AI Governance & Regulation: EU AI Act, NIST AI RMF and ISO/IEC 42001Frameworks: NIST AI RMF and ISO/IEC 42001 · Lesson 8 of 17

NIST AI RMF and the Generative AI Profile

Article · 16 min · 8 min lecture

Video lecture

NIST AI RMF and the Generative AI Profile

13 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 13

NIST AI RMF

  • Voluntary, free, widely recognized
  • 7 trustworthy characteristics
  • Govern, Map, Measure, Manage
  • 12 generative AI risks

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

What the NIST AI RMF is (and isn't)

The AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1), published by the US National Institute of Standards and Technology in January 2023, is a voluntary, sector-agnostic framework for managing AI risks. It is not a law and there is no certification. Its value is a shared vocabulary and a structured checklist that works anywhere: US companies use it, EU companies map it to the AI Act, and Gulf and Pakistani organizations use it because it is free, practical and widely recognized by enterprise buyers.

NIST also publishes an AI RMF Playbook with suggested actions for each subcategory, and in July 2024 released NIST AI 600-1, the Generative AI Profile, which applies the framework to generative AI. NIST continues to add resources (for example profiles for specific contexts), so check the NIST AI Resource Center for the latest.

Trustworthy AI characteristics

The RMF describes seven characteristics of trustworthy AI:

  1. Valid and reliable (the base for the others)
  2. Safe
  3. Secure and resilient
  4. Accountable and transparent (spans the others)
  5. Explainable and interpretable
  6. Privacy-enhanced
  7. Fair, with harmful bias managed

These are trade-offs, not a checklist to max out. Improving interpretability can reduce accuracy; privacy techniques can reduce fairness testing ability. Governance is deciding those trade-offs consciously.

The four functions

FunctionPurposePractical outputs
GovernCulture, policies, roles, accountability; applies across the othersAI policy, RACI, risk tolerance statement, training, third-party policy
MapUnderstand context: purpose, users, affected people, benefits, risksUse-case description, stakeholder map, impact assessment
MeasureAnalyze and track risks with qualitative and quantitative methodsTest plans, evaluation results, bias metrics, red-team findings
ManagePrioritize and act on risks; respond, recover, communicateRisk treatment plan, monitoring, incident response, decommission criteria

Govern sits at the center; Map, Measure and Manage cycle for each system. Each function breaks into categories and subcategories (for example, "GOVERN 1.1: Legal and regulatory requirements involving AI are understood, managed, and documented").

The Generative AI Profile (NIST AI 600-1)

The profile names 12 risks that are unique to or exacerbated by generative AI:

RiskMarketing/business example
CBRN information or capabilitiesMostly relevant to model developers
ConfabulationChatbot invents a refund policy
Dangerous, violent or hateful contentImage tool generates offensive ad imagery
Data privacyStaff paste customer lists into a public chatbot
Environmental impactsHeavy, unnecessary generation workloads
Harmful bias and homogenizationAd creative that stereotypes, or all brands sounding identical
Human-AI configurationOver-reliance: staff stop checking outputs
Information integritySynthetic content used to mislead; deepfakes
Information securityPrompt injection, data exfiltration via agents
Intellectual propertyOutputs resembling copyrighted works or trademarks
Obscene, degrading and/or abusive contentNon-consensual intimate imagery
Value chain and component integrationUndisclosed third-party models, plugins and data

For each risk the profile suggests actions mapped to RMF subcategories, more than 200 in total. You do not implement all of them. You pick the ones relevant to your use cases and risk tolerance.

Mapping NIST to the EU AI Act

AI Act conceptNIST function
AI literacy, policies, rolesGovern
Classification, intended purpose, FRIAMap
Accuracy, robustness, bias testingMeasure
Human oversight, monitoring, incident reportingManage
Article 50 transparencyGovern (policy) + Manage (implementation)

Using NIST's structure to organize your AI Act evidence is common and efficient.

Worked example: a US home-services company's AI booking chatbot

  • Govern: policy says chatbots may answer FAQs and book appointments, never quote prices outside the published price list; the customer experience manager owns it.
  • Map: users are homeowners in three states; risks include confabulated prices, privacy of addresses, accessibility for older users.
  • Measure: 200 test conversations covering pricing questions, off-topic requests and prompt-injection attempts; target of zero invented prices; monthly sample review.
  • Manage: escalation to a human after two failed intents; incident log; weekly metric review; kill switch documented.

Hands-on: a one-page RMF profile for a single use case

use_case: "Website support chatbot (Nova Dental, UAE and UK patients)"
govern:
  owner: "Patient Experience Manager"
  policy_refs: ["AI Acceptable Use v2", "Clinical Content Rule: no diagnosis"]
  risk_tolerance: "Zero tolerance for clinical advice; low tolerance for booking errors"
map:
  purpose: "Answer non-clinical FAQs, book and reschedule appointments"
  affected: ["patients", "front-desk staff"]
  genai_risks: ["confabulation", "data privacy", "human-AI configuration", "information security"]
  legal: ["UAE PDPL", "UK GDPR", "EU AI Act Art. 50 for EU users"]
measure:
  tests: ["150 scripted conversations incl. 30 clinical-advice traps", "prompt-injection suite", "Arabic and English parity check"]
  metrics: {clinical_advice_rate: "0%", booking_success: ">=95%", handoff_latency_s: "<60"}
manage:
  controls: ["system prompt refusals", "retrieval limited to approved FAQ", "human handoff button", "PII redaction in logs"]
  monitoring: "Weekly 50-conversation sample review"
  incident: "Disable bot via feature flag; notify DPO within 24h if data exposed"
  review_date: "2027-03-01"

Pitfalls

  • Treating NIST as a compliance certificate. It is voluntary guidance.
  • Copying all 200+ GenAI actions into a spreadsheet nobody reads. Select, justify and act.
  • Skipping Measure. Without tests and metrics, Manage is guesswork.

Key takeaways

  • NIST AI RMF 1.0 is voluntary guidance with four functions: Govern, Map, Measure, Manage.
  • Seven trustworthy characteristics trade off against each other; governance decides trade-offs consciously.
  • NIST AI 600-1 names 12 generative AI risks such as confabulation, data privacy, information integrity and value chain risks.
  • NIST structure maps cleanly to EU AI Act evidence; select relevant actions rather than copying all of them.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. A team runs 200 scripted test conversations to check a chatbot never invents prices. Which NIST function is this?
  2. Staff start approving AI outputs without checking them. Which GenAI Profile risk is this closest to?
  3. Which statement about the NIST AI RMF is correct?

Put it into practice

Write a one-page RMF profile (YAML template) for your highest-impact AI use case, including owner, GenAI risks, tests, metrics, controls and a review date.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.