Skip to content

AI agents · Governance

NIST AI RMF for AI agents: a practical crosswalk.

The NIST AI Risk Management Framework was written before AI agents went into production, but it applies to them well: Govern, Map, Measure and Manage still describe what a company has to do. What changes is the detail. An agent reads untrusted content, holds credentials and takes actions, so each function needs controls that a chatbot never did.

This guide shows how we apply the AI RMF to agents. Appropia has implemented OpenClaw since February 2026 and runs dozens of agents in production for several clients. The crosswalk below is our working interpretation, not a formal NIST mapping or a certification.

Talk to our team

The NIST AI RMF in one minute

  • AI RMF 1.0 was released on January 26, 2023. It is voluntary and applies to any organization that designs, deploys or uses AI.
  • It is organized in four functions: Govern (culture, policies, accountability), Map (context and risks of each system), Measure (testing and tracking those risks) and Manage (prioritizing and acting on them). Govern runs across the other three.
  • On July 26, 2024 NIST published the Generative AI Profile (NIST AI 600-1), which lists twelve risks specific to generative AI and suggested actions for each.
  • NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan, so expect updates.

Why agents need more than a chatbot policy

A chatbot answers; an agent acts. It reads email, documents and web pages that nobody vetted, it uses tools with real credentials, and it can work on a schedule without anyone watching. Three consequences matter for the AI RMF:

  • Prompt injection becomes an action risk, not just a content risk: a hidden instruction can end up executed with the agent's permissions.
  • The agent is part of your supply chain: third-party skills, connectors and models all run with its access.
  • Accountability has to name a person for each agent, because the agent itself cannot be accountable.

Of the twelve GenAI Profile risks, the ones that weigh most for agents are information security, data privacy, confabulation, human-AI configuration and value chain and component integration.

Crosswalk: AgenticOS controls by AI RMF function

These are the 25 controls of our public AgenticOS Security Framework, grouped by the AI RMF function they mostly support. Many controls support more than one function.

AI RMF functionWhat it asks for, for agentsAgenticOS controls
GovernAn inventory of agents, a named owner for each, written policies on what needs approval, and records kept as the law requires.HO-3 named owner · IA-1 identity per agent · SC-3 inventory of skills and connectors · HO-1 actions that require approval · LA-3 retention · IA-3 periodic permission reviews
MapThe context of each agent: which process, which data, which systems, which threats.DM-1 data classification · IS-3 no direct production access during the pilot · the eight threats of the framework (prompt injection, compromised skills, excessive agency, credential exposure, data leakage, memory poisoning, unbounded consumption, vulnerable software)
MeasureTests before production and evidence afterwards.TE-1 prompt-injection and permission-abuse tests · TE-2 quality evaluation with real cases · TE-3 re-review after changes and continuous evaluation · LA-1 logging of instruction, tools, data and result
ManageControls that reduce the risks found, and a way to respond when something fails.IA-2 least privilege · IS-1 and IS-2 isolation and allow-listed egress · SC-1 and SC-2 skill review and pinned versions · DM-2 rules on which model processes which data · DM-3 encryption, including memory · HO-2 approvals with context · LA-2 tamper-proof logs · OP-1 patching · OP-2 cost and rate limits · OP-3 alerts and tested shutdown · OP-4 rehearsed incident response

The full controls, with the maturity level at which each becomes required, are in the AgenticOS Security Framework.

What NIST is doing about agents in 2026

  • AI Agent Standards Initiative: launched by NIST's Center for AI Standards and Innovation (CAISI) on February 17, 2026, with three pillars: industry-led standards, open-source protocols for agents, and research on agent security and identity. It opened a request for information on AI agent security and a concept paper on AI agent identity and authorization.
  • Control overlays for securing AI systems (COSAiS): a NIST project that adapts SP 800-53 controls to AI. Its concept paper (August 14, 2025) includes use cases for single-agent and multi-agent systems. If your company already runs an SP 800-53 program, these overlays are the natural bridge for agents once published.

None of this replaces the AI RMF. It adds detail where agents differ from other AI systems.

How to start

  • Inventory: list every agent, its owner, its tools and the data it touches. Include the ones teams built on their own.
  • Tier by actions, not by model: an agent that can pay, send to clients or change production is high risk, whatever model it uses.
  • Pilot at level 1 of our framework: one process, limited data, an isolated environment, human approval on everything and basic logging.
  • Measure against a baseline and widen permissions only with evidence.

A note for Canada

Canada has no federal AI statute in force: the proposed Artificial Intelligence and Data Act died when Parliament was prorogued in January 2025. PIPEDA governs personal data and Quebec's Law 25 sets rules for automated decisions. Many Canadian companies use the NIST AI RMF as a practical reference for the rest. This is context, not legal advice.

Frequently asked questions

Does the NIST AI RMF cover AI agents?+

It covers any AI system, agents included, but it was written before agents went into production. You apply its four functions with agent-specific controls: identity, least privilege, isolation, human approval and logging.

Is the NIST AI RMF mandatory?+

No. It is voluntary. Companies use it as a reference for governance, and customers or regulators may ask how you align with it.

Is there a NIST standard specifically for AI agents?+

Not yet as a final document. In 2026 NIST launched the AI Agent Standards Initiative and is developing SP 800-53 control overlays that include single-agent and multi-agent use cases.

Is your crosswalk an official NIST mapping?+

No. It is our working interpretation of how the AgenticOS Security Framework supports each AI RMF function. It is not a certification or a formal mapping.

Where should we start?+

With an inventory of agents and owners, then a controlled pilot on one process with human approval on every action.

Keep reading

Sources

Information as of October 5, 2026.

Talk to our team

Want to review your agents against the AI RMF?

WhatsApp
WhatsAppTalk to us