The expansion of generative AI deployments is driving demand for AI TRiSM capabilities focused on model risk, reliability, security, and governance. NIST released the Generative Artificial Intelligence Profile in July 2024 to help organisations identify and manage risks specific to generative AI. In 2026, NIST also released guidance informed by a public working group of more than 2,500 participants, reinforcing the need for structured AI risk-management practices across AI development, deployment, monitoring, governance, and incident management.
Security & runtime control to hold strongest share
The security & runtime control segment is expected to account for the largest share of the AI TRiSM market, driven by the growing need to protect AI models, applications, and agents against security threats and unintended behaviour during operation. Enterprises are increasingly deploying generative and agentic AI systems that interact with sensitive data, users, and enterprise tools, creating risks such as prompt injection, data leakage, unauthorised access, model manipulation, and unsafe agent actions. Runtime controls enable organisations to continuously inspect AI inputs, outputs, interactions, and agent activities while enforcing security and governance policies. The increasing focus on post-deployment AI monitoring and continuous risk management is further supporting adoption, as organisations seek real-time visibility, automated intervention, and policy enforcement to maintain secure, reliable, and compliant AI operations.
SMEs to see the highest growth
The SMEs segment is expected to register the highest CAGR, driven by the rapid adoption of AI applications and the growing need to manage AI-related security, privacy, reliability, and compliance risks with limited internal resources. SMEs increasingly require cost-effective solutions to assess AI models, monitor AI applications, detect security vulnerabilities, and establish governance policies without building dedicated AI risk teams. NIST has specifically developed guidance for small and under-resourced organisations, including its AI RMF and small-enterprise risk-management guidance, supporting structured approaches to managing technology and AI risks. As smaller organisations increasingly deploy generative AI and AI-powered business applications, demand for scalable and easy-to-integrate AI TRiSM solutions is expected to accelerate.
Strong AI ecosystem in North America
North America is expected to account for the largest share of the AI TRiSM market during the forecast period, driven by the region’s strong AI ecosystem, presence of leading technology and cyber security vendors, and increasing enterprise focus on AI governance, security, privacy, and risk management. The US is witnessing accelerated adoption of AI TRiSM capabilities across BFSI, healthcare, government, technology, and critical infrastructure, supported by initiatives such as the NIST AI Risk Management Framework and the 2026 development of an AI RMF Profile for Trustworthy AI in Critical Infrastructure. Leading vendors, including Microsoft, IBM, Palo Alto Networks, and Google, are expanding AI governance, model security, runtime monitoring, AI red teaming, and AI-agent protection capabilities. Microsoft provides AI governance guidance aligned with NIST AI RMF, while Palo Alto Networks is expanding AI TRiSM capabilities across AI governance and runtime enforcement. In Canada, government initiatives supporting safe and responsible AI, including the Safe and Secure Artificial Intelligence Advisory Group, Canadian AI Safety Institute, and Voluntary Code of Conduct for Advanced Generative AI Systems, are further strengthening regional demand for AI risk-management solutions. These developments, coupled with sustained investments in generative AI, agentic AI, cloud technologies, and cyber security, are positioning North America as a leading hub for AI TRiSM innovation, commercialisation, and enterprise adoption.
Some of the key players
Businesses named by the researchers as prominent players in the AI TRisM market include organisations such as, IBM, Microsoft, Palo Alto Networks, Accenture, Deloitte, Neuraltrust, Cisco, Onetrust, Zenity, Credo AI, and Fiddler AI, amongst others.

















