NIST AI RMF
The NIST AI Risk Management Framework: a voluntary, use-case-agnostic US framework for managing AI risks. NIST's related work also stresses monitoring deployed AI systems after launch.
The NIST AI Risk Management Framework is guidance published by the US National Institute of Standards and Technology to help organizations identify, assess and manage risks from AI systems. It is voluntary and intentionally use-case agnostic: it describes outcomes and practices rather than prescribing controls for one industry.
Monitoring after deployment
NIST's work on monitoring deployed AI makes a point that is directly relevant to operations: post-deployment monitoring is crucial because AI systems can show variability and unpredictable behavior in real-world settings, and the monitoring problem is still fragmented. That makes preserving field evidence more important, not less.
How it relates
A framework like this tells an organization what to govern. It does not replace operational practice such as AI incident reporting, where first reports keep an observation record before the root cause is known, or concrete guardrails. Company-specific disclosure processes from AI vendors are not enterprise standards; a broad framework such as this one is a better reference for an enterprise program.
Read more in The first AI incident report should be incomplete.
Related terms
AI incident reporting
Recording anomalous AI behaviour as evidence at the moment it is observed, before root cause is known, keeping what was seen separate from the later explanation of why.
Guardrails
Controls placed around an AI system — input and output checks, permission limits, review steps and escalation rules — that keep its behaviour within acceptable bounds.
Observation vs. explanation
The split between recording what happened in an AI incident (observation) and the current theory of why (explanation), so early facts are preserved while explanations are revised.
Used in these essays
The wrong questions about AI right now
Many of the questions that helped us orient ourselves around generative AI are now too blunt to be useful. The harder work is no longer asking what AI is in the abstract, but specifying where it works, where it fails, what authority it should have, and what the whole system costs.
Make the AI vendor demo fail
A polished AI demo proves that a system can succeed under prepared conditions. A buying decision needs different evidence: what happens when the system is wrong, blocked, uncertain or halfway through an action.
The first AI incident report should be incomplete
OpenAI's new misalignment disclosure framework exposes a useful enterprise design principle: record anomalous AI behavior before the organization has finished explaining it. Otherwise incident systems quietly become filters for what teams already understand.
The next AI interface may never be seen
Agents are turning software capabilities into an interface of their own. The next enterprise design problem is deciding what should be callable, by whom, and under which boundaries.