NIST AI 100-1

NIST AI RMF and the Generative AI Profile, Applied to AI Agents that Act

The NIST AI Risk Management Framework is a voluntary framework for structuring an AI risk program. It was published before agents were common, we take its four functions and apply them to agentic AI that calls tools and acts on its own.

NIST AI 100-1
NIST AI RMF and the Generative AI Profile, Applied to AI Agents that Act

What Is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1) is a voluntary framework, published in January 2023, for managing the risks of AI systems. Its core has four functions: Govern sets policies and accountability, Map establishes each system’s context and risks, Measure analyzes and tracks those risks, and Manage prioritizes and acts on them.

Lumenova AI is an agentic AI governance platform that supports the work under each function for AI agents: policy and approvals for Govern, an inventory and risk tiers for Map, validated evaluations and probes for Measure, and enforcement before the action for Manage. It doesn’t map evidence to NIST subcategories. Your team does that.

The framework also names seven characteristics of trustworthy AI: valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair, with harmful bias managed. The four functions contain 19 categories and 72 subcategories.

Key Dates

  1. 26 Jul 2024Generative AI Profile (NIST AI 600-1) published. It's still the current version of the profile.
  2. 17 Feb 2026NIST's Center for AI Standards and Innovation launches the AI Agent Standards Initiative, focused on agent security, identity, and interoperability.
  3. 2026NIST is revising AI RMF 1.0 under the White House AI Action Plan. No version 2.0 had been published as of Sep 28, 2026.

CORE CHECKS

What the Four Functions of the Framework Ask

Voluntary in the US, and widely used to show AI risk is managed with care.

Govern the Program

Sets the policies, processes, and accountability for AI risk across the organization, with roles assigned, a risk tolerance defined, and risks from third-party AI addressed.

Map the Context

Establishes what each AI system is for, who uses it, and who it could affect, along with its potential benefits and harms and how it depends on data, models, third-party components, and other systems.

Measure the Risks

Uses methods and metrics to analyze, assess, and track the risks mapped, including testing against the framework’s trustworthiness characteristics before and after deployment.

Manage the Responses

Prioritizes and treats risks by likely impact, plans for incidents and recovery, monitors systems after deployment, and retires any that no longer perform as intended.


How Lumenova AI Supports Each Function

Govern – Versioned Policy and Approvals

Limits for each agent written as versioned policy, and an owner, approver, and approval status on each use case.

Map – A Registry of Agents and their Dependencies

Agents, MCP servers, skills, and prompts in one registry, with a dependency graph and a risk tier on each use case.

Measure – Evaluations Checked Against People

Evaluation scores checked against your own reviewers, and black-box probes whose findings keep the request and response behind them.

Manage – Limits Enforced Before the Action

Policy runs before each model call, tool call, and handoff, and fixes are verified by replaying the attacks that worked.

Records for Every Function

Decision records and findings export as CSV or JSON, so your team can map them to the subcategories you assess against.

Vendor Agents Tested Too

Probe third-party agents from the outside and keep the evidence behind each finding for the third-party risk work under Govern.


How to Get Ready

  • Name the owner of AI risk and the approver for each use case;
  • Register what exists, agents and their tools included, before you assess;
  • Set a risk tier for each use case, and decide the testing it needs;
  • Check each automated evaluator against a person before you rely on it;
  • Enforce each limit before the action runs;
  • Agree who can pull decision records, and for what purpose.

Frequently Asked Questions

No. The AI RMF is voluntary, and there’s no certification against it. Organizations use it to structure an AI risk program and to show auditors, customers, and regulators how that program works. Some laws and contracts reference it, so check the ones that apply to you.

Its four functions apply to agents as they do to any AI system. Agents add risks to map and manage: they call tools, move data, and hand work to other agents. In practice, that means registering each agent’s tools and dependencies under Map, and enforcing limits on each action under Manage.

The AI RMF is a voluntary US framework for managing AI risk. ISO/IEC 42001 is an international standard for an AI management system, and organizations can be certified against it. Organizations can use both: the RMF to structure the risk work, and 42001 to run and certify the management system around it.

Not yet. As of September 2026, the current version is AI RMF 1.0, published in January 2023. NIST has said it is revising the framework under the White House AI Action Plan, and it has extended the framework through profiles such as the Generative AI Profile rather than a new version. Programs built on 1.0 remain current.

No. Lumenova AI supports the work under each function and exports its records as CSV or JSON. Your team maps those records to the subcategories you assess against.

Control, Test, and Prove What Your AI Agents Do

This is one piece of Lumenova AI. See how it connects to the rest on your own use case.

Book a discovery call