Article reader Listen + reading controls
Article reader
Preparing the reader…
Reading settings
A framework needs a community of practice¶
The National Institute of Standards and Technology (NIST) has launched its Trustworthy and Responsible Artificial Intelligence Resource Center, known as the Artificial Intelligence Resource Center (AIRC). The new site gathers the Artificial Intelligence Risk Management Framework (AI RMF), its playbook, crosswalks, and implementation resources in one place.
Central access is useful. The larger opportunity is to create a place where organizations learn how the framework behaves in practice.
Guidance becomes useful through situated examples¶
The AI RMF gives organizations a shared vocabulary: Govern, Map, Measure, and Manage. It deliberately avoids prescribing a single implementation because artificial intelligence (AI) systems operate in very different contexts. That flexibility is necessary. It also means the hardest work begins after a team downloads the document.
What does adequate mapping look like for a maintenance assistant? Which measurements matter for a model supporting a time-sensitive operational decision? How should a small organization divide governance responsibilities? When does a use-case change require a new assessment?
Answers emerge through use. Teams interpret the framework, build profiles and artifacts, discover friction, and adapt their routines. Unless those lessons are exchanged, each organization pays the same learning cost independently.
A repository is not yet a community¶
Knowledge-management research distinguishes between storing information and developing practice. Wenger's work on communities of practice describes learning as participation in a community organized around a shared domain and recurring problems. People build a repertoire of language, stories, tools, and ways of judging good work.
AIRC can support that process, but a website alone cannot create it. The valuable unit is not merely the finished template. It is the explanation around it: the context, choice, disagreement, failure, and revision that made the artifact useful.
Consider an AI impact assessment. A blank form is easy to share. A completed example may be more helpful. The richest knowledge, however, may lie in why a team rejected one metric, how operators challenged the stated use, or which incident forced the monitoring plan to change.
Those lessons are often sensitive and difficult to publish. Organizations can still share at several levels: anonymized patterns, synthetic case studies, failure taxonomies, control mappings, and evaluation methods. The goal is not to expose proprietary systems. It is to make implementation knowledge less private.
Build a local practice that can connect outward¶
Inside an organization, the framework should have a home that is broader than a compliance office. A small community of practice can bring together product managers, data scientists, security professionals, human-factors specialists, lawyers, acquisition staff, and domain operators.
Its recurring work should be concrete:
- review one live use case rather than discuss AI in general;
- compare how teams interpret a framework outcome;
- maintain reusable examples and decision records;
- hold short postmortems on evaluation failures and near misses;
- identify questions that deserve external research or NIST feedback; and
- rotate practitioners through the group so knowledge does not centralize in a few experts.
The artifacts should remain connected to their circumstances. A risk register copied without the original assumptions can be worse than no template at all. Include intended use, system boundary, owner, date, evidence, and known limits with every reusable example.
Contribute the hard parts¶
NIST developed the AI RMF through an open process and is inviting continued participation. Organizations will naturally look to AIRC for answers. They should also treat it as an invitation to contribute questions and evidence.
Frameworks mature when practitioners reveal where language is ambiguous, measurements fail, or organizational boundaries resist the neat diagram. That feedback is not evidence that the framework failed. It is the material from which a usable practice grows.
The AI RMF gives the field a common map. AIRC can help build the community that learns the terrain. The organizations that benefit most will be active members of that learning system, not passive readers waiting for a perfect checklist to arrive.
Sources and research trail¶
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework overview (AIRC launch noted March 30, 2023).
- Artificial Intelligence Resource Center, About AIRC.
- National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (2023).
- Wenger, Communities of Practice: Learning, Meaning, and Identity (1998).
- Brown and Duguid, “Organizational Learning and Communities-of-Practice” (1991).