NIST AI RMF 1.0

NIST AI Risk Management
Framework Mapping

How A2A Infrastructure maps to the 4 core functions of the NIST AI Risk Management Framework. Runtime enforcement, not paper compliance.

NIST AI RMF: 4 Core Functions

The NIST AI Risk Management Framework organises AI risk into 4 functions. A2A Infrastructure maps to all 4.

GOVERN

Policies, roles, and accountability for AI risk management.

NIST RequiresA2A Delivers
Risk management policiesPipeline ground rules (immutable Layer 1 + editable Layer 3/4). Safety scenario templates.
Roles and responsibilitiesWorkspace RBAC: Architect (bypass scope), Expert (scoped), Observer (read-only). Team roles: Owner/Admin/Member/Viewer.
AccountabilityOCSF audit trail with actor identity. Approval workflow with approvedBy + timestamp.
Human oversightrequireApproval pipeline config. Article 14 approval/rejection with reason.

MAP

Identify, categorise, and understand AI systems and their risks.

NIST RequiresA2A Delivers
AI system registryPipelines (named, slugged, configurable). Per-pipeline firewall config, timeout, LLM provider.
Risk categorisationGate 2 LLM judge evaluates risk per action. Task severity field (low/medium/high/critical).
Threat identificationGate 1: 36+ denylist patterns. Gate 3: 5 behavioral attack patterns. Safety scenario cards.
Context mappingWorkspace scope manifest: which agents can do what. Device policies: per-device risk mode.

MEASURE

Quantitatively assess, track, and benchmark AI risks.

NIST RequiresA2A Delivers
Performance metricsGate-by-gate latency (ms). Block rate %. Daily evaluation volume chart. Safety doughnut breakdown.
Risk trackingOCSF audit trail with gate1/gate2/gate3/scope results per evaluation. Severity classification.
Anomaly detectionGate 3 behavioral: recon-escalation, exfiltration-sequence, brute-force, command-spam, credential-harvest.
Audit evidenceExport JSON (SIEM-ready) + CSV. Up to 5,000 events. SHA-256 content hash per record (tamper evidence).

MANAGE

Mitigate, monitor, and respond to identified AI risks.

NIST RequiresA2A Delivers
Risk mitigation4-gate safety shield: regex (<1μs) + LLM judge (your LLM latency) + behavioral analysis + scope enforcement.
Continuous monitoringReal-time webhooks (9 events). 23+ chat platform alerts. Dashboard with 30-day charts.
Incident responseKillswitch (device/site/global) with real task abort. Approval rejection with reason logging.
Data residencyBring your own LLM. Air-gapped deployment. Zero cloud dependency option.

US State AI Laws

Three major state AI laws took effect in 2026. A2A Infrastructure maps to all of them.

Colorado AI Act (SB 24-205)
Effective June 30, 2026
  • Reasonable care: Gate 2 evaluates every action for risk
  • Impact assessments: OCSF export for auditor review
  • Record-keeping: Immutable audit trail, 12-month retention
  • Risk management: 4-gate pipeline, behavioral detection
California SB 53 + SB 942
Effective January 1, 2026
  • SB 53 (Frontier AI): Risk frameworks via pipelines. Incident alerting via webhooks. Audit records.
  • SB 942 (Transparency): Gate reasoning in every OCSF event. Full breakdown per evaluation.
  • AB 2013: N/A (A2A evaluates actions, not training data)
Texas TRAIGA (HB 149)
Effective January 1, 2026
  • Deployer obligations: OCSF audit trail + real-time dashboard
  • Deceptive practices: Gate 2 evaluates intent + context
  • Safe harbour: Full audit trail provides evidence of reasonable care

HIPAA Compliance

A2A Infrastructure supports HIPAA-covered entities running AI agents that interact with Protected Health Information (PHI). Runtime safeguards, not checkbox compliance.

Privacy Rule
45 CFR Part 164 Subpart E
  • Minimum necessary: Workspace scope enforcement — agents only access data within their scope manifest
  • Audit trail: OCSF event log of every AI interaction with PHI — who, what, when, which pipeline
  • Access controls: RBAC roles (Architect/Expert/Observer) restrict agent permissions per workspace
  • Disclosure tracking: Gate 2 LLM judge evaluates every action for PHI exposure risk before execution
Security Rule
45 CFR Part 164 Subpart C
  • Administrative safeguards: 4-layer safety screening (regex + LLM judge + behavioral + scope). Ground rules per pipeline.
  • Technical safeguards: Gate 1 blocks credential exfiltration. Gate 3 detects behavioral attack patterns. Encrypted transport.
  • Physical safeguards: Air-gapped deployment option. Bring your own LLM — PHI never leaves your infrastructure.
  • Risk analysis: Per-task severity classification (low/medium/high/critical). Exportable audit for risk assessments.
Breach Notification
45 CFR Part 164 Subpart D
  • Real-time alerts: Webhook notifications (9 event types) — instant detection of blocked PHI access attempts
  • 23+ channels: Slack, Teams, PagerDuty, email — breach-relevant events routed to your incident response team
  • Audit export: JSON (SIEM-ready) + CSV export up to 5,000 events with SHA-256 tamper evidence
  • Killswitch: Emergency device/site/global shutdown — immediately halt all agent activity if breach suspected

Business Associate Agreement (BAA): Enterprise plan customers processing PHI can request a signed BAA. A2A Infrastructure acts as a Business Associate under HIPAA when processing evaluations containing PHI. Contact us to request a BAA.

EU + US. One platform.

A2A Infrastructure maps to EU AI Act, NIST AI RMF, Colorado AI Act, California SB 53/942, Texas TRAIGA, SOC 2, HIPAA, GDPR, PCI DSS, and ISO 27001. Runtime enforcement, not paper compliance.

Help

Help

Need help? Here are some quick links: