NIST AI RMF and the EU AI Act
One is a voluntary US framework. The other is binding EU law with penalties up to 7% of global turnover. They are not alternatives, and treating a NIST-aligned programme as AI Act readiness is a category error, but the overlap is real enough to be worth mapping properly.
The fundamental difference
NIST AI RMF
- Voluntary
- Not certifiable
- No penalties
- Outcome-oriented; you choose the artefacts
- Applies to whoever adopts it
EU AI Act
- Binding law
- Conformity assessment and CE marking for high-risk
- Penalties by tier — up to €15M/3% for high-risk and transparency breaches, €35M/7% for Article 5 prohibitions
- Prescribed artefacts — Annex IV, declaration of conformity, registration
- Applies by scope, not by choice. Article 2 →
The category error to avoid
“We follow the NIST AI RMF” is a useful statement about your maturity. It is not an answer to “are you compliant with the EU AI Act?”, and it will not be treated as one by a market surveillance authority, a notified body or a serious procurement team.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The crosswalk
Expert analysis. This is a conceptual mapping, not an official one. It is offered as a way for teams already running the framework to find where their existing work lands.
| Function | What it covers | Nearest AI Act home | What the AI Act adds |
|---|---|---|---|
| GOVERN | Policies, roles, accountability, culture, third-party risk | Art. 17 QMS, particularly the accountability framework | Thirteen enumerated elements, documented as written policies, procedures and instructions. |
| MAP | Context, categorisation, capabilities, impacts | Art. 2 scope, Art. 6 classification, Art. 9 identification | Classification has legal consequences and a documentation duty under Art. 6(4). Intended purpose becomes a registered, binding statement. |
| MEASURE | Metrics, testing, evaluation, tracking | Art. 15, Art. 9(6) testing | Declared accuracy metrics in the instructions for use, sustained across the lifecycle. Five named attack classes. |
| MANAGE | Risk treatment, response, recovery, monitoring | Art. 9(5) treatment, Art. 14, Art. 72, Art. 73 | A prescribed hierarchy of measures, defined oversight capabilities, and statutory incident deadlines of 15, 10 and 2 days. |
What the framework does not produce
Even a mature NIST-aligned programme will not have generated these, because nothing in the framework asks for them:
- Annex IV technical documentation in the prescribed nine-heading structure. Annex IV →
- An EU declaration of conformity and CE marking. Conformity assessment →
- Registration in the EU database. Article 49 →
- Article 50 transparency disclosures in the product surface — live now. Article 50 →
- An Article 27 FRIA, for deployers who owe one. FRIA vs DPIA →
- An Article 4 AI literacy record.
Practical advice for US-headquartered organisations
- Let the AI Act set scope. It is the binding instrument; it decides what you must produce and by when.
- Keep the framework as the operating structure if your teams already use it. Re-teaching a governance vocabulary is a real cost with no compliance benefit.
- Map once, explicitly. A written crosswalk from your existing controls to the AI Act articles is worth more than a second parallel programme.
- Check scope before assuming you are out. The output-used-in-the-EU hook catches organisations with no EU entity and no EU customers of record. Article 2 →
Status labels on this page
Verified fact: The NIST AI RMF's release date, voluntary and non-certifiable nature, four core functions, and the AI Act artefacts listed above.
Expert analysis: The entire crosswalk, which is conceptual and ours rather than official.
Unsettled: Whether any formal EU recognition of non-EU frameworks emerges. None exists today.
Map your existing controls once
The efficient move for a NIST-aligned organisation is a single written crosswalk from what you already run to the AI Act articles, showing what transfers and what has to be built. That document also answers most customer questionnaires.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework, released on 26 January 2023, is a voluntary framework published by the US National Institute of Standards and Technology to help organisations manage risks associated with AI. It is organised around four core functions: GOVERN, MAP, MEASURE and MANAGE. It is accompanied by a Playbook of suggested actions and by profiles, including a Generative AI Profile. It is voluntary, non-certifiable, and creates no legal obligations.
Does the NIST AI RMF satisfy the EU AI Act?
No. The NIST AI RMF is a voluntary US framework with no legal effect in the European Union. It is not a harmonised standard and confers no Article 40 presumption of conformity. Following it is useful preparation because the governance vocabulary and much of the process overlap with what the AI Act requires, but conformity is assessed against the Regulation, not against the framework.
How does the NIST AI RMF map to the EU AI Act?
GOVERN maps loosely onto the Article 17 quality management system and the accountability framework it requires. MAP maps onto scope determination, classification and the identification limb of Article 9. MEASURE maps onto Article 15 accuracy and robustness testing and onto the Article 9 testing requirement. MANAGE maps onto Article 9 risk treatment, Article 14 human oversight and the Article 72 post-market monitoring loop. The mapping is conceptual rather than one-to-one, and the AI Act adds prescribed artefacts the framework does not require.
Which should a US company do first, NIST AI RMF or EU AI Act?
If you have EU exposure, the AI Act creates binding obligations with penalties and the NIST framework does not, so the AI Act determines what you must produce and by when. The NIST framework is a reasonable way to organise the work internally, particularly for organisations that already use it, but it should not set the scope. The practical approach is to run the AI Act obligations as the requirement set and use whichever framework your teams already know as the operating structure.