NIST AI RMF 1.0
The default US vocabulary for AI risk: govern, map, measure, manage. A safe harbor under Texas law.
Approach
The same path every time, so you always know what's next and what it will cost before we start it. It is the way Solidare has always built software; it turns out to be the right way to bring in AI, too.
01
We sit with the people who do the work — not only leadership — and learn how it runs today, what takes the hours, and what's already being pasted into chatbots.
02
What data you hold, where it lives, who touches it, which laws govern it, which AI tools are already in use, and where AI would take real work off the table.
03
Policy, priorities, private or public by class of data, and what to build first. Written so a non-technical board or a room of trustees can approve it in one meeting.
04
Assistants over your own material, connections to the systems you run, agents with approval gates — in your environment, tested against the threats that matter, documented and handed over.
05
We monitor what runs, tune it, and update the rules as AI and the law change. Quarterly reviews with leadership. You own everything we build and can leave with it.
Solidarity principles
These are in every proposal we write. If a client asks us to cross one, we say no and explain why.
Nothing you share with us, or with the AI we build, trains anyone else's model. Data that names a person stays inside your environment.
AI drafts, sorts and flags. A person approves anything that touches a member, an employee, a patient or a dollar. That is written into the build, not left to habit.
Every AI use is disclosed to the people it affects, in plain language, before it affects them.
You own the policies, the agents, the prompts and the setup. If you ever want to walk away, you take it with you. No grant-funded lock-in, no surprise renewal.
We'll tell you when the answer is “not yet” or “not this.” We don't get paid to push a product, and we say so in writing.
What we work to
Aligned, not "certified." We design to these so your program holds up to a regulator, an auditor or a trustee, and so certification is reachable later if you want it.
The default US vocabulary for AI risk: govern, map, measure, manage. A safe harbor under Texas law.
The generative-AI profile: twelve risk categories that shape our use policies.
The AI management-system standard. We design to its structure so certification is reachable later.
The threat lists we build against, for assistants and for agents.
Adversary tactics against AI systems; our threat models map to it.
Industry-endorsed guidance (Aug 2026) we follow for anything touching workers.
Laws we keep track of
Federal guidance on AI in hiring was withdrawn in 2025; Title VII, the ADA, the ADEA and the NLRA still fully apply. The states have filled the gap, and they name dates.
Illinois HB 3773
In force Jan 1, 2026
No discriminatory effect from AI in employment decisions; notice to employees; private right of action.
California CRD regulations
In force Oct 1, 2025
Automated decision systems in employment held to a disparate-impact standard; anti-bias testing as a defense; four-year records.
Texas TRAIGA
In force Jan 1, 2026
Duties for developers and deployers; NIST AI RMF alignment recognized as a safe harbor.
Colorado SB 26-189
Effective Jan 1, 2027
Notice before AI is used in a consequential decision, a plain-language explanation of adverse outcomes, and a path to human review.
California CPPA ADMT rules
Compliance by Jan 1, 2027
Notice, opt-out and risk assessments for automated decision-making about employment and other significant decisions.
NYC Local Law 144
In force since 2023
Annual independent bias audit and candidate notice for automated hiring tools.
This is a summary, not legal advice. We work alongside your counsel and put what they decide into the policy and the build.
Next step
Thirty minutes, the people who do the work, and a plain answer about what AI should and shouldn't do here.
NO SALES DECK · NO OBLIGATION · ASK@SOLIDARE.AI