Skip to content

PE and AI

NIST’s AI RMF is a governance language. PE still has to price the exposure.

AI RMF 1.0 gives portfolio companies a voluntary vocabulary — Govern, Map, Measure, Manage. It does not tell an operating partner what residual loss remains if a portco agent is allowed to act.

NIST’s AI RMF is a governance language. PE still has to price the exposure. product viewOpen full-size product view ↗

Every PE operating partner now has at least one portfolio company that has “adopted AI.” The sentence is doing too much work. Sometimes it means a copilot in the shared inbox. Sometimes it means a model sitting on customer data. Sometimes it means an agent that can open a ticket, change a price, or talk to a supplier without a person in the loop. Those are different authorization problems, and they do not become the same problem because someone filed a model card.

The most useful public language for that distinction is still NIST’s Artificial Intelligence Risk Management Framework (AI RMF 1.0), published January 26, 2023 as NIST AI 100-1. It is voluntary, rights-preserving, non-sector-specific, and use-case agnostic. That last clause is the one operators skip. A framework that is use-case agnostic cannot tell you what a specific agent is allowed to commit at a specific company.

What NIST actually standardized

AI RMF 1.0 organizes work into four functions: Govern, Map, Measure, and Manage. Govern is meant to apply across the organization’s AI risk process. Map, Measure, and Manage can be applied to a particular system and lifecycle stage. The document also names trustworthiness characteristics — valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.

None of that is a product claim for Valty, and none of it is a dollar. NIST is explicit that the framework is a resource for organizations designing, developing, deploying, or using AI systems. It is not a certification. It is not a sector rule. A later review with formal community input is expected no later than 2028; until then, 1.0 is the current generation.

If a portco says they are “aligned to the AI RMF,” the only honest follow-up is: show me Govern for the company, then Map/Measure/Manage for the two systems that can move money, data, or production. A slide with the four words and no system boundary is a poster.

The questions that survive the framework

An operating partner can keep the RMF and still ask a shorter list.

Who can commit the company? If an agent can send a customer-facing message, change a quote, or trigger a payment, that is an authorization decision. The RMF will help you name the system. It will not set the dollar threshold.

What data does it see? Training data, retrieval stores, and logs are different exposure surfaces. “We do not train on customer data” can be true and still leave a retrieval layer that holds the same records.

What happens when it is wrong? Measure is where most programs stall. Accuracy on a benchmark is not residual loss if the failure mode is a bad refund, a leaked file, or a shut-down line.

Who owns the exception? Govern without an exception path is how shadow tools return. Someone has to be allowed to say no, and someone has to be allowed to accept a residual and write it down.

What the RMF does not do

It does not price EBITDA-impacting cyber loss exposure. It does not net out insurance. It does not tell you whether to fund prompt logging or network segmentation first. It does not make a design-partner sprint unnecessary. Those are financial and operating decisions that sit on top of the vocabulary.

Valty’s current offer is a capacity-capped, one-company design-partner sprint that connects verified control posture and financial-risk inputs to a P10–P90 loss-exposure range, net of insurance. AI systems enter that work as sources and as scenarios, not as a separate product. If you want to see the labeled artifact first, inspect the sample. If you want the sprint, apply as a design partner.

Sources

Limitations

This note cites the published 1.0 framework and NIST’s public overview. It does not evaluate any portfolio company’s AI program, and it does not treat “RMF aligned” as a measured control state. Trustworthiness characteristics are design goals, not evidence of residual loss.

Back to blogMore in PE and AI