Skip to main content
    AI Policy Radar

    NIST AI RMF

    In the absence of a federal statute, the AI RMF is the closest thing to a US compliance baseline — several state laws grant affirmative defenses to companies aligned with it, effectively making a voluntary framework quasi-binding.

    What it is

    The voluntary US reference framework for AI risk management (Govern/Map/Measure/Manage), extended by a Generative AI Profile in 2024. Widely embedded in state laws (e.g., Colorado, Texas safe harbors reference it) and enterprise programs.

    Who is affected

    In the absence of a federal statute, the AI RMF is the closest thing to a US compliance baseline — several state laws grant affirmative defenses to companies aligned with it, effectively making a voluntary framework quasi-binding.

    Key obligations

    • Voluntary: risk governance structures, mapping, measurement and management of AI risks
    • Referenced as a safe harbor / defense in Colorado and Texas AI statutes

    Recent signals

    • 11 December 2025

      US executive order targets state AI laws for preemption

      EO 14365 creates a DOJ AI Litigation Task Force and funding levers against state AI regulation, setting up the defining federalism fight of US AI governance.

    • 23 July 2025

      White House releases America's AI Action Plan

      90+ actions across innovation, infrastructure and international leadership — including procurement rules for 'ideologically neutral' AI and full-stack export packages.

    • 19 May 2025

      US enacts TAKE IT DOWN Act on deepfake intimate imagery

      Rare bipartisan federal AI statute criminalizes non-consensual intimate deepfakes and mandates 48-hour platform takedowns.

    • 23 January 2025

      US revokes 2023 AI executive order, pivots to AI dominance agenda

      EO 14179 removes the safety-focused federal framework and directs the AI Action Plan, resetting US AI policy.