Skip to main content
TrustEdge AI

AI Governance

Govern, Map, Measure, Manage — and why the safe harbour is gone

The NIST AI RMF gives you a defensible process for AI risk. What it no longer gives you, since May 2026, is a safe harbour in any US state.

The NIST AI Risk Management Framework is the most widely adopted voluntary structure for managing AI risk in the United States. Four functions — Govern, Map, Measure, Manage — applied iteratively across the AI lifecycle. It is deliberately scalable, which makes it workable for a mid-market organization rather than only for a Fortune 500.

One correction to how it is often sold. Colorado's 2024 AI Act offered a rebuttable presumption of compliance to organizations following a recognised framework such as the AI RMF. That provision was repealed. SB 26-189, signed 14 May 2026, repealed and reenacted the statute without it. No US state currently grants a formal safe harbour for adopting the AI RMF.

The case for it is now evidentiary rather than statutory — and under an effect-based liability standard, evidence is what you need. Illinois HB 3773 makes it a civil rights violation to use AI that has the effect of discriminating, regardless of intent. Against that standard, a documented and repeated bias-testing process is the difference between a defensible position and an unexplained outcome.

The four functions

What each produces

The framework is only useful if it generates artifacts. These are the artifacts.

Govern — named owners and explicit limits

An AI use policy that says which tools are approved, who owns the risk register, and what is forbidden outright. In a healthcare context that means explicit prohibitions: no PHI to public models, no clinical decision on AI output without clinician review. Without a named owner, deployments proliferate unsupervised.

Map — a living inventory with risk tiers

Every AI asset categorised by intended use, data consumed, and potential impact. A grammar checker and an automated credit decision are not the same risk and should not share a control set. The map is not a one-time document; it is updated when the use, the data, or the law changes.

Measure — evidence, not assurance

Bias testing across protected classes, accuracy validation, and adversarial testing. This is where red-teaming lives. Measurement is scheduled and re-triggered when the underlying model changes, because a vendor updating a model silently invalidates everything you measured before it.

Manage — controls that actually bind

Human review where the decision warrants it, technical guardrails, monitoring, and an AI-specific incident response plan. This function is where a framework either becomes operational or stays a binder.

Where NIST is still catching up

Be aware of the gaps. NIST's SP 800-53 control overlays for AI remain in development, with only the predictive-AI use case at published discussion-draft stage as of early 2026. NIST launched an AI Agent Standards Initiative in February 2026 — an acknowledgement that agent security, interoperability and identity are not yet covered.

How it maps onto everything else

The AI RMF composes cleanly with ISO/IEC 42001 and with the EU AI Act's Article 9 risk-management duty. Build the evidence once and it satisfies several regimes, which is the main practical argument for starting here.

Questions

Frequently asked

Does adopting the AI RMF give us legal protection?

Not a formal one, not any more. Colorado's rebuttable presumption was repealed in May 2026 and no other state has enacted an equivalent. What it gives you is evidence — a documented, repeatable process that shows you identified the risk, tested for it, and acted. Under effect-based standards like Illinois HB 3773, and in front of a regulator or a court, that is materially better than the alternative, but it is not a defence you can point to in a statute.

Is it too heavy for a mid-sized organization?

No, and this is genuinely its strength. The framework is written to be scaled to the organization. A 60-person healthcare company can implement all four functions in a form that fits, and the output — a policy, an inventory, a testing schedule, an incident plan — is exactly what an assessor asks for regardless of your size.

How does this relate to the Generative AI Profile?

NIST AI 600-1, the Generative AI Profile, extends the core framework to risks specific to generative systems. If your deployment is generative — and most now are — it is the more directly applicable document, and we work from it alongside the core framework.

Should we do this or ISO/IEC 42001?

They answer different questions and are not alternatives. The AI RMF is a risk process; ISO/IEC 42001 is a certifiable management system. If nobody is asking you for a certificate, start with the AI RMF — it is free, it is proportionate, and it produces most of the same artifacts. Certify later if a customer ever requires it.

Want to know where you actually stand?

We will tell you what is in scope, what an assessor will accept, and what you do not need.