✳ US · NIST AI RMF

NIST AI RMF 1.0: voluntary four functions (not a certificate, not LLM Top 10, not an Atlas seal)

An educational overview of NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF) 1.0, published 2023-01-26, as a voluntary, rights-preserving, non-sector-specific, use-case-agnostic framework for organizing AI risk work. Govern, Map, Measure, and Manage are organizing jobs. Naming them is not a certificate, not OWASP GenAI LLM Top 10 2026, not web Top 10:2025, not ASVS, not finished G1 through G3, not G3 Map-it sealed, and not an Atlas AI or AppSec seal.

US · NIST AI RMFVoluntary framework explainerLast reviewed

What category of voluntary framework this is

The NIST Artificial Intelligence Risk Management Framework (AI RMF) 1.0 is a voluntary, rights-preserving, non-sector-specific, use-case-agnostic framework. It helps organizations manage risks of AI systems and incorporate trustworthiness considerations into design, development, use, and evaluation. It is not the OWASP GenAI LLM Top 10, not the web OWASP Top 10, not ASVS, and not a consumer conformity mark.

Who it commonly frames: AI path readers leaving G3 Map-it who only had a Reference field guide, LLM explainer readers who already see that the list is not AI RMF, buyers who treat AI RMF certified as one seal, and AppSec or GRC readers who collapse AI RMF with the LLM Top 10 or the web Top 10. This is a voluntary framework. It is not a U.S. statute that forces conformity, and it is not a certification scheme.

What security people most often confuse: they fold four function names, ten LLM checkboxes, web Top 10:2025, an ASVS level, finished G1 through G3, and an Atlas lesson into one seal. This page keeps those objects apart. The LLM explainer at /learn/explainers/owasp-llm-top-10/ stays the LLM awareness list. The web Top 10 explainer at /learn/explainers/owasp-top-10/ stays the web awareness list. The ASVS explainer at /learn/explainers/owasp-asvs/ stays the verification project. G3 Map-it at /learn/topics/human-oversight-gates/#map-it stays the practice sort. The field guide at /reference/frameworks/nist-ai-rmf-1-0/ stays the edition-pin home. This explainer complements them. It does not replace any of them, and it does not reprint subcategory catalogs.

Edition pin

The edition string to teach is NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF) 1.0, published 26 January 2023 (2023-01-26), DOI 10.6028/NIST.AI.100-1. Official hubs are https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10, https://www.nist.gov/itl/ai-risk-management-framework, and https://doi.org/10.6028/NIST.AI.100-1. Re-opened on 2026-09-26: the publication page still says Published January 26, 2023, report number NIST AI 100-1, and the same DOI. The landing page still describes voluntary use and the same DOI.

The NIST landing page states that AI RMF 1.0 is being revised as part of the White House AI Action Plan. That sentence is a process notice. It is not a published replacement edition. A future generation beyond 1.0 is UNKNOWN. This card does not invent AI RMF 2.0 content, dates, or function renames. If a newer Final is published, update this pin and treat the older claim as UNKNOWN. This card does not invent an adoption percentage.

Govern, Map, Measure, and Manage are literacy labels

Govern, Map, Measure, and Manage are the Core functions at slogan depth. Govern names who is accountable, including policies, roles, and oversight culture for AI risk. Map names what the system is, the context, and where harm could land. Measure names how you test, evaluate, and track AI risks and trustworthiness. Manage names what you do with the result: prioritize, respond, control, and improve.

These are organizing jobs. They are not a finished test plan, and they are not permission to paste the Playbook or a subcategory catalog into Atlas. This page does not list subcategory identifiers. G3 already sorts one LanePay control onto those four rows at /learn/topics/human-oversight-gates/#map-it. That sort is practice. It does not make this page a fourth AI lesson, and finishing the sort is not a conformity assessment. Tool-permission practice stays on the lab at /labs/agent-tool-auth/.

Name the function, then keep the evidence

Pick one real or synthetic AI-powered feature. LanePay on the AI path, and a high-impact tool action in the agent lab, are the synthetic examples already on this site. Use one AI RMF function as a shared name for the conversation, then move to verifiable evidence: a named human gate, tool authorization, a measure that would catch a miss, or a manage response when a measure fails.

Practice stays on the existing pages. G3 Map-it is /learn/topics/human-oversight-gates/#map-it. G1 is /learn/topics/prompt-injection-and-retrieval/. G2 is /learn/topics/excessive-agency/. The lab is /labs/agent-tool-auth/. The path is /learn/paths/ai-agent-security/. The landscape segment, when you are comparing control purposes, is /landscape/segments/ai-agent-security/. This page does not replace those.

When the need is LLM-application awareness labels, use the LLM explainer at /learn/explainers/owasp-llm-top-10/. When the need is web awareness, use /learn/explainers/owasp-top-10/. When the need is leveled verification, use /learn/explainers/owasp-asvs/. Do not collapse those lanes. The six-map comparison is /reference/frameworks/compare/. It does not add a seventh map object for this framework. The field guide remains /reference/frameworks/nist-ai-rmf-1-0/.

NIST AI 600-1 is a companion, not this edition

NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, published July 26, 2024 (2024-07-26, DOI 10.6028/NIST.AI.600-1), is a later companion profile. Do not swap it into the AI RMF 1.0 edition string. This page does not open a full AI 600-1 Atlas page.

What this card is not

Not an AI RMF course. Not a G4 revival. Not an Agentic Top 10 card. Not a Playbook, Crosswalk, Roadmap, or Critical Infrastructure Profile dump. Not a subcategory encyclopedia. Not exploit or red-team PoC homework. Not a web Top 10 rewrite. Not an ASVS rewrite. Not an LLM Top 10 rewrite. Not a replacement for the field guide at /reference/frameworks/nist-ai-rmf-1-0/, for G3 Map-it at /learn/topics/human-oversight-gates/#map-it, or for the LLM explainer at /learn/explainers/owasp-llm-top-10/. Not permission to invent an adoption statistic. Not a claim that G1 through G3 done means this framework is sealed. Not an Atlas attestation of AI RMF completion.

Not a CSF 2.0 profile. Outcomes live on /learn/topics/outcomes-then-controls/. The six-map comparison at /reference/frameworks/compare/ does not add a seventh map object for AI RMF. A row is not this page. This page is the labeled literacy home beside the field guide.

Rewrite the one-line claim

Replace "we are AI RMF, LLM Top 10, Top 10, ASVS, OWASP AI, and Atlas AI compliant" with a reading sentence. We use NIST AI RMF 1.0 (AI 100-1, 2023-01-26) as a voluntary four-function organizer (Govern, Map, Measure, Manage). That is different from OWASP GenAI LLM Top 10 2026 awareness, from web Top 10:2025, from ASVS 5.0.0 verification depth, from finished G1 through G3 practice, and from an Atlas seal.

When a slide says "AI RMF certified" or "NIST AI verified," privately ask which edition, which function was actually evidenced on which system, and whether the live need is AI RMF placement, LLM awareness, web Top 10 awareness, or ASVS verification depth. Do not paste proprietary prompts, customer data, or exploit kits into Atlas.

Four function names are not certified, not LLM Top 10, not web Top 10, not ASVS, and not an Atlas seal

Teaching table only. It does not assign a certificate, a finished assessment, an ASVS level, an LLM Top 10 result, or an Atlas seal.

Eight phrases people fold into one AI RMF badge. Not a seal, and not a subcategory catalog.
Phrase people sayLiteracy correction
We named Govern / Map / Measure / Manage, so we are AI RMF certified / completeAI RMF 1.0 is a voluntary framework. Naming four functions is not a finished assessment and not a certification.
AI RMF done means LLM Top 10:2026 doneOWASP GenAI LLM Top 10 2026 is a separate LLM-application awareness list. Explainer: /learn/explainers/owasp-llm-top-10/. Do not collapse.
AI RMF done means web Top 10:2025 doneOWASP Top 10:2025 is a separate web-application awareness list. Explainer: /learn/explainers/owasp-top-10/.
AI RMF done means ASVS Level N verifiedASVS is a separate requirements and verification project. Explainer: /learn/explainers/owasp-asvs/. Function names are not ASVS evidence.
We finished G1 through G3 / G3 Map-it, so AI RMF is sealed / Atlas AI sealedG1 through G3 teach selected themes and one Map-it sort. Path progress is not the framework finished, and Atlas does not issue an AI seal. Map-it: /learn/topics/human-oversight-gates/#map-it.
We are AI RMF certified / NIST AI verified / Atlas AppSec sealedThis framework is not an Atlas certificate and not a mail-order seal. Completing this lesson is not attested, not certified, and not AI RMF complete. It is not an Atlas AppSec seal. Six-map comparison: /reference/frameworks/compare/.
We can paste the Playbook / subcategory tree / Crosswalk / exploit PoCs as Atlas homeworkThis card does not reprint NIST subcategory catalogs, Playbook actions, or attack PoCs. Point readers to nist.gov and the DOI. No exploit homework. Field guide: /reference/frameworks/nist-ai-rmf-1-0/.
NIST AI 600-1 is the same edition pin as AI RMF 1.0NIST AI 600-1 is a Generative AI Profile companion (July 26, 2024, DOI 10.6028/NIST.AI.600-1). Do not swap it into the 1.0 edition string.

Claims to retire

Four function names mean AI RMF certified, an agent that is safe, or an Atlas seal.

AI RMF 1.0 is a voluntary framework. Naming Govern, Map, Measure, and Manage is not a finished assessment and not a certification.

AI RMF, the LLM Top 10, the web Top 10, and ASVS are the same homework.

They are different objects. NIST AI RMF 1.0 places work in Govern, Map, Measure, and Manage. OWASP GenAI LLM Top 10 2026 is a separate awareness list. Top 10:2025 names web risk themes. ASVS is leveled verification depth. Do not collapse them.

Finishing G1 through G3, or G3 Map-it, means AI RMF is sealed.

G1 through G3 teach selected themes and one Map-it sort. Path progress is not the framework finished, and Atlas does not issue an AI seal.

This page replaces the field guide, G3 Map-it, or the LLM explainer.

Those pages stay. This page is the labeled literacy home beside them. It does not replace any of them.

Atlas, or a vendor homepage shield, attests AI RMF completion.

Atlas does not issue AI RMF certified or complete seals, OWASP AI verified seals, or Atlas AI or AppSec seals. Completing this lesson is not certified. A homepage shield is not evidence a function was practiced on your system.

The Playbook, the subcategory tree, or exploit scenarios should be pasted into Atlas lessons.

This card does not reprint NIST subcategory catalogs, Playbook actions, or attack PoCs. Read the official publication instead of pasting it into Atlas.

NIST AI 600-1 is the AI RMF 1.0 edition pin.

NIST AI 600-1 is a Generative AI Profile companion (July 26, 2024). Do not swap it into the 1.0 edition string.

Govern, Map, Measure, Manage, as labels

Slogan depth only. This table does not reprint subcategory catalogs, Playbook actions, or a Crosswalk.

Four organizing jobs. Not a finished assessment, and not a certification.
FunctionOne-line literacyBoundary
GovernWho is accountable; policies, roles, oversight culture for AI riskOrganizing job. Not a finished assessment.
MapWhat the system is, context, and where harm could landOrganizing job. Not a finished assessment.
MeasureHow you test, evaluate, and track AI risks and trustworthinessOrganizing job. Not a finished assessment.
ManageWhat you do with the result: prioritize, respond, control, improveOrganizing job. Not a finished assessment.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.