Frameworks · NIST AI Risk Management Framework
You shipped AI.
Now govern it.
Your company uses AI — in your product, in hiring, in everyday work. New laws and customer contracts now ask a blunt question: who's making sure the AI doesn't cause harm? The NIST AI rules are the accepted answer — in Texas, following them is literally a legal defense — and government buyers now require proof before they purchase AI at all. The Cyber Tackle Box™ platform keeps that proof organized and current — set it up yourself, or have Lionfish & partner consultants stand it up with you.
Technical evaluator? Skip the pitch — jump to the deep dive ↓
For the technical reader — the deep dive
- ▸Core: AI RMF 1.0 (NIST AI 100-1, Jan 2023) — Govern, Map, Measure, Manage; ~72 subcategories across 19 categories.
- ▸Generative AI Profile (NIST AI 600-1, July 2024): 12 GenAI risk categories (confabulation, information security, data privacy, IP, CBRN…) with 200+ suggested actions.
- ▸Legal hooks: Texas TRAIGA (HB 149, effective Jan 1, 2026) — substantial AI RMF compliance is an affirmative defense; OMB M-25-21/M-25-22 govern federal AI use and procurement for solicitations issued on/after Sept 30, 2025.
- ▸Adjacent: ISO/IEC 42001 (AI management systems) — our implementation maps across both.
- ▸In the Tackle Box: AI system inventory, risk categorization per the profile, impact-assessment playbooks, policy set, and AI-literacy training records.
Want to go deeper than a web page? Book a call — you'll be talking to a practitioner, not a salesperson.
AI governance stopped being optional
Sources: NIST AI 600-1; April 2026 federal agency AI inventories; Texas HB 149 (TRAIGA). State AI law is volatile — Colorado's act was delayed and narrowed, a federal preemption EO is in litigation — which is exactly why the NIST framework is the safe anchor.
Who this is for
For teams whose AI outran their governance
The regulatory map changes monthly. The NIST AI RMF is the one fixed point every regime references — align there and you're defensible everywhere.
- ✓Companies deploying AI in consequential decisions — hiring, lending, healthcare, insurance — especially with Texas exposure, where AI RMF alignment is the statutory defense.
- ✓Vendors selling AI to the federal government — OMB's procurement rules apply to solicitations since September 30, 2025, with governance flow-down terms in the contract.
- ✓Enterprises with GenAI sprawl — copilots, chatbots, and shadow AI everywhere, and a board asking who's accountable. (Our own AI research is IEEE-published — we govern what we build.)
Sound familiar?
The pain we hear on every first call
- !You can't govern what you can't inventory. Shadow AI is the asbestos of 2026 — an AI system inventory is the first artifact every regulator and questionnaire asks for.
- !Frameworks without a checklist. 4 functions, 12 GenAI risk categories, 200+ suggested actions — knowing which subset applies to your systems is the actual work.
- !Regulatory whiplash. Colorado rewritten twice, a federal preemption order in court, EU AI Act deadlines marching on — you need a baseline that doesn't move.
The platform
How the Cyber Tackle Box™ runs your AI RMF program
The same GRC backbone that runs your security frameworks runs your AI governance — one platform, one evidence library, one team accountable.
AI Policy Templates
Acceptable-use, model documentation, human-oversight, and vendor-AI policies — the document set every AI governance questionnaire requests.
Map & Measure Objectives
Every AI system inventoried, risk-categorized, and tracked against the RMF functions with owners and dates.
Findings → Action
Impact-assessment findings become assigned remediation items — evidence of managing AI risk, not just acknowledging it.
AI System Inventory & Intel
The living inventory regulators ask for first — plus intelligence on the moving regulatory map, from Texas to the EU.
Impact Assessment Playbooks
Repeatable runbooks for AI impact assessments and procurement responses — answer the governance section once, reuse it every deal.
AI Literacy Training
Workforce training on responsible AI use — built by a team with four IEEE-published papers on AI and security, tracked per person.
Software, services, or both
Two ways to work with Lionfish
The Cyber Tackle Box™ is a product you can run yourself. Our consulting team is a service you can add. Take either — or both. They're priced separately, and we'll tell you straight which one you actually need.
The platform — Cyber Tackle Box™
Software you run yourself: framework-mapped controls, policy templates, evidence, POA&Ms, and workforce training in one system of record. Your team (or your MSP) drives; the platform keeps everything organized and audit-ready.
Book a platform demoThe services — Lionfish & partner consultants
Add Lionfish & partner consultants — led by the team that trains certified CMMC assessors, backed by our vetted Trusted Partner Network — to run the gap assessment, drive remediation, and prepare you for the audit, by, with, and through your team, inside the same platform.
Book a readiness callFor MSPs & partners
Multi-tenant by design: run every client's compliance program from one console and add a services line without adding headcount. White-glove onboarding for your first clients.
Partner with usStraight answers
AI governance questions we answer every week
What is the NIST AI RMF?
The NIST AI Risk Management Framework (AI RMF 1.0, January 2023) is a voluntary framework for managing AI risk across four functions: Govern, Map, Measure, and Manage. Its Generative AI Profile (July 2024) adds 12 GenAI-specific risk categories with 200+ suggested actions. It's the reference point most US AI regulation and procurement now builds on — which makes it the most durable place to anchor your program.
Why does Texas matter to my AI program?
The Texas Responsible AI Governance Act took effect January 1, 2026, with attorney-general enforcement against AI misuse in consequential decisions — and it names substantial compliance with the NIST AI RMF as an affirmative defense. Documented AI RMF alignment is currently the cleanest legal ROI in AI governance: it's not just best practice, it's a statutory shield.
We sell AI to the government — what do we need?
Federal AI procurement under OMB's 2025 memoranda applies to solicitations issued since September 30, 2025: expect contract terms on training-data use, IP and data portability, and documented risk management. Agencies reported 3,611 AI use cases (445 high-impact) as of April 2026 — the market is real, and governance artifacts are the entry fee. We build the artifact set.
Isn't the AI regulatory landscape too unsettled to invest in?
That's exactly backwards. Colorado's law was delayed and narrowed, a December 2025 executive order put state AI laws in litigation, and the EU AI Act marches on regardless — the landscape is unsettled, but every version of it references the same NIST foundation. An AI RMF program is the one investment that pays off under every scenario, including the one where your biggest customer just wants the questionnaire answered.
Get in touch
Get your AI governance documented
Tell us where AI lives in your business — product features, internal tools, or both — and what's driving the ask. Straight scope within one business day.
- 1We reply within one business day — usually faster.
- 2A 30-minute call with someone who can actually answer your questions.
- 3A straight recommendation — even if it's that you don't need us yet.
Prefer to skip the form? Book a time directly or call 1-877-732-6772.