app.cubelet.ai← cubelet.ai
GRID42INTELLIGENCE TRACKERAI governance · compliance · regulatory signals
← All digests

NIST AI RMF

2026-09-16
Today · AI GOVERNANCE RMF

FDA is actively developing regulatory frameworks for generative AI in medical devices, addressing non-deterministic behavior and post-market monitoring challenges. NIST's updated governance standards, particularly the new Govern function in CSF 2.0, establish foundational organizational context that AI governance frameworks must build upon.

  • FDA Regulatory Framework for Generative AI in Medical Devices: Practitioners in high-risk healthcare domains must understand FDA's emerging requirements for non-deterministic AI behavior, post-market surveillance, and device validation in regulated environments.
  • NIST CSF 2.0 Govern Function as AI Governance Foundation: The new Govern function establishes organizational governance structures and risk management context that must underpin enterprise AI governance frameworks and compliance programs.
  • Core AI Risk Framework Components Standardization: Understanding foundational RMF elements—structure, process, accountability, measurement, and documentation—is essential for practitioners designing or implementing organizational AI governance programs.

Review NIST CSF 2.0's Govern function immediately to ensure your AI governance framework aligns with updated foundational standards, and monitor FDA guidance on generative AI in medical devices if your organization operates in regulated healthcare sectors.

Signals in this digest
What is an AI Risk Framework? | Airia

An AI risk framework is a comprehensive methodology for managing AI-related risks across the enterprise. It provides: Structure: A systematic way to categorize and assess AI risks Process: Defined procedures for identifying, evaluating, and addressing risks Accountability: Clear ownership of risk management responsibilities Measurement: Metrics and indicators that track risk posture over time Documentation: Evidence that risks are being actively managed [...] An AI risk framework is a stru

Generative AI Is Coming to Medical Devices. FDA Is Already Thinking About What Comes Next.

Imagine a medical device that can answer questions, summarize patient records, suggest next steps, and interact with users through a conversation that feels natural. Now imagine that the device does not always provide the same response twice and may continue changing after it reaches the market through software updates....<BR />By: <a href="https://www.jdsupra.com/profile/Womble_Bond_Dickinson/">Womble Bond Dickinson</a>

NIST Cybersecurity Framework - Wikipedia

5. "Implement the action plan, and update the Organizational Profile.": The final step is to act and follow the plan made in the previous step to achieve the Target Profile. The Target Profile can have a deadline that the organization has selected or remain an ongoing process. [...] 3. A new Function, Govern, has been added to provide organizational context and the roles and responsibilities associated with developing a cybersecurity governance model. There is also an additional category in this

National Institute of Standards and Technology - Wikipedia

NIST released a draft of the CSF 2.0 for public comment to November 4, 2023. NIST decided to update the framework to make it more applicable to small and medium size enterprises that use the framework, as well as to accommodate the constantly changing nature of cybersecurity.