NIST AI RMF Agentic Profile Implementation Guide: The 60 Controls That Map Every Architecture Pillar to the Four Core Functions
The Cloud Security Alliance's analysis of NIST's planned AI Agent Interoperability Profile (Q4 2026 release) identified a gap that 2026 production deployments must address: the operational controls that bridge the AI RMF's high-level functions (Govern, Map, Measure, Manage) to the actual runtime implementations of AI agent systems. The gap exists because the original AI RMF 1.0 (March 2023) and its generative AI extension NIST AI 600-1 (July 2024) were designed for AI systems in general; the agentic AI deployment patterns that have emerged in 2025–2026 require specific control implementations that the high-level framework does not specify.
The Axis Intelligence analysis of the 2026 agentic AI security statistics documented the operational reality: most enterprises have adopted the AI RMF as a governance framework; most enterprises have not implemented the specific agentic controls that the framework implies. The gap is between the framework and the runtime; the gap is what this implementation guide addresses.
The guide maps the 60 operational controls that production AI agent deployments in 2026 require to the four AI RMF core functions. The mapping is based on the implementations that have emerged from the Facio analyses from June and July 2026 — covering audit trails, runtime guardrails, kill switches, behavioral analytics, supply chain security, network isolation, identity governance, MCP authentication, tamper-evident logs, and HITL workflows — and the regulatory frameworks (EU AI Act, GDPR, HIPAA, PCI-DSS, SEC, FINRA) that the controls must satisfy.
The organizations that will achieve AI RMF compliance in 2026 are the ones that implement the 60 controls as an integrated architecture, mapping each control to the function it serves, the runtime it operates in, and the evidence it produces for the audit trail. The alternative is the next "we adopted the AI RMF framework but cannot demonstrate control implementation" compliance finding — the kind of finding that, in 2026, is increasingly being cited as evidence of inadequate governance.
The Four Core Functions Recap
The AI RMF 1.0 defines four core functions. The functions form the governance spine; every AI agent control can be categorized under one of the four.
GOVERN. The governance function establishes the policies, processes, procedures, and practices across the organization. The function defines the AI risk management roles, responsibilities, and lines of communication. The function is the policy plane; the function is where the organization's AI risk tolerance is articulated.
MAP. The map function establishes the context to frame risks related to the development and deployment of AI systems. The function identifies the AI system's purpose, the stakeholders, the lifecycle stage, and the potential impacts. The function is the contextualization plane; the function is where the system's risk profile is understood.
MEASURE. The measure function employs quantitative, qualitative, or mixed-method tools, techniques, and methodologies to analyze, assess, benchmark, and monitor AI risk. The function produces the empirical evidence about the system's risk posture. The function is the measurement plane; the function is where the system's actual risk is observed.
MANAGE. The manage function allocates risk resources to mapped and measured risks on a regular basis and as defined by the govern function. The function treats, responds to, and recovers from AI risks. The function is the response plane; the function is where the organization's risk treatments are executed.
These four functions together form the governance cycle. The cycle is continuous; the cycle produces the audit evidence that compliance frameworks require.
The 60 Controls Mapped to the Four Functions
The 60 controls are organized into 15 categories, each category addressing a specific aspect of AI agent deployment. The categorization maps to one of the four AI RMF functions; the mapping is based on the function the control primarily serves.
GOVERN Function Controls (15 controls)
Category G1: AI Risk Governance and Roles (5 controls).
- G1.1: Establish an AI risk governance committee with executive sponsorship.
- G1.2: Define AI agent ownership — the human accountable for each agent's behavior.
- G1.3: Define AI agent developer roles and the secure development lifecycle responsibilities.
- G1.4: Define AI agent operator roles and the runtime oversight responsibilities.
- G1.5: Define escalation paths for AI agent incidents, with named individuals and decision authorities.
Category G2: Policy and Standards (5 controls).
- G2.1: Publish the AI agent acceptable use policy.
- G2.2: Publish the AI agent development security standard.
- G2.3: Publish the AI agent runtime control standard (the architectural pillars).
- G2.4: Publish the AI agent incident response standard.
- G2.5: Publish the AI agent supply chain security standard.
Category G3: Training and Awareness (5 controls).
- G3.1: Provide annual AI agent security awareness training for all employees.
- G3.2: Provide specialized AI agent security training for developers.
- G3.3: Provide specialized AI agent runtime training for operators.
- G3.4: Provide specialized AI agent incident response training for the security team.
- G3.5: Conduct tabletop exercises for AI agent incident scenarios.
MAP Function Controls (15 controls)
Category M1: Agent Discovery and Inventory (5 controls).
- M1.1: Deploy Agent Discovery and Governance (ADG) tooling to discover shadow AI agents (covered in the Facio analysis from July 2026).
- M1.2: Maintain an authoritative inventory of all AI agents with classification by risk profile.
- M1.3: Tag each agent with its owner, purpose, data sensitivity, and regulatory exposure.
- M1.4: Implement continuous agent discovery scanning with weekly reporting.
- M1.5: Implement NHI governance for each agent's workload identities (covered in the Facio analysis from June 2026 on SPIFFE).
Category M2: Risk Assessment and Context (5 controls).
- M2.1: Perform a documented AI agent risk assessment for each new agent deployment.
- M2.2: Map each agent's data flows to identify sensitive data exposure.
- M2.3: Map each agent's blast radius to identify potential impact.
- M2.4: Document each agent's trust relationships with upstream systems and downstream services.
- M2.5: Re-assess each agent's risk profile annually or upon significant change.
Category M3: Stakeholder and Impact Analysis (5 controls).
- M3.1: Identify affected stakeholders for each agent's deployment.
- M3.2: Document potential harms (privacy, security, financial, operational) for each agent.
- M3.3: Document the reversibility of each agent's actions.
- M3.4: Document the reversibility window for each agent's actions.
- M3.5: Establish stakeholder notification protocols for agent incidents.
MEASURE Function Controls (15 controls)
Category Me1: Telemetry and Observability (5 controls).
- Me1.1: Implement comprehensive agent telemetry emission (tool calls, reasoning traces, data accesses, destinations).
- Me1.2: Implement decision tracing for every agent decision point (covered in the Facio analysis from July 2026).
- Me1.3: Implement tamper-evident audit logging with hash chains and external timestamping (covered in the Facio analysis from July 2026).
- Me1.4: Implement behavioral analytics with anomaly detection (covered in the Facio analysis from July 2026).
- Me1.5: Implement continuous adversarial evaluation testing (covered in the Facio analysis from July 2026).
Category Me2: Runtime Controls (5 controls).
- Me2.1: Deploy runtime policy engine for tool call argument validation (covered in the Facio analysis from June 2026).
- Me2.2: Deploy runtime egress filtering for destination allowlisting (covered in the Facio analysis from June 2026).
- Me2.3: Deploy runtime DLP for sensitive data detection in tool arguments and outputs (covered in the Facio analyses from June and July 2026).
- Me2.4: Deploy runtime kill switch as a runtime control plane (covered in the Facio analysis from July 2026).
- Me2.5: Deploy runtime HITL workflow with Placet.io integration (covered in the Facio analyses from July 2026).
Category Me3: Supply Chain Security (5 controls).
- Me3.1: Implement MCP server tool provenance tracking (covered in the Facio analysis from June 2026).
- Me3.2: Implement model provenance tracking for the underlying AI models.
- Me3.3: Implement dependency vulnerability scanning for agent frameworks.
- Me3.4: Implement prompt template integrity verification.
- Me3.5: Implement MCP server authentication with OAuth 2.1 + PKCE (covered in the Facio analysis from July 2026).
MANAGE Function Controls (15 controls)
Category Ma1: Risk Treatment and Response (5 controls).
- Ma1.1: Implement the kill switch runtime control plane (covered in the Facio analysis from July 2026).
- Ma1.2: Implement the incident response workflow for agent compromises.
- Ma1.3: Implement the rollback workflow for agent action reversal.
- Ma1.4: Implement the credential rotation workflow for compromised credentials.
- Ma1.5: Implement the kill switch testing cadence as part of adversarial evaluation.
Category Ma2: Operational Continuity (5 controls).
- Ma2.1: Implement agent health monitoring with defined service level objectives.
- Ma2.2: Implement agent recovery procedures with defined recovery time objectives.
- Ma2.3: Implement agent failover procedures for multi-region deployments.
- Ma2.4: Implement agent version management with rollback capability.
- Ma2.5: Implement agent configuration management with audit trail.
Category Ma3: Continuous Improvement (5 controls).
- Ma3.1: Conduct post-incident reviews for every agent security incident.
- Ma3.2: Track AI agent security metrics (MTTD, MTTR, false positive rates).
- Ma3.3: Update the AI agent risk register quarterly.
- Ma3.4: Update the AI agent security standards annually based on threat intelligence.
- Ma3.5: Participate in industry threat intelligence sharing for agentic AI threats.
These 60 controls together form the implementation guide. The guide is comprehensive; the guide is the operational expression of the AI RMF for AI agent deployments.
The Cross-Functional Integration
The 60 controls are not isolated. The controls integrate across functions; the integration is what makes the framework effective.
Govern → Map → Measure → Manage. The governance function establishes the policies that the map function operationalizes; the map function produces the context that the measure function quantifies; the measure function produces the evidence that the manage function responds to. The functions form a continuous cycle.
Map → Measure. The risk assessment (M2.1) identifies the agent's risk profile; the risk profile determines the runtime control configuration (Me2.x); the runtime control produces the telemetry that measures the actual risk. The map-measure integration is what ensures the controls match the risks.
Measure → Manage. The behavioral analytics (Me1.4) detects anomalies; the adversarial evaluation (Me1.5) tests the controls; the kill switch (Ma1.1) responds to confirmed anomalies. The measure-manage integration is what converts detection into response.
Manage → Govern. The post-incident reviews (Ma3.1) identify governance gaps; the governance gaps update the policies (G2.x); the policies drive the next risk assessment. The manage-govern integration is what produces continuous improvement.
These four integrations together form the AI RMF cycle. The cycle is continuous; the cycle produces the evidence that compliance frameworks require; the cycle is what the 2026 AI RMF agentic deployments must operate.
The Runtime Mapping
Each runtime control (Me2.x, Me3.x, Ma1.x) maps to a specific runtime component. The mapping is what converts the abstract control into the operational implementation.
Runtime policy engine → Me2.1, Me2.3. The runtime policy engine (Facio's policy engine as the reference implementation) enforces the policy at the execution layer. The policy engine validates tool call arguments, detects sensitive data, and rejects forbidden actions. The policy engine produces the runtime evidence for the controls.
Runtime egress filter → Me2.2. The runtime egress filter (Facio's egress filter as the reference implementation) enforces destination allowlisting at the network layer. The egress filter produces the runtime evidence for the egress control.
Runtime kill switch → Me2.4, Ma1.1. The runtime kill switch (Facio's kill switch as the reference implementation, covered in the Facio analysis from July 2026) provides the response capability. The kill switch is the runtime implementation of the manage function for the most severe risk scenarios.
Runtime HITL → Me2.5. The runtime HITL workflow (Placet.io as the reference implementation, covered in the Facio analyses from July 2026) provides the human oversight capability. The HITL workflow satisfies the EU AI Act Article 14 requirements; the HITL workflow is the human oversight evidence for compliance.
Audit trail → Me1.3. The tamper-evident audit trail (Facio's audit trail as the reference implementation, covered in the Facio analysis from July 2026) is the evidence backbone. Every runtime control produces audit entries; every audit entry is tamper-evident; every entry is queryable for the AI RMF measurement evidence.
These five runtime mappings cover the most critical controls. The other controls map to organizational processes, security tooling, and operational practices.
The Evidence Requirements
Each control must produce evidence that the control is implemented and operating. The evidence is what the AI RMF auditor reviews; the evidence is what the compliance auditor verifies.
Policy evidence. The govern function controls produce policy documents (acceptable use policy, security standards, incident response plans). The documents must be current, approved by the named governance roles, and accessible to the relevant personnel. The documents are the evidence.
Inventory evidence. The map function controls produce inventory data (agent inventory, risk assessments, data flow diagrams). The data must be complete, accurate, and current. The data is the evidence.
Telemetry evidence. The measure function controls produce telemetry data (audit logs, behavioral analytics outputs, adversarial evaluation results). The data must be tamper-evident, queryable, and retained for the regulatory periods. The data is the evidence.
Response evidence. The manage function controls produce response records (incident reports, rollback logs, recovery records). The records must be complete, accurate, and signed by the responsible parties. The records are the evidence.
The four evidence categories together form the AI RMF audit trail. The audit trail is what the AI RMF auditor reviews; the audit trail is what the compliance auditor verifies; the audit trail is the AI RMF implementation's proof of effectiveness.
The Compliance Crosswalk
The 60 controls satisfy multiple compliance frameworks. The crosswalk identifies the framework-specific requirements that each control addresses.
EU AI Act. Article 9 (risk management) → M2.x, Ma1.x. Article 10 (data governance) → M2.2. Article 11 (technical documentation) → All controls (documentation). Article 12 (record-keeping) → Me1.3. Article 13 (transparency) → Me2.5. Article 14 (human oversight) → Me2.5, Ma1.1. Article 15 (accuracy, robustness, cybersecurity) → Me1.4, Me1.5, Ma1.1.
GDPR. Article 25 (data protection by design) → Me2.3. Article 30 (records of processing) → Me1.3. Article 32 (security of processing) → Me2.x, Me3.x. Article 33 (breach notification) → Ma1.2. Article 35 (data protection impact assessment) → M2.1.
NIST 800-53. AC-2 (account management) → M1.5. AC-3 (access enforcement) → Me2.1. AU-2 (event logging) → Me1.3. AU-9 (protection of audit information) → Me1.3. CA-7 (continuous monitoring) → Me1.4. CM-2 (baseline configuration) → Ma2.5. IR-4 (incident handling) → Ma1.2. RA-3 (risk assessment) → M2.1. SC-7 (boundary protection) → Me2.2. SI-4 (information system monitoring) → Me1.4.
ISO 27001. A.5.10 (acceptable use) → G2.1. A.5.15 (access control) → Me2.1. A.5.24 (information security incident management planning) → Ma1.2. A.5.28 (collection of evidence) → Me1.3. A.8.16 (monitoring activities) → Me1.4. A.8.28 (secure coding) → Me2.1. A.8.29 (security testing in development) → Me1.5.
The crosswalk demonstrates the compliance efficiency of the 60-control implementation. A single AI RMF-aligned deployment satisfies multiple regulatory frameworks; the crosswalk is what makes the implementation cost-effective.
The Implementation Sequencing
The 60 controls cannot be implemented simultaneously. The implementation must be sequenced based on risk priority, regulatory deadlines, and operational dependencies.
Phase 1: Foundation (months 1–2). Implement the govern function controls (G1.x, G2.x, G3.x) and the discovery controls (M1.x). The foundation establishes the governance and the inventory; the foundation is the prerequisite for the other phases.
Phase 2: Runtime Controls (months 2–4). Implement the runtime control pillar (Me2.x), the supply chain controls (Me3.x), and the initial audit trail (Me1.3). The runtime controls are the most critical for production deployments; the runtime controls are what the EU AI Act Article 14 deadline requires.
Phase 3: Measurement and Response (months 4–6). Implement the telemetry and observability controls (Me1.x) and the response controls (Ma1.x). The measurement capabilities produce the evidence; the response capabilities execute the manage function.
Phase 4: Continuous Improvement (months 6+). Implement the operational continuity controls (Ma2.x) and the continuous improvement controls (Ma3.x). The continuous improvement operationalizes the AI RMF cycle.
The four phases together produce the AI RMF implementation. The phases are sequenced to minimize risk during the implementation; the phases are sequenced to deliver the most critical controls first.
Facio and Placet.io as the Reference Implementation
Facio (the HITL-first agent runtime) is the runtime implementation for the 60 controls' runtime pillar. Facio implements:
- Runtime policy engine for Me2.1, Me2.3 (covered in the Facio analysis from June 2026).
- Runtime egress filter for Me2.2 (covered in the Facio analysis from June 2026).
- Runtime kill switch for Me2.4, Ma1.1 (covered in the Facio analysis from July 2026).
- Tamper-evident audit trail for Me1.3 (covered in the Facio analysis from July 2026).
- Behavioral analytics integration for Me1.4 (covered in the Facio analysis from July 2026).
- Adversarial evaluation integration for Me1.5 (covered in the Facio analysis from July 2026).
- MCP authentication for Me3.5 (covered in the Facio analysis from July 2026).
- NHI governance for M1.5 (covered in the Facio analysis from July 2026).
- HITL integration with Placet.io for Me2.5.
Placet.io (the HITL inbox and messenger) is the human oversight implementation. Placet.io implements:
- The HITL workflow for Me2.5.
- The notification channel for kill switch alerts.
- The inspection surface for paused agents.
- The justification capture for human oversight decisions.
Together, Facio and Placet.io provide the operational implementation for the 60 controls. The implementation is what the AI RMF audit verifies; the implementation is what the compliance auditor reviews.
The Bottom Line
The NIST AI RMF Agentic Profile (Q4 2026 release) will codify the controls that 2026 production deployments already require. The 60-control implementation guide is the operational expression of the profile; the 60 controls map every architectural pillar from the Facio analyses to one of the four AI RMF functions.
The implementation requires the four function categories: Govern (15 controls across policy, roles, training), Map (15 controls across discovery, risk assessment, stakeholder analysis), Measure (15 controls across telemetry, runtime, supply chain), and Manage (15 controls across response, continuity, continuous improvement). The controls integrate across functions; the controls produce the evidence that compliance audits require; the controls satisfy multiple regulatory frameworks through a single implementation.
The organizations that will achieve AI RMF compliance in 2026 are the ones that have implemented the 60 controls as an integrated architecture, sequenced the implementation across the four phases, and produced the evidence that the auditor reviews. The alternative is the next "framework adopted, controls not implemented" compliance finding — the kind that the 2026 compliance audits are increasingly citing.
Facio (the HITL-first agent runtime) and Placet.io (the HITL inbox and messenger) provide the operational implementation for the 60 controls. The implementation is the AI RMF in production; the implementation is the compliance evidence; the implementation is what the audit verifies.
Further reading:
- NIST: AI Risk Management Framework
- Cloud Security Alliance: NIST AI Risk Management Framework — Agentic Profile
- Reg Intel: Agentic AI Regulation — The Closing Gap in AI Law (2026)
- Axis Intelligence: Agentic AI Security Statistics 2026 — Incidents, Frameworks, and Compliance
- AI Security and Safety: NIST AI Risk Management Framework — Implementation Guide (2026)
- Human-in-the-Loop Is Now a Legal Requirement: HITL Architecture for Article 14
- Why Most 2026 Enterprises Cannot Stop a Runaway Agent in Their Own IR Window