Overview
Severity: MEDIUM | Affected: NIST | Category: policy
The U.S. National Institute of Standards and Technology (NIST) has published the finalized version of its AI Risk Management Framework (AI-RMF) 2.0. This significant update introduces legally binding requirements for federal agencies and contractors deploying AI systems in critical infrastructure sectors such as energy, finance, and healthcare. A key mandate is the implementation of continuous, documented red teaming exercises to proactively identify and mitigate security and safety vulnerabilities. The framework requires organizations to test their AI systems against a range of threats, including adversarial attacks, data poisoning, and model evasion. AI-RMF 2.0 aims to standardize security and safety practices, moving beyond voluntary guidelines to establish a robust baseline for trustworthy AI in high-stakes applications. Compliance will be phased in over the next 18 months, with the goal of enhancing the resilience of the nation's most vital services against sophisticated AI-specific threats.