Ai Ethics
AI Acceptable Use Policy: What Every Employee Should Know
Powerful AI tools are available within seconds, but convenience does not make every tool, prompt, upload, or workplace use appropriate....
AI risk management breaks down when governance, context, testing and response are treated as separate activities.
The NIST AI RMF is a voluntary framework that helps organizations manage risks associated with artificial intelligence and incorporate trustworthiness considerations into how AI systems are designed, developed, deployed, used and evaluated.
Its Core organizes AI risk management around four interconnected functions: Govern, Map, Measure and Manage. Govern establishes the organizational foundation. Map clarifies context and identifies risks. Measure produces evidence about those risks. Manage uses that evidence to prioritize and guide action.
The functions are not four mandatory sequential steps. Govern is cross-cutting, while Map, Measure and Manage interact repeatedly as systems, evidence and organizational conditions change.
For a broader introduction to the framework, read our NIST AI Risk Management Framework. The official NIST AI Risk Management Framework page provides the current framework, Playbook and related resources.
NIST AI RMF is intended for voluntary use and does not automatically establish legal compliance.
Govern is a cross-cutting function that supports Map, Measure and Manage.
Map establishes context and identifies risks connected to an AI system’s use.
Measure assesses, analyzes, benchmarks and monitors relevant risks and impacts.
Manage prioritizes risks and supports decisions about appropriate responses.
The functions interact continuously rather than forming a fixed implementation sequence.
The NIST AI RMF is an artificial intelligence risk-management framework published by the National Institute of Standards and Technology.
It provides a common structure for managing AI risks that may affect individuals, organizations, communities, society or the environment. It is designed to be flexible enough for organizations in different sectors and at different levels of AI maturity.
NIST AI RMF stands for the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework.
NIST is an agency of the United States Department of Commerce. AI RMF is the abbreviated name for its framework on incorporating trustworthiness considerations into AI risk management.
The purpose of NIST AI RMF is to improve organizations’ ability to identify, assess, prioritize and manage AI risks while supporting the responsible development and use of trustworthy AI systems.
The framework describes several characteristics of trustworthy AI, including systems that are valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
These characteristics can involve trade-offs. The appropriate balance depends on the system, its intended use, the people who may be affected and the environment in which it operates.
The complete framework is available in Artificial Intelligence Risk Management Framework 1.0, NIST AI 100-1.
As of September 2026, AI RMF 1.0 remains the current published framework. It was released on January 26, 2023.
NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan. A revised framework is in progress, but NIST has not stated that a new version has replaced AI RMF 1.0. NIST also says that the AI RMF Playbook will be updated after the framework is revised.
Organizations using the framework should monitor the official NIST page for revision announcements rather than assuming that draft or future material has replaced the published version.
No. NIST AI RMF is intended for voluntary use.
Organizations can use it to strengthen AI governance and support risk-management activities alongside applicable laws, regulations, standards, contractual obligations and internal requirements.
Using NIST AI RMF does not automatically make an organization legally compliant. The framework does not replace legal analysis or obligations that apply to a particular sector, jurisdiction or AI use case.
NIST AI RMF organizes its Core around four functions: Govern, Map, Measure and Manage.
|
Function |
What it does |
|
Govern |
Establishes and maintains the organizational conditions for AI risk management |
|
Map |
Establishes context and identifies risks connected to that context |
|
Measure |
Assesses, analyzes, benchmarks and monitors identified risks and impacts |
|
Manage |
Prioritizes risks and supports decisions and actions based on their projected impact |
Each function contains categories and subcategories that describe outcomes and actions. NIST states that these actions do not constitute a checklist and are not necessarily an ordered set of steps.
Govern provides the organizational foundation for AI risk management. It establishes policies, accountability, competencies, risk tolerance and decision processes that inform the other functions.
Map develops an understanding of the AI system and its operating context. It identifies the people, purposes, assumptions, limitations, benefits and possible negative impacts that matter to the use case.
Measure uses this contextual knowledge to select appropriate evaluation methods and gather evidence about relevant risks, impacts and controls.
Manage uses information from Map and Measure to prioritize risks, allocate resources and decide how the organization should respond.
The relationship can be understood as follows:
|
Function |
Information received |
Decision enabled |
Possible organizational output |
|
Govern |
Organizational objectives, responsibilities and obligations |
Who owns, oversees and acts on AI risk? |
Policy, responsibility matrix or escalation route |
|
Map |
System purpose, stakeholders and deployment context |
Which risks and impacts require attention? |
Context record or risk description |
|
Measure |
Test results, monitoring data and qualitative evidence |
How significant or uncertain is the risk? |
Evaluation report or monitoring result |
|
Manage |
Prioritized findings and available response options |
What action should the organization take? |
Treatment decision or action plan |
The final column contains examples of practices an organization might use. NIST does not require every organization to create these specific documents.
Govern should not be treated merely as the first activity. NIST describes it as cross-cutting and intended to inform and be infused throughout Map, Measure and Manage.
The process is also iterative. A measurement result can reveal that the system’s context was misunderstood. A management decision can require further testing. An incident can lead to updated governance, responsibilities or risk tolerance.
Govern establishes and maintains the culture, accountability and organizational processes needed to manage AI risk.
It connects AI risk management to leadership, policies, legal and regulatory considerations, workforce competency and broader organizational objectives. It also determines how risk information reaches people with the authority to make decisions.
Govern applies across the organization’s AI risk-management activities. It should continue to influence Map, Measure and Manage throughout the AI lifecycle.
The Govern function covers six broad areas in the NIST AI RMF Core.
|
Govern category |
Main focus |
|
Govern 1 |
Policies, processes, procedures and practices for AI risk management |
|
Govern 2 |
Accountability structures, roles, responsibilities and training |
|
Govern 3 |
Workforce diversity, equity, inclusion and multidisciplinary perspectives |
|
Govern 4 |
A culture that considers and communicates AI risk |
|
Govern 5 |
Engagement with relevant AI actors and stakeholders |
|
Govern 6 |
Third-party software, data and supply-chain risks |
In organizational practice, these areas can include policies, decision authority, risk tolerance, reporting channels, legal review, documentation, workforce competency, human oversight and processes for monitoring risk-management performance.
Organizations do not need to use identical governance structures. A smaller organization may assign responsibilities through existing management, security, compliance and product teams. A larger enterprise may use more specialized oversight arrangements.
The framework describes outcomes. The NIST AI RMF Playbook provides voluntary suggested actions that organizations can tailor to their needs. NIST explicitly states that the Playbook is neither a checklist nor a set of steps that must be followed in full.
Consider a hypothetical company using an AI system to help screen job applications.
Under Govern, the company could assign ownership of the system, define who approves its use and determine who evaluates employment, privacy, security and model risks.
It could specify the role of human recruiters, establish escalation procedures, document applicable organizational and legal considerations, and decide what level of risk the organization is prepared to tolerate.
The company might also train recruiters and technical staff, establish a process for reviewing vendor information and determine how applicants can request human review.
These are practical examples, not governance arrangements universally mandated by NIST.
Govern gives the other functions authority, structure and continuity.
It determines who performs mapping and measurement, who reviews the results, how risks are escalated and who can approve, restrict or stop an AI use case.
Without clear governance, an organization may identify risks but fail to assign responsibility. It may conduct testing without agreed decision criteria or discover a significant problem without a route for action.
The Map function establishes the context in which an AI system operates and identifies risks connected to that context.
Map is not simply a generic list of possible AI harms. It links risks to a particular purpose, population, deployment environment and human decision process.
According to NIST, completing Map adequately provides the contextual knowledge needed to inform an initial decision about whether an AI system should be designed, developed or deployed.
Map can examine an AI system’s intended purpose, potentially beneficial uses, users, affected individuals, deployment setting, assumptions, limitations and foreseeable impacts.
It can also consider relevant laws and expectations, human-AI interactions, data and system dependencies, third-party components, alternative approaches, potential misuse and risks that may arise across the AI lifecycle.
The precise scope depends on the use case. Mapping an internal tool that categorizes non-sensitive documents will differ from mapping an AI system that influences employment, healthcare, credit or access to public services.
The official NIST Map Playbook provides the Map categories, subcategories and suggested actions.
AI risk depends on how, where, why and by whom a system is used.
A model may perform well during testing but still create harm when deployed for a different population or purpose. The same model can create different risks depending on whether it provides optional recommendations or automatically determines an outcome.
Human interaction also changes risk. A trained professional who can review and challenge a recommendation creates a different context from a user who assumes the system is always correct.
Context determines what an organization should measure, whose interests should be considered and what consequences require management. Measuring a system before understanding its use can produce technically accurate results that do not answer the organization’s most important risk questions.
For the hypothetical recruitment system, the company could document that the system ranks applications for specific job categories but does not make final hiring decisions.
Relevant stakeholders might include applicants, recruiters, hiring managers, technical teams and the system provider.
The company could examine how historical recruitment data was created, whether the system may disadvantage particular applicants, how candidates with disabilities may interact with the process and whether recruiters could over-rely on rankings.
It could also evaluate expected benefits, such as helping recruiters review large application volumes, against possible negative impacts, such as excluding qualified candidates or reducing meaningful human review.
Map may reveal that the system is unsuitable for a proposed purpose before the organization commits further resources to deployment.
Map produces a context-rich account of the system and the risks that deserve attention.
Its outputs help the organization choose meaningful evaluation methods under Measure and determine which risks may require priority treatment under Manage.
Measure uses quantitative, qualitative or mixed methods to analyze, assess, benchmark and monitor AI risks and related impacts.
It takes the context and risks identified through Map and turns them into evidence that can inform management decisions.
Measure is broader than model-performance testing. It can examine technical behavior, human interaction, organizational controls and effects on individuals or communities.
Depending on the system and use case, organizations can evaluate validity, accuracy, reliability, robustness, safety, security, resilience, privacy, fairness, harmful bias, transparency, explainability, interpretability and human-AI interaction.
They may also assess broader impacts and whether existing controls work as intended.
Not every characteristic should be measured identically for every system. The methods and metrics should correspond to the significant risks identified through Map.
NIST does not prescribe universal thresholds for accuracy, fairness, bias, safety or other characteristics. Appropriate test sets, metrics, baselines and tolerances depend on the AI system, deployment context and organizational objectives.
Measure can include test, evaluation, validation and verification, often shortened to TEVV.
Organizations can use technical testing, qualitative review, user research, expert assessment, benchmarking, red teaming, impact analysis and operational monitoring when those methods are appropriate to the use case.
NIST emphasizes documenting measurement methods, test sets, tools, assumptions, uncertainty and evaluation results. Documentation helps decision-makers understand what the evidence shows and where its limitations remain.
Organizations should also distinguish among three levels of evidence:
|
Evidence level |
Example question |
|
Model evaluation |
How accurately and reliably does the model perform under defined conditions? |
|
System evaluation |
How do data, interfaces, safeguards and human users affect overall performance? |
|
Impact evaluation |
What outcomes or harms occur when the system is used in its actual context? |
Testing frequency should reflect governance arrangements, system changes and risk. NIST does not establish one universal testing schedule for every AI application.
The NIST Measure guidance provides suggested actions for selecting methods, evaluating trustworthy characteristics and tracking risks.
For the hypothetical recruitment system, the company could examine whether its ranking performance remains valid across the jobs for which it is used.
Where lawful and appropriate, it might analyze error patterns across relevant applicant groups, test system behavior when application data is incomplete and examine whether qualified candidates are being systematically missed.
The company could also assess recruiter behavior. It might investigate whether recruiters treat rankings as recommendations or defer to them automatically.
Post-deployment monitoring could examine performance drift, complaints, overrides and unexpected outcomes. The selected methods should follow from the context identified through Map.
Measure produces evidence about the nature, severity and uncertainty of AI risks.
That evidence helps organizations determine whether controls are effective, detect changes during operation and compare possible responses.
Measure does not make the final risk decision. It gives decision-makers a defensible basis for prioritization and action under Manage.
The Manage function prioritizes, responds to and monitors AI risks using information produced through Map and Measure.
Manage connects risk analysis to organizational decisions. It helps determine which risks require immediate attention, what resources should be assigned and whether an AI system’s development or deployment should proceed.
NIST’s Manage function considers factors such as impact, likelihood and available resources or methods.
Organizations can also consider the number and vulnerability of affected people, reversibility of harm, uncertainty in the evidence, legal or contractual considerations, organizational risk tolerance, expected benefits and the effectiveness of available controls.
NIST does not prescribe a universal numerical scoring formula. An organization can use risk criteria suited to its sector, systems and existing risk-management processes.
Priority should not be determined only by what is easiest to quantify. A difficult-to-measure risk may still require urgent attention if its potential impact is serious.
NIST identifies mitigating, transferring, avoiding and accepting as possible risk-response options.
An organization may mitigate a risk by changing the system, limiting its use, strengthening human review, improving security or introducing additional monitoring. It may avoid a risk by discontinuing a use case or selecting a non-AI alternative.
Acceptance should be an informed decision within established risk tolerance, not the result of failing to act. Transfer may shift certain financial or operational exposures, but it does not necessarily remove accountability or legal responsibility.
Organizations should also consider residual risk, meaning the risk that remains after responses and controls have been applied. If residual risk remains outside organizational tolerance, further action may be necessary.
The appropriate response depends on the system, evidence, potential impacts, applicable requirements and available alternatives.
Suppose the hypothetical recruitment system shows a significant and unexplained pattern of excluding qualified applicants from a relevant group.
The company could pause its use for affected job categories, increase human review, investigate the data and model, change the decision process or require remediation from the provider.
If the risk cannot be reduced to an acceptable level, the company could discontinue the system or use a different approach.
The response would depend on the evidence, potential impact, available alternatives and applicable requirements. NIST does not prescribe one response for every recruitment system.
The official NIST Manage Playbook explains how risks identified through Map and Measure can be prioritized and managed.
Manage turns contextual knowledge and evaluation evidence into prioritized decisions.
It supports resource allocation, risk response, monitoring and decisions about whether an AI system should proceed, change, pause or stop.
Manage can also lead back to the other functions. A response may require new measurements, a revised understanding of context or changes to governance.
|
NIST AI RMF function |
Core question |
Main focus |
|
Govern |
Who is accountable, and how will AI risk be overseen? |
Culture, policy, roles, competency and risk processes |
|
Map |
What is the system’s context, and which risks matter within it? |
Purpose, use, stakeholders, impacts, assumptions and limitations |
|
Measure |
What evidence do we have about those risks? |
Testing, evaluation, analysis, benchmarking and monitoring |
|
Manage |
Which risks matter most, and what should we do? |
Prioritization, response, resources and continuing action |
Govern establishes the foundation. Map establishes context and identifies risks. Measure evaluates and monitors risks. Manage prioritizes and responds to risks.
These functions are interconnected rather than mandatory sequential steps. Govern remains cross-cutting, while Map, Measure and Manage exchange information as systems and risks evolve.
Consider a hypothetical company using an AI system to help screen job applications. The system ranks applicants, but human recruiters retain responsibility for deciding who progresses.
|
Function |
Application to the recruitment system |
|
Govern |
Assign ownership, define recruiter and provider responsibilities, establish oversight and create escalation routes |
|
Map |
Document intended use, affected applicants, human-AI interaction, benefits, limitations and possible impacts |
|
Measure |
Evaluate reliability, error patterns, harmful bias, robustness, human reliance and control effectiveness |
|
Manage |
Prioritize significant risks, select responses and decide whether use should continue, change, pause or stop |
Under Govern, the company establishes responsibility for procurement, technical evaluation, recruitment decisions and risk oversight. It defines how concerns are escalated and who can authorize changes.
Under Map, it examines the jobs covered, applicant populations, data sources, system limitations, decision points and foreseeable impacts. It also considers whether another approach could achieve the same business purpose with less risk.
Under Measure, the company evaluates relevant performance and impact questions. It documents testing methods and limitations, examines whether human oversight works as intended and monitors the system after deployment.
Under Manage, decision-makers review the evidence, prioritize material risks and select appropriate responses. They may restrict use, strengthen controls, require provider changes or decide that the system should not be used for a particular purpose.
AI risk management continues after an initial response.
The company monitors performance, incidents, complaints, overrides and changes in use. If the provider updates the model, the company may need to reconsider assumptions established under Map and repeat relevant evaluations.
Changes in data, users, laws, organizational objectives or deployment environments can also alter risk. New evidence may lead to updated controls, responsibilities, training or risk tolerance.
This feedback demonstrates why Govern, Map, Measure and Manage operate as a continuing system rather than a one-time project.

The following NIST AI RMF implementation approach is a practical organizational interpretation. It is not an official NIST six-step process or mandatory implementation sequence.
Define responsibility, decision authority, risk tolerance and escalation channels. Connect AI risk management with relevant legal, compliance, privacy, security, procurement, product and enterprise-risk processes.
Develop enough visibility to understand where AI is being developed, purchased or used. An inventory may be helpful, but its structure and level of detail should reflect organizational needs and risk priorities.
For priority use cases, document purpose, stakeholders, affected people, dependencies, limitations, potential benefits and possible negative impacts.
Choose evaluation methods connected to the significant risks identified through Map. Define suitable metrics, qualitative methods, baselines, documentation and monitoring.
Compare the evidence with organizational risk tolerance and applicable requirements. Select proportionate responses, assign responsibility and determine whether development or deployment should proceed.
Reassess risks when the system, data, provider, users, environment or purpose changes. Feed lessons back into governance, mapping, measurement and management decisions.
Professionals who want to move from understanding the framework to applying AI governance and risk concepts in organizational settings can explore AGC’s NIST AI Risk Management Framework In Practice Course. The training can help learners develop deeper knowledge of governance responsibilities, risk identification, evaluation and oversight without presenting training as a guarantee of compliance.
Yes. AI RMF 1.0 can be applied to generative AI systems.
NIST published the Generative Artificial Intelligence Profile, NIST AI 600-1 on July 26, 2024. It is a cross-sectoral profile and companion resource that helps organizations apply AI RMF 1.0 to generative AI risks.
As of September 2026, NIST AI 600-1 remains the published Generative AI Profile. It supplements AI RMF 1.0 rather than replacing it.
Organizations developing, procuring or using generative systems can use the Profile to strengthen generative AI risk management.
Depending on the system and use case, relevant risks can include confabulation, information-integrity problems, privacy exposure, harmful bias, cybersecurity threats, intellectual-property concerns, harmful content, human over-reliance and third-party dependencies.
Not every generative AI system presents every risk at the same level. A public chatbot, internal summarization tool, coding assistant and healthcare application have different users, data, potential impacts and control requirements.
|
Function |
Possible generative AI application |
|
Govern |
Define approved uses, accountability, provider oversight, data rules and incident processes |
|
Map |
Identify users, data flows, dependencies, output uses, affected parties and foreseeable misuse |
|
Measure |
Evaluate factuality, security, privacy, harmful content, bias, robustness and human reliance where relevant |
|
Manage |
Prioritize material risks, restrict uses, add safeguards, strengthen review or discontinue unacceptable applications |
These are examples of how organizations can apply the Core. They are not controls universally required for every generative AI system.
|
Mistake |
Why it weakens AI risk management |
|
Treating AI RMF as a checklist |
It ignores the framework’s voluntary, flexible and context-sensitive design |
|
Treating the functions as a fixed sequence |
It misses the feedback between governance, context, evidence and response |
|
Focusing only on technical performance |
It overlooks human, organizational and societal impacts |
|
Measuring without mapping context |
It can produce evidence disconnected from actual risks |
|
Managing risks without accountability |
Findings may lack owners, resources or decision authority |
|
Treating risk management as a one-time activity |
It misses changes in systems, data, users and deployment conditions |
The NIST AI RMF Playbook FAQ confirms that users are not expected to implement every suggestion or follow the Playbook as an ordered series of steps.
NIST AI RMF is a broad structure for organizing AI risk-management activities. An AI risk assessment is a more focused activity used to identify, analyze or evaluate risks associated with a particular system or use case.
Assessment findings can contribute to Map by identifying context-specific risks, to Measure by producing evidence and to Manage by informing prioritization and response.
Govern provides the organizational conditions under which assessments are commissioned, reviewed, escalated and acted upon.
An AI risk assessment can therefore be part of AI risk management, but it is not equivalent to the entire NIST AI RMF.
The following official resources provide the most reliable starting points:
NIST AI RMF is the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework. It is a voluntary framework that helps organizations incorporate trustworthiness considerations into the design, development, deployment, use and evaluation of AI systems.
The four functions are Govern, Map, Measure and Manage. Govern supports organizational oversight, Map establishes context and identifies risks, Measure evaluates and monitors those risks, and Manage prioritizes risks and guides appropriate responses.
Govern establishes the policies, accountability, roles, competencies, culture and processes needed for AI risk management. It is a cross-cutting function that informs Map, Measure and Manage throughout the AI lifecycle.
Map establishes the context in which an AI system is developed or used. It examines purpose, users, stakeholders, affected people, potential impacts, assumptions and limitations so the organization can identify risks relevant to the use case.
Measure uses quantitative, qualitative or mixed methods to assess, analyze, benchmark and monitor AI risks and impacts identified through Map. Appropriate methods depend on the AI system, context and risks.
Manage uses information from Map and Measure to prioritize risks and determine appropriate responses. It also supports decisions about whether an AI system should proceed, change, pause or stop.
No. The functions are interconnected rather than mandatory sequential steps. Govern is cross-cutting, while Map, Measure and Manage can be revisited as systems, risks, evidence and organizational conditions change.
No. NIST AI RMF is intended for voluntary use. Organizations may apply it alongside laws, regulations, contracts, standards and internal requirements, but using it does not automatically establish legal compliance.
Organizations can apply all four functions to generative AI. NIST AI 600-1 supplements AI RMF 1.0 with generative-AI-specific risks and suggested actions that organizations can tailor to their systems, goals and priorities.
An organization can establish governance, identify AI use cases, map context and risks, select appropriate evaluation methods, prioritize responses and monitor systems over time. The approach should be tailored rather than treated as one mandatory sequence.
Ai Ethics
Powerful AI tools are available within seconds, but convenience does not make every tool, prompt, upload, or workplace use appropriate....
GPT-6 Astra moves advanced AI beyond answering questions and toward completing complex, multi-stage work. According to the official OpenAI API...