17 free courses, no signup wall
Architect-led enterprise cloud, security & AI
Fixed-price engagements, scoped on a discovery call
Skip to content

The NIST AI RMF Is Being Revised. Should You Still Build On It?

By Kehinde Ogunlowo ·

Quick answer: Yes. NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan, but the framework's four functions, Govern, Map, Measure and Manage, describe a risk management loop that a revision will refine rather than replace. The artifacts you build under version 1.0, an AI system inventory, documented risk assessments, evaluation evidence and incident procedures, are the same artifacts any successor will expect. Waiting costs you organisational lead time and buys nothing.

Last updated: August 2026 | Author: Kehinde Ogunlowo, Principal AI Platform Architect


What is actually changing?

NIST released the AI Risk Management Framework 1.0 on 26 January 2023 as a voluntary framework for managing risks in the design, development, deployment and use of AI systems (NIST AI Risk Management Framework). Its current page states directly that the AI RMF 1.0 is being revised as part of the White House AI Action Plan (America's AI Action Plan).

Two other documents in the same family matter for anyone deploying agents. On 26 July 2024 NIST released a Generative AI Profile, which helps organisations identify risks unique to generative AI and proposes actions for managing them. On 7 April 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, intended to guide critical infrastructure operators toward specific risk management practices.

That pattern, a stable core framework with profiles layered on top for particular contexts, is worth noticing because it tells you where the volatility is. The functions are the stable part. The profiles are where sector and technology specificity gets added, and where a revision is most likely to change what you actually do.

Why does a pending revision not justify waiting?

Because the expensive part of adopting a risk framework has nothing to do with the framework's text.

The work that takes time is organisational. Building an inventory of every AI system and agent in the estate. Agreeing who owns the risk for each one. Establishing a repeatable assessment method and getting security, legal and the business to accept it. Instrumenting systems so that risk can be measured rather than asserted. Standing up an incident path for AI-specific failures. None of that is sensitive to whether the framework is on version 1.0 or 2.0, and all of it takes quarters rather than weeks.

There is a second reason, which is that the framework is voluntary and its practical force comes from adoption rather than obligation. Procurement questionnaires ask about AI RMF alignment now. Sector supervisors reference it now. Other frameworks map to it now. An organisation that can evidence the practice answers a lot of questions with one body of work, and that value is available immediately.

The third reason is the one most teams underweight: a revision to a framework you have already implemented is a gap analysis. A revision to a framework you have not implemented is still a full implementation, just started later. Waiting converts a small future task into a large future task.

How do the four functions apply to AI agents?

The functions transfer without modification. What changes, and changes a great deal, is the evidence each one demands when the system plans and acts rather than predicts.

FunctionFamiliar interpretationWhat an agent deployment requires
GovernPolicy, roles, accountability for AI useA named risk owner per agent, an autonomy decision authority separate from the build team, and a register that includes agents nobody formally launched
MapContext, intended purpose, stakeholdersThe tool inventory, the delegation graph, the data each agent can reach, and the worst permitted single action per tool
MeasureModel accuracy, bias, robustness testingEnd-to-end task success, guardrail trip rates, approval and rework rates, and multi-turn adversarial results rather than single-prompt refusals
ManageMitigation, monitoring, responseCredential scope, blast-radius ceilings, a drilled kill switch, and an incident path that assumes machine-speed failure

Two rows deserve elaboration.

Measure is where most agent programmes are weakest, because model-level metrics are readily available and task-level metrics are not. An agent that scores well on a benchmark and completes 60% of real tasks correctly is a governance problem that model evaluation will never surface. The measurement that matters is over the composed system doing the actual job, with a defined sample of sessions reviewed by domain experts and the findings logged. That review record then becomes the evidence for every subsequent autonomy decision, which is why we treat it as a phase-one artifact in our phased governance rollout.

Manage changes because response time assumptions break. An incident process designed around a human noticing something and escalating within the hour is calibrated to human-paced failure. An agent making tool calls at machine speed can do a great deal inside that hour, so the containment mechanism has to be automatic ceilings plus a tested stop, not a runbook that begins with somebody noticing.

Does the AI RMF replace ISO/IEC 42001?

No, and the two are more complementary than competing.

The AI RMF is a risk framework. It tells you how to think about identifying, measuring and managing AI risk, and it is deliberately flexible about the mechanics. ISO/IEC 42001 is a management system standard (ISO/IEC 42001). It tells you what processes, roles, records and review cycles must exist, in the same structural style as ISO/IEC 27001 for information security, and it is certifiable.

The practical difference is what each produces. The AI RMF produces better risk decisions and a defensible methodology. ISO/IEC 42001 produces a certificate, which is a thing a procurement team can read without understanding your internal process. Most organisations with a substantial portfolio end up doing both, using the AI RMF and its Generative AI Profile to structure the risk thinking and the management system standard to structure the operating rhythm. We mapped the control overlap onto agent deployments in ISO 42001 and NIST AI RMF mapped to AI agents.

The same complementarity applies to regulation. Neither framework is a regulation and neither confers compliance with one, but the evidence they generate, the inventory, the risk assessments, the evaluation records, the incident history, is very close to what the EU AI Act's high-risk regime asks for, and that regime now applies from 2 December 2027 following the Digital Omnibus deferral. We covered what to do with that window in the December 2027 deadline post.

What should you build now, in order?

  1. Inventory. Every AI system and agent, its purpose, owner, data reach and tool access. Everything else depends on this, and it is the step with the longest political lead time because it requires disclosure.
  2. Govern. Name a risk owner per system and an approval authority for autonomy increases that is not the team building the agent. Builders grading their own graduation reliably graduate.
  3. Map. For each agent, document the delegation graph, the tools, the parameters those tools accept, and the worst single permitted action. This document is also your blast-radius analysis.
  4. Measure. Stand up task-level evaluation with expert-reviewed sampling, plus multi-turn adversarial testing. Log the results in a form you can cite later.
  5. Manage. Least-privilege credentials, volume and value ceilings, a drilled stop mechanism, an immutable session ledger, and an incident path that does not depend on someone noticing.
  6. Apply the Generative AI Profile. For every system using generative models, walk the profile and record which of its suggested actions you have taken and which you have consciously declined.
  7. Re-run the loop on a fixed cycle. The framework is a loop, and a risk assessment performed once and filed is a document rather than a practice.

Our AI governance service runs this sequence against a live estate, and the fixed-fee Agent Assurance Assessment produces steps 1 through 3 with a prioritised gap register in three weeks.

What will the revision most likely change?

Predicting the text would be speculation, and it is not necessary. What can be said with confidence is which parts of your work are exposed to change and which are not.

Low exposure: the inventory, the risk-owner assignments, the delegation and tool maps, the evaluation harness, the session ledger, the incident procedure. These are artifacts about your systems, not about the framework. Any successor framework, and any regulator, will want them.

Higher exposure: the specific mapping document that says which of your controls satisfies which framework subcategory, and any profile-level detail you have adopted verbatim. Those are cheap to re-map precisely because the underlying artifacts do not move.

The practical implication is to keep the crosswalk as a separate, thin document rather than baking framework subcategory references into every control description. Then a revision is an afternoon spent updating one file, rather than a re-write of the control library. That is a five-minute structural decision that pays for itself the first time any framework you reference publishes a new version, which, across the AI RMF, ISO/IEC 42001 and the AI Act's harmonised standards, is going to happen more than once in the next two years.

Frequently asked questions

Should we wait for the revised AI RMF before adopting it?

No. The framework's four functions, Govern, Map, Measure and Manage, describe a risk management loop that no plausible revision will remove, and the artifacts you build under version 1.0 are the same artifacts a revision will expect. Waiting produces no compliance benefit and costs you the organisational lead time, which is the part that cannot be compressed. A revision applied to an implemented framework is a gap analysis; a revision applied to nothing is still a full implementation, just started later and under more time pressure.

Is the AI RMF mandatory?

The AI RMF is voluntary. It is not a regulation and there is no certification against it. Its practical force comes from adoption rather than obligation: procurement questionnaires ask about it, sector regulators reference it, and other frameworks map to it, so an organisation that can evidence AI RMF practice answers a large number of questions with one body of work. Treating it as optional because it is voluntary misreads how it functions commercially, particularly for anyone selling into regulated buyers.

How does the AI RMF apply to autonomous agents specifically?

The functions apply unchanged; the evidence required to satisfy them changes substantially. Map has to cover tools, delegation paths and the composed system rather than a single model. Measure has to evaluate end-to-end task outcomes rather than model-level accuracy. Manage has to include containment mechanisms that operate at machine speed, because an agent can act many times inside the window a human-paced incident process assumes. Govern has to name an autonomy decision authority separate from the team building the agent.

Do we need both the AI RMF and ISO/IEC 42001?

Most organisations with a substantial portfolio end up using both, because they answer different questions. The AI RMF is a risk framework: it tells you how to think about identifying, measuring and managing AI risk. ISO/IEC 42001 is a management system standard: it tells you what processes, roles and records have to exist, and it is certifiable, which the AI RMF is not. Use the framework to structure the thinking and the standard to structure the operating rhythm, and the evidence produced serves regulatory purposes as well.

What is the Generative AI Profile and do we need it?

The Generative AI Profile is a companion document NIST released on 26 July 2024 that identifies risks specific to generative AI and proposes actions for managing them. If any part of your portfolio uses generative models, and for an agent deployment it does by definition, the profile is the more directly applicable document of the two. The useful discipline is to walk its suggested actions and record, for each one, whether you have implemented it, deferred it, or consciously declined it and why. That record is more valuable in an audit than a claim of alignment.

Where to go from here

A framework under revision is not a reason to defer. The parts that take an organisation the longest, knowing what you run, agreeing who owns it, and being able to measure whether it works, are stable across every version of every AI risk framework currently in circulation.

If you have agents in production and cannot produce an inventory, a risk owner per system, or evaluation evidence you would be willing to show a regulator, the fixed-fee Agent Assurance Assessment produces exactly those artifacts in three weeks. For the architectural patterns underneath, see our AI agents overview, and for portfolio-level programme structure, our enterprise page. To discuss it against your own estate, book a call.