NIST is not a regulator, but its AI Risk Management Framework (AI RMF 1.0, January 2023) has become the de facto template US banks use to structure AI governance — especially since the April 2026 interagency model-risk guidance left generative and agentic AI to banks' broader risk programs. The framework's four functions (Govern, Map, Measure, Manage) plus its July 2024 Generative AI Profile give banks an examiner-legible way to demonstrate control over AI that formal model-risk rules no longer cover.
| Full name | National Institute of Standards and Technology — AI Risk Management Framework |
| Role | Standards body |
| Force on banks | Voluntary framework |
| Applies to | Any organization; widely adopted by US banks as the scaffold for AI governance programs |
| Key document | AI Risk Management Framework 1.0 (Jan 2023) + Generative AI Profile (Jul 2024) |
| Latest move | Growing role as the default governance scaffold after the 2026 US model-risk revision excluded generative AI |
| Documents tracked | 8 · all documents → |
The AI RMF is voluntary, but voluntary frameworks harden fast in banking: when examiners ask how a bank governs its generative AI and there is no binding rule to point to, institutions answer with NIST-aligned programs. The Generative AI Profile (NIST AI 600-1) enumerates risks specific to generative systems — confabulation, data leakage, prompt injection — with suggested actions that map cleanly onto bank control frameworks.
For banks operating internationally, the RMF also functions as a crosswalk: its categories align with the FSB's sound-practices work and provide a defensible baseline for the governance the EU AI Act requires of high-risk system deployers.
What has the NIST actually published on AI?
| Date | Document | Status |
|---|---|---|
| Apr 7, 2026 | AI RMF critical-infrastructure profile (concept note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure | Proposed |
| Jan 12, 2026 | CAISI RFI on AI agent security (2026) — Request for Information: Security Considerations for Artificial Intelligence Agents | Proposed · comment period closed |
| Dec 16, 2025 | NIST IR 8596 (Cyber AI Profile) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft | Proposed · comment period closed |
| Aug 14, 2025 | NIST COSAiS control overlays — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI | Proposed |
| Mar 24, 2025 | NIST AI 100-2e2025 (Adversarial ML) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) | Final |
| Jul 26, 2024 | NIST AI 600-1 (Generative AI Profile) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) | In force |
| Jan 26, 2023 | NIST AI RMF 1.0 — Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 | In force |
| Jan 26, 2023 | NIST AI RMF Playbook — AI Risk Management Framework Playbook | In force |
| Date | Type | Document / event |
|---|---|---|
| Apr 17, 2026 | Milestone | US model-risk revision amplifies the RMF's role. With generative and agentic AI excluded from formal interagency model-risk guidance (SR 26-2), NIST's framework becomes the leading reference for how banks govern those systems. |
| Apr 7, 2026 | Consultation | AI RMF critical-infrastructure profile (concept note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure. On April 7, 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, the first new AI RMF profile since the 2024 Generative AI Profile. source ↗ |
| Jan 12, 2026 | Consultation | CAISI RFI on AI agent security (2026) — Request for Information: Security Considerations for Artificial Intelligence Agents. On January 12, 2026 NIST's Center for AI Standards and Innovation (CAISI) issued a Request for Information on security considerations for AI agents — systems that plan and take autonomous actions affecting real-world systems — with comments due March 9, 2026 (docket NIST-2025-0035). source ↗ |
| Dec 16, 2025 | Consultation | NIST IR 8596 (Cyber AI Profile) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft. NIST released the preliminary draft of NIST IR 8596, the Cybersecurity Framework Profile for Artificial Intelligence ('Cyber AI Profile'), on December 16, 2025, with comments due January 30, 2026. source ↗ |
| Aug 14, 2025 | Consultation | NIST COSAiS control overlays — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI. COSAiS is a NIST Computer Security Division project, created in July 2025, to write SP 800-53 control overlays for five AI use cases: adapting and using generative AI (assistants/LLMs), using and fine-tuning predictive AI, single-agent AI systems, multi-agent AI systems, and security controls for AI developers. source ↗ |
| Mar 24, 2025 | Report | NIST AI 100-2e2025 (Adversarial ML) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025). NIST AI 100-2e2025, finalized on March 24, 2025, is NIST's taxonomy and terminology of adversarial machine learning attacks and mitigations, updating the January 2024 edition (AI 100-2e2023). source ↗ |
| Jul 26, 2024 | Framework | NIST AI 600-1 (Generative AI Profile) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1). NIST AI 600-1, the Generative AI Profile of the AI RMF, was published on July 26, 2024 as a companion to AI RMF 1.0. source ↗ |
| Jan 26, 2023 | Framework | NIST AI RMF 1.0 — Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST published the AI Risk Management Framework 1.0 (NIST AI 100-1) on January 26, 2023, as directed by the National AI Initiative Act of 2020. source ↗ |
| Jan 26, 2023 | Guidance | NIST AI RMF Playbook — AI Risk Management Framework Playbook. The AI RMF Playbook is NIST's companion to AI RMF 1.0, released alongside the framework on January 26, 2023 and hosted at the NIST AI Resource Center. source ↗ |
Which of the 100 largest US banks answer to the NIST on AI?
9 of the 100 bank pages on this site name the NIST among the authorities their AI programme answers to. Each page lists the documents that apply and why.
- The AI RMF 1.0 revision NIST is preparing under the July 2025 White House AI Action Plan (the Playbook will be updated after it), and whether bank governance programs need re-mapping
- The initial public draft of the Cyber AI Profile (NIST IR 8596) following the preliminary draft's January 30, 2026 comment close
- COSAiS SP 800-53 control overlays for generative AI, predictive AI and single/multi-agent systems
- Output of CAISI's AI Agent Standards Initiative (launched February 17, 2026), including its agent-security RFI and finance-sector listening sessions
- Whether US banking agencies formally reference the AI RMF in the AI governance guidance the OCC has signalled
- Use of the RMF as an EU AI Act compliance crosswalk by global banks
Is the NIST AI RMF mandatory for banks?
No — it is voluntary. But it has become the standard scaffold US banks use for AI governance, particularly for generative and agentic AI, which the April 2026 interagency model-risk guidance deliberately left to banks' broader risk-management programs.
How does the NIST AI RMF relate to bank model risk management?
Model risk guidance covers validation of quantitative models; the AI RMF covers organization-wide AI risk governance, including systems outside formal model-risk scope. Most banks run them side by side: revised interagency guidance for traditional/ML models, NIST-aligned governance for generative AI.
Does NIST have guidance on agentic AI?
Not yet a finished profile. As of August 2026 NIST's agentic work is in progress: CAISI's AI Agent Standards Initiative (February 17, 2026), an RFI on security considerations for AI agents (comments closed March 9, 2026), a COSAiS project drafting SP 800-53 control overlays for single-agent and multi-agent systems, and an NCCoE concept paper on software and AI agent identity and authorization. Banks deploying agents today typically map them to the AI RMF and the Generative AI Profile (AI 600-1).
Follow every move these regulators make
the daily brief · six sourced stories · in your inbox by 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning