TwinEthosRequest access

Standard or framework

NIST AI RMF 1.0

NIST (U.S. Dept of Commerce) · International (INTL), United States (federal) (US) · 2 provisions encoded · verified against the official source as of 2026-08-30.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: nvlpubs.nist.gov.

Standard / soft law

Deployed AI should have override, decommission, and monitoring mechanisms

NIST AI RMF 1.0 — MANAGE 4.1 · official text · Soft law or guidance (not binding law) · United States (federal) (US)

NIST AI RMF MANAGE 4.1 expects post-deployment monitoring plus appeal, override, decommissioning, and incident response. Detect a deployed AI system (especially agentic) with no override/disengage/kill-switch or monitoring hooks.

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: consequential decision
  • Organisations adopting NIST AI RMF for deployed AI. Voluntary.

The guard to add

Check a runtime kill switch before each automated AI action, add a circuit breaker and operator override, and emit monitored action metrics with an incident route.

In the agent loop, worker, or scheduled job that applies model output, check a runtime disengage control before every action: a feature flag or config value (for example a LaunchDarkly flag ai-agent-enabled or AI_AGENT_ENABLED) that operators can flip without a deploy, plus a circuit breaker that halts the loop when anomalies cross a limit. Each action emits a span or counter (OpenTelemetry, Prometheus) wired to an alert and an incident route, an operator override endpoint can cancel or reverse queued actions, and a decommission runbook in the repository says how to retire the model and what takes its place.

Where it goes: 15 agent action surface, 3 config and feature flags, 10 logs and telemetry.

Example (Python agent + LaunchDarkly + OpenTelemetry), before:

for call in response.tool_calls:
    result = TOOLS[call.name](**call.arguments)

After:

ld = ldclient.get()
ctx = Context.builder('support-agent').kind('service').build()
tracer = trace.get_tracer('agent')

for call in response.tool_calls:
    if not ld.variation('ai-agent-enabled', ctx, False):   # operators flip it, no deploy
        raise AgentDisengaged('kill switch off')
    if breaker.is_open():                                   # e.g. error or refund spike
        raise AgentDisengaged('circuit breaker open')
    with tracer.start_as_current_span('agent.tool_call') as span:
        span.set_attribute('tool.name', call.name)
        result = TOOLS[call.name](**call.arguments)
    ACTIONS.labels(tool=call.name).inc()                    # alerted in Prometheus

Control: No override/decommission mechanism for deployed AI. The same guard addresses 1 item. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id nist-ai-rmf.manage-4-1-oversight · review status: primary source derived

Standard / soft law

AI decision systems should have a documented fairness/bias evaluation

NIST AI RMF 1.0 — MEASURE 2.11 · official text · Soft law or guidance (not binding law) · United States (federal) (US)

NIST AI RMF MEASURE 2.11 expects AI systems to be evaluated for harmful bias and discrimination with documented results. Detect an AI decision system with no linked fairness/bias evaluation artifact. Voluntary outcome, but a TRAIGA safe-harbor target.

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: consequential decision
  • Any organisation adopting NIST AI RMF for AI decision systems. Voluntary.

The guard to add

Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.

Run and keep a documented fairness evaluation of the AI decision system, with per-group results, the method used, and the decision taken on each gap.

A fairness evaluation report owned by the system owner and kept with each model version (reports/fairness/<model_version>.md or the model card): which groups were evaluated, the metrics (selection rate, error-rate gaps, disparate-impact ratio), the data used, the results, the thresholds, and the mitigation or acceptance decision with who signed off. It is refreshed at each release and on a set cadence. Where the code can show it, fairness tests in the test suite assert that metrics stay within the agreed thresholds, and a CI check confirms a report exists for the version being deployed.

Where it goes: 11 CI/CD pipeline, 12 repository artifacts, 13 tests and evals.

Example (pytest + fairlearn), before:

def test_model_accuracy():
    assert accuracy_score(y_test, model.predict(X_test)) > 0.85

After:

def test_model_accuracy():
    assert accuracy_score(y_test, model.predict(X_test)) > 0.85

def test_selection_rate_ratio_by_group():
    y_pred = model.predict(X_test)
    mf = MetricFrame(metrics=selection_rate, y_true=y_test, y_pred=y_pred,
                     sensitive_features=A_test)
    assert mf.ratio() >= MIN_SELECTION_RATIO, mf.by_group.to_dict()   # threshold from the evaluation plan

Control: No documented fairness/bias evaluation of AI. The same guard addresses 1 item. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id nist-ai-rmf.measure-2-11-fairness · review status: primary source derived