Hael
Book a meeting
NIST AI RMF · United States

US NIST AI RMF consultants

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Texas gives substantial compliance with the framework an enforcement safe harbour under its AI legislation, in effect since 1 January 2026.
  • Colorado's original AI Act contained a similar affirmative defence. It was repealed in May 2026 and the defence did not survive.
  • Federal agencies use the framework and the Generative AI Profile, and requirements flow to suppliers through contracts.
  • There is no certification, so decide early how you will demonstrate adoption to a buyer.
  • US implementations commonly run $20,000 to $60,000, driven by system count.

The Texas safe harbour

US companies implement the NIST AI Risk Management Framework for three reasons: one state gives it a defined legal benefit, federal work requires it, and enterprise buyers recognise it when nothing else in the American landscape is recognised consistently.

There is still no comprehensive federal AI statute. Binding duties sit in state law, and the framework is the closest thing to a common language across a fragmented picture.

Texas enacted its AI legislation in June 2025, and it took effect on 1 January 2026. It grants substantial compliance with the NIST AI Risk Management Framework an enforcement safe harbour.

This is the clearest legal benefit the framework carries anywhere, and for companies with Texas exposure it changes the calculation from "good practice" to "worth doing deliberately". Two points matter in practice.

Substantial compliance is not a defined test with a checklist behind it. What it will mean is a question for enforcement and, eventually, for courts. What you can control is the quality of your evidence: an inventory, per-system documentation, measurement results and recorded decisions.

The safe harbour covers enforcement under that statute. It does not extend to other states, to federal action, or to private claims.

The Colorado correction

Colorado's 2024 AI Act contained an affirmative defence for organisations following the NIST AI Risk Management Framework or a comparable standard.

That statute was repealed and replaced by a narrower automated decision law signed in May 2026, with core duties beginning on 1 January 2027. The original act never took effect, and the affirmative defence did not survive into the successor.

Any adviser still presenting Colorado as a framework-based defence is working from material more than a year out of date, and it is a fast way to assess whether a firm is current.

Federal work

Federal agencies use the framework, and agencies deploying generative AI use the Generative AI Profile, NIST AI 600-1, as their reference for risk assessment.

Those expectations flow to suppliers through contract clauses. If you sell to federal agencies or to prime contractors, expect framework-shaped questions, and expect the Generative AI Profile to be named where large language models are involved.

NIST is also developing control overlays for securing AI systems under SP 800-53, which will apply to federal deployments in higher-risk categories. Suppliers into that space should watch it.

The state patchwork

Beyond Texas, several state laws now impose duties that the framework helps you satisfy without discharging.

California's frontier model and training data statutes took effect on 1 January 2026, alongside its automated decision-making regulations. Illinois amended its Human Rights Act for AI in employment from the same date. Utah's AI Policy Act has applied since 2024, and New York City Local Law 144 since 2023. New York State's frontier developer statute arrives on 1 January 2027, as does Colorado's replacement law.

State laws generally attach based on where the affected person is rather than where the company sits, so growth into a new market can create duties quietly. The framework gives you one internal structure from which to answer all of them, which is the practical reason to build once.

What it costs

ComponentTypical range
Inventory and current-state assessment$7,000 to $20,000
Gap assessment across the 72 subcategories$8,000 to $25,000
Full implementation$20,000 to $60,000
Generative AI Profile overlay$5,000 to $15,000
Independent assessment$10,000 to $35,000

Cost scales with system count, how many are generative, and how many affect people.

What a US-facing consultant should cover

They should establish your Texas exposure specifically, because that is where the framework carries defined legal benefit, and shape the evidence with substantial compliance in mind.

They should be current on Colorado rather than repeating the repealed defence.

They should ask whether federal or prime contractor work is in your pipeline, because that changes which profiles apply.

They should build the documentation so it also answers state law duties and enterprise questionnaires, rather than producing something that only serves one audience. Our buyer assurance and security reviews service covers questionnaire response.

And they should be clear that no certification exists, and set out how you will demonstrate adoption instead. That is covered in NIST AI RMF - Independent Assessment Consultants.

Where SOC 2 and ISO 27001 fit

Most US companies implementing the framework already hold SOC 2. The security controls and evidence discipline transfer into GOVERN and MANAGE, but MAP and MEASURE are genuinely new work: model context, affected people, bias testing, performance monitoring.

Where a buyer wants a verifiable credential rather than a structure, ISO/IEC 42001 is certifiable and NIST publishes a crosswalk to it. See our ISO/IEC 42001 and SOC 2 service pages.

What to do next

Establish two things: whether you have Texas exposure, and whether federal or prime contractor work is in your pipeline. Those two answers determine how much the framework is worth to you and which profiles apply.

Our free AI impact assessment gives a first view, and the NIST AI RMF service page sets out how we run the implementation.

References

FAQ

Does the NIST AI RMF give a legal safe harbour?

In Texas, substantial compliance carries an enforcement safe harbour under its AI legislation, in effect since 1 January 2026. Elsewhere the framework creates no legal position.

Is the Colorado defence still available?

No. Colorado's 2024 AI Act was repealed and replaced in May 2026, and the framework-based affirmative defence did not survive.

Do federal contracts require it?

Agencies use the framework and the Generative AI Profile, and those expectations reach suppliers through contract clauses.

Is there a NIST AI RMF certification?

No. Organisations demonstrate adoption through documentation, questionnaires, an independent assessment, or by certifying to ISO/IEC 42001.

What does implementation cost in the US?

Commonly $20,000 to $60,000 for a first implementation, scaling with system count and how many systems are generative.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We take companies through the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001, building one governance programme that answers multiple regimes rather than several parallel ones. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not professional advice on your particular circumstances.

Free check

See where you stand on NIST AI RMF, free.

Answer a short set of questions and see what NIST AI RMF expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether NIST AI RMF applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to NIST AI RMF.

Or speak to us about your deadline. Book a meeting.