CV Courseversity

Responsible AI

A capstone survey of how organizations and governments manage AI risk, covering the NIST AI RMF and the EU AI Act and OECD AI Principles.

Managing AI Risk: The NIST AI Risk Management Framework · 15 min

By the time an AI system reaches production, an organization has already made hundreds of design, data, and deployment decisions that shape whether it will behave safely, fairly, and predictably in the real world. The United States National Institute of Standards and Technology released the AI Risk Management Framework, known as AI RMF 1.0, in January 2023 to give organizations a structured, voluntary way to think about those decisions. The framework is not a checklist or a certification scheme; it is explicitly voluntary and non-sector-specific, intended to help organizations of any size, in any industry, better manage risks to individuals, organizations, and society associated with artificial intelligence. Its stated aim is to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems throughout their lifecycle. Because AI risk cannot be reduced to a single number or a one-time audit, the framework treats risk management as an ongoing, iterative practice woven into an organization's culture rather than a gate passed once before launch.

The AI RMF organizes this practice around four core functions: Govern, Map, Measure, and Manage. Govern cultivates and implements a culture of risk management within organizations that design, develop, deploy, evaluate, or acquire AI systems, establishing the policies, processes, and accountability structures that make the other three functions possible; because it underlies all AI risk management activity, Govern is meant to be applied continuously and cross-cuts the entire framework rather than acting as a discrete first step. Map establishes the contextual understanding necessary to identify risks: it surfaces a system's intended purpose, its likely and potential impacts, its capabilities and limitations, and the benefits and risks associated with each stage of its lifecycle, so that an organization can make an informed decision about whether to proceed with design or deployment at all. Measure then employs quantitative, qualitative, or mixed-method tools, techniques, and methodologies to analyze, assess, benchmark, and monitor AI risk and related impacts, turning the contextual picture from Map into rigorous testing, evaluation, and ongoing tracking. Manage takes the outputs of Measure and allocates resources to identified risks on a regular basis, prioritizing response, treatment, and recovery plans so that an organization maximizes the benefits of an AI system while minimizing its negative impacts, both before deployment and continuously afterward.

Running through all four functions is a set of characteristics NIST associates with trustworthy AI: systems should be valid and reliable, meaning they perform accurately and consistently under expected conditions; safe, meaning they do not endanger human life, health, property, or the environment; and secure and resilient, meaning they maintain confidentiality, integrity, and availability while withstanding unexpected adverse events. Trustworthy systems should also be accountable and transparent, so that decision-making processes and outcomes are documented and appropriately accessible to those who need to understand them, and explainable and interpretable, so that their mechanisms and outputs can actually be understood by the operators and users who rely on them. Finally, NIST calls for AI systems to be privacy-enhanced, safeguarding human autonomy, identity, and dignity through privacy-respecting design choices, and fair with harmful bias managed, meaning systemic, computational, and human-cognitive sources of bias are actively identified and mitigated rather than assumed away. None of these characteristics stands alone: a system that is accurate but opaque, or secure but biased, still falls short of the trustworthiness the framework is designed to help organizations pursue, which is why Govern, Map, Measure, and Manage are meant to operate together rather than as a sequential checklist that ends once a product ships.

Regulating AI: The EU AI Act and the OECD AI Principles · 15 min

Voluntary frameworks like the NIST AI RMF describe how an organization can manage AI risk, but they do not compel it to do so; that is the role governments and international bodies play through law and formal agreement. The European Union has taken the most far-reaching legislative approach to date with the EU AI Act, widely described as the first comprehensive, horizontal law specifically regulating artificial intelligence. Rather than treating all AI systems the same way, the Act adopts a risk-tiered regulatory model that calibrates legal obligations to the level of risk a given AI use case poses to health, safety, and fundamental rights. This tiered structure lets regulators concentrate scrutiny where it matters most, imposing heavy obligations on systems that could cause serious harm while leaving low-stakes applications largely free of new red tape, an approach meant to protect people without freezing beneficial innovation in place.

The Act defines four risk levels. At the top, unacceptable-risk practices are banned outright from use in the EU because the harms they pose are considered incompatible with EU values; examples include AI used for cognitive manipulation, certain forms of predictive policing, emotion recognition in workplaces and schools, social scoring, and specified uses of real-time remote facial recognition by law enforcement. High-risk systems, such as AI used in medical diagnosis or autonomous driving, are not banned but must satisfy strict requirements before and after they reach the market, including rigorous testing, documentation, transparency, and human oversight. Limited-risk systems, such as chatbots, are subject to targeted transparency obligations, chiefly a requirement that people be informed when they are interacting with AI-generated content rather than a human. Minimal-or-no-risk systems, which the Act notes describes most AI applications in use today, such as AI-enabled video games or spam filters, remain unregulated by the Act's substantive rules; the framework separately addresses general-purpose AI models, applying lighter obligations to most of them and stricter obligations to the subset judged to pose systemic risk.

Years before the EU AI Act, the Organisation for Economic Co-operation and Development adopted the OECD AI Principles in May 2019, a set of intergovernmental standards on trustworthy AI that predate binding legislation in most jurisdictions and were updated in May 2024 to reflect subsequent technological and policy developments; the OECD describes them as the first intergovernmental standard on AI, and dozens of countries plus the European Union now adhere to them. Rather than setting hard legal tiers, the OECD Principles articulate five values-based commitments for responsible stewardship of AI: pursuing inclusive growth, sustainable development, and well-being so that AI's benefits are broadly shared; respecting human rights and democratic values, including fairness and privacy; ensuring transparency and explainability so that people can understand AI-informed outcomes; building robustness, security, and safety into systems throughout their lifecycle; and holding organizations and individuals accountable for the proper functioning of the AI systems they develop and deploy. Because the OECD's AI system definition and lifecycle framing were later incorporated into other major instruments, including EU and U.S. regulatory guidance, the Principles function less as a rival to laws like the EU AI Act and more as a shared vocabulary that different jurisdictions have built on when drafting their own binding rules, much as the voluntary NIST AI RMF gives organizations a common internal vocabulary for managing the risks those laws are designed to address.

Practice

Responsible AI: NIST, the EU AI Act, and the OECD

AI RMF Core Functions Govern Map Measure Manage

Govern cross-cuts all three others — the AI RMF treats risk management as continuous practice, not a one-time gate before launch.

  • The NIST AI RMF is explicitly voluntary and non-sector-specific — not a checklist or certification — designed to help any organization weave trustworthiness considerations into an AI system's design, development, use, and evaluation across its whole lifecycle.
  • The EU AI Act uses a risk-tiered model with four levels: unacceptable-risk practices (like social scoring or workplace emotion recognition) are banned outright; high-risk systems face strict pre- and post-market requirements; limited-risk systems get transparency obligations; minimal-risk systems — most AI in use today — stay unregulated by its substantive rules.
  • The OECD AI Principles (2019, updated 2024) predate binding legislation in most jurisdictions and function less as a rival to laws like the EU AI Act and more as a shared vocabulary — much like NIST's voluntary AI RMF gives organizations a common internal vocabulary for the risks those laws address.

Recall Practice

What the AI RMF isClick to reveal
What best describes the NIST AI Risk Management Framework (AI RMF 1.0), released January 2023?
A voluntary, non-sector-specific framework to help organizations of any kind better manage risks to individuals, organizations, and society associated with AI — not binding law, not a certification exam, and not specific to any one region.
Map's roleClick to reveal
Within the AI RMF's four core functions, which one establishes the contextual understanding needed to identify a system's intended purpose, capabilities, and potential impacts?
Map — it surfaces intended purpose, likely and potential impacts, capabilities and limitations, and lifecycle risks and benefits, enabling an informed decision about whether to proceed with design or deployment at all.
EU AI Act's tiersClick to reveal
How many risk levels does the EU AI Act define, and what happens to systems in the top tier?
Four levels: unacceptable, high, limited, and minimal-or-no risk. Unacceptable-risk systems — such as those used for social scoring or workplace/school emotion recognition — are banned outright from use in the EU.
OECD's five commitmentsClick to reveal
Name one of the OECD AI Principles' five core values-based commitments.
Any of: inclusive growth/sustainable development/well-being; human rights and democratic values (fairness, privacy); transparency and explainability; robustness, security, and safety throughout the lifecycle; or accountability for proper functioning.

Ready to test yourself?

5 questions on this module.

Start Quiz