Nist Ai Rmf
Go deeperRead the long-form companion article: Nist Ai Rmf →The United States does not really have an AI law yet, and in the meantime a voluntary framework is doing most of the work.
In early 2023, the National Institute of Standards and Technology released a document called the AI Risk Management Framework. It does not carry the force of regulation. No company has to follow it. It does not come with fines. What it is, instead, is a carefully negotiated description of how to think about AI risks across a full lifecycle, from the first scoping of a system to its eventual retirement. The framework names four big functions that a responsible deployer is supposed to perform, governing, mapping, measuring, and managing, and it unpacks each of them into a set of practices. It is the kind of document that looks bureaucratic from a distance and turns out, up close, to be quite thoughtful.
The trouble with a voluntary framework is exactly what you would expect. The organisations that were already going to take AI risk seriously adopt it enthusiastically and align their internal processes to it. The organisations that were going to cut corners find it easy to ignore, or to claim alignment without actually doing the work. Since there is no regulator checking, the claim of alignment is nearly indistinguishable from the reality of alignment, and both are indistinguishable from pure marketing. The framework is better than nothing, and for a lot of American education technology it is the single most influential reference point on how to do AI responsibly. Whether that adds up to actual safety depends entirely on the organisation, and the public has no way to tell from the outside. When you use a piece of AI from a company that says it follows a framework, how much does that claim actually reassure you?
Last week we looked at a global agreement on AI ethics. This week we look at the voluntary American framework that is doing most of the practical work in the absence of a law.