AI Governance Frameworks

NIST AI RMF

NIST AI Risk Management Framework 1.0 (AI RMF)

The US government's voluntary framework for managing AI risk, built around four functions: Govern, Map, Measure, and Manage. Explained here as it applies to data privacy and everyday AI use at work.

United States (voluntary, used internationally)Voluntary framework, published January 2023; Generative AI Profile added July 2024Verified 2026-08-31

What it means for AI and data privacy

The NIST AI RMF is not a law, but it has become the reference point US and Canadian organizations are measured against when something goes wrong with AI: regulators, insurers, and enterprise customers all ask whether you followed it. For data privacy, its core demand is simple to state and hard to do: know where AI is used in your organization (Map), check what data flows into it (Measure), put controls on those flows (Manage), and make someone accountable for all of it (Govern). Shadow AI use, where employees paste confidential data into unapproved tools, is a direct failure of the Map and Manage functions.

Who it applies to

  • Any organization that designs, develops, deploys, or uses AI systems, in any sector
  • US federal agencies and contractors, where adoption is increasingly expected in procurement
  • Organizations answering security questionnaires or diligence requests that cite the framework
  • Canadian and international organizations using it as a de facto baseline in the absence of binding AI law

Enforcement and penalties

The framework itself carries no penalties: it is voluntary. Its teeth come from elsewhere. Regulators such as the FTC cite failure to manage known AI risks in enforcement actions, plaintiffs cite the framework as the standard of care in negligence claims, and cyber insurers and enterprise buyers increasingly condition coverage and contracts on alignment with it. Ignoring a free, public standard of care is difficult to defend after an incident.

Key provisions for AI and data privacy

Govern

Cultivate a risk-management culture with clear accountability

Govern is the cross-cutting function that makes the other three work: policies, roles, and accountability for AI risk have to exist before anyone can map or measure anything. It calls for documented AI policies, defined risk tolerance, clear ownership, and processes that keep working as tools and staff change.

For data privacy, Govern means someone owns the question of which AI tools employees may use and with what data. An organization where 63% is the norm (IBM found in 2025 that 63% of organizations have no AI governance policy) fails this function on day one. A written acceptable-use policy, an approved-tools list, and a named owner are the minimum evidence.

Map

Establish context and identify where AI touches your data

Map asks the organization to inventory its AI systems and understand the context each one operates in: what data goes in, who is affected, what could go wrong. You cannot manage a risk you have not located.

The hard part of Map in practice is not the AI you bought, it is the AI employees adopted on their own. Prompts to consumer chatbots are AI data flows like any other, and LayerX measured in 2025 that organizations have no insight into roughly 89% of AI usage. Mapping means discovering actual usage across the organization, not just listing sanctioned vendors.

Measure

Assess, analyze, and track AI risks with evidence

Measure turns the Map inventory into tracked, quantified risk: test systems, monitor them in use, and measure whether controls work. It explicitly covers privacy risk alongside safety, security, and bias.

For privacy, Measure means being able to answer with evidence: how often does confidential or personal data leave in prompts, of what types, to which tools? An organization that cannot produce those numbers is not measuring. Point-of-entry monitoring of prompts is what makes the answer verifiable rather than a guess.

Manage

Act on mapped and measured risks with real controls

Manage is where risk treatment happens: prioritize the risks surfaced by Map and Measure, apply controls proportionate to them, respond to incidents, and feed lessons back into governance.

For data flowing into AI tools, Manage means technical controls at the point of entry, not just policy documents. IBM's 2025 breach study found only 17% of organizations have technical controls that redact or block sensitive data at the point of entry, and that shadow AI involvement added an average of $670K to breach costs. Policy without enforcement is a documented risk you chose not to treat.

Practical compliance steps

  1. 1Name an owner for AI risk and publish an AI acceptable-use policy employees can actually follow
  2. 2Inventory real AI usage across the organization, including unapproved browser-based tools, not just procured systems
  3. 3Classify which data types must never enter external AI tools: client identifiers, health data, source code, financials
  4. 4Put a technical control at the point of entry that catches sensitive data in prompts before it leaves
  5. 5Track metrics on interceptions and tool usage so Measure has evidence instead of assumptions
  6. 6Review the inventory and policy on a schedule, and after any new tool or incident, closing the Govern loop

How Sanitized AI maps to this

Map

The extension shows administrators which AI tools employees actually use across the browser, turning shadow usage into an inventory the Map function can work with.

Measure

Dashboards report what categories of sensitive data were caught in prompts and how often, giving the Measure function evidence rather than survey answers.

Manage

Sensitive data in prompts is redacted before submission, which is exactly the point-of-entry technical control the Manage function calls for on data flows to external tools.

Govern

Usage and interception reporting gives the accountable owner ongoing evidence that the acceptable-use policy is followed, not just published.

Frequently asked questions

Is the NIST AI RMF mandatory?

No. It is a voluntary framework. But US federal agencies are directed toward it, procurement and security questionnaires increasingly cite it, and after an AI-related incident it functions as the standard of care you will be compared against. Voluntary describes the adoption, not the consequences of ignoring it.

What are the four functions of the NIST AI RMF?

Govern (policies, accountability, and culture for AI risk), Map (inventory AI systems and their context), Measure (assess and track the risks with evidence), and Manage (apply controls and respond). Govern is cross-cutting; the other three form the operational cycle.

How does the AI RMF apply to employees using ChatGPT or other chatbots?

Employee use of external AI tools is an AI data flow the framework expects you to map, measure, and manage like any other. Unapproved usage with confidential data is a live gap in all four functions: no governance covering it, unmapped usage, unmeasured data exposure, and no managing control at the point of entry.

Does the AI RMF cover generative AI specifically?

Yes. NIST published a Generative AI Profile (NIST AI 600-1) in July 2024 that applies the four functions to generative AI risks, including data leakage through prompts, confabulation, and information-security risks specific to large language models.

How is the NIST AI RMF different from ISO/IEC 42001?

The AI RMF is a free, voluntary US framework you align with; ISO/IEC 42001 is a certifiable international management-system standard you can be audited against. They cover similar ground and NIST publishes a crosswalk between them. Many organizations use the RMF to structure the work and ISO 42001 when a customer or regulator wants a certificate.

Primary sources

This guide summarizes the cited primary sources as of the verification date. It is general information, not legal advice.

The gap in every framework is the prompt box.

Sanitized AI catches sensitive data in prompts before it leaves and shows administrators which AI tools employees actually use.

Get a demo

Related standards