What it helps you do
Place AI system risk work into four functions. Oversight and roles sit under Govern. Hazard framing sits under Map. Evaluations sit under Measure. Response and controls sit under Manage. LanePay can use that placement for a high-impact tool action. G4 already walks a light map. This card does not rewrite G1 through G3.
A useful way to begin
- Pin NIST AI 100-1, AI RMF 1.0, published 26 January 2023, DOI 10.6028/NIST.AI.100-1.
- Read the Core as four jobs: Govern (who is accountable), Map (what the system is and where harm could land), Measure (how you test), Manage (what you do with the result).
- Point Atlas lessons at a function. Oversight lives in Govern. Hazard framing lives in Map. Evaluations live in Measure. Response and controls live in Manage. Leave G1 through G3 as they are.
- When a conversation cites the OWASP LLM Top 10, keep it as a separate 2026 awareness list. Prompt injection is LLM01:2026. Excessive agency is LLM03:2026. Neither list replaces AI RMF 1.0.
What good evidence looks like
A named human approval gate for a high-impact tool action on a synthetic agent, the same habit Lab 6 practices. A certificate PDF is not that gate.
Other records you might already have
- A LanePay record that names the human who must approve a high-impact payment tool action before it runs.
- A one-row map that places that gate under Govern and the check of the gate under Measure.
Two different lists
- NIST AI RMF 1.0. Voluntary risk framework. Govern, Map, Measure, and Manage organize the work. No consumer conformity mark is part of this edition.
- OWASP Top 10 for LLM Applications 2026. Awareness list for LLM applications. Prompt injection is LLM01:2026. Excessive agency is LLM03:2026. It is a separate list from AI RMF 1.0.
Labeled companions
- NIST AI 600-1. Generative AI Profile companion. Do not swap it for the AI RMF 1.0 edition string.
Claims to retire
There is an AI RMF certification.
AI RMF 1.0 (NIST AI 100-1, 2023-01-26) is voluntary. This card does not award a certificate, and completing a worksheet is not a conformity assessment.
Completing the core means the agent is safe.
Govern, Map, Measure, and Manage organize the work. Naming the four functions does not make an agent safe.
AI RMF is the same as the OWASP LLM Top 10.
AI RMF 1.0 is a voluntary risk framework. The OWASP Top 10 for LLM Applications 2026 is a separate awareness list.
Related lessons
This is an original educational guide. Use the publisher’s official materials for the authoritative requirements and licensing terms. A relationship between maps is not one-to-one control equivalence. This card complements the six live maps. It is not a row in that comparison.