Skip to main content
v2026.11,610 entries · CC-BY 4.0

The NIST AI Risk Management Framework: What It Means for Research Institutions

A plain explanation of NIST AI RMF 1.0 — its four core functions, why research institutions are building policy around it, and how its Measure function connects to content-provenance and AI-text detection in an academic-integrity context.

Ask about The NIST AI Risk Management Framework: What It Means for Research Institutions

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

If you have been asked to draft — or comply with — your institution’s AI-use policy, there is a good chance someone in the room said “just reference the NIST framework.” That framework is the NIST AI Risk Management Framework (AI RMF 1.0), and it is worth understanding on its own terms before you write a single line of institutional policy against it. It is not a regulation, it does not mention research misconduct or plagiarism, and it is not, at its core, “about” detecting AI-generated text. This guide walks through what it actually says, why research institutions specifically have started building policy around it, and where one narrow but genuinely relevant piece of it — content provenance and misuse detection — connects to a real, if limited, category of tooling.

What Is the NIST AI Risk Management Framework (AI RMF 1.0)?

The NIST AI Risk Management Framework (AI RMF 1.0, published as NIST AI 100-1 in January 2023) is a voluntary, cross-sector framework for identifying, assessing, and managing risk across an AI system’s lifecycle. NIST — the National Institute of Standards and Technology, a non-regulatory agency of the US Department of Commerce — has no statutory authority to require anyone to adopt it. There is no certification, no audit, no fine for non-adoption. It is best understood as a shared vocabulary and process structure: a way for very different organizations (a hospital, a bank, a university research office, a defense contractor) to talk about AI risk using the same four buckets, without NIST prescribing exactly what any one of them must do inside those buckets.

In 2024, NIST published a companion Generative AI Profile (NIST AI 600-1) that maps the same four functions onto risks specific to generative and foundation models — confabulation (what most people call hallucination), training-data privacy exposure, harmful bias amplification, and intellectual-property questions around training data and outputs. If your institution is writing policy that touches generative AI specifically (chatbots, drafting assistants, code generation), the Generative AI Profile is the more directly applicable document; the base AI RMF is the structure it sits inside.

NIST has also published a crosswalk mapping the RMF’s four functions onto ISO/IEC 42001, the certifiable AI management-system standard released the same year. That distinction matters for a policy-drafting audience: AI RMF is guidance with no certification mechanism attached, while ISO/IEC 42001 is a standard an organization can actually be audited and certified against. Institutions sometimes use the RMF as the internal thinking framework and reach for ISO/IEC 42001 only if they need a certifiable claim to make externally (to a sponsor, a partner, or a regulator).

The Four Core Functions: Govern, Map, Measure, Manage

The AI RMF organizes everything around four functions, meant to operate continuously and iteratively rather than as a one-time checklist:

  • Govern — the cross-cutting function that touches the other three: organizational culture, roles and accountability, policies, and processes for managing AI risk across the institution as a whole, not system-by-system. In a university context, this is where an AI-use policy itself lives — who owns it, who can approve a new AI tool for institutional use, how exceptions get handled.
  • Map — establishing context for a specific AI system or use case: what it’s actually for, who is affected by it, what could plausibly go wrong given that specific context. A grant-writing assistant, a plagiarism screen, and a lab-scheduling chatbot map to very different risk profiles even though all three are “AI.”
  • Measure — analyzing, assessing, benchmarking, and tracking the risks identified in Map, using quantitative, qualitative, or mixed methods. This is the testing-and-metrics function: does the system actually behave the way it’s supposed to, and how do you know.
  • Manage — allocating resources to treat the risks that Map and Measure surfaced: prioritizing them, responding to incidents, deciding what residual risk is acceptable and what isn’t.

A companion Playbook (also published by NIST) attaches concrete suggested actions to each function’s sub-categories — it is the “here’s what doing this might actually look like” document, as distinct from the framework document itself, which stays deliberately abstract.

Why Research Institutions Are Adopting NIST AI RMF

None of this is research-specific — NIST wrote the RMF for any organization deploying or affected by AI, from banks to retailers. So why are research administrators specifically the ones being handed this framework and told to build policy around it? A few real, converging reasons:

It’s the default reference point, not a research-specific mandate. Be direct about the regulatory status here, because it’s easy to overstate: the AI RMF has always been voluntary. Executive Order 14110 (October 2023) briefly gave it more teeth by directing federal agencies to adopt RMF-aligned practices internally and requiring the largest model developers to report certain safety test results. EO 14110 was revoked on January 20, 2025 (EO 14148) and replaced three days later by EO 14179, “Removing Barriers to American Leadership in Artificial Intelligence,” which carries no equivalent reporting mandate. As things stand, there is no active executive order requiring federal agencies — let alone their grant recipients — to use the AI RMF. If a colleague tells you federal funding is conditioned on AI RMF compliance, that is not accurate as a blanket statement; check the specific funding announcement or agency guidance rather than assuming a government-wide rule.

What is real: agencies increasingly govern their own AI use this way, and that shapes expectations for the institutions they fund. Federal agencies’ own internal AI governance — how they evaluate systems, what “responsible AI use” is understood to mean in official guidance — has continued to draw on the RMF’s four-function structure even after EO 14110’s specific mandate lapsed. When a program officer or agency guidance document references “responsible AI practices” without spelling out a bespoke framework, the RMF is very often the implicit reference, because it’s the framework the agency itself is oriented around.

It runs alongside, and increasingly overlaps with, research security. The federal research-security apparatus that has grown up under National Security Presidential Memorandum 33 (NSPM-33) — see CASRAI’s guide to NSPM-33’s four required program elements — already requires institutions receiving federal research funding to run formal research-security programs, with disclosure and foreign-influence-screening obligations. AI tooling now sits inside that scope in practice: an institution assessing “what could go wrong with the AI systems our researchers use” and an institution assessing “what could go wrong with foreign access to our research” increasingly share the same compliance office, the same risk register, and — practically — the same instinct to reach for the RMF’s vocabulary for the AI slice of that work, even though NSPM-33 itself doesn’t name the RMF.

It’s simply the best available public document to write policy against. Most research institutions writing an internal AI-use policy in 2026 are not doing so because a specific clause requires it — they’re doing it because faculty, students, and staff are already using generative AI tools, someone has to say what’s permitted, and the AI RMF is a free, well-documented, broadly credible structure to hang that policy on rather than inventing a taxonomy from scratch. That is a real and sufficient reason to learn it well, distinct from (and more honest than) a claim that adoption is externally mandated.

How AI RMF’s Measure Function Applies to Research Integrity and Content Provenance

Of the four functions, Measure is the one with the most direct line to a research-integrity office’s day-to-day work. Measure is where a system’s actual behavior gets tested against what it’s supposed to do — and one of the risk categories NIST’s Generative AI Profile explicitly calls out under Measure is content provenance and the authenticity of AI-generated or AI-modified content: can you tell where a piece of content came from, and can you detect when generative AI produced or altered it.

For a research institution, that abstract requirement has a concrete, everyday shape: verifying that AI-generated text isn’t miscredited as a researcher’s own original work in a grant proposal, a manuscript, or a research output more broadly. That’s not a hypothetical edge case — CASRAI has covered the growing footprint of AI-text screening at scholarly publishers directly (see AI detection tools adoption in academic publishing) and the mechanics of what a detector score does and doesn’t mean for a flagged submission (see Turnitin AI detection: how it works and what a score actually means). Content-provenance and misuse-detection tooling is a real, named piece of the Measure function’s scope — not an add-on someone bolted onto the RMF after the fact.

This is the point where a specific tool becomes relevant to mention rather than abstract. Pangram is an AI-text detector built specifically for academic-integrity use cases — screening submissions for AI-generated prose so an institution can catch miscredited authorship before it reaches a grant reviewer, a journal editor, or a degree committee. If your institution’s AI-use policy has a “how do we verify authenticity of submitted work” gap under its Measure section, a tool in this category is one honest way to operationalize that specific sub-requirement.

Editorial disclosure: Some links on this page are CASRAI referral links. If you sign up through one, CASRAI may earn a commission at no extra cost to you — this helps fund our nonprofit mission. We only recommend tools our editorial team has independently researched, and we say plainly where a tool is not the right fit. Read our full disclosure policy →

Tip: try code CASRAI at checkout for 15% off, if the offer is currently active for this program — codes vary by vendor and aren’t guaranteed.

See how Pangram screens for AI-generated text →

The Honest Limit: What NIST AI RMF Is Not About

Say this plainly, because it’s the single most important caveat on this page: the NIST AI Risk Management Framework is not, in any real sense, “about” AI-text detection. It is a broad, voluntary, institution-wide governance framework meant to cover the full surface of AI risk — algorithmic bias, safety failures, security vulnerabilities in AI systems themselves, third-party and vendor AI risk, fairness and equity harms, environmental cost, and a great deal more, spanning all four functions across every AI system an institution touches. Content provenance and misuse detection is one risk category, inside one sub-category, inside one of four functions.

Adopting the AI RMF does not require an institution to buy, deploy, or even consider a text detector. Plenty of institutions build a complete, defensible AI-use policy under the RMF’s Govern/Map/Measure/Manage structure without touching AI-text detection at all — because their Measure priorities, once they actually map their own AI use cases, turn out to be about model-vendor risk, data-privacy exposure in a chatbot, or algorithmic bias in an admissions or hiring tool instead. If you take one thing from this page for your own policy work, take this: use the RMF to think about the whole surface of your institution’s AI risk first, and let content-provenance tooling fall out as one answer to one narrow question within that — not the other way around.

FAQ

Is NIST AI RMF mandatory for federally funded research?

No. It has always been voluntary — NIST has no statutory authority to mandate it. Executive Order 14110 (October 2023) directed federal agencies to align their own internal practices with it, but that order was revoked in January 2025 and replaced with one (EO 14179) that carries no equivalent requirement. As of today, no government-wide rule conditions federal research funding on AI RMF compliance. Some specific funding announcements or agency AI-governance guidance may reference it — check the actual award terms and current agency guidance for your specific funder rather than assuming a blanket mandate.

How does AI-generated content detection fit into an institutional AI risk framework?

It sits inside the Measure function, specifically under content provenance and authenticity — one risk category among many the RMF’s Generative AI Profile identifies. It is a legitimate, named piece of the framework, but a narrow one: most of Measure, and all of Govern, Map, and Manage, cover ground that has nothing to do with detecting AI-written text.

What’s the difference between NIST AI RMF and a university’s own AI-use policy?

The RMF is a general-purpose external framework — a shared vocabulary and process structure any organization can use to think through AI risk. A university’s AI-use policy is the institution’s own document: what tools are approved, who can use them for what, disclosure requirements for coursework or research outputs, and who owns exceptions. Many institutions write their policy using the RMF’s four functions as the organizing structure, but the policy itself is always the institution’s own decisions layered on top of that structure — the RMF doesn’t hand you the policy, only the scaffolding to build one.

Where This Leaves a Research Administrator

If you’re building or reviewing an institutional AI-use policy, the RMF’s four functions are a genuinely useful structure to organize that work around — start with Govern (who owns this and how are exceptions handled), work through Map (what are our actual AI use cases), and let Measure and Manage follow from what Map turns up, rather than starting from a tool and working backward. When content authenticity turns out to be a real gap in your Measure work — and for institutions handling grant proposals, manuscripts, and student work at any scale, it usually is somewhere in the mix — that’s the point to look at dedicated tooling rather than the starting point for the whole policy.

Explore Pangram for academic-integrity screening →

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.