AI Disclosure: This news brief was drafted with AI assistance by Mentis Intelligence and reviewed by Zain Aamer, CEO of Bespoke Mentis, before publication. All regulatory and factual claims reference publicly available sources cited below.
NIST Releases Draft Update to AI Risk Management Framework, Opens 45-Day Comment Period
NIST’s draft AI RMF update targets generative AI and supply chain risks, inviting public feedback through July 9.
CEO, Bespoke Mentis · AI-assisted + reviewed before publication · AC11 Governed
Key Takeaway
NIST’s draft AI RMF update targets generative AI and supply chain risks, inviting public feedback through July 9.
Topics: NIST · AI Risk Management Framework · public comment
NIST has published a preliminary draft update to its AI Risk Management Framework (AI RMF), with a 45-day public comment window, to address new risks from generative AI and AI supply chain vulnerabilities NIST. This update is critical for regulated enterprises relying on AI in critical infrastructure and compliance-heavy sectors.
On May 24, 2024, the National Institute of Standards and Technology (NIST) released a draft update to its AI Risk Management Framework (AI RMF) and opened a 45-day public comment period ending July 9, 2024. The update specifically addresses emerging risks from generative AI systems and highlights vulnerabilities within AI supply chains, aiming to improve the security and resilience of AI deployments in sectors such as healthcare, finance, and critical infrastructure NIST TechCrunch.
The AI RMF is a voluntary guidance document widely referenced by U.S. enterprises and regulators to manage AI risks. This update is significant for organizations subject to regulatory oversight—such as HIPAA in healthcare, SEC rules in finance, and the EU AI Act for global operations—because it introduces new controls and best practices for generative AI, which has rapidly expanded in enterprise use cases. The draft also emphasizes the need for robust supply chain risk management, reflecting recent incidents where compromised AI components have led to security breaches and compliance failures NIST. NIST’s call for public input signals a move toward more inclusive, stakeholder-driven standards that could influence both U.S. and international regulatory expectations TechCrunch.
Enterprise CTOs, CISOs, and Compliance Officers should review the draft AI RMF update and prepare to submit feedback before July 9. Organizations should assess their current AI risk management practices, especially regarding generative AI and third-party AI components, to ensure alignment with the anticipated changes. Monitoring NIST’s final guidance will be essential, as the updated framework is likely to shape future regulatory audits, procurement requirements, and internal risk controls over the next 30-90 days NIST.
What This Means for Enterprise AI
NIST’s draft update directly impacts operational risk management for enterprises deploying generative AI, which is now explicitly addressed in the framework. For regulated sectors, this means new expectations for model transparency, data provenance, and monitoring of AI outputs to prevent compliance violations under HIPAA, SEC, and the EU AI Act NIST.
The new focus on AI supply chain vulnerabilities requires organizations to map and vet all third-party AI components, including open-source models and vendor APIs, for security and compliance risks. This aligns with recent SEC guidance on third-party risk and the EU AI Act’s requirements for supply chain due diligence TechCrunch.
Action items: Review the draft AI RMF update, identify gaps in current AI governance programs—especially around generative AI and supply chain security—and prepare to update internal policies once the final framework is released. Engage with NIST’s comment process to ensure your sector’s needs are represented, as this framework will likely become a de facto standard for regulatory compliance and vendor management in AI deployments NIST.
AI systems analyst and governance specialist at Bespoke Mentis. Covers enterprise AI compliance, regulated industry strategy, and the operational decisions that determine whether AI deployments succeed or fail audit.
This development affects your AI strategy.
Bespoke Mentis tracks every regulatory shift, enforcement action, and governance development so you can act before your competitors. Talk to us about what this means for your architecture.
