ApexClaw
HomeStandards › NIST AI RMF
Standards

NIST AI RMF is voluntary guidance that Texas law turned into an affirmative defence for AI governance.

Four functions — GOVERN, MAP, MEASURE, MANAGE — written for AI systems generally rather than for agents specifically. Under TRAIGA, effective 1 January 2026, compliance provides an affirmative defense, which gives a voluntary framework unusual weight.

Get an Agent Trust Gap Brief

A voluntary framework that became a legal defence

The Texas Responsible AI Governance Act (TRAIGA, HB 149), effective 1 January 2026, provides an affirmative defense for organisations that comply with the NIST AI RMF. A voluntary framework acquiring statutory weight is unusual, and it changes the calculus: adopting NIST AI RMF is no longer only a governance posture in Texas.

Verified 2026-08-06. Not legal advice — the scope and conditions of that defence are a question for counsel.

The four functions, read for agents

GOVERN

Roles, responsibilities, accountability. For agents this is the identity question: every agent needs a named accountable human, or the rest of the framework has nobody to attach to. Agent identity →

MAP

Context, capabilities, dependencies. For agents: the tool inventory and what each tool can reach. You cannot map an estate you have not discovered. MCP governance →

MEASURE

Traceability, monitoring, evaluation. MEASURE 2.8 on traceability is where execution receipts do structurally what logs approximate. Execution receipts →

MANAGE

Risk response, including MANAGE 2.2 and 2.4 on mechanisms to supersede or deactivate. That is the kill switch, and it has to be measured rather than asserted. Policy enforcement →

What NIST AI RMF is not

  • Not certifiable. There is no formal assessment process and no certificate. Anyone offering NIST AI RMF certification is selling something the framework does not define.
  • Not agent-specific. It was written for AI systems generally. Agentic behaviour — planning, memory, tool use, delegation — is covered only by extension.
  • Not a substitute for the EU AI Act. Different instruments, different force. NIST is voluntary guidance; the AI Act is binding law with penalties.

NIST's AI Resource Center hosts a community crosswalk pairing RMF subcategories with ISO/IEC 42001, which is the practical way to run both without duplicating work. The Cloud Security Alliance published agentic-specific guidance built on NIST standards in March 2026.

See the full control crosswalk

Common questions

Can you be certified against NIST AI RMF?

No. There is no certification body and no certificate. What exists is documented conformance evidence.

Why does it matter then?

Texas TRAIGA provides an affirmative defence for organisations complying with a recognised risk framework, which gives documented conformance direct legal value.

What are the four functions?

Govern, Map, Measure, Manage. Govern is the one most often skipped and the one that determines whether the rest holds.

How does it apply to agents specifically?

Map the action surface, measure refusals and incidents, manage through policy and caps, and govern by naming an accountable owner.

Is it enough on its own?

It is a structure, not a control set. It tells you what to have decided, not what to build.