NIST AI RMF mapping for agents
A worked mapping of the AI RMF functions onto agentic architectures — what each requires when the system acts rather than predicts.
Why it exists
The AI RMF is written for AI systems broadly. Agents stress specific subcategories far harder than others, and teams waste months treating all of it as equally applicable.
What it contains
Govern — accountability for autonomous action, and where the human owner of an agent is recorded
Map — context and intended use when the system composes its own steps at runtime
Measure — what to evaluate when behaviour is emergent and provider-version dependent
Manage — response, containment and rollback for an action that has already taken effect
Per-subcategory notes on which are load-bearing for agents and which are near-inert
Status
The full reference document is being prepared for publication. If you want it as soon as it is out — or want to review a draft and push back on it — say so and I will send it.
Want this applied to your architecture?
The artifacts are general by design. Applying one to a specific estate is what the governance review does.