Table of Contents
What Is the NIST AI Risk Management Framework (AI RMF)?
The NIST AI Risk Management Framework (AI RMF) is a set of guidelines developed by the National Institute of Standards and Technology to help organizations manage risks associated with artificial intelligence systems. The framework is voluntary, flexible, and adaptable across industries and use cases, offering structured guidance for identifying, assessing, and mitigating risks throughout the AI system lifecycle.
By providing a standardized approach, the AI RMF aims to ensure that AI deployments are trustworthy, reliable, and aligned with organizational values and legal requirements. Unlike prescriptive regulations, the NIST AI RMF does not dictate specific technical controls or solutions. Instead, it outlines best practices and key functions, such as governance, risk mapping, measurement, and management, so organizations can develop their own risk management strategies tailored to their needs.
The framework also considers the evolving nature of AI technology and its associated risks, emphasizing ongoing evaluation and adaptation as AI capabilities and threat landscapes change.
This is part of a series of articles about AI cyber security
Why the NIST AI RMF is Critical for 2026 Governance
AI Risk Is Broader Than Cybersecurity Risk
AI systems introduce risks that extend beyond traditional cybersecurity. While cybersecurity risk focuses on threats like unauthorized access, data breaches, and system compromise, AI risk also includes bias, fairness, transparency, and unintended consequences from automated decision-making.
For example, an AI system could produce discriminatory outcomes even if its underlying infrastructure is secure. This broader risk landscape requires a more holistic approach to risk management.
The complexity of AI models and the data they process complicates risk identification and mitigation. As AI systems become embedded in critical business processes, failures or adverse outcomes can have legal, reputational, and operational consequences.
How the guidelines help:
The NIST AI RMF provides guidance that addresses the full spectrum of AI-related risks, not just those limited to cybersecurity.
Organizations Need a Common AI Governance Language
As organizations adopt AI at scale, internal teams and external stakeholders need a shared vocabulary to discuss, assess, and manage risks. Without a common language, misunderstandings can arise between technical, legal, compliance, and business units, leading to gaps in governance and inconsistent risk management practices.
How the guidelines help:
The NIST AI RMF addresses this by offering clear definitions, concepts, and processes that can be used across functions and industries.
A standardized framework like the AI RMF also supports communication with regulators, auditors, and partners, ensuring that all parties understand how AI risks are identified and addressed. This governance language improves transparency and accountability, making it easier to demonstrate compliance and build trust in AI systems within the organization and with external stakeholders.
Generative AI Has Introduced New Risk Categories
The rise of generative AI technologies, such as large language models and image generators, has expanded the risk landscape with new challenges. These systems can produce convincing but incorrect or misleading outputs, raising concerns about misinformation, intellectual property infringement, and content manipulation.
Generative AI also introduces risks related to data poisoning, prompt injection attacks, and the creation of harmful or inappropriate content that traditional risk management approaches may not address. As generative AI becomes more prevalent in business and consumer applications, organizations must adapt their risk management strategies to account for these threats.
How the guidelines help:
The NIST AI RMF provides a flexible structure that enables organizations to identify, assess, and manage these risks, ensuring that generative AI deployments align with ethical guidelines, legal requirements, and societal expectations.
The Seven Characteristics of Trustworthy AI
Safety
Safety means an AI system should not cause unacceptable harm to people, organizations, or the environment during normal operation or reasonably foreseeable misuse. Organizations should identify potential hazards early, test systems under realistic conditions, and implement safeguards that reduce the likelihood and impact of failures.
Safety is an ongoing process rather than a one-time validation. As models, data, and operating environments change, organizations should continuously monitor outcomes, investigate incidents, and update controls to address newly identified risks.
Security
Security focuses on protecting AI systems, models, data, and supporting infrastructure from malicious attacks and unauthorized access. AI introduces additional attack surfaces, including model theft, adversarial examples, prompt injection, data poisoning, and manipulation of training or inference pipelines.
Organizations should integrate AI security into their existing cybersecurity programs. This includes access controls, secure development practices, model integrity checks, monitoring, incident response, and regular testing against AI-specific threats.
Privacy
Privacy ensures that AI systems collect, use, store, and share personal data in ways that comply with legal requirements and organizational policies. Because AI models often rely on large datasets, organizations must understand what personal information is being processed and whether its use is appropriate.
Privacy protections should be built into the AI lifecycle through practices such as data minimization, access controls, anonymization where appropriate, and clear data governance. Regular reviews help ensure that models continue to respect privacy as data sources and use cases evolve.
Explainability
Explainability refers to the ability to understand and communicate how an AI system produces its outputs. The level of explanation required depends on the application, but users and stakeholders should have enough information to evaluate whether a system’s decisions are appropriate and trustworthy.
Organizations can improve explainability by documenting model design, data sources, assumptions, limitations, and decision logic where possible. This supports auditing, debugging, regulatory compliance, and informed human oversight.
Fairness
Fairness means AI systems should avoid producing unjustified or systematic differences in outcomes for individuals or groups. Bias can enter through training data, model design, deployment decisions, or feedback loops, making fairness an issue throughout the AI lifecycle.
Managing fairness requires testing for disparate impacts, evaluating data quality, and monitoring model performance across different populations. Organizations should also define fairness objectives that align with the context and intended use of the system.
Accountability
Accountability means organizations remain responsible for the outcomes of their AI systems, even when decisions are partially automated. Clear governance structures help ensure that roles, responsibilities, and decision-making authority are defined throughout development, deployment, and operation.
Effective accountability includes documenting key decisions, maintaining audit trails, establishing oversight processes, and providing mechanisms to investigate incidents and address issues when they occur. Human oversight remains an important part of managing AI risk.
Reliability
Reliability means an AI system consistently performs as intended under expected operating conditions. A reliable system produces stable results, maintains acceptable performance over time, and behaves predictably when exposed to changing inputs or environments.
Organizations should validate models before deployment and continuously monitor performance for issues such as model drift, data quality problems, and changing business conditions. Ongoing testing and maintenance help ensure that AI systems continue to meet their intended objectives.
Tips from the expert

Steve Moore is Vice President and Chief Security Strategist at Exabeam, helping drive solutions for threat detection and advising customers on security programs and breach response. He is the host of the “The New CISO Podcast,” a Forbes Tech Council member, and Co-founder of TEN18 at Exabeam.
Tips from the expert:
In my experience, here are tips that can help you better implement the NIST AI Risk Management Framework (AI RMF):
- Treat prompts as a security boundary: Monitor and govern prompts with the same rigor as API calls. Prompt injection, sensitive data disclosure, and policy bypass attempts should be logged, reviewed, and included in threat detection.
- Version risk assessments with the model: Whenever a model, prompt template, retrieval source, or inference configuration changes, update the associated risk assessment. Small changes can significantly alter the model’s behavior and risk profile.
- Separate model risk from application risk: Evaluate the AI model and the application that uses it independently. A secure model can still create risk if the surrounding application lacks proper authentication, authorization, or input validation.
- Monitor retrieval pipelines, not just the model: For retrieval-augmented generation (RAG) systems, validate and monitor vector databases, document repositories, and retrieval logic. Manipulated knowledge sources can produce harmful outputs even when the model itself is unchanged.
- Define acceptable failure modes: Before deployment, document what types of errors are acceptable, which require human review, and which require the system to stop responding. This creates measurable risk thresholds for operations teams.
The Four Core Functions of the NIST AI RMF
Govern
The “Govern” function establishes the policies, procedures, and oversight structures for AI risk management. This involves defining roles and responsibilities, setting organizational risk tolerances, and creating accountability mechanisms to ensure compliance with internal standards and external regulations. Governance provides the structure needed to make informed decisions and enforce consistency in how AI risks are managed across the organization.
Governance also includes regular reviews of AI policies and practices to ensure alignment with evolving risks, stakeholder expectations, and legal requirements. By embedding governance into organizational culture, companies can create an environment where responsible AI development is prioritized and issues are addressed before they escalate.
Map
The “Map” function involves identifying and documenting the AI systems in use, their intended purposes, and associated risks. Organizations inventory their AI assets, understand data flows, and analyze how AI interacts with users and other systems. Mapping ensures a clear understanding of where AI is deployed and the contexts in which it operates, serving as the foundation for risk assessments.
Mapping also helps identify dependencies, external data sources, and third-party components that may introduce additional risks. By maintaining an up-to-date map of AI systems and their risk profiles, organizations can prioritize mitigation efforts and allocate resources.
Measure
The “Measure” function focuses on quantifying AI risks and evaluating the effectiveness of risk controls. Organizations establish metrics and key performance indicators (KPIs) to assess factors such as accuracy, bias, robustness, and compliance. Measurement enables ongoing monitoring and provides evidence for decision-making, helping organizations determine whether their risk management strategies achieve the intended outcomes.
Consistent measurement supports transparency and accountability, as organizations can demonstrate to stakeholders how risks are managed and what impact controls have. By collecting and analyzing measurement data, organizations can identify emerging risks, track progress toward risk reduction goals, and support continuous improvement.
Manage
The “Manage” function includes implementing risk mitigation strategies, response plans, and corrective actions. Once risks are identified and measured, organizations develop and deploy controls to reduce their likelihood or impact. Management activities include updating policies, retraining models, improving data quality, and responding to incidents in a timely manner.
Effective risk management requires ongoing evaluation and adaptation. Organizations should review the effectiveness of their controls, update risk management plans as threats emerge, and incorporate lessons learned from incidents into future practices. The “Manage” function ensures that risk mitigation remains an active process rather than a one-time exercise.
Key AI Risks Addressed by the NIST AI RMF
Bias and Fairness Risks
Bias in AI systems can result from skewed training data, flawed algorithms, or design choices, leading to unfair or discriminatory outcomes. These risks are significant in sectors like hiring, lending, and law enforcement, where biased AI decisions can affect individuals’ lives and opportunities. The NIST AI RMF provides guidance for identifying sources of bias, assessing their impact, and implementing controls to support fairness throughout the AI lifecycle.
How to address:
Addressing bias and fairness requires technical and organizational measures, such as diversifying training datasets, applying fairness metrics, and involving stakeholders from different backgrounds in the development process.
Security and Adversarial Risks
AI systems face security threats that differ from those affecting traditional software. Attackers may manipulate training data, craft adversarial inputs that cause incorrect predictions, steal models, or exploit prompt injection techniques in generative AI applications. These attacks can reduce model reliability, expose sensitive information, or allow unauthorized behavior even when the surrounding infrastructure is secure.
How to address:
The NIST AI RMF encourages organizations to evaluate AI-specific attack surfaces alongside conventional cybersecurity risks. This includes testing models for robustness, validating training data sources, monitoring for abnormal behavior, and implementing secure development and deployment practices.
Privacy and Data Leakage Risks
AI systems often rely on large volumes of data that may contain personal, confidential, or proprietary information. Poor data handling practices can lead to unauthorized disclosure during training, inference, or model outputs. Generative AI systems introduce additional concerns because they may reveal sensitive information through prompts or generated content if safeguards are not in place.
How to address:
The NIST AI RMF emphasizes managing privacy risk throughout the AI lifecycle. Organizations should understand what data is collected, how it is used, who can access it, and how long it is retained. Privacy-preserving techniques, access controls, data minimization, and ongoing monitoring help reduce the risk of data leakage while supporting compliance with privacy laws and organizational policies.
Reliability and Accuracy Risks
AI systems must produce results that are accurate, consistent, and appropriate for their intended use. Performance can degrade over time because of changing data, shifting user behavior, or deployment in environments that differ from those used during development. Without continuous validation, organizations may make decisions based on inaccurate or outdated model outputs.
How to address:
The NIST AI RMF promotes ongoing evaluation of model performance rather than relying only on pre-deployment testing. Organizations should define performance metrics, monitor models in production, detect model drift, and establish processes for retraining or replacing models when necessary.
Transparency and Explainability Risks
Many AI models, particularly complex machine learning and generative AI systems, can be difficult for users and stakeholders to understand. Limited transparency makes it harder to explain how decisions are made, investigate errors, or demonstrate compliance with regulatory and organizational requirements. This lack of visibility can reduce trust and complicate accountability.
How to address:
The NIST AI RMF encourages organizations to provide documentation and explanations appropriate for the intended audience. This may include describing model purpose, training data sources, known limitations, evaluation methods, and factors that influence predictions. Improving transparency enables users, auditors, and decision-makers to better assess AI behavior and make informed judgments about when and how AI systems should be used.
Best Practices for Implementing NIST AI RMF
Organizations should consider the following best practices to ensure effective implementation of the AI RMF guidelines.
1. Build an AI Inventory
Organizations should start by creating a complete inventory of AI systems, models, datasets, vendors, and integrations. The inventory should include systems in production, pilots, internal tools, and embedded AI features in third-party platforms. Without this baseline, teams cannot assess risk consistently or identify where AI is used.
Each inventory entry should capture the system owner, business purpose, data inputs, model type, deployment environment, user groups, and downstream dependencies. It should also document whether the system makes decisions, supports decisions, generates content, or automates workflows. This information gives governance, security, and compliance teams a shared view of the AI environment.
The inventory should be updated as part of normal technology and procurement processes. New AI tools, model changes, vendor features, and data connections should trigger a review. This prevents shadow AI from becoming a hidden source of operational, legal, or security risk.
Key actions:
- Inventory AI systems, models, and datasets.
- Document owners, purpose, and data sources.
- Update the inventory as AI systems change.
2. Classify AI Systems by Risk
Not all AI systems require the same level of oversight. Organizations should classify AI systems based on their potential impact on people, operations, security, compliance, and business outcomes. A low-risk internal productivity tool should not be managed the same way as an AI system used for lending, hiring, healthcare, fraud detection, or customer authentication.
Risk classification should consider the sensitivity of the data, the level of automation, the system’s decision authority, the consequences of failure, and the ability for humans to review or override outputs. Higher-risk systems should require stronger controls, more frequent testing, clearer documentation, and executive-level visibility.
Classification should also account for context. The same model may present low risk in one use case and high risk in another. For example, a language model used to summarize public marketing content creates different risks than the same model used to summarize legal evidence or employee health records.
Key actions:
- Classify systems by business and security impact.
- Apply stronger controls to high-risk AI.
- Review classifications regularly.
3. Assign Ownership and Governance
Every AI system should have a defined business owner, technical owner, and risk owner. The business owner is responsible for the system’s purpose and outcomes. The technical owner manages implementation, testing, and performance. The risk owner ensures that controls, documentation, and review processes are in place.
Governance should define approval workflows for new AI use cases, model updates, vendor onboarding, and major changes in data or system behavior. Clear ownership prevents gaps where teams assume someone else is managing risk. It also makes escalation faster when issues arise.
Organizations should include representatives from security, legal, privacy, compliance, data science, and affected business units in governance processes. This cross-functional model helps identify risks that a single team may miss and ensures AI decisions reflect technical requirements and business obligations.
Key actions:
- Assign business, technical, and risk owners.
- Define approval and review workflows.
- Involve security, legal, and compliance teams.
4. Connect AI Risk Management to Incident Response
AI incidents should be integrated into existing incident response processes. This includes events such as harmful outputs, model drift, data leakage, prompt injection, unauthorized model access, biased decisions, or unexpected automation behavior. Treating AI incidents separately can delay response and reduce visibility for security and operations teams.
Organizations should define AI-specific incident categories, severity levels, escalation paths, and response playbooks. Response plans should include steps for disabling AI features, rolling back model versions, preserving evidence, notifying stakeholders, and reviewing root causes. This helps teams respond quickly and improve controls after each incident.
Incident response teams should understand how AI systems are connected to data stores, applications, identities, and automated workflows. This allows responders to assess the full scope of an incident and determine whether an issue is limited to model behavior or tied to a broader security or operational failure.
Key actions:
- Create AI-specific incident playbooks.
- Define escalation paths and response procedures.
- Review incidents to improve controls.
5. Map AI Risks to Security and Operational Telemetry
AI risk management depends on visibility into how systems behave in real environments. Organizations should map key AI risks to available telemetry from applications, infrastructure, identity systems, data pipelines, model endpoints, and user activity logs. This allows teams to detect problems based on observable signals rather than manual reviews.
Useful telemetry may include prompt activity, model responses, API usage, access patterns, data movement, output quality metrics, policy violations, and changes in model performance. Mapping these signals to specific risks helps security and operations teams monitor AI systems continuously and prioritize relevant alerts.
For example, data leakage risk may map to logs showing sensitive data in prompts, unusual download activity, or access to restricted datasets. Model misuse may map to abnormal API volumes, repeated blocked requests, or unusual user behavior. Clear mappings help teams convert AI risk statements into measurable detection logic.
Key actions:
- Monitor AI activity across applications and infrastructure.
- Map telemetry to specific AI risks.
- Alert on policy violations and abnormal behavior.
Related content: Explore AI-driven cyber security technologies and best practices.
6. Use Behavioral Analytics to Detect AI Misuse
Behavioral analytics can detect misuse of AI systems by identifying unusual patterns in user, application, or model activity. Examples include excessive prompt submissions, attempts to extract sensitive data, repeated policy bypass attempts, abnormal API usage, or unusual access to training data and model files.
These signals are especially important for generative AI systems, where misuse may occur through natural language rather than traditional exploit techniques. Behavioral analytics can help identify prompt injection, insider misuse, data exfiltration attempts, and unauthorized automation.
Effective behavioral analytics requires a baseline of normal activity for users, applications, and model endpoints. Once this baseline is established, teams can detect deviations that may indicate abuse or failure. Alerts should be reviewed with business context so teams can distinguish misuse from legitimate high-volume activity.
Key actions:
- Baseline normal AI usage patterns.
- Detect anomalous prompts and API activity.
- Investigate potential misuse and abuse.
7. Maintain Evidence for Audits and Executive Review
Organizations should maintain evidence showing how AI risks are identified, assessed, controlled, and reviewed. This includes AI inventories, risk classifications, model documentation, testing results, approval records, monitoring reports, incident records, and control mappings. Evidence should be organized to support audits, regulatory inquiries, and internal governance reviews.
Executives need reporting that connects AI risk to business impact. Audit teams need records that show controls operate as intended. Maintaining both levels of evidence helps organizations demonstrate accountability, track improvements, and make decisions about AI investments and risk exposure.
Evidence should be maintained continuously, not assembled only when an audit begins. Regular reporting can show which AI systems are high risk, which controls are in place, where exceptions exist, and whether remediation is on track. This gives leadership a clear view of AI risk posture over time.
Key actions:
- Document AI risks, controls, and decisions.
- Maintain records of testing and incidents.
- Report AI risk posture to leadership.
Operationalizing the NIST AI RMF with Exabeam New-Scale Fusion
Putting the NIST AI RMF into practice requires continuous visibility into how AI systems, users, and automated agents actually behave in production, mapped to the telemetry that security and operations teams already rely on. The Exabeam New-Scale Fusion security operations platform supports this by combining New-Scale SIEM and New-Scale Analytics in a modular, cloud-native platform that applies AI, behavioral analytics, and automation to security operations workflows. By integrating pre-deployment policy verification via Praxen, runtime telemetry collection via Observra, and secure model connections via Model Context Protocol (MCP), the platform provides the observable signals needed to govern, map, measure, and manage AI risk. This enables organizations to baseline normal machine activity, discover shadow AI, and secure AI agents and other non-human identities across the enterprise lifecycle.
Key capabilities of Exabeam New-Scale Fusion:
- Behavioral analytics for humans and AI agents: Learns normal behavior for human, non-human, and AI agent identities and scores anomalies by rarity with business context, focusing analyst attention on events that require action rather than raw alert volume.
- Pre-deployment verification (Praxen): Leverages the open-source Praxen framework to compare declared agent policies with code, configuration, and logs before deployment, identifying excessive permissions and configuration gaps to govern AI systems in accordance with the NIST AI RMF.
- Runtime agent telemetry (Observra): Uses the open-source Observra SDK to capture, normalize, and enrich runtime activity such as model calls, tool execution, and token usage, eliminating visibility blind spots to map and measure AI risks.
- Secure model interoperability (MCP Server): Integrates AI models with Exabeam APIs via the Model Context Protocol (MCP) using user-delegated authentication, securing model-to-tool connections and logging all interactions in the Exabeam Audit Log to maintain clear accountability and audit trails.
- Agent Behavior Analytics (ABA): Monitors AI agents and automated identities by collecting their activity, correlating it with users and devices, and highlighting actions that need review, with detections mapped directly to the OWASP Top 10 for Agentic AI.
- Shadow AI discovery: Automatically detects unauthorized AI tool usage, unmanaged API integrations, and rogue LLM subscriptions across the enterprise network by analyzing endpoint and network logs to prevent sensitive data exposure.
- SIEM augmentation without rip and replace: Integrates with your current architecture to add behavioral detections without replacing your SIEM, using hundreds of prebuilt integrations and the Open API Standard (OAS) to connect to thousands more tools.
- AI-driven triage and investigation: Exabeam Nova agents analyze detections, gather context, and build case summaries to move teams faster from alert to resolution, while accelerating detection engineering with AI-assisted rule creation and tuning.
- Entity context and risk prioritization: Attack Surface Insights aggregates identity and device data from multiple sources into a unified view, building detailed profiles and linking attributes to expose relationships and uncover hidden risk.
To see how behavioral analytics can surface the anomalous activity behind adversarial AI attacks before they affect downstream systems, explore Exabeam Agent Behavior Analytics.
Learn More About Exabeam
Learn about the Exabeam platform and expand your knowledge of information security with our collection of white papers, podcasts, webinars, and more.
-
Video
Mizuho Financial Group Enhances Security Governance and Advances Internal Fraud Prevention with Exabeam
- Show More