# How does the NIST regulate AI in banking?

Source: https://www.bankingnewsai.com/ai-regulation/nist
Last updated: Oct 5, 2026

NIST is not a regulator, but its AI Risk Management Framework (AI RMF 1.0, January 2023) has become the de facto template US banks use to structure AI governance — especially since the April 2026 interagency model-risk guidance left generative and agentic AI to banks' broader risk programs. The framework's four functions (Govern, Map, Measure, Manage) plus its July 2024 Generative AI Profile give banks an examiner-legible way to demonstrate control over AI that formal model-risk rules no longer cover.

## At a glance

| Field | Value |
| --- | --- |
| Full name | National Institute of Standards and Technology — AI Risk Management Framework |
| Jurisdiction | United States (voluntary, used globally) |
| Role | Standards body |
| How binding | Voluntary framework |
| Applies to | Any organization; widely adopted by US banks as the scaffold for AI governance programs |
| Key document | AI Risk Management Framework 1.0 (Jan 2023) + Generative AI Profile (Jul 2024) |
| Latest move | Growing role as the default governance scaffold after the 2026 US model-risk revision excluded generative AI |

## Overview

The AI RMF is voluntary, but voluntary frameworks harden fast in banking: when examiners ask how a bank governs its generative AI and there is no binding rule to point to, institutions answer with NIST-aligned programs. The Generative AI Profile (NIST AI 600-1) enumerates risks specific to generative systems — confabulation, data leakage, prompt injection — with suggested actions that map cleanly onto bank control frameworks.

For banks operating internationally, the RMF also functions as a crosswalk: its categories align with the FSB's sound-practices work and provide a defensible baseline for the governance the EU AI Act requires of high-risk system deployers.

## Documents (9)

- Apr 7, 2026 — [AI RMF critical-infrastructure profile (concept note)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-critical-infrastructure-profile-concept-note): Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure (Proposed)
- Jan 12, 2026 — [CAISI RFI on AI agent security (2026)](https://www.bankingnewsai.com/ai-regulation/documents/nist-caisi-rfi-ai-agent-security-2026): Request for Information: Security Considerations for Artificial Intelligence Agents (Proposed · comment period closed)
- Dec 16, 2025 — [NIST IR 8596 (Cyber AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ir-8596): Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft (Proposed · comment period closed)
- Aug 14, 2025 — [NIST COSAiS control overlays](https://www.bankingnewsai.com/ai-regulation/documents/nist-cosais-control-overlays): Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI (Proposed)
- Mar 24, 2025 — [NIST AI 100-2e2025 (Adversarial ML)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-2e2025): Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) (Final)
- Jul 26, 2024 — [NIST SP 800-218A (SSDF profile for generative AI)](https://www.bankingnewsai.com/ai-regulation/documents/nist-sp-800-218a): Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (NIST SP 800-218A) (In force)
- Jul 26, 2024 — [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1): Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) (In force)
- Jan 26, 2023 — [NIST AI RMF Playbook](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-playbook): AI Risk Management Framework Playbook (In force)
- Jan 26, 2023 — [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1): Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (In force)

## Timeline

- Sep 16, 2026 — Conference of State Bank Supervisors cites the RMF in its new AI Supervisory Framework — CSBS published an Artificial Intelligence Supervisory Framework for state bank examiners that explicitly draws on the NIST AI Risk Management Framework, the Cyber Risk Institute's Financial Services AI RMF, and the US Treasury AI Lexicon. It is not a federal banking-agency document, but it is the first banking-supervisory framework to formally build on the RMF since the 2026 interagency model-risk revision excluded generative and agentic AI.
- Apr 17, 2026 — [US model-risk revision amplifies the RMF's role](https://www.federalreserve.gov/supervisionreg/srletters/SR2602.htm) — With generative and agentic AI excluded from formal interagency model-risk guidance (SR 26-2), NIST's framework becomes the leading reference for how banks govern those systems.
- Apr 7, 2026 — [AI RMF critical-infrastructure profile (concept note)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-critical-infrastructure-profile-concept-note): AI RMF critical-infrastructure profile (concept note) — Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure — On April 7, 2026 NIST released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure, the first new AI RMF profile since the 2024 Generative AI Profile.
- Jan 12, 2026 — [CAISI RFI on AI agent security (2026)](https://www.bankingnewsai.com/ai-regulation/documents/nist-caisi-rfi-ai-agent-security-2026): CAISI RFI on AI agent security (2026) — Request for Information: Security Considerations for Artificial Intelligence Agents — On January 12, 2026 NIST's Center for AI Standards and Innovation (CAISI) issued a Request for Information on security considerations for AI agents — systems that plan and take autonomous actions affecting real-world systems — with comments due March 9, 2026 (docket NIST-2025-0035).
- Dec 16, 2025 — [NIST IR 8596 (Cyber AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ir-8596): NIST IR 8596 (Cyber AI Profile) — Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile), NIST IR 8596 — preliminary draft — NIST released the preliminary draft of NIST IR 8596, the Cybersecurity Framework Profile for Artificial Intelligence ('Cyber AI Profile'), on December 16, 2025, with comments due January 30, 2026.
- Aug 14, 2025 — [NIST COSAiS control overlays](https://www.bankingnewsai.com/ai-regulation/documents/nist-cosais-control-overlays): NIST COSAiS control overlays — Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for generative, predictive and agentic AI — COSAiS is a NIST Computer Security Division project, created in July 2025, to write SP 800-53 control overlays for five AI use cases: adapting and using generative AI (assistants/LLMs), using and fine-tuning predictive AI, single-agent AI systems, multi-agent AI systems, and security controls for AI developers.
- Mar 24, 2025 — [NIST AI 100-2e2025 (Adversarial ML)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-2e2025): NIST AI 100-2e2025 (Adversarial ML) — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations (NIST AI 100-2e2025) — NIST AI 100-2e2025, finalized on March 24, 2025, is NIST's taxonomy and terminology of adversarial machine learning attacks and mitigations, updating the January 2024 edition (AI 100-2e2023).
- Jul 26, 2024 — [NIST SP 800-218A (SSDF profile for generative AI)](https://www.bankingnewsai.com/ai-regulation/documents/nist-sp-800-218a): NIST SP 800-218A (SSDF profile for generative AI) — Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile (NIST SP 800-218A) — NIST SP 800-218A, published on July 26, 2024, is a community profile of the Secure Software Development Framework (SSDF, SP 800-218 version 1.1) for generative AI and dual-use foundation models.
- Jul 26, 2024 — [NIST AI 600-1 (Generative AI Profile)](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-600-1): NIST AI 600-1 (Generative AI Profile) — Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1) — NIST AI 600-1, the Generative AI Profile of the AI RMF, was published on July 26, 2024 as a companion to AI RMF 1.0.
- Jan 26, 2023 — [NIST AI RMF Playbook](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-rmf-playbook): NIST AI RMF Playbook — AI Risk Management Framework Playbook — The AI RMF Playbook is NIST's companion to AI RMF 1.0, released alongside the framework on January 26, 2023 and hosted at the NIST AI Resource Center.
- Jan 26, 2023 — [NIST AI RMF 1.0](https://www.bankingnewsai.com/ai-regulation/documents/nist-ai-100-1): NIST AI RMF 1.0 — Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 — NIST published the AI Risk Management Framework 1.0 (NIST AI 100-1) on January 26, 2023, as directed by the National AI Initiative Act of 2020.

## What to watch next

- The AI RMF 1.0 revision NIST is preparing under the July 2025 White House AI Action Plan (the Playbook will be updated after it), and whether bank governance programs need re-mapping
- The initial public draft of the Cyber AI Profile (NIST IR 8596) following the preliminary draft's January 30, 2026 comment close — still not published as of October 2026
- COSAiS SP 800-53 control overlays for generative AI, predictive AI and single/multi-agent systems
- Output of CAISI's AI Agent Standards Initiative (launched February 17, 2026), including its agent-security RFI and finance-sector listening sessions, and NIST's planned AI Agent Interoperability Profile (targeted for Q4 2026)
- Whether a federal banking agency (not just the state-supervisor CSBS, which cited the RMF in its September 16, 2026 AI Supervisory Framework) formally references the AI RMF in the AI governance guidance the OCC has signalled
- Use of the RMF as an EU AI Act compliance crosswalk by global banks

## FAQ

### Is the NIST AI RMF mandatory for banks?

No — it is voluntary. But it has become the standard scaffold US banks use for AI governance, particularly for generative and agentic AI, which the April 2026 interagency model-risk guidance deliberately left to banks' broader risk-management programs.

### How does the NIST AI RMF relate to bank model risk management?

Model risk guidance covers validation of quantitative models; the AI RMF covers organization-wide AI risk governance, including systems outside formal model-risk scope. Most banks run them side by side: revised interagency guidance for traditional/ML models, NIST-aligned governance for generative AI.

### Does NIST have guidance on agentic AI?

Not yet a finished profile. As of October 2026 NIST's agentic work is still in progress: CAISI's AI Agent Standards Initiative (February 17, 2026, with an AI Agent Interoperability Profile targeted for Q4 2026), an RFI on security considerations for AI agents (comments closed March 9, 2026), a COSAiS project drafting SP 800-53 control overlays for single-agent and multi-agent systems, and an NCCoE concept paper on software and AI agent identity and authorization. Banks deploying agents today typically map them to the AI RMF and the Generative AI Profile (AI 600-1).

## Compare

- [NIST AI RMF vs ISO 42001](https://www.bankingnewsai.com/ai-regulation/compare/nist-ai-rmf-vs-iso-42001): NIST AI RMF vs ISO/IEC 42001: Which Should a Bank Use?

Related authorities: [OCC](https://www.bankingnewsai.com/ai-regulation/occ), [Federal Reserve](https://www.bankingnewsai.com/ai-regulation/federal-reserve), [FSB](https://www.bankingnewsai.com/ai-regulation/fsb).

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/nist
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
