The updated NIST AI Risk Management Framework (AI RMF) gives organizations a structured way to identify, measure, and mitigate AI-related risks. It centers on four continuous actions—Govern, Map, Measure, Manage—and outlines seven qualities of trustworthy AI: reliability, safety, security, privacy, fairness, transparency, and accountability. NIST’s February 2025 update and its Generative AI Profile specifically address how large-language and image models should be monitored once deployed.
The framework is voluntary, but many regulators and investors already treat it as a baseline for credible AI operations. “The AI RMF provides a common language for managing risk—across industry sectors and international borders,” said Elham Tabassi, NIST’s Chief of Staff, in a 2025 briefing.
Action for companies:
While NIST guides internal control, the OECD/G7 Hiroshima AI Process (HAIP) Reporting Framework opens the curtain on external accountability. Launched in February 2025, it invites developers of advanced AI systems to publicly share how they manage safety, governance, and incident response. Nineteen companies participated in the first round of voluntary reports this spring.
The OECD says these submissions help regulators and peers learn what effective oversight looks like—creating comparability across industries.
Disclosures focus on:
Action for companies:
In January 2025, more than 100 experts from 30 countries released the International Scientific Report on the Safety of Advanced AI. The report, chaired by Yoshua Bengio, outlines three risk categories: malicious use (AI-driven cyber or disinformation attacks), malfunction or failure (unintended model behavior or misalignment), and systemic risk (job displacement, concentration of power, or uncontrollable system scaling).
The authors emphasize that while mitigation techniques exist—like red-teaming, model evaluation, and human oversight—research and verification still lag behind AI capabilities. This scientific consensus strengthens the argument for company-level readiness and scenario planning.
Action for companies:
- Expand risk reviews to include long-term societal or supply-chain impacts.
- Test AI systems under stress conditions and record outcomes.
- Integrate AI risk into enterprise risk management and sustainability reporting.
The convergence of these frameworks signals that AI trust will define competitiveness. Organizations that proactively govern, measure, and disclose their AI operations will attract partners, regulators, and customers seeking reliability.
What to do next:
As AI becomes the backbone of modern infrastructure, credible governance will be as vital as innovation itself. Those who lead with clarity and transparency today will define what “responsible AI” means tomorrow.