Skip to main content
Bespoke Mentis

AI Disclosure: This news brief was drafted with AI assistance by Mentis Intelligence and reviewed by Zain Aamer, CEO of Bespoke Mentis, before publication. All regulatory and factual claims reference publicly available sources cited below.

News BriefCybersecurity 3 min read August 28, 2026 at 03:01 PM UTC Updated Aug 28, 2026

NIST Opens Public Comment on AI RMF Update, Targets GenAI & Supply Chain Risks

NIST’s draft update to the AI Risk Management Framework (AI RMF) is open for 45 days, focusing on generative AI and supply chain vulnerabilities.

Zain Aamer

CEO, Bespoke Mentis · AI-assisted + reviewed before publication · AC11 Governed

Key Takeaway

NIST’s draft update to the AI Risk Management Framework (AI RMF) is open for 45 days, focusing on generative AI and supply chain vulnerabilities.

Topics: NIST · AI Risk Management Framework · public comment

NIST has released a preliminary draft update to its AI Risk Management Framework (AI RMF) and is accepting public comments for 45 days, with a focus on addressing risks from generative AI and AI supply chain vulnerabilities NIST. Regulated enterprises must assess how these changes could impact their AI governance and compliance strategies.

NIST published the draft update to its AI RMF on June 10, 2024, launching a 45-day public comment period to solicit feedback from industry, academia, and the public NIST. The update specifically addresses new risks introduced by generative AI systems and highlights vulnerabilities in AI supply chains. The framework is intended for organizations designing, developing, deploying, or using AI systems, especially those in regulated sectors.

The draft update is significant for enterprise AI leaders in healthcare, finance, and other regulated industries because it directly addresses compliance with emerging AI regulations and standards. The framework’s expanded focus on generative AI aligns with recent regulatory scrutiny, including the EU AI Act’s requirements for high-risk AI systems and the SEC’s guidance on AI-related disclosures Tech Policy Journal. NIST’s emphasis on supply chain vulnerabilities echoes growing concerns about third-party risk management under NIST SP 800-53 and HIPAA Security Rule requirements NIST SP 800-53.

CTOs, CISOs, and Compliance Officers should review the draft AI RMF update and prepare to submit feedback before the 45-day window closes. Enterprises should evaluate their current AI risk management practices, especially regarding generative AI and third-party AI components, to ensure alignment with the evolving framework. Monitoring the finalization of the updated AI RMF will be critical for updating internal policies, risk assessments, and compliance documentation in Q3 2024.

What This Means for Enterprise AI

NIST’s draft update to the AI RMF introduces new expectations for managing risks associated with generative AI, including model hallucinations, data poisoning, and misuse scenarios. Enterprises deploying large language models or generative AI tools must reassess their risk controls and documentation to demonstrate compliance with both NIST and sector-specific regulations like HIPAA and the EU AI Act NIST.

The framework’s expanded focus on AI supply chain vulnerabilities requires organizations to scrutinize third-party AI vendors, model provenance, and software dependencies. This aligns with NIST SP 800-53’s supply chain risk management controls and may require updates to vendor risk assessments, contract language, and incident response plans NIST SP 800-53.

Action items for enterprise leaders: (1) Assign internal stakeholders to review the draft AI RMF and prepare formal comments; (2) Map current AI risk management practices to the updated framework, focusing on generative AI and supply chain controls; (3) Prepare to update compliance documentation and training once the final framework is released in late Q3 or early Q4 2024 Tech Policy Journal.

Share X / Twitter LinkedIn
ZA
Zain AamerMentis Intelligence

AI systems analyst and governance specialist at Bespoke Mentis. Covers enterprise AI compliance, regulated industry strategy, and the operational decisions that determine whether AI deployments succeed or fail audit.

View all articles· AC11 Governed · Reviewed before publication
Stay Informed on AI Governance

This development affects your AI strategy.

Bespoke Mentis tracks every regulatory shift, enforcement action, and governance development so you can act before your competitors. Talk to us about what this means for your architecture.