attacks, failures, unexpected inputs, and changing conditions while maintaining essential functions or recovering appropriately.
Risks may arise from malicious inputs, compromised training data, prompt injection, model extraction, unauthorized access, supply-chain weaknesses, provider outages, and vulnerabilities in connected software or tools.
Resilience also covers nonmalicious disruption, such as deteriorating data quality, model updates, service failures, or unfamiliar operating conditions.
Accountability requires clear responsibility for decisions and outcomes throughout the AI lifecycle. Transparency concerns the availability of appropriate information about the system, its purpose, governance, performance, limitations, and use.
Organizations can strengthen accountability by assigning system owners, defining approval authority, documenting risk decisions, establishing escalation routes, and clarifying responsibilities between internal teams and external providers.
The appropriate degree of transparency depends on the audience, context, legal obligations, intellectual-property considerations, and security constraints.
Explainability concerns how the mechanisms underlying an AI output can be represented or understood. Interpretability concerns what that output means in its intended context.
Different stakeholders may require different explanations. Developers may need technical diagnostics, while users or decision-makers may need clear information about influential factors, uncertainty, limitations, and the role of human judgment.
An explanation should be useful and accurate. A simplified explanation that misrepresents system behavior may create false confidence.
Privacy-enhanced AI incorporates practices that protect autonomy, identity, dignity, and confidentiality.
Relevant measures can include limiting data collection, controlling access, defining retention periods, monitoring data flows, assessing re-identification risk, and applying suitable privacy-enhancing technologies.
Privacy risk can arise from training data, prompts, outputs, logs, user profiling, model memorization, third-party integrations, and provider access. It should be evaluated throughout the AI lifecycle.
AI systems can produce or reinforce harmful disparities because of data, design decisions, evaluation choices, deployment conditions, or interaction with existing organizational and social practices.
Managing harmful bias requires more than checking whether a dataset appears balanced. Organizations should identify potentially affected groups, examine error distribution, assess how outputs influence decisions, involve relevant stakeholders, and respond when inequitable outcomes emerge.
Fairness is contextual. Teams should document their objectives, methods, evidence, limitations, and relevant trade-offs.
AI RMF 1.0 helps organizations manage risks to individuals, groups, communities, organizations, and society associated with AI.
Its intended audience includes organizations designing, developing, deploying, or using AI systems. The framework is flexible, non-sector-specific, and intended for voluntary use.
The NIST AI RMF contains four functions:
Govern
Map
Measure
Manage
These functions connect organizational governance with contextual analysis, testing, risk assessment, prioritization, and risk treatment. The seven trustworthy-AI characteristics provide dimensions for evaluating system risks and behavior.
AI RMF does not prescribe one identical control set for every organization. It is not a certification scheme and should be tailored to the system’s context and potential impacts.
NIST currently states that AI RMF 1.0 is being revised. Organizations should continue using the current published framework where appropriate while monitoring the official page for updated drafts and final publications.
The NIST AI RMF Playbook complements AI RMF 1.0 by suggesting actions for achieving outcomes in the framework’s Core.
The actions are aligned with subcategories under Govern, Map, Measure, and Manage. Organizations can use them to compare existing practices with potential activities, identify gaps, assign responsibilities, and plan improvements.
The Playbook is not a mandatory checklist or a fixed sequence that every organization must complete. Suggested actions should be selected and adapted based on organizational resources, maturity, risk tolerance, lifecycle role, and system context.
NIST states that the Playbook will be updated after AI RMF 1.0 is revised.
The Generative Artificial Intelligence Profile, NIST AI 600-1, is a cross-sectoral companion to AI RMF 1.0.
It helps organizations identify risks that are distinctive to or intensified by generative AI and consider actions for managing those risks. The profile does not replace AI RMF. It applies the framework’s concepts to the characteristics and dependencies associated with generative systems.
Organizations can use this NIST guidance for generative AI when evaluating foundation models, externally hosted AI services, generative features embedded in software, or internal applications built on third-party models.
Adversarial machine learning concerns attempts to manipulate, misuse, extract information from, or compromise machine-learning systems.
NIST AI 100-2e2025, Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations, provides standardized concepts and terminology for adversarial machine-learning threats.
Its taxonomy covers attacks affecting predictive and generative AI, including evasion, poisoning, privacy attacks, and misuse attacks involving generative systems.
Organizations can use this resource to establish a shared threat vocabulary, improve AI threat modeling, identify attack paths, plan security testing, evaluate dependencies, and incorporate AI incidents into cybersecurity response processes.
NIST supports the development and use of voluntary consensus standards for AI. Its work includes national coordination, international engagement, measurement research, terminology, testing, and evaluation.
The NIST AI Standards page explains how standards, guidelines, methodologies, and tools can complement AI risk management. NIST also maintains AI measurement and evaluation projects that support the development of methods for evaluating AI capabilities and risks.
Frameworks can define risk-management objectives, but implementation depends on credible evidence. Standards and measurement science can help make AI evaluations more consistent, repeatable, and meaningful.
NIST’s AI guidance ecosystem continues to expand beyond AI RMF 1.0.
The Center for AI Standards and Innovation Guidelines hub publishes voluntary guidance concerning advanced AI models, systems, and agents. This includes work on benchmark evaluations for language models and AI agent systems.
NIST’s AI standards activities also include the AI Standards “Zero Drafts” pilot, which develops preliminary stakeholder-informed materials for potential use in voluntary consensus standards processes. In July 2026, NIST released an initial public draft addressing guidance and templates for public-facing AI documentation.
NIST has also released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure. The proposed profile is intended to help critical-infrastructure operators identify context-specific AI risk-management practices.
Organizations should distinguish between final publications, initial public drafts, concept notes, and works in progress. Draft material can inform horizon scanning, but it should not be presented as finalized NIST guidance.

The four functions organize AI risk-management outcomes. They can interact across the AI lifecycle rather than operating as a rigid one-time sequence.
Govern establishes the organizational conditions for effective AI risk management.
It covers policies, accountability, roles, responsibilities, risk culture, oversight, and relevant legal or policy considerations. In practice, organizations may assign system owners, define approval authority, establish escalation routes, set risk tolerances, and clarify responsibilities involving third-party providers.
Govern has a cross-cutting role. Weak governance can undermine every other function because teams may lack the authority or accountability needed to address identified risks.
Map develops an understanding of the AI system and its context.
Organizations consider intended purpose, users, affected stakeholders, deployment conditions, dependencies, limitations, potential impacts, and foreseeable misuse.
This prevents teams from assessing a model in isolation. The same model may create substantially different risks when used for marketing assistance, recruitment, lending, healthcare, education, or critical infrastructure.
Measure involves analyzing and assessing AI risks through appropriate qualitative, quantitative, or mixed methods.
Activities can include validation, testing, benchmarking, impact assessment, bias analysis, security evaluation, and adversarial testing.
Measures should reflect the system’s intended use and potential consequences. A single performance score cannot establish that a system is valid, safe, secure, privacy-enhanced, explainable, and fair.
Manage connects risk findings to prioritization and treatment.
An organization may mitigate, avoid, transfer, accept, or monitor a risk, depending on its authority, objectives, evidence, and risk tolerance. Actions can include selecting controls, assigning owners, restricting system capabilities, documenting residual risks, or delaying deployment.
Manage also supports monitoring and adjustment when incidents, threats, or contextual changes emerge.
Understanding Govern, Map, Measure, and Manage is an important starting point. Applying them also requires teams to connect governance, contextual analysis, testing, documentation, risk treatment, and monitoring.
Professionals and organizations seeking structured learning can explore our NIST AI Risk Management Framework Training. The course provides focused learning on the framework and its role in organizational AI risk management.
Generative AI can produce persuasive text, images, audio, video, and software code at scale. Its outputs may also be inaccurate, unpredictable, harmful, insecure, or unsuitable for the context in which they are used.
Risk can arise from the model, training data, prompts, retrieval systems, external providers, connected tools, system configuration, user behavior, or downstream automation.
Relevant concerns include confabulated output, information-integrity risks, harmful content, exposure of confidential information, prompt injection, intellectual-property concerns, model dependencies, overreliance, and inadequate human oversight.
Not every risk applies equally to every application. A writing assistant and a system influencing consequential decisions require different testing, documentation, access controls, and oversight.
Organizations can apply the GenAI Profile through a concise process:
Define the use case. Specify what the system may do, what it should not do, who will use it, and whether outputs influence consequential decisions.
Establish context. Identify stakeholders, data flows, deployment conditions, connected tools, providers, and foreseeable misuse.
Identify risks. Consider inaccurate output, harmful content, privacy, security, intellectual property, information integrity, and overreliance.
Assess and measure risks. Test realistic tasks, edge cases, adversarial prompts, output quality, access controls, and failure conditions.
Implement mitigations. Apply proportionate technical, procedural, contractual, and human controls.
Monitor the system. Track incidents, complaints, misuse, provider updates, performance changes, and control effectiveness.
Update controls. Revise testing, restrictions, documentation, and oversight when the system or context changes.
The following practices translate NIST’s risk-based concepts into organizational actions. They are implementation recommendations derived from NIST guidance, not universal mandatory controls.
Define decision authority, risk ownership, escalation routes, acceptable-use rules, and oversight responsibilities. Involve relevant functions such as technology, security, privacy, legal, compliance, procurement, risk, and business operations.
Record AI systems being developed, procured, tested, deployed, or retired. Include internal systems, third-party services, embedded AI features, approved generative tools, system owners, intended purposes, providers, data categories, and risk classifications.
Assess effects on individuals, groups, organizations, and society where relevant. Consider errors, discrimination, privacy loss, security compromise, unsafe behavior, operational disruption, misuse, and overreliance.
Select evaluation methods based on intended purpose and potential harm. Test realistic conditions, edge cases, different affected groups, adversarial interactions, degraded inputs, and relevant human-oversight arrangements.
Record intended purpose, limitations, evidence, evaluation methods, findings, control decisions, risk owners, approvals, and residual risks. Documentation should allow future reviewers to understand why decisions were made.
Define when people must review, confirm, override, or stop AI-supported actions. Reviewers need adequate authority, information, time, and competence. A nominal approval step is insufficient if reviewers cannot meaningfully challenge the system.
Track performance, incidents, complaints, overrides, unexpected use, emerging threats, provider changes, and shifts in data or context. Establish triggers for reassessment, restriction, suspension, or retirement.
Use incidents, testing results, stakeholder feedback, audit findings, and regulatory developments to update controls and governance. Risk management should evolve with the system and its deployment environment.
A concise roadmap for implementing NIST AI RMF and related NIST resources includes these steps:
Establish policies, accountability, decision authority, and risk tolerance.
Inventory internally developed, purchased, and embedded AI systems.
Document intended purpose, stakeholders, context, data flows, and dependencies.
Identify technical and nontechnical risks, including foreseeable misuse.
Evaluate the relevant trustworthy-AI characteristics.
Select proportionate technical, procedural, contractual, and human controls.
Document findings, residual risks, approvals, and monitoring requirements.
Monitor deployed systems and reassess them after material changes.
This roadmap is an organization-level interpretation of NIST concepts. It is not an official mandatory NIST sequence. Organizations needing a more detailed process should consult a dedicated implementation guide rather than treating this summary as a complete AI RMF program.
NIST AI RMF and ISO/IEC 42001 both support structured AI governance, but they serve different purposes.
|
Area |
NIST AI RMF |
ISO/IEC 42001 |
|
Primary focus |
AI risk management |
AI management system |
|
Nature |
Voluntary framework |
International management-system standard |
|
Main objective |
Managing AI risks |
Establishing and improving an AI management system |
|
Structure |
Govern, Map, Measure, Manage |
Management-system requirements |
|
Certification |
AI RMF itself is not a certification |
Certification can be pursued through appropriate certification bodies |
|
Relationship |
Can support AI governance |
Can be used alongside NIST AI RMF |
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system.
NIST develops AI RMF as a risk-management framework. ISO and IEC developed ISO/IEC 42001 as a management-system standard. Certification against ISO/IEC 42001 can be pursued through an appropriate independent certification body, but ISO itself does not certify organizations.
Yes. NIST and ISO 42001 can be complementary.
ISO/IEC 42001 can provide the management-system structure for policies, objectives, responsibilities, documented processes, audits, corrective actions, and continual improvement.
AI RMF can support more detailed analysis of AI risks through Govern, Map, Measure, and Manage. Its trustworthy-AI characteristics can also inform how organizations evaluate systems and prioritize risk treatment.
Using both does not make them equivalent. ISO/IEC 42001 certification does not automatically demonstrate every AI RMF outcome, and AI RMF alignment does not provide ISO/IEC 42001 certification.
NIST guidance, standards, organizational controls, and regulations serve different functions.
NIST guidance helps organizations structure risk-management activities. Standards may define agreed requirements, terminology, technical methods, or management processes. Organizational controls translate governance objectives into operational practices. Regulations create legal obligations within a particular jurisdiction and scope.
Organizations may use NIST resources to support activities relevant to the EU AI Act, privacy laws, cybersecurity requirements, consumer-protection rules, employment obligations, sector-specific regulation, procurement conditions, or contractual requirements.
However, NIST alignment does not automatically establish legal compliance.
Organizations should map NIST-informed processes to the exact obligations applying to their roles, systems, sectors, and jurisdictions. Requirements concerning documentation, transparency, human oversight, security, data governance, testing, or incident reporting must be evaluated independently.
Treating AI RMF as mandatory law: The framework is voluntary. Separate laws, policies, or contracts may create obligations, but AI RMF itself is not a regulation.
Using it as a one-time checklist: AI systems, providers, data, users, and deployment conditions change. Risk decisions require periodic reassessment.
Focusing only on model performance: Accuracy cannot address every risk. Governance, privacy, safety, security, harmful bias, transparency, human behavior, and downstream impacts also matter.
Ignoring accountability: Testing cannot compensate for unclear ownership. Organizations need decision-makers who can approve, restrict, suspend, or retire systems.
Ignoring post-deployment monitoring: Real-world operation may reveal misuse, drift, emerging threats, or impacts that were not visible during testing.
Applying identical controls to every system: Controls should reflect purpose, autonomy, scale, data sensitivity, affected stakeholders, and severity of potential harm.
Confusing AI RMF with ISO/IEC 42001: One is a risk-management framework and the other is a management-system standard. They can complement each other but are not interchangeable.
Overlooking GenAI-specific risks: Generic assessments may miss confabulation, prompt injection, harmful content, sensitive prompt data, information-integrity risks, and external foundation-model dependencies.
Establish AI governance policies
Define roles and responsibilities
Inventory AI systems and use cases
Define intended purpose and context
Identify stakeholders and potential impacts
Identify AI risks
Evaluate trustworthy-AI characteristics
Test and measure AI systems
Address security and privacy risks
Assess harmful bias
Document risk decisions
Establish human oversight
Monitor deployed AI systems
Review and update controls
Use specialized NIST guidance where appropriate
This checklist is an organization-level implementation aid based on NIST concepts. It is not an official NIST checklist, mandatory control set, or required sequence.
NIST AI guidelines form a broad and evolving ecosystem rather than one universal guideline document. AI RMF is a central component, providing the Govern, Map, Measure, and Manage functions for structured AI risk management.
The seven trustworthy-AI characteristics provide important dimensions for evaluating AI systems. The Playbook offers suggested implementation actions, while the Generative AI Profile addresses risks that are distinctive to or intensified by generative AI. NIST also contributes security publications, measurement initiatives, advanced AI guidance, and standards-related resources.
Organizations should tailor these resources to their systems, lifecycle roles, stakeholders, and risk context. NIST guidance can strengthen AI governance and complement ISO/IEC 42001, but it does not create universal certification or automatically establish regulatory compliance.
Because AI RMF 1.0 is being revised and the wider NIST AI ecosystem continues to develop, organizations should monitor official publications while applying the current guidance appropriate to their use cases.
NIST AI guidelines are an ecosystem of frameworks, profiles, technical publications, implementation resources, measurement programs, and standards activities. They help organizations govern AI and manage risks associated with developing, purchasing, deploying, and using AI systems. There is no single universal NIST publication officially titled “NIST AI Guidelines.”
AI RMF 1.0 identifies seven trustworthy-AI characteristics: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed. Their relevance and the trade-offs between them depend on the system’s use and risk context.
No. AI RMF is a voluntary framework, not an AI law or universal regulatory requirement. A contract, procurement condition, policy, or other obligation may make particular NIST practices relevant, but that requirement comes from the separate instrument rather than from AI RMF itself.
The four functions are Govern, Map, Measure, and Manage. Govern addresses policies and accountability. Map establishes context and potential impacts. Measure evaluates risks and trustworthiness. Manage prioritizes and treats risks while supporting monitoring and improvement.
Yes. NIST AI 600-1, the Generative Artificial Intelligence Profile, is a cross-sectoral companion to AI RMF 1.0. It addresses risks that are distinctive to or intensified by generative AI and provides actions organizations can consider when managing those risks.
The Playbook provides suggested actions aligned with outcomes in the AI RMF Core. It helps organizations consider ways to operationalize Govern, Map, Measure, and Manage. NIST does not describe it as a checklist or a sequence every organization must follow in full.
No. AI RMF is not a certification program, and adopting it does not make an organization “NIST certified.” Organizations may assess and document their alignment with the framework, but they should not imply that NIST has formally certified or approved them.
NIST AI RMF is a voluntary AI risk-management framework organized around four functions. ISO/IEC 42001 is an international AI management-system standard containing auditable management-system requirements. They are not interchangeable, although organizations can use them together.
Yes. NIST guidance can support governance, risk assessment, testing, documentation, security, privacy, and monitoring processes relevant to compliance. It does not automatically prove compliance with the EU AI Act, privacy regulations, contracts, sector-specific requirements, or every other applicable obligation.
Begin by establishing governance and inventorying AI systems. Map each system’s purpose, stakeholders, context, and impacts. Assess relevant risks and trustworthy-AI characteristics, implement proportionate controls, document decisions, establish meaningful human oversight, and monitor the system after deployment.
Learn what AI governance is, why it matters, how frameworks support it, who is responsible, and how to build an...
AGI
Artificial general intelligence (AGI) generally describes AI with broad cognitive capabilities that can learn, reason, solve problems, and apply knowledge...