AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

Not sure where to start? Answer 3 questions and get a tailored compliance action plan.

What applies to me? →
VoluntaryFrameworkUSHigh risk

NIST Artificial Intelligence Technology Evaluation Program

Issued by

National Institute of Standards and Technology, Information Technology Laboratory

liveEffective 2026-08-14NIST AITEVerified August 2026
Official document →

The NIST Artificial Intelligence Technology Evaluation (AITE) program establishes a structured federal approach to testing, benchmarking, and validating AI systems, particularly those with high-impact applications. It applies to AI developers, federal agencies, and enterprises seeking credible, standardized evaluation of their models. The program addresses model testing methodologies, provenance controls, data governance standards, and enterprise validation processes.

Applies To

Large enterprisePublic sectorAI developerAI deployer

Overview

Launched in August 2026 under the NIST Information Technology Laboratory AI Program, AITE provides a coordinated framework for evaluating AI systems against defined performance, safety, and trustworthiness criteria. The program covers model benchmarking, data provenance documentation, and validation workflows designed for high-impact AI deployments across both public and private sectors. It builds on existing NIST AI Risk Management Framework (AI RMF) principles, extending them into operational evaluation practice. Organizations may use AITE-conformant evaluation processes to substantiate AI system claims in procurement, regulatory, and internal governance contexts. NIST intends the program to serve as a reference point for agencies and enterprises developing or procuring AI systems where performance assurance and auditability are required. Enforcement is not mandated under this framework, but conformance may be referenced in federal acquisition requirements and sector-specific regulations.

Key Requirements

  • Conduct AI system evaluations using NIST-defined benchmarking methodologies applicable to high-impact use cases
  • Maintain documented provenance controls for training data, model versions, and evaluation datasets
  • Apply data governance standards that ensure evaluation inputs are traceable, reproducible, and free from undisclosed biases
  • Complete validation processes that produce auditable records suitable for internal review and external scrutiny
  • Align evaluation activities with the NIST AI RMF risk tier classifications to ensure proportionate rigor
  • Retain evaluation documentation in a format that supports third-party review or federal procurement verification

What Your Organization Must Do

  • Audit all high-impact AI systems currently in production and map them to NIST AITE evaluation criteria to identify coverage gaps
  • Establish or update internal model testing protocols to incorporate NIST-aligned benchmarking procedures before procurement or deployment decisions
  • Implement data provenance tracking tools that capture lineage for training and evaluation datasets across the model lifecycle
  • Revise vendor contracts to require AITE-conformant evaluation documentation for any AI system supplied to or deployed within the organization
  • Assign ownership of evaluation records management to a designated governance role, ensuring documentation is audit-ready at all times
  • Monitor NIST ITL publications for supplementary guidance, updated benchmarks, or references to AITE in federal acquisition rules

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Is NIST AITE legally binding for federal agencies procuring AI systems?
NIST AITE is a voluntary framework, not a mandatory regulation. However, conformance may be referenced in federal acquisition requirements, meaning agencies could effectively require AITE-aligned evaluations through contract specifications even without a direct legal mandate.
How does NIST AITE differ from the NIST AI RMF, and do organizations need to comply with both?
The AI RMF provides high-level risk management principles, while AITE extends those principles into operational evaluation and benchmarking practice. Organizations using AITE should align their risk tier classifications with the AI RMF, so the two frameworks work together rather than as independent compliance tracks.
What data provenance documentation does NIST AITE require for AI model evaluations?
Organizations must maintain traceable records covering training data lineage, model version histories, and evaluation dataset origins. Documentation must be reproducible, free from undisclosed biases, and formatted to support both internal audits and potential third-party or federal procurement reviews.
Can NIST AITE conformance be used to satisfy AI evaluation requirements in sector-specific regulations?
NIST intends AITE to serve as a reference point that agencies and enterprises can cite in procurement and regulatory contexts. Whether conformance satisfies a specific sectoral obligation depends on how individual regulators incorporate or reference AITE criteria in their own rules.
What penalties apply if an organization's AI system fails to meet NIST AITE evaluation standards?
NIST AITE carries no direct enforcement mechanism or financial penalties. The primary risk of non-conformance is disqualification from federal procurement opportunities where AITE-aligned evaluation documentation is specified as a contract requirement.
When do organizations need to have AITE-conformant evaluation processes in place given the August 2026 effective date?
The program is currently in draft review with an anticipated effective date of August 14, 2026. Organizations supplying or deploying high-impact AI systems in federal contexts should begin aligning internal benchmarking and provenance protocols now, since procurement rules referencing AITE could appear close to or shortly after that date.