NIST Didn’t Publish an AI Framework. It Built a Stack.

Executive at a desk considering a stacked tower of NIST AI publications, from the Cybersecurity Framework at the base up through the AI RMF, control overlays, profiles, and the AI Agent Standards Initiative

I have a confession. For someone who has spent most of the last several years living inside IT Governance, I have a long-standing soft spot for NIST publications, and it predates AI by more than a decade.

The document that hooked me was the Cybersecurity Framework (CSF). I had worked with NIST material before it, SP 800-53 in particular, and I respected the rigor. But the CSF did something controls catalogs could never do. It gave me five words I could put in front of a board. Identify, Protect, Detect, Respond, Recover. No acronyms, no translation layer. A director could read the function names and ask a useful question in the same breath. That is rare, and I have been chasing it ever since. And in 2024, NIST added a Govern function to that list, you know that makes me smile. The CSF is the cast-iron skillet of frameworks. Nothing fancy, hard to break, and it gets better the longer you use it.

A BOARDROOM TEST I STILL USE

If a director cannot ask a useful question after reading the top line of a framework, the framework is not ready for the boardroom. It needs an interpreter, and interpreters are where governance goes to get lost.

The CSF passed that test in 2014. The AI RMF passed it in 2023 with four verbs: Govern, Map, Measure, Manage. The question for this post is whether what NIST has built underneath those four verbs passes it too, and what you do with it if it does.

Part of my attraction is personal. I have contributed to a few NIST publications over the years, and I have watched how they were made. Request for Information, public draft, workshop, second draft, more comments, final. Nobody gets to skip the line. The result is guidance that reads like it was written by people who have had to implement it, because it was.  So, while I was busy with other governance frameworks, NIST quietly built something I believe is the best AI risk guidance currently available. Let me make the case.

A short history, because it’s important here. NIST started life in 1901 as the National Bureau of Standards, keeping the country’s weights and measures honest. It became NIST in 1988. For most of the governance community, NIST arrived on the radar through the SP 800 series (800-53 for controls, 800-37 for the Risk Management Framework) and then, decisively, with the Cybersecurity Framework in 2014. The pattern was set early: voluntary, consensus-driven, and structured so that different industries can adopt the same backbone without pretending they are the same industry.

Then in January 2023 came the AI Risk Management Framework (AI RMF 1.0). Most executives I talk to know this one. Few of them know what has happened since.

Timeline of NIST standards from the 1901 National Bureau of Standards through the 2014 Cybersecurity Framework, the 2023 AI RMF, and the 2024 to 2026 AI profiles and overlays

Before I get to what came after, here is the AI RMF itself in one picture. Four functions in the Core, with Govern sitting in the middle because it touches everything else. Seven characteristics of trustworthy AI that the functions are meant to deliver. And a profile mechanism that lets you tailor the whole thing to your sector or use case without rewriting it. Keep this picture in mind, because everything NIST has published since 2023 hangs off it.

NIST AI RMF core shown as a wheel with Govern in the center and Map, Measure, and Manage around it, alongside the seven characteristics of trustworthy AI

One more picture before we move on, because this is the one executives tend to miss. The AI RMF is not a checklist you run once at project start. Different functions carry the weight at different points in an AI system’s life, and Govern never leaves the room, which is exactly why NIST drew it in the middle.

The AI RMF across the AI lifecycle showing lead and supporting functions for design, test, deploy, monitor, and retire, with Govern running underneath every phase

The misconception I keep running into. When an executive tells me, “We follow NIST for AI,” they almost always mean the AI RMF and nothing else. That was a complete answer in 2023. It is not a complete answer now. NIST stopped writing a framework and started writing a stack, and the stack is where the work is. Here is the current inventory, as of this writing.

  • The AI RMF 1.0 (NIST AI 100-1, January 2023) is the base of the stack. Four functions, nineteen categories, and the profile mechanism everything below it depends on.
  • The Generative AI Profile (NIST AI 600-1, July 2024) takes the RMF’s four functions and applies them to the specific risks of generative models.
  • The Cyber AI Profile (NIST IR 8596), in preliminary draft since December 2025, does the same thing from the other direction… it organizes AI cybersecurity risk around the six Cybersecurity Framework functions and assigns priority tiers to subcategories, so you know what to do first.
  • The SP 800-53 Control Overlays for Securing AI Systems (COSAiS) project, with a concept paper in August 2025 and an annotated outline in January 2026, is where NIST gets down to the control level. Overlays are tailored sets of 800-53 controls for a specific use case. This is the altitude practitioners have been asking for.
  • The Critical Infrastructure Profile concept note (April 2026) extends the RMF to operators of IT, OT, and industrial control environments.
  • The AI Agent Standards Initiative, launched by NIST’s Center for AI Standards and Innovation in February 2026, is building guidance on agent identity, authorization, monitoring, and logging… with an interoperability profile targeted for later this year.
The NIST AI stack by altitude: AI RMF at the strategic altitude, the GenAI, Cyber AI, Critical Infrastructure, and Agent profiles at the tactical altitude, and SP 800-53 control overlays at the operational altitude

Notice the shape. The AI RMF sits at the strategic altitude and answers who decided and on what principles. The profiles sit at the tactical altitude and answer how it runs in your context. The overlays sit at the operational altitude and answer what it can touch. Three altitudes, one lineage, and no need to invent a new vocabulary every time the technology shifts. That is not an accident. That is thirty years of NIST discipline applied to a new challenge.

I asked my colleague Greg Witte, who has contributed to more NIST publications than most of us have read, how he thinks about it.

GREG WITTE

As Mark correctly points out, all of the NIST models are designed to work together, a modular approach that scales from the smallest business to the most complex enterprise. From supply chain to privacy to ICT risk to ERM (all supported by internationally-recognized AI and encryption models), NIST provides a great foundation to build a tailored trust solution.

Greg Witte, co-author and contributor to multiple NIST publications

I could not have said it better, and I have tried.

Yes, the AI RMF is being revised. No, you should not wait. The White House AI Action Plan directed NIST to revise AI RMF 1.0, and NIST’s own framework page confirms the revision is underway. The directed changes are narrow in scope and, as of this writing, no revised draft has been published for comment. The four functions are not changing. The profiles and overlays continue to build on the current text.

I bring this up because I have heard “let’s wait for 2.0” in more than one boardroom this year. That is a mistake. The strategic altitude is stable. The tactical and operational altitudes are where the action is, and they are not waiting for anyone.

FOUR QUESTIONS THAT SURVIVE ANY REVISION

Whatever the revision changes, these four questions will not. One per function, in plain English, ready for the boardroom.

MAP: What are we building, why, and where are the risks?

MEASURE: How risky is it, and how do we know?

MANAGE: What are we doing about it, and who owns the response?

GOVERN: Who is accountable, and does the culture back them up?

If your AI steering group cannot answer all four for a given system, you do not have a framework problem. You have a governance problem, and no revision will fix it.

Where this meets digital trust. Here is the part I care most about. A framework can tell you what to do. It cannot tell you whether anyone believes you did it. That is the digital trust question, and it is why I keep ISACA’s Digital Trust Ecosystem Framework (DTEF) next to the NIST stack rather than separate from it.

Think of it this way. The AI RMF gives you the principles your board can stand behind. The profiles give you the evidence that you adapted those principles to your actual environment. The overlays give you the control-level receipts. Every altitude produces something a customer, regulator, or auditor can inspect and that is the whole point. Trust that is assumed lives in a policy binder. Trust that is earned lives in artifacts someone outside your organization can verify.

Seen that way, the NIST stack is an artifact-generating machine. Adopt it and you are not just managing AI risk, you are creating the evidence that lets other people rely on you. Adopt it and fail to produce the evidence, and you have not adopted it. You have cited it.

Altitude

NIST document(s)

The trust question it answers

The artifact it produces

Strategic

AI RMF 1.0

Did leadership decide, and on what principles?

A board-approved AI risk posture mapped to Govern, Map, Measure, Manage

Tactical

GenAI Profile, Cyber AI Profile, Critical Infrastructure Profile, Agent guidance

Did you adapt those principles to how AI runs here?

A profile-based gap assessment with prioritized actions and owners

Operational

SP 800-53 overlays (COSAiS)

Can you prove the controls are in place and working?

Control-level evidence an auditor can test

And now the best part. Every NIST document I named above is free. Not “free trial,” free. Not “free with registration,” free. Free as in NIST would genuinely like you to download it and use it. I have sat in rooms where organizations spent six figures on AI governance consulting that could have started with a PDF. Start with the PDF. THEN call me.

Final Thoughts

1. Stop saying “we follow NIST” and start saying which altitude. The RMF alone is a principle set, not a program. Try this: ask your AI governance lead to name every NIST AI document in use today. If the answer is one, you have found your gap.

2. Adopt the Cyber AI Profile now, even in draft. The priority tiers alone are worth the read. Try this: map your current AI controls to the Profile’s High-Priority subcategories and count the blanks.

3. Watch the overlays, because they are where auditors will land. Control-level guidance is what gets tested. Try this: assign someone to track COSAiS releases and brief the risk committee quarterly.

4. Do not pause for the RMF revision. The four functions are stable, the scope of change is narrow, and the dependent profiles are moving forward. Try this: document your current RMF alignment with a date stamp so the revision becomes a delta exercise, not a restart.

5. Treat every NIST artifact as a digital trust deliverable. If it cannot be shown to someone outside the organization, it is not finished. Try this: for each adopted document, name the external party who could ask for proof and what you would hand them.

Which NIST document is your organization quietly treating as “the whole answer”? Tell me in the comments. I suspect I already know.