What category of voluntary framework this is
The NIST Artificial Intelligence Risk Management Framework (AI RMF) 1.0 is a voluntary, rights-preserving, non-sector-specific, use-case-agnostic framework. It helps organizations manage risks of AI systems and incorporate trustworthiness considerations into design, development, use, and evaluation. It is not the OWASP GenAI LLM Top 10, not the web OWASP Top 10, not ASVS, and not a consumer conformity mark.
Who it commonly frames: AI path readers leaving G3 Map-it who only had a Reference field guide, LLM explainer readers who already see that the list is not AI RMF, buyers who treat AI RMF certified as one seal, and AppSec or GRC readers who collapse AI RMF with the LLM Top 10 or the web Top 10. This is a voluntary framework. It is not a U.S. statute that forces conformity, and it is not a certification scheme.
What security people most often confuse: they fold four function names, ten LLM checkboxes, web Top 10:2025, an ASVS level, finished G1 through G3, and an Atlas lesson into one seal. This page keeps those objects apart. The LLM explainer at /learn/explainers/owasp-llm-top-10/ stays the LLM awareness list. The web Top 10 explainer at /learn/explainers/owasp-top-10/ stays the web awareness list. The ASVS explainer at /learn/explainers/owasp-asvs/ stays the verification project. G3 Map-it at /learn/topics/human-oversight-gates/#map-it stays the practice sort. The field guide at /reference/frameworks/nist-ai-rmf-1-0/ stays the edition-pin home. This explainer complements them. It does not replace any of them, and it does not reprint subcategory catalogs.
Edition pin
The edition string to teach is NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF) 1.0, published 26 January 2023 (2023-01-26), DOI 10.6028/NIST.AI.100-1. Official hubs are https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10, https://www.nist.gov/itl/ai-risk-management-framework, and https://doi.org/10.6028/NIST.AI.100-1. Re-opened on 2026-09-26: the publication page still says Published January 26, 2023, report number NIST AI 100-1, and the same DOI. The landing page still describes voluntary use and the same DOI.
The NIST landing page states that AI RMF 1.0 is being revised as part of the White House AI Action Plan. That sentence is a process notice. It is not a published replacement edition. A future generation beyond 1.0 is UNKNOWN. This card does not invent AI RMF 2.0 content, dates, or function renames. If a newer Final is published, update this pin and treat the older claim as UNKNOWN. This card does not invent an adoption percentage.
Govern, Map, Measure, and Manage are literacy labels
Govern, Map, Measure, and Manage are the Core functions at slogan depth. Govern names who is accountable, including policies, roles, and oversight culture for AI risk. Map names what the system is, the context, and where harm could land. Measure names how you test, evaluate, and track AI risks and trustworthiness. Manage names what you do with the result: prioritize, respond, control, and improve.
These are organizing jobs. They are not a finished test plan, and they are not permission to paste the Playbook or a subcategory catalog into Atlas. This page does not list subcategory identifiers. G3 already sorts one LanePay control onto those four rows at /learn/topics/human-oversight-gates/#map-it. That sort is practice. It does not make this page a fourth AI lesson, and finishing the sort is not a conformity assessment. Tool-permission practice stays on the lab at /labs/agent-tool-auth/.
Name the function, then keep the evidence
Pick one real or synthetic AI-powered feature. LanePay on the AI path, and a high-impact tool action in the agent lab, are the synthetic examples already on this site. Use one AI RMF function as a shared name for the conversation, then move to verifiable evidence: a named human gate, tool authorization, a measure that would catch a miss, or a manage response when a measure fails.
Practice stays on the existing pages. G3 Map-it is /learn/topics/human-oversight-gates/#map-it. G1 is /learn/topics/prompt-injection-and-retrieval/. G2 is /learn/topics/excessive-agency/. The lab is /labs/agent-tool-auth/. The path is /learn/paths/ai-agent-security/. The landscape segment, when you are comparing control purposes, is /landscape/segments/ai-agent-security/. This page does not replace those.
When the need is LLM-application awareness labels, use the LLM explainer at /learn/explainers/owasp-llm-top-10/. When the need is web awareness, use /learn/explainers/owasp-top-10/. When the need is leveled verification, use /learn/explainers/owasp-asvs/. Do not collapse those lanes. The six-map comparison is /reference/frameworks/compare/. It does not add a seventh map object for this framework. The field guide remains /reference/frameworks/nist-ai-rmf-1-0/.
NIST AI 600-1 is a companion, not this edition
NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, published July 26, 2024 (2024-07-26, DOI 10.6028/NIST.AI.600-1), is a later companion profile. Do not swap it into the AI RMF 1.0 edition string. This page does not open a full AI 600-1 Atlas page.
What this card is not
Not an AI RMF course. Not a G4 revival. Not an Agentic Top 10 card. Not a Playbook, Crosswalk, Roadmap, or Critical Infrastructure Profile dump. Not a subcategory encyclopedia. Not exploit or red-team PoC homework. Not a web Top 10 rewrite. Not an ASVS rewrite. Not an LLM Top 10 rewrite. Not a replacement for the field guide at /reference/frameworks/nist-ai-rmf-1-0/, for G3 Map-it at /learn/topics/human-oversight-gates/#map-it, or for the LLM explainer at /learn/explainers/owasp-llm-top-10/. Not permission to invent an adoption statistic. Not a claim that G1 through G3 done means this framework is sealed. Not an Atlas attestation of AI RMF completion.
Not a CSF 2.0 profile. Outcomes live on /learn/topics/outcomes-then-controls/. The six-map comparison at /reference/frameworks/compare/ does not add a seventh map object for AI RMF. A row is not this page. This page is the labeled literacy home beside the field guide.
Rewrite the one-line claim
Replace "we are AI RMF, LLM Top 10, Top 10, ASVS, OWASP AI, and Atlas AI compliant" with a reading sentence. We use NIST AI RMF 1.0 (AI 100-1, 2023-01-26) as a voluntary four-function organizer (Govern, Map, Measure, Manage). That is different from OWASP GenAI LLM Top 10 2026 awareness, from web Top 10:2025, from ASVS 5.0.0 verification depth, from finished G1 through G3 practice, and from an Atlas seal.
When a slide says "AI RMF certified" or "NIST AI verified," privately ask which edition, which function was actually evidenced on which system, and whether the live need is AI RMF placement, LLM awareness, web Top 10 awareness, or ASVS verification depth. Do not paste proprietary prompts, customer data, or exploit kits into Atlas.
Four function names are not certified, not LLM Top 10, not web Top 10, not ASVS, and not an Atlas seal
Teaching table only. It does not assign a certificate, a finished assessment, an ASVS level, an LLM Top 10 result, or an Atlas seal.
| Phrase people say | Literacy correction |
|---|---|
| We named Govern / Map / Measure / Manage, so we are AI RMF certified / complete | AI RMF 1.0 is a voluntary framework. Naming four functions is not a finished assessment and not a certification. |
| AI RMF done means LLM Top 10:2026 done | OWASP GenAI LLM Top 10 2026 is a separate LLM-application awareness list. Explainer: /learn/explainers/owasp-llm-top-10/. Do not collapse. |
| AI RMF done means web Top 10:2025 done | OWASP Top 10:2025 is a separate web-application awareness list. Explainer: /learn/explainers/owasp-top-10/. |
| AI RMF done means ASVS Level N verified | ASVS is a separate requirements and verification project. Explainer: /learn/explainers/owasp-asvs/. Function names are not ASVS evidence. |
| We finished G1 through G3 / G3 Map-it, so AI RMF is sealed / Atlas AI sealed | G1 through G3 teach selected themes and one Map-it sort. Path progress is not the framework finished, and Atlas does not issue an AI seal. Map-it: /learn/topics/human-oversight-gates/#map-it. |
| We are AI RMF certified / NIST AI verified / Atlas AppSec sealed | This framework is not an Atlas certificate and not a mail-order seal. Completing this lesson is not attested, not certified, and not AI RMF complete. It is not an Atlas AppSec seal. Six-map comparison: /reference/frameworks/compare/. |
| We can paste the Playbook / subcategory tree / Crosswalk / exploit PoCs as Atlas homework | This card does not reprint NIST subcategory catalogs, Playbook actions, or attack PoCs. Point readers to nist.gov and the DOI. No exploit homework. Field guide: /reference/frameworks/nist-ai-rmf-1-0/. |
| NIST AI 600-1 is the same edition pin as AI RMF 1.0 | NIST AI 600-1 is a Generative AI Profile companion (July 26, 2024, DOI 10.6028/NIST.AI.600-1). Do not swap it into the 1.0 edition string. |
Claims to retire
Four function names mean AI RMF certified, an agent that is safe, or an Atlas seal.
AI RMF 1.0 is a voluntary framework. Naming Govern, Map, Measure, and Manage is not a finished assessment and not a certification.
AI RMF, the LLM Top 10, the web Top 10, and ASVS are the same homework.
They are different objects. NIST AI RMF 1.0 places work in Govern, Map, Measure, and Manage. OWASP GenAI LLM Top 10 2026 is a separate awareness list. Top 10:2025 names web risk themes. ASVS is leveled verification depth. Do not collapse them.
Finishing G1 through G3, or G3 Map-it, means AI RMF is sealed.
G1 through G3 teach selected themes and one Map-it sort. Path progress is not the framework finished, and Atlas does not issue an AI seal.
This page replaces the field guide, G3 Map-it, or the LLM explainer.
Those pages stay. This page is the labeled literacy home beside them. It does not replace any of them.
Atlas, or a vendor homepage shield, attests AI RMF completion.
Atlas does not issue AI RMF certified or complete seals, OWASP AI verified seals, or Atlas AI or AppSec seals. Completing this lesson is not certified. A homepage shield is not evidence a function was practiced on your system.
The Playbook, the subcategory tree, or exploit scenarios should be pasted into Atlas lessons.
This card does not reprint NIST subcategory catalogs, Playbook actions, or attack PoCs. Read the official publication instead of pasting it into Atlas.
NIST AI 600-1 is the AI RMF 1.0 edition pin.
NIST AI 600-1 is a Generative AI Profile companion (July 26, 2024). Do not swap it into the 1.0 edition string.
Govern, Map, Measure, Manage, as labels
Slogan depth only. This table does not reprint subcategory catalogs, Playbook actions, or a Crosswalk.
| Function | One-line literacy | Boundary |
|---|---|---|
| Govern | Who is accountable; policies, roles, oversight culture for AI risk | Organizing job. Not a finished assessment. |
| Map | What the system is, context, and where harm could land | Organizing job. Not a finished assessment. |
| Measure | How you test, evaluate, and track AI risks and trustworthiness | Organizing job. Not a finished assessment. |
| Manage | What you do with the result: prioritize, respond, control, improve | Organizing job. Not a finished assessment. |
CHECK THE CATEGORY
Which sentence matches this page?
Glossary and nearby pages
- OWASP LLM Top 10 explainer (awareness list, not this framework)
- OWASP Top 10 explainer (web awareness list, not this framework)
- OWASP ASVS explainer (verification requirements, not this framework)
- NIST AI RMF 1.0 field guide (edition pin companion, not replaced by this page)
- Compare the six maps (a row is not this framework, and not a seventh map)
- Prompt injection and retrieval trust (G1)
- Excessive agency (G2)
- Map it (AI RMF functions), in human oversight (G3)
- Lab: Two tools, one blast radius
- AI application and agent security path
- Landscape: AI application and agent security
- NIST SSDF Version 1.1 explainer (software practice vocabulary, not this framework)
- NIST SP 800-207 ZTA explainer (architecture paradigm, not this framework)
- Understand and build toward an Agentic SOC (S4)
- Outcomes first, then controls (F8a)
- Privacy is not a CIA checkbox
Use the agency page in the sources for the authoritative text. This page has no figure.