The three pillars: EU AI Act, NIST AI RMF, ISO/IEC 42001

Lesson 5 of 5 in How AI Governance Works: Laws, Standards, and Everything Between.

Everything you have learned in this module converges on three documents. Whatever corner of AI governance you end up working in, these are the pillars every conversation assumes — one from each layer of the stack: a binding statute, a voluntary framework, and a certifiable standard. This lesson gives you the orientation tour; each pillar gets its own full domain later in the path.

Meet them as answers to three different questions. The EU AI Act answers "what does the law require?" The NIST AI RMF answers "how do we think about and manage AI risk?" ISO/IEC 42001 answers "how do we run an organization so that trustworthy AI happens repeatably — and prove it to an auditor?" Different questions, deliberately compatible answers: 42001-style management systems help satisfy AI Act obligations, and NIST’s risk vocabulary maps onto both.

EU AI Act

The world’s first comprehensive, binding, horizontal AI statute. Adopted 2024; obligations phasing in through 2028.

Its architecture is the risk pyramid you met in the harms module’s sequel: prohibited practices (Art 5), high-risk systems (Art 6 + Annex III) carrying the full obligation load — risk management, data governance, documentation, logging, transparency, human oversight, accuracy and robustness (Arts 8–15) — transparency-risk systems like chatbots and deepfakes (Art 50), and everything else left alone. A separate track governs general-purpose AI models (Arts 51–56), with extra duties above the 10²⁵-FLOP systemic-risk threshold.

Enforced by national authorities plus a new EU AI Office for GPAI; fines reach €35M/7% of turnover. Extraterritorial: it catches providers anywhere whose systems’ outputs are used in the EU — the Brussels effect in statutory form.

NIST AI RMF

The United States’ flagship contribution — and proof that soft law can organize a field. Version 1.0 landed January 2023; a Generative AI Profile followed July 2024.

The RMF defines seven trustworthiness characteristics (valid & reliable, safe, secure & resilient, accountable & transparent, explainable & interpretable, privacy-enhanced, fair with harmful bias managed) and four functions — Govern, Map, Measure, Manage — describing outcomes, not rules. Organizations build profiles tailoring it to their context.

Entirely voluntary; NIST regulates nobody. Yet it shows up everywhere: in federal procurement expectations, in state statutes offering safe harbors to companies that follow it, in insurer questionnaires, and in courtrooms as the reference for reasonable AI risk practice.

ISO/IEC 42001

The certifiable one. Published December 2023 — the first AI management system standard (AIMS), doing for AI what ISO 27001 did for information security.

It doesn’t evaluate your model; it evaluates your organization: leadership commitment, an AI policy, risk and impact assessment processes, lifecycle controls, supplier management, continual improvement — with an Annex A catalogue of AI-specific controls. Accredited certification bodies audit against it, so conformity becomes a portable, third-party-verified trust signal you can hand to customers and regulators.

Watch the layers interlock: European harmonized standards for the AI Act draw on ISO/IEC work, and a certified AIMS gives any company a running start on the AI Act’s quality-management obligations (Art 17). Voluntary standard, statutory gravity.

The three pillars at a glance
EU AI ActNIST AI RMFISO/IEC 42001

What it is

Binding statute (regulation)

Voluntary risk framework

Certifiable management-system standard

Who wrote it

EU legislature (Parliament + Council)

US NIST, with public consultation

ISO/IEC JTC 1/SC 42 expert committee

Binding?

Yes — fines to €35M / 7% turnover

No — pure soft law

No — but auditable and certifiable once adopted

Core mechanism

Risk tiers: banned → high-risk obligations → transparency → free; separate GPAI track

Govern–Map–Measure–Manage functions; 7 trustworthiness characteristics; profiles

Plan-Do-Check-Act management system + Annex A controls; third-party audit

Unit of attention

The AI system (and GPAI model) and its use case

The risk across the AI lifecycle

The organization and its processes

You would reach for it when…

Determining legal obligations for an EU-touching system

Structuring how your team identifies and manages AI risk

Building a governance program you can certify and show to customers

How the three pillars arrived

  • 2019-02-11EO 13859 — American AI Initiative:

    The first US executive order on AI: R&D investment and NIST tasked with technical standards — the seed of the AI RMF.

  • 2021-04-21European Commission proposes the AI Act:

    The first comprehensive horizontal AI law: product-safety architecture, risk tiers, prohibited practices. Three years of negotiation begin.

  • 2022-03-15NIST SP 1270 on AI bias:

    Names three bias families — systemic, computational, and human-cognitive — reframing bias as a socio-technical problem, not just a dataset defect.

  • 2023-01-26NIST AI RMF 1.0 released:

    Govern, Map, Measure, Manage — the voluntary framework that becomes the de facto grammar of US AI risk management and a safe-harbor hook in state laws.

  • 2024-07-26NIST Generative AI Profile (AI 600-1):

    Twelve generative-AI risk categories with hundreds of suggested actions — the RMF operationalized for the ChatGPT era.

  • 2023-05-22Commission issues the AI Act standardisation request:

    CEN/CENELEC JTC 21 is formally tasked with the harmonized standards for Arts 9–15 — the technical clock that must beat the legal clock.

  • 2023-12-08AI Act trilogue deal:

    After a 36-hour final negotiation — GPAI rules and biometric carve-outs the sticking points — Parliament, Council, and Commission agree the text.

  • 2023-12-18ISO/IEC 42001 published:

    The world’s first certifiable AI management system standard — clauses 4–10 plus Annex A controls. The ISO 27001 playbook, rebuilt for AI.

  • 2024-08-01EU AI Act enters into force:

    Regulation (EU) 2024/1689 begins its phased application: prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026, high-risk tiers thereafter.

  • 2025-02-02AI Act prohibitions + AI literacy apply:

    The eight Art 5 bans (social scoring, workplace emotion recognition, untargeted face scraping…) become enforceable, alongside the Art 4 AI-literacy duty.

  • 2025-07-10EU GPAI Code of Practice published:

    Three chapters — transparency, copyright, safety & security — the practical compliance route for general-purpose model providers ahead of the August deadline.

  • 2025-08-02AI Act GPAI rules, governance, and penalties apply:

    Model-provider duties (Art 53), systemic-risk obligations (Art 55), the AI Office’s supervisory powers, and the penalty regime all go live.

  • 2025-11-19Digital Omnibus proposes AI Act simplification:

    The Commission’s package defers high-risk application dates — Annex III to 2 Dec 2027, Annex I to 2 Aug 2028 — among wider changes. Final adopted details: check current status.

  • 2026-08-02AI Act general application:

    The Act’s main body applies — transparency duties, governance structures, sandboxes operational in every Member State. High-risk tiers follow on the deferred schedule.

  • 2026-12-02Synthetic-content marking compliance deadline:

    Art 50(2) machine-readable marking and detectability duties for AI-generated content become enforceable (per the Omnibus schedule).

  • 2027-12-02High-risk rules apply — Annex III systems:

    The full Arts 8–15 + conformity-assessment stack becomes enforceable for use-case-based high-risk AI (hiring, credit, education, policing…). Deferred from Aug 2026 by the Omnibus.

  • 2027-08-02Legacy GPAI models must comply:

    Models placed on the market before August 2025 reach their compliance deadline for the Art 53/55 duties.

  • 2028-08-02High-risk rules apply — Annex I products:

    AI embedded in regulated products (machinery, medical devices, vehicles…) reaches full AI Act enforceability, aligned with sectoral conformity regimes.

Tool: Global Governance Atlas — Explore the Governance Atlas: see which instrument types — statutes, frameworks, standards — each jurisdiction leans on, and how the three pillars radiate outward.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.