Upcoming Workshop: Citizen Developer Agentic Software Factory on AWS

Register Here!

NIST AI RMF oversight for agents that change your cloud.

Your teams already use coding agents that can plan and apply infrastructure. The AI RMF asks you to inventory those AI systems, define human oversight for them, and keep a way to switch them off. For the infrastructure an agent touches, Massdriver turns each of those into a policy and a record.

The agent may plan and propose in non-production. It cannot deploy anywhere, and it cannot touch production at all.

The AI system in this case is the agent

Most AI RMF work looks at models a company builds. A coding agent with cloud access is an AI system your company uses, and its outputs are changes to production. Oversight for it means knowing which agents hold access, what each one may change, who approves its changes, and how to stop it.

AI RMF subcategories mapped to Massdriver controls

Each row names an AI RMF subcategory, what it asks for, what Massdriver does for agent changes to infrastructure, and the evidence your risk team can request.

SubcategoryWhat it asks forWhat Massdriver doesEvidence produced
GOVERN 1.4The risk management process and its outcomes are established through transparent policies, procedures, and other controls.What an agent may do is an attribute-based policy: which actions, on which environments, projects, or teams. Massdriver reads each policy back in plain language.Policy definitions and their plain-language form
GOVERN 1.6Mechanisms are in place to inventory AI systems.Each agent gets its own service account, so the list of service accounts is an inventory of the agents that can reach your infrastructure.Service accounts with their groups and token expiry
GOVERN 2.1Roles, responsibilities, and lines of communication for managing AI risk are documented and clear.Groups separate who may propose a change from who may deploy it, for agents and people alike.Group membership and group policies
MAP 3.5Processes for human oversight are defined, assessed, and documented.An agent can propose a production change. A person with deploy permission sees the plan diff and the policy results, then approves or rejects it.Approval records with the approver, the plan diff, and the policy results
MANAGE 2.4Mechanisms are in place to supersede, disengage, or deactivate AI systems that behave inconsistently with intended use.Revoke the agent’s token or remove its service account from its group, and its access ends, with no cloud IAM change.Token and group membership state for each service account
MANAGE 4.1Post-deployment monitoring plans include override, recovery, and change management.Every agent action is recorded with the agent as the actor, and deterministic execution lets each change be traced back and rolled back.Agent action log; deployment history

Massdriver records the changes that go through it. Your auditor or assessor decides whether these records meet a control, and changes made outside Massdriver, in a cloud console or with a cloud key, do not appear in them.

What Massdriver does not cover

The AI RMF covers the whole life of an AI system. Massdriver covers what an agent can do to your infrastructure.

  • Model evaluation. Validity, accuracy, bias, and robustness testing under MEASURE belong to whoever builds or selects the model.
  • The agent’s other work. Code an agent writes for your applications, and anything it does outside Massdriver, need their own review.
  • Third-party model risk. GOVERN 6 asks you to manage risk from the vendors whose models you use. That review stays with your procurement and risk teams.
  • AI systems you build for customers. Impact assessment and transparency duties for your own AI products are outside the infrastructure path.

AI RMF questions about coding agents

Is the NIST AI RMF mandatory?

No. NIST published it as a voluntary framework in January 2023. Many enterprises and their customers use it as the reference for AI governance, so security reviews often ask how you apply it.

Does the AI RMF apply to coding agents we did not build?

The framework addresses organizations that design, develop, deploy, or use AI systems. A coding agent with access to your cloud is an AI system your organization uses and deploys into its own workflow.

How do we keep a human in the loop without slowing agents down?

Let agents deploy on their own in development, and require a person to deploy in production. Both rules are policies on the same service account, so the agent keeps working while a production change waits for review.

Other framework mappings

SOC 2

Change management, logical access, and monitoring criteria, mapped to the record each change leaves.

See the mapping →

HIPAA

Security Rule access, audit, and integrity standards for the infrastructure that holds ePHI.

See the mapping →

EU DORA / Digital Operational Resilience Act

ICT change management, access, and asset inventory duties under Regulation (EU) 2022/2554.

See the mapping →