The NIST AI RMF Is an Operating Model, Not a Checklist
The Federal Artificial Intelligence Risk Management Act of 2024 proposed requiring federal agencies to use the National Institute of Standards and Technology’s AI Risk Management Framework. The idea was sensible and bipartisan: federal AI should be governed through a common, credible risk-management structure rather than a patchwork of improvised agency practices.
The danger is equally familiar. Institutions can “adopt” a framework by mapping its language into policy, completing templates, and producing inventories while leaving the decisions that determine AI risk largely unchanged.
The NIST AI Risk Management Framework is most valuable when treated as an operating model: a way to connect mission context, evidence, authority, delivery, monitoring, and accountability across the lifecycle of a system.