AI Regulation Tracker · United States (voluntary, used globally)

How does the NIST regulate AI in banking?

Last updated Aug 19, 2026 · Updated as rules change

NIST is not a regulator, but its AI Risk Management Framework (AI RMF 1.0, January 2023) has become the de facto template US banks use to structure AI governance — especially since the April 2026 interagency model-risk guidance left generative and agentic AI to banks' broader risk programs. The framework's four functions (Govern, Map, Measure, Manage) plus its July 2024 Generative AI Profile give banks an examiner-legible way to demonstrate control over AI that formal model-risk rules no longer cover.

Full nameNational Institute of Standards and Technology — AI Risk Management Framework
RoleStandards body
Force on banksVoluntary framework
Applies toAny organization; widely adopted by US banks as the scaffold for AI governance programs
Key documentAI Risk Management Framework 1.0 (Jan 2023) + Generative AI Profile (Jul 2024)
Latest moveGrowing role as the default governance scaffold after the 2026 US model-risk revision excluded generative AI

The AI RMF is voluntary, but voluntary frameworks harden fast in banking: when examiners ask how a bank governs its generative AI and there is no binding rule to point to, institutions answer with NIST-aligned programs. The Generative AI Profile (NIST AI 600-1) enumerates risks specific to generative systems — confabulation, data leakage, prompt injection — with suggested actions that map cleanly onto bank control frameworks.

For banks operating internationally, the RMF also functions as a crosswalk: its categories align with the FSB's sound-practices work and provide a defensible baseline for the governance the EU AI Act requires of high-risk system deployers.

DateTypeDocument / event
Jan 26, 2023FrameworkAI Risk Management Framework 1.0 released. Voluntary framework organizing AI risk management into four functions: Govern, Map, Measure, Manage.
Jul 26, 2024FrameworkGenerative AI Profile (NIST AI 600-1). Companion profile enumerating generative-AI-specific risks — confabulation, information leakage, prompt injection — with suggested mitigations.
Apr 17, 2026MilestoneUS model-risk revision amplifies the RMF's role. With generative and agentic AI excluded from formal interagency model-risk guidance (SR 26-2), NIST's framework becomes the leading reference for how banks govern those systems.
  • Whether US banking agencies formally reference the AI RMF in the AI governance guidance the OCC has signalled
  • Updates to the Generative AI Profile as agentic AI risks crystallize
  • Use of the RMF as an EU AI Act compliance crosswalk by global banks

Is the NIST AI RMF mandatory for banks?

No — it is voluntary. But it has become the standard scaffold US banks use for AI governance, particularly for generative and agentic AI, which the April 2026 interagency model-risk guidance deliberately left to banks' broader risk-management programs.

How does the NIST AI RMF relate to bank model risk management?

Model risk guidance covers validation of quantitative models; the AI RMF covers organization-wide AI risk governance, including systems outside formal model-risk scope. Most banks run them side by side: revised interagency guidance for traditional/ML models, NIST-aligned governance for generative AI.

Follow every move these regulators make

6 curated AI stories for banking executives · Every morning · Free

Subscribe to BankingNewsAI →