The framework is voluntary.
The AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance for organisations that design, develop, deploy, or use AI. It does not certify systems. Its Generative AI Profile applies the same functions to generative models.
Framework alignment · Self-assessment
The NIST AI Risk Management Framework sets out how organisations should govern, map, measure, and manage AI risk. This page shows where DET.io’s research architecture addresses each function, the level of evidence behind each point, and where the gaps are.
Reviewed 10 October 2026 · Not a NIST assessment, endorsement, or certification
01 · How to read this mapping
The AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance for organisations that design, develop, deploy, or use AI. It does not certify systems. Its Generative AI Profile applies the same functions to generative models.
The category summaries are paraphrased. Matching a research design to a category shows that it addresses the same concern. It does not show that the risk is managed in practice, and no external party has reviewed this mapping.
Each entry is tagged with the same maturity ladder used across the research. Most points are published design. None has reached integration or independent validation.
Where the architecture does not address a category, or addresses it only on paper, the mapping says so rather than leaving the category out.
02 · The four core functions
Policies, accountability, culture, engagement, and third-party risk across the organisation.
Gap. Network governance is stake-weighted and not yet tested for capture. Diversity and accessibility of oversight (GOVERN 3) are not yet addressed.
Establish context, categorise the system, and characterise its impacts on people and society.
Gap. No characterisation yet of impacts on specific communities, such as people excluded by identity checks.
Identify metrics, evaluate trustworthiness, track risks over time, and check that measurement works.
Gap. The metrics are defined but not yet measured. No independent evaluation has been performed.
Prioritise and respond to risks, manage third parties, and document response and recovery.
Gap. There is no published incident-response plan for a live network, because the network is not live.
03 · Characteristics of trustworthy AI
The framework describes seven characteristics of trustworthy AI. The architecture says most about safety, security, accountability, and privacy. It says least about explainability and fairness.
| Characteristic | Architecture feature | Status |
|---|---|---|
| Valid and reliable | Reputation from recorded, held-out task performance; Bosun's reviewed-diff evidence. | Designed · Bosun operating |
| Safe | Independent authority, budget, and containment gates before any agent action. | Designed |
| Secure and resilient | Hardware attestation; many independent providers rather than one operator. | In source |
| Accountable and transparent | Open source, a record linking mandate to settlement, and a signed constitution. | Partly in source · record linkage designed |
| Explainable and interpretable | Decisions are recorded and can be replayed. Model internals are not addressed. | Gap |
| Privacy-enhanced | On-device processing and minimal, purpose-specific identity proofs. | In source |
| Fair, with harmful bias managed | False rejection and access barriers are named metrics for the identity research. | Gap · not yet measured |
04 · Evidence levels
Specified in a public document. No implementation is claimed.
Code exists in an open repository. The network is not live and the code is not independently audited.
Used in practice by its maintainers. Experimental, configuration-dependent, and not independently evaluated.
A signed legal instrument binding the Foundation. It does not bind networks, agents, or external systems.
Demonstrated working across components on one task. Not yet reached by any part of the architecture.
Evaluated by parties outside the Foundation under adversarial conditions. Not yet reached.
Read the research synthesis →Try the end-to-end taskDiscuss an evaluation