NIST AI Risk Management
Framework Mapping
How A2A Infrastructure maps to the 4 core functions of the NIST AI Risk Management Framework. Runtime enforcement, not paper compliance.
NIST AI RMF: 4 Core Functions
The NIST AI Risk Management Framework organises AI risk into 4 functions. A2A Infrastructure maps to all 4.
GOVERN
Policies, roles, and accountability for AI risk management.
| NIST Requires | A2A Delivers |
|---|---|
| Risk management policies | Pipeline ground rules (immutable Layer 1 + editable Layer 3/4). Safety scenario templates. |
| Roles and responsibilities | Workspace RBAC: Architect (bypass scope), Expert (scoped), Observer (read-only). Team roles: Owner/Admin/Member/Viewer. |
| Accountability | OCSF audit trail with actor identity. Approval workflow with approvedBy + timestamp. |
| Human oversight | requireApproval pipeline config. Article 14 approval/rejection with reason. |
MAP
Identify, categorise, and understand AI systems and their risks.
| NIST Requires | A2A Delivers |
|---|---|
| AI system registry | Pipelines (named, slugged, configurable). Per-pipeline firewall config, timeout, LLM provider. |
| Risk categorisation | Gate 2 LLM judge evaluates risk per action. Task severity field (low/medium/high/critical). |
| Threat identification | Gate 1: 36+ denylist patterns. Gate 3: 5 behavioral attack patterns. Safety scenario cards. |
| Context mapping | Workspace scope manifest: which agents can do what. Device policies: per-device risk mode. |
MEASURE
Quantitatively assess, track, and benchmark AI risks.
| NIST Requires | A2A Delivers |
|---|---|
| Performance metrics | Gate-by-gate latency (ms). Block rate %. Daily evaluation volume chart. Safety doughnut breakdown. |
| Risk tracking | OCSF audit trail with gate1/gate2/gate3/scope results per evaluation. Severity classification. |
| Anomaly detection | Gate 3 behavioral: recon-escalation, exfiltration-sequence, brute-force, command-spam, credential-harvest. |
| Audit evidence | Export JSON (SIEM-ready) + CSV. Up to 5,000 events. SHA-256 content hash per record (tamper evidence). |
MANAGE
Mitigate, monitor, and respond to identified AI risks.
| NIST Requires | A2A Delivers |
|---|---|
| Risk mitigation | 4-gate safety shield: regex (<1μs) + LLM judge (your LLM latency) + behavioral analysis + scope enforcement. |
| Continuous monitoring | Real-time webhooks (9 events). 23+ chat platform alerts. Dashboard with 30-day charts. |
| Incident response | Killswitch (device/site/global) with real task abort. Approval rejection with reason logging. |
| Data residency | Bring your own LLM. Air-gapped deployment. Zero cloud dependency option. |
US State AI Laws
Three major state AI laws took effect in 2026. A2A Infrastructure maps to all of them.
Colorado AI Act (SB 24-205)
Effective June 30, 2026- Reasonable care: Gate 2 evaluates every action for risk
- Impact assessments: OCSF export for auditor review
- Record-keeping: Immutable audit trail, 12-month retention
- Risk management: 4-gate pipeline, behavioral detection
California SB 53 + SB 942
Effective January 1, 2026- SB 53 (Frontier AI): Risk frameworks via pipelines. Incident alerting via webhooks. Audit records.
- SB 942 (Transparency): Gate reasoning in every OCSF event. Full breakdown per evaluation.
- AB 2013: N/A (A2A evaluates actions, not training data)
Texas TRAIGA (HB 149)
Effective January 1, 2026- Deployer obligations: OCSF audit trail + real-time dashboard
- Deceptive practices: Gate 2 evaluates intent + context
- Safe harbour: Full audit trail provides evidence of reasonable care
HIPAA Compliance
A2A Infrastructure supports HIPAA-covered entities running AI agents that interact with Protected Health Information (PHI). Runtime safeguards, not checkbox compliance.
Privacy Rule
45 CFR Part 164 Subpart E- Minimum necessary: Workspace scope enforcement — agents only access data within their scope manifest
- Audit trail: OCSF event log of every AI interaction with PHI — who, what, when, which pipeline
- Access controls: RBAC roles (Architect/Expert/Observer) restrict agent permissions per workspace
- Disclosure tracking: Gate 2 LLM judge evaluates every action for PHI exposure risk before execution
Security Rule
45 CFR Part 164 Subpart C- Administrative safeguards: 4-layer safety screening (regex + LLM judge + behavioral + scope). Ground rules per pipeline.
- Technical safeguards: Gate 1 blocks credential exfiltration. Gate 3 detects behavioral attack patterns. Encrypted transport.
- Physical safeguards: Air-gapped deployment option. Bring your own LLM — PHI never leaves your infrastructure.
- Risk analysis: Per-task severity classification (low/medium/high/critical). Exportable audit for risk assessments.
Breach Notification
45 CFR Part 164 Subpart D- Real-time alerts: Webhook notifications (9 event types) — instant detection of blocked PHI access attempts
- 23+ channels: Slack, Teams, PagerDuty, email — breach-relevant events routed to your incident response team
- Audit export: JSON (SIEM-ready) + CSV export up to 5,000 events with SHA-256 tamper evidence
- Killswitch: Emergency device/site/global shutdown — immediately halt all agent activity if breach suspected
Business Associate Agreement (BAA): Enterprise plan customers processing PHI can request a signed BAA. A2A Infrastructure acts as a Business Associate under HIPAA when processing evaluations containing PHI. Contact us to request a BAA.
EU + US. One platform.
A2A Infrastructure maps to EU AI Act, NIST AI RMF, Colorado AI Act, California SB 53/942, Texas TRAIGA, SOC 2, HIPAA, GDPR, PCI DSS, and ISO 27001. Runtime enforcement, not paper compliance.