Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Frameworks · comparison

NIST AI RMF and the EU AI Act

One is a voluntary US framework. The other is binding EU law with penalties up to 7% of global turnover. They are not alternatives, and treating a NIST-aligned programme as AI Act readiness is a category error, but the overlap is real enough to be worth mapping properly.

NIST AI RMF 1.0, 26 Jan 2023voluntary · non-certifiable · no EU legal effect

The fundamental difference

NIST AI RMF

  • Voluntary
  • Not certifiable
  • No penalties
  • Outcome-oriented; you choose the artefacts
  • Applies to whoever adopts it

EU AI Act

  • Binding law
  • Conformity assessment and CE marking for high-risk
  • Penalties by tier — up to €15M/3% for high-risk and transparency breaches, €35M/7% for Article 5 prohibitions
  • Prescribed artefacts — Annex IV, declaration of conformity, registration
  • Applies by scope, not by choice. Article 2 →

The category error to avoid

“We follow the NIST AI RMF” is a useful statement about your maturity. It is not an answer to “are you compliant with the EU AI Act?”, and it will not be treated as one by a market surveillance authority, a notified body or a serious procurement team.

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

The crosswalk

Expert analysis. This is a conceptual mapping, not an official one. It is offered as a way for teams already running the framework to find where their existing work lands.

FunctionWhat it coversNearest AI Act homeWhat the AI Act adds
GOVERNPolicies, roles, accountability, culture, third-party riskArt. 17 QMS, particularly the accountability frameworkThirteen enumerated elements, documented as written policies, procedures and instructions.
MAPContext, categorisation, capabilities, impactsArt. 2 scope, Art. 6 classification, Art. 9 identificationClassification has legal consequences and a documentation duty under Art. 6(4). Intended purpose becomes a registered, binding statement.
MEASUREMetrics, testing, evaluation, trackingArt. 15, Art. 9(6) testingDeclared accuracy metrics in the instructions for use, sustained across the lifecycle. Five named attack classes.
MANAGERisk treatment, response, recovery, monitoringArt. 9(5) treatment, Art. 14, Art. 72, Art. 73A prescribed hierarchy of measures, defined oversight capabilities, and statutory incident deadlines of 15, 10 and 2 days.

What the framework does not produce

Even a mature NIST-aligned programme will not have generated these, because nothing in the framework asks for them:

Practical advice for US-headquartered organisations

  1. Let the AI Act set scope. It is the binding instrument; it decides what you must produce and by when.
  2. Keep the framework as the operating structure if your teams already use it. Re-teaching a governance vocabulary is a real cost with no compliance benefit.
  3. Map once, explicitly. A written crosswalk from your existing controls to the AI Act articles is worth more than a second parallel programme.
  4. Check scope before assuming you are out. The output-used-in-the-EU hook catches organisations with no EU entity and no EU customers of record. Article 2 →

Status labels on this page

Verified fact: The NIST AI RMF's release date, voluntary and non-certifiable nature, four core functions, and the AI Act artefacts listed above.

Expert analysis: The entire crosswalk, which is conceptual and ours rather than official.

Unsettled: Whether any formal EU recognition of non-EU frameworks emerges. None exists today.

Next step

Map your existing controls once

The efficient move for a NIST-aligned organisation is a single written crosswalk from what you already run to the AI Act articles, showing what transfers and what has to be built. That document also answers most customer questionnaires.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

What is the NIST AI Risk Management Framework?

The NIST AI Risk Management Framework, released on 26 January 2023, is a voluntary framework published by the US National Institute of Standards and Technology to help organisations manage risks associated with AI. It is organised around four core functions: GOVERN, MAP, MEASURE and MANAGE. It is accompanied by a Playbook of suggested actions and by profiles, including a Generative AI Profile. It is voluntary, non-certifiable, and creates no legal obligations.

Does the NIST AI RMF satisfy the EU AI Act?

No. The NIST AI RMF is a voluntary US framework with no legal effect in the European Union. It is not a harmonised standard and confers no Article 40 presumption of conformity. Following it is useful preparation because the governance vocabulary and much of the process overlap with what the AI Act requires, but conformity is assessed against the Regulation, not against the framework.

How does the NIST AI RMF map to the EU AI Act?

GOVERN maps loosely onto the Article 17 quality management system and the accountability framework it requires. MAP maps onto scope determination, classification and the identification limb of Article 9. MEASURE maps onto Article 15 accuracy and robustness testing and onto the Article 9 testing requirement. MANAGE maps onto Article 9 risk treatment, Article 14 human oversight and the Article 72 post-market monitoring loop. The mapping is conceptual rather than one-to-one, and the AI Act adds prescribed artefacts the framework does not require.

Which should a US company do first, NIST AI RMF or EU AI Act?

If you have EU exposure, the AI Act creates binding obligations with penalties and the NIST framework does not, so the AI Act determines what you must produce and by when. The NIST framework is a reasonable way to organise the work internally, particularly for organisations that already use it, but it should not set the scope. The practical approach is to run the AI Act obligations as the requirement set and use whichever framework your teams already know as the operating structure.