Agentshield

NIST AI RMF for AI Agents: How the Four Functions Map to Agent Controls

Dana Whitfield, Security·Jul 21, 2026·9 min read

Try it live

Watch Agentshield block an attack in real time.

Pick a scenario and drive the inspection lane yourself. No signup needed.

Threat Console
12,408 injections blocked this week

Run a request

Inspection lane

INSPECTING
untrusted input

Policy trace

High-risk action held for approval

Audit trail

The NIST AI Risk Management Framework applies to AI agents the same way it applies to any AI system: it gives you four functions to organize risk work, Govern, Map, Measure, and Manage, but it does not hand you a list of controls to install. For an autonomous agent, that means the framework tells you what outcomes to reach, least-privilege access, oversight of high-impact actions, monitoring, and traceable records, and leaves the runtime controls that achieve them to you. This article maps the four functions to concrete agent controls and is honest about where NIST has published agent-specific guidance and where it has not.

What the NIST AI RMF actually is

The framework is NIST AI 100-1, published January 26, 2023. NIST describes it as voluntary, rights-preserving, non-sector-specific, and use-case agnostic. It is outcome-based, not prescriptive: it will not tell you to require human approval on a wire transfer, but it will tell you to manage the risks you mapped and measured. In July 2024 NIST added the Generative AI Profile, NIST AI 600-1, which lists twelve categories of generative-AI risk and suggested actions. Neither document is a compliance mandate on its own; they are structures organizations adopt to demonstrate a defensible risk process.

Mapping the four functions to agent controls

An agent adds risk that a single-turn model does not have: it holds credentials, calls tools, remembers, and acts on text it read. Reading the four functions through that lens gives a clean mapping. Treat this as an honest alignment, the framework says align with these outcomes, not NIST requires this exact control.

NIST AI RMF functionWhat it asks forAgent runtime control that aligns
GovernA culture and policy for managing AI risk, with clear accountabilityWritten per-agent policy, distinct agent identity, and an audit trail that attributes every action
MapEstablish the context and enumerate where risk sits, including human-AI configurationInventory each agent's tools, data access, and autonomy level; decide which actions need a human
MeasureAnalyze, benchmark, and monitor AI risk over timeReal-time monitoring of every agent action and verdict, with the record to review trends
ManageAllocate resources to treat the risks you mapped and measuredLeast-privilege permissions, injection inspection, and approval gates enforced in the action path

The Measure function is worth calling out, because NIST's own description of it uses the word monitor. Continuous agent monitoring is not a nice-to-have if you are mapping to the RMF; it is close to a literal reading of the function. Likewise, Manage is where access control and enforcement live, because those are the treatments that actually reduce a mapped risk rather than just describe it.

What NIST has published for agents, and what it has not

Be careful here, because this is where claims get inflated. As of mid-2026, the only finalized generative-AI-specific NIST document is the July 2024 Generative AI Profile. NIST has agent-relevant work underway but not finalized: the Control Overlays for Securing AI Systems effort, a concept paper released August 14, 2025, explicitly scopes single- and multi-agent systems and will produce SP 800-53 control overlays, with drafts expected across late 2026 and 2027. There is also a broader AI standards initiative that began organizing in early 2026. None of that is a numbered, final agent standard yet.

One common error to avoid: the Agentic AI framework profile circulating in 2026 is from the Cloud Security Alliance, not from NIST. If a vendor tells you they are compliant with the NIST agentic profile, ask which document, because NIST has not published one under that name.

How to use the RMF for an agent program in practice

The framework is most useful as the spine of an evidence story. Because each of your controls produces its own record, you can map controls to functions and hand a reviewer the trail rather than a policy statement. That is the same operating discipline described in AI agent governance, with the RMF supplying the vocabulary a federal reviewer already knows. In regulated settings, the same mapping supports your broader AI compliance and government AI agent security work, since federal use of AI is governed more directly by the April 2025 OMB memos while the RMF supplies the risk structure underneath.

  1. Map first. Inventory every agent, its tools, its data reach, and its autonomy level. You cannot manage a risk you have not mapped.
  2. Scope least privilege. Grant each agent only what its task needs; this is your primary Manage treatment.
  3. Decide the human line. Identify high-impact actions and require approval on them, satisfying the human oversight the framework and OMB policy expect.
  4. Monitor and record. Stream every action to monitoring and write it to an immutable audit trail, covering Measure and the evidence Govern wants.
  5. Review on a cadence. Use the trail to reassess risk as agents gain new tools, closing the loop back to Map.

You do not meet the framework by writing a policy; you meet it by running controls that produce evidence. A compliance program that maps each control to the obligation it satisfies turns that evidence into an audit story, and the agent controls above are what generate it.

See the firewall block an attack live.

Drive the Threat Console and watch a real prompt injection get stopped, then put Agentshield in front of your own agents.

Open the console