National Institute of Standards and Technology (NIST) — Information Technology Laboratory (ITL)

Artificial Intelligence Risk Management Framework

Trustworthy AI in Critical Infrastructure

Raymond Sheh, Martin Stanley


To meet growing demand for safety, security, reliability, capability, and efficiency, Critical Infrastructure (CI) will increasingly rely on technological advances such as Artificial Intelligence (AI) across Information Technology (IT), Operational Technology (OT), and Industrial Control Systems (ICS) environments.

Adopting AI in these highly critical environments, however, demands one fundamental requirement: trust in AI systems.

With that goal, NIST developed the AI Risk Management Framework (AI RMF), which defines and promotes the trustworthiness of AI systems through a repeatable, lifecycle-based approach, allowing organizations to capture the benefits of AI while managing its risks appropriately.


A strategic step toward AI in critical infrastructure

As part of its technology leadership strategy for the 21st century, NIST — through its ITL laboratory — is driving the development of the "Trustworthy AI in Critical Infrastructure Profile". The profile is designed to:


Use cases for trustworthy AI in critical infrastructure

The profile addresses key trustworthiness characteristics in AI systems. Examples include:


Goals of the profile

The framework seeks to operationalize AI risk management in complex scenarios, aligning multiple domains: AI, IT, OT, ICS, cybersecurity, and software development. Its main contributions include:

Interoperability and standardization

It harmonizes key definitions and concepts across sectors to make collaboration easier.

Risk management adapted to critical environments

It accounts for realities such as legacy systems, distributed assets, and operational constraints.

Strict operating requirements

It includes guidance on deterministic behavior, explainability, controlled degradation, and fail-safe operation.

Robustness against adversarial threats

It strengthens AI resilience at every stage of the lifecycle.

Rigorous validation (TEVV)

It promotes robust testing, evaluation, verification, and validation, along with supply chain visibility and transparency.

A practical approach

It defines measurable actions for organizations at any level of maturity.


Ecosystem participation

NIST invites companies, regulators, academia, industry, and the technology community to take part through seminars and working sessions, technical proposals, position papers, and feedback on drafts. Key areas of interest include:


Toward trustworthy AI adoption

The ultimate goal is to give critical infrastructure sectors the confidence they need to adopt AI-based solutions safely, while developers and vendors gain clearer direction and regulatory alignment. The result: a safer, more transparent, and more trustworthy AI ecosystem.

At Netmask, we understand that adopting technologies like Artificial Intelligence in critical environments is not only a technology decision, but a business strategy that affects the security, continuity, and resilience of organizations.

That is why we support our clients at every stage of this journey, combining innovation, cybersecurity, and risk governance to deploy trustworthy AI solutions aligned with international standards and ready for the challenges of IT and OT environments.