Compliance Automation Toolby Agent Trust Cloud

AI regulatory compliance

Three texts shape most AI compliance programmes: the EU AI Act (binding law in the EU), the NIST AI Risk Management Framework (voluntary, US) and ISO/IEC 42001 (an international standard you can be certified against). They overlap heavily; the table below shows where.

EU AI Act: dates that matter

Regulation (EU) 2024/1689 applies in stages under its Article 113:

Regulation (EU) 2026/1744 (the Digital Omnibus on AI) amended the Act. It sets the date for the high-risk requirements in Chapter III, Sections 1 to 3 to 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and 2 August 2028 for those under Article 6(1) and Annex I. It also rewrote Article 4 so that providers and deployers take measures to support the AI literacy of their staff. Obligations depend on your role (provider, deployer, importer or distributor) and on how each system is classified; this page is not legal advice.

NIST AI RMF

The NIST AI RMF was released on 26 January 2023 for voluntary use. It is organised into four functions, Govern, Map, Measure and Manage, broken into categories and subcategories such as GOVERN 1.6 (an inventory of AI systems).

ISO/IEC 42001

ISO/IEC 42001:2023 sets requirements for an AI management system and lists reference controls in Annex A. Organisations can be certified against it by accredited certification bodies.

Where they meet: 14 AI controls

ControlEU AI ActNIST AI RMFISO/IEC 42001
AI-POL AI policy–GOVERN 1.25.2, A.2.2
ROLES Security and AI roles assigned–GOVERN 2.15.3, A.3.2
RISK Risk assessment and treatmentArt. 9GOVERN 1.36.1.2, 6.1.3, 8.2
AI-IMPACT AI system impact assessmentArt. 27MAP 1.1, MAP 5.16.1.4, A.5.2, A.5.4
AI-INV AI system and agent inventory–GOVERN 1.6A.4.2, A.4.3
AI-MONITOR AI system event logs and monitoringArt. 12, Art. 72MEASURE 2.4, MANAGE 4.1A.6.2.6, A.6.2.8
INCIDENT Incident responseArt. 73MANAGE 4.3A.8.4
VENDOR Vendor and AI supplier riskArt. 25GOVERN 6.1, MANAGE 3.1A.10.3
TRAINING Security and AI awareness trainingArt. 4GOVERN 2.27.2, 7.3
AI-DATA Data quality and provenance for AIArt. 10MAP 2.3A.7.4, A.7.5, A.7.6
AI-TEST AI testing, including security and misuseArt. 15MEASURE 2.5, MEASURE 2.7A.6.2.4
AI-OVERSIGHT Human oversight of AI decisions and actionsArt. 14, Art. 26GOVERN 3.2A.9.4
AI-TRANSPARENCY Information for users about AIArt. 13, Art. 50MEASURE 2.9A.8.2
AUDIT Internal audit and management review–GOVERN 1.59.2, 9.3

References point to the official texts; descriptions are our own. Many EU AI Act articles listed here apply to high-risk systems only, so check each system's classification first. For security frameworks alongside these, see compliance control mapping.

Map your AI controls across all three

Sources

Questions

When do the EU AI Act's high-risk rules apply?

Regulation (EU) 2026/1744 moved the high-risk requirements in Chapter III, Sections 1 to 3: to 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and to 2 August 2028 for those under Article 6(1) and Annex I. Check EUR-Lex for later changes.

Is the NIST AI RMF mandatory?

No. NIST released the AI Risk Management Framework on 26 January 2023 for voluntary use.

Can we be certified for AI governance?

Yes, against ISO/IEC 42001:2023, the AI management system standard, by an accredited certification body. Neither the NIST AI RMF nor the AI Act is a certification scheme of that kind.