AI regulatory compliance
Three texts shape most AI compliance programmes: the EU AI Act (binding law in the EU), the NIST AI Risk Management Framework (voluntary, US) and ISO/IEC 42001 (an international standard you can be certified against). They overlap heavily; the table below shows where.
EU AI Act: dates that matter
Regulation (EU) 2024/1689 applies in stages under its Article 113:
- 2 February 2025: Chapters I and II, including the prohibited AI practices and the AI literacy article.
- 2 August 2025: the rules on notifying authorities and notified bodies, general-purpose AI models, governance and penalties (with the exceptions Article 113 lists).
- 2 August 2026: the general date of application, including the Article 50 transparency obligations for certain AI systems (the Omnibus gives providers of generative AI systems already on the market a transition period for the Article 50(2) marking obligation).
Regulation (EU) 2026/1744 (the Digital Omnibus on AI) amended the Act. It sets the date for the high-risk requirements in Chapter III, Sections 1 to 3 to 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and 2 August 2028 for those under Article 6(1) and Annex I. It also rewrote Article 4 so that providers and deployers take measures to support the AI literacy of their staff. Obligations depend on your role (provider, deployer, importer or distributor) and on how each system is classified; this page is not legal advice.
NIST AI RMF
The NIST AI RMF was released on 26 January 2023 for voluntary use. It is organised into four functions, Govern, Map, Measure and Manage, broken into categories and subcategories such as GOVERN 1.6 (an inventory of AI systems).
ISO/IEC 42001
ISO/IEC 42001:2023 sets requirements for an AI management system and lists reference controls in Annex A. Organisations can be certified against it by accredited certification bodies.
Where they meet: 14 AI controls
| Control | EU AI Act | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|---|
| AI-POL AI policy | – | GOVERN 1.2 | 5.2, A.2.2 |
| ROLES Security and AI roles assigned | – | GOVERN 2.1 | 5.3, A.3.2 |
| RISK Risk assessment and treatment | Art. 9 | GOVERN 1.3 | 6.1.2, 6.1.3, 8.2 |
| AI-IMPACT AI system impact assessment | Art. 27 | MAP 1.1, MAP 5.1 | 6.1.4, A.5.2, A.5.4 |
| AI-INV AI system and agent inventory | – | GOVERN 1.6 | A.4.2, A.4.3 |
| AI-MONITOR AI system event logs and monitoring | Art. 12, Art. 72 | MEASURE 2.4, MANAGE 4.1 | A.6.2.6, A.6.2.8 |
| INCIDENT Incident response | Art. 73 | MANAGE 4.3 | A.8.4 |
| VENDOR Vendor and AI supplier risk | Art. 25 | GOVERN 6.1, MANAGE 3.1 | A.10.3 |
| TRAINING Security and AI awareness training | Art. 4 | GOVERN 2.2 | 7.2, 7.3 |
| AI-DATA Data quality and provenance for AI | Art. 10 | MAP 2.3 | A.7.4, A.7.5, A.7.6 |
| AI-TEST AI testing, including security and misuse | Art. 15 | MEASURE 2.5, MEASURE 2.7 | A.6.2.4 |
| AI-OVERSIGHT Human oversight of AI decisions and actions | Art. 14, Art. 26 | GOVERN 3.2 | A.9.4 |
| AI-TRANSPARENCY Information for users about AI | Art. 13, Art. 50 | MEASURE 2.9 | A.8.2 |
| AUDIT Internal audit and management review | – | GOVERN 1.5 | 9.2, 9.3 |
References point to the official texts; descriptions are our own. Many EU AI Act articles listed here apply to high-risk systems only, so check each system's classification first. For security frameworks alongside these, see compliance control mapping.
Sources
Questions
When do the EU AI Act's high-risk rules apply?
Regulation (EU) 2026/1744 moved the high-risk requirements in Chapter III, Sections 1 to 3: to 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and to 2 August 2028 for those under Article 6(1) and Annex I. Check EUR-Lex for later changes.
Is the NIST AI RMF mandatory?
No. NIST released the AI Risk Management Framework on 26 January 2023 for voluntary use.
Can we be certified for AI governance?
Yes, against ISO/IEC 42001:2023, the AI management system standard, by an accredited certification body. Neither the NIST AI RMF nor the AI Act is a certification scheme of that kind.