AI policy & ethics · July 2026

Corporate Compliance with the NIST AI RMF

NIST's AI Risk Management Framework is voluntary, so a company gets to decide whether to adopt it, how much of it to apply, and what to say about the results. We picked the two labs with the least excuse to cut corners on this, Anthropic and Google, and checked their public safety reporting against the RMF's four functions line by line.

Two labs, four functions

Anthropic's Responsible Scaling Policy and Google's Responsible AI Progress Report both line up with GOVERN, MAP, MEASURE, and MANAGE. Anthropic has a named Responsible Scaling Officer and board oversight; Google runs Launch Review forums and an AGI Futures Council. Both lean hard on red-teaming and outside evaluators for MEASURE, which turned out to be the best-documented function on either side. The full function-by-function tables are in the paper.

Where it falls apart

Here's the catch: in both cases, the company still decides what gets measured, disclosed, and redacted, and nobody outside gets to check its work. Anthropic edits its own redactions. Google's report reads more like a highlight reel of good launches than a consistent record. And this isn't just an Anthropic-and-Google problem. Earlier work applying the RMF to facial recognition and to AI supply chains ran into the same wall: the framework assumes one company builds and ships a system start to finish, so it has almost nothing to say about data retention, deletion, or what happens once a system passes through several hands.

A framework that never asks a question can't catch a company for answering it wrong.Not bad faith on either company's part. Just a framework that never asked for more.

What we'd change

Our recommendation: make the standards mandatory, with real penalties for skipping them, closer to how GDPR works. And move the auditing outside the company, to independent regulatory agencies instead of reviewers the company hand-picks and pays. Right now compliance runs entirely on the honor system, and that's a strange place to leave it for the industry building the most consequential technology of the decade.

Written with Alyssa Samuel, David Hernandez, Srivatsa Balasubramanyam, and Amanda Betag for DS 6002: Ethics in Big Data, UVA M.S. in Data Science.

AI GovernanceNIST AI RMFPolicy Analysis