The three pillars: EU AI Act, NIST AI RMF, ISO/IEC 42001
Lesson 5 of 5 in How AI Governance Works: Laws, Standards, and Everything Between.
Everything you have learned in this module converges on three documents. Whatever corner of AI governance you end up working in, these are the pillars every conversation assumes — one from each layer of the stack: a binding statute, a voluntary framework, and a certifiable standard. This lesson gives you the orientation tour; each pillar gets its own full domain later in the path.
Meet them as answers to three different questions. The EU AI Act answers "what does the law require?" The NIST AI RMF answers "how do we think about and manage AI risk?" ISO/IEC 42001 answers "how do we run an organization so that trustworthy AI happens repeatably — and prove it to an auditor?" Different questions, deliberately compatible answers: 42001-style management systems help satisfy AI Act obligations, and NIST’s risk vocabulary maps onto both.
EU AI Act
The world’s first comprehensive, binding, horizontal AI statute. Adopted 2024; obligations phasing in through 2028.
Its architecture is the risk pyramid you met in the harms module’s sequel: prohibited practices (Art 5), high-risk systems (Art 6 + Annex III) carrying the full obligation load — risk management, data governance, documentation, logging, transparency, human oversight, accuracy and robustness (Arts 8–15) — transparency-risk systems like chatbots and deepfakes (Art 50), and everything else left alone. A separate track governs general-purpose AI models (Arts 51–56), with extra duties above the 10²⁵-FLOP systemic-risk threshold.
Enforced by national authorities plus a new EU AI Office for GPAI; fines reach €35M/7% of turnover. Extraterritorial: it catches providers anywhere whose systems’ outputs are used in the EU — the Brussels effect in statutory form.
NIST AI RMF
The United States’ flagship contribution — and proof that soft law can organize a field. Version 1.0 landed January 2023; a Generative AI Profile followed July 2024.
The RMF defines seven trustworthiness characteristics (valid & reliable, safe, secure & resilient, accountable & transparent, explainable & interpretable, privacy-enhanced, fair with harmful bias managed) and four functions — Govern, Map, Measure, Manage — describing outcomes, not rules. Organizations build profiles tailoring it to their context.
Entirely voluntary; NIST regulates nobody. Yet it shows up everywhere: in federal procurement expectations, in state statutes offering safe harbors to companies that follow it, in insurer questionnaires, and in courtrooms as the reference for reasonable AI risk practice.
ISO/IEC 42001
The certifiable one. Published December 2023 — the first AI management system standard (AIMS), doing for AI what ISO 27001 did for information security.
It doesn’t evaluate your model; it evaluates your organization: leadership commitment, an AI policy, risk and impact assessment processes, lifecycle controls, supplier management, continual improvement — with an Annex A catalogue of AI-specific controls. Accredited certification bodies audit against it, so conformity becomes a portable, third-party-verified trust signal you can hand to customers and regulators.
Watch the layers interlock: European harmonized standards for the AI Act draw on ISO/IEC work, and a certified AIMS gives any company a running start on the AI Act’s quality-management obligations (Art 17). Voluntary standard, statutory gravity.
| EU AI Act | NIST AI RMF | ISO/IEC 42001 | |
|---|---|---|---|
What it is | Binding statute (regulation) | Voluntary risk framework | Certifiable management-system standard |
Who wrote it | EU legislature (Parliament + Council) | US NIST, with public consultation | ISO/IEC JTC 1/SC 42 expert committee |
Binding? | Yes — fines to €35M / 7% turnover | No — pure soft law | No — but auditable and certifiable once adopted |
Core mechanism | Risk tiers: banned → high-risk obligations → transparency → free; separate GPAI track | Govern–Map–Measure–Manage functions; 7 trustworthiness characteristics; profiles | Plan-Do-Check-Act management system + Annex A controls; third-party audit |
Unit of attention | The AI system (and GPAI model) and its use case | The risk across the AI lifecycle | The organization and its processes |
You would reach for it when… | Determining legal obligations for an EU-touching system | Structuring how your team identifies and manages AI risk | Building a governance program you can certify and show to customers |
How the three pillars arrived
- 2019-02-11 — EO 13859 — American AI Initiative:
The first US executive order on AI: R&D investment and NIST tasked with technical standards — the seed of the AI RMF.
- 2021-04-21 — European Commission proposes the AI Act:
The first comprehensive horizontal AI law: product-safety architecture, risk tiers, prohibited practices. Three years of negotiation begin.
- 2022-03-15 — NIST SP 1270 on AI bias:
Names three bias families — systemic, computational, and human-cognitive — reframing bias as a socio-technical problem, not just a dataset defect.
- 2023-01-26 — NIST AI RMF 1.0 released:
Govern, Map, Measure, Manage — the voluntary framework that becomes the de facto grammar of US AI risk management and a safe-harbor hook in state laws.
- 2024-07-26 — NIST Generative AI Profile (AI 600-1):
Twelve generative-AI risk categories with hundreds of suggested actions — the RMF operationalized for the ChatGPT era.
- 2023-05-22 — Commission issues the AI Act standardisation request:
CEN/CENELEC JTC 21 is formally tasked with the harmonized standards for Arts 9–15 — the technical clock that must beat the legal clock.
- 2023-12-08 — AI Act trilogue deal:
After a 36-hour final negotiation — GPAI rules and biometric carve-outs the sticking points — Parliament, Council, and Commission agree the text.
- 2023-12-18 — ISO/IEC 42001 published:
The world’s first certifiable AI management system standard — clauses 4–10 plus Annex A controls. The ISO 27001 playbook, rebuilt for AI.
- 2024-08-01 — EU AI Act enters into force:
Regulation (EU) 2024/1689 begins its phased application: prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026, high-risk tiers thereafter.
- 2025-02-02 — AI Act prohibitions + AI literacy apply:
The eight Art 5 bans (social scoring, workplace emotion recognition, untargeted face scraping…) become enforceable, alongside the Art 4 AI-literacy duty.
- 2025-07-10 — EU GPAI Code of Practice published:
Three chapters — transparency, copyright, safety & security — the practical compliance route for general-purpose model providers ahead of the August deadline.
- 2025-08-02 — AI Act GPAI rules, governance, and penalties apply:
Model-provider duties (Art 53), systemic-risk obligations (Art 55), the AI Office’s supervisory powers, and the penalty regime all go live.
- 2025-11-19 — Digital Omnibus proposes AI Act simplification:
The Commission’s package defers high-risk application dates — Annex III to 2 Dec 2027, Annex I to 2 Aug 2028 — among wider changes. Final adopted details: check current status.
- 2026-08-02 — AI Act general application:
The Act’s main body applies — transparency duties, governance structures, sandboxes operational in every Member State. High-risk tiers follow on the deferred schedule.
- 2026-12-02 — Synthetic-content marking compliance deadline:
Art 50(2) machine-readable marking and detectability duties for AI-generated content become enforceable (per the Omnibus schedule).
- 2027-12-02 — High-risk rules apply — Annex III systems:
The full Arts 8–15 + conformity-assessment stack becomes enforceable for use-case-based high-risk AI (hiring, credit, education, policing…). Deferred from Aug 2026 by the Omnibus.
- 2027-08-02 — Legacy GPAI models must comply:
Models placed on the market before August 2025 reach their compliance deadline for the Art 53/55 duties.
- 2028-08-02 — High-risk rules apply — Annex I products:
AI embedded in regulated products (machinery, medical devices, vehicles…) reaches full AI Act enforceability, aligned with sectoral conformity regimes.
Tool: Global Governance Atlas — Explore the Governance Atlas: see which instrument types — statutes, frameworks, standards — each jurisdiction leans on, and how the three pillars radiate outward.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.