NIST Starts an AI RMF Profile for Critical Infrastructure — Concept Note, Not a Mandate
NIST’s April 7 concept note launches work on an AI RMF Profile for Trustworthy AI in Critical Infrastructure — sector-specific practices for CI operators across IT/OT/ICS and supply-chain trustworthiness communication. Voluntary framework extension; Community of Interest for feedback — not a binding rule.

General AI RMF guidance is deliberately abstract. This concept note’s frame: translate trustworthiness into operator- and vendor-speak for the 16 CI sectors — energy, water, transport, healthcare, and the rest — where AI failure modes hit safety, not just brand risk.
NIST (April 7) released a concept note to develop an AI Risk Management Framework Profile on Trustworthy AI in Critical Infrastructure. Aims: actionable practices for CI operators adopting AI across IT, OT, and ICS; help operators state trustworthiness requirements to developers/vendors across AI and CI lifecycles/supply chains; support innovative risk-managed solutions. Ties to NIST’s Strategy for American Technology Leadership. Community of Interest for seminars, working sessions, RFIs — open to the CI ecosystem.
What it is / isn’t
| Is | Isn’t |
|---|---|
| Profile development kickoff under AI RMF | Finished mandatory standard |
| Sector-aware risk practices + supply-chain communication | Prescriptive model whitelist |
| Voluntary engagement path | Enforcement action |
Claims vs checks
Scope and process are NIST primary. Whether the eventual profile is “practical and widely adopted” is aspirational — success depends on later drafts and operator uptake, not the concept note.
Limits
- Concept stage — requirements not frozen.
- Voluntary NIST profiles lack statutory teeth unless agencies later incorporate them.
- CI heterogeneity (16 sectors) makes one profile’s depth a standing design tension.
Sources
- NIST: “Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure” (April 7, 2026).
- NIST AI RMF page updates referencing the April 7 release.