The RMF in the wild: legal life, critiques, and the revision
Lesson 5 of 5 in NIST AI RMF Deep Dive: Govern, Map, Measure, Manage.
Follow the RMF out of the PDF and into practice, and you find it doing four distinct legal jobs:
1. Statutory defense. Texas TRAIGA (effective January 2026) gives defendants a defense against enforcement where they substantially comply with the NIST AI RMF — a voluntary framework converted into a liability shield by a single legislative sentence. Colorado’s original SB 24-205 named the RMF (alongside ISO 42001) as the benchmark for deployer risk management programs before that act was repealed and replaced in May 2026; the pattern it set still circulates in statehouse drafting.
2. Procurement gate. Federal agencies buying AI under OMB’s M-25-22 regime, and a growing share of private enterprise contracts, ask vendors to evidence RMF-aligned risk management. No certificate exists, so the evidence is the artifacts themselves: profiles, impact assessments, TEVV results, monitoring plans.
3. Reasonableness benchmark. When the FTC asks whether a company’s AI deployment was unfair — or a plaintiff asks whether it was negligent — the practical question becomes “what would a reasonable organization have done?” A published, consensus-built, government-authored framework is the most citable answer available. Documented RMF alignment is exculpatory; a documented decision to skip it can be damning.
4. Common language. When a deployer asks a developer “what did you test?”, the RMF gives both sides shared nouns. Vendor questionnaires, model cards, and audit scopes across the US industry are quietly organized around its categories.
Critique: “Voluntary means toothless”
Half right. Nothing forces adoption, and surveys consistently find implementation shallowest where risk is highest — small vendors shipping consequential systems. But the borrowing mechanism (statutes, procurement, reasonableness) means the market enforces what NIST cannot. The honest version of the critique: the RMF binds exactly those organizations already inclined to behave, unless a contract or a statute extends its reach.
Critique: “It never tells you how much is enough”
True, and by design. The RMF specifies no thresholds — no maximum error rate, no minimum fairness metric, no required test suite. NIST’s position is that thresholds are context-dependent and belong to those accountable for the context. The cost of that position: two organizations can both claim RMF alignment while doing wildly different amounts of work, and “substantial compliance” in statutes like TRAIGA inherits the ambiguity. Expect litigation to sharpen it.
Critique: “It is a big-company framework”
The 72 subcategories assume staff that a 20-person startup does not have. NIST’s answer is proportionality — profiles let you scale depth to risk — but the resource asymmetry is real: the fixed cost of standing up GOVERN falls hardest on the smallest players, which can entrench incumbents. Watch this argument reappear in every state-law fight about small-business exemptions.
Critique: “Process is not outcome”
The deepest objection: an organization can execute every function, produce beautiful documentation, and still ship a harmful system — the RMF audits the quality of your deciding, not the decision. Defenders answer that in a domain with no consensus outcome metrics, disciplined process is the best available proxy, and that documented process at least creates accountability when outcomes fail. Both things are true; hold them together.
Tool: Lifecycle Governance Simulator — Walk a system through Map → Measure → Manage yourself: pick a use case, set context, choose metrics and treatments, and get scored against the seven trustworthiness characteristics.
Interactive checkpoint quiz (1 questions) — open this page in a browser to take it.