SECAI Core · phase 8 of 15

National Institute of Standards and Technology

A nonregulatory government agency that develops computer security standards used by US federal agencies and publishes best practice guides and research.

The Explain card

Plain English
NIST is a nonregulatory US government agency that develops computer security standards used by federal agencies and publishes best-practice guides and research that the wider industry adopts.
Example
A security team building an AI assurance programme borrows from NIST publications: the Cybersecurity Framework for overall structure, the SP 800-53 control catalogue for specific safeguards, and the AI Risk Management Framework for AI-specific risk.
Why it matters
NIST guidance is free, widely respected and often referenced in contracts and regulations. Aligning AI security controls to NIST makes them easier to defend to auditors and easier to explain to executives.
Hook
The standards body that does not fine you, but everyone quotes.

Where it sits in the deck

Phase 8: Governance, Risk, and Compliance Frameworks

Individual controls need a governance envelope — introduce the risk and compliance structures, standards bodies, and regulations that frame AI accountability at scale.