Direct comparison
EU AI Act vs NIST AI RMF vs ISO 42001
Binding law, voluntary framework, or certifiable standard? How the EU AI Act, NIST AI RMF, and ISO/IEC 42001 differ in scope, obligations, and conformance.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · free to try
Ask about EU AI Act vs NIST AI RMF vs ISO 42001
Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.
Ask CASRAI answers research-administration questions and cites the passages behind every claim. When our sources don't cover a question, it says so.
Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
Works on this site and inside Claude, Cursor and the AI tools you already use.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do EU AI Act, NIST AI RMF, ISO/IEC 42001 compare side by side?
The table below compares EU AI Act, NIST AI RMF, ISO/IEC 42001 across 5 procurement-relevant dimensions, from what kind of instrument it is through current timeline / status (as of september 2026).
Side-by-side comparison
| Dimension | EU AI Act | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|---|
| What kind of instrument it is | Binding EU law (Regulation (EU) 2024/1689). Entered into force 1 August 2024; non-compliance carries fines set out in the Regulation. | Voluntary framework published by NIST, a US federal agency. Explicitly non-regulatory — NIST states it is "intended for voluntary use." | A certifiable international management-system standard (published 2023), structured like ISO/IEC 27001. Adoption and certification are both voluntary, but certification against it is independently audited. |
| What it covers | A risk-tiered rulebook: prohibited practices (e.g. social scoring, manipulative techniques), high-risk systems in domains listed in Annex III (employment, education, law enforcement, critical infrastructure, etc.) and Annex I (AI embedded in already-regulated products), limited-risk transparency duties (e.g. disclosing AI-generated content), and separate obligations for general-purpose AI (GPAI) models, with extra duties for GPAI models trained above 10^25 FLOPs. | Trustworthy-AI risk management organized around four functions — Govern, Map, Measure, Manage — plus voluntary use-case profiles, including a dedicated Generative AI Profile (NIST-AI-600-1, July 2024). | Requirements for an organization-wide AI management system: leadership commitment, risk assessment, resourcing, documented processes and controls across the AI lifecycle from design through decommissioning, and continual improvement — the same plan-do-check-act structure as other ISO management-system standards. |
| Who it applies to | Providers and deployers of AI systems placed on or used in the EU market, regardless of where the provider is established — reach is extraterritorial if the system's output is used in the EU. Providers carry the heavier obligations; deployers (organizations using the system professionally) carry lighter ones. | Any organization designing, developing, deploying, or evaluating AI systems that chooses to adopt it — there is no jurisdictional trigger because there is no legal obligation to begin with. | Any organization, of any size or sector, that provides or uses AI-based products or services — an organization defines and scopes its own AI management system before seeking certification. |
| How conformance is demonstrated | High-risk providers must maintain technical documentation, run a conformity assessment (internal control, or a notified body for certain systems), issue an EU declaration of conformity, affix CE marking, and register the system in the EU database. | No conformance or certification mechanism exists. Organizations self-assess against the framework's functions and categories; NIST does not audit or certify anyone against the AI RMF. | Independent, accredited third-party certification: an accredited certification body audits the organization's AI management system against the standard's clauses and issues a time-limited certificate. ISO itself does not certify organizations — certification bodies do, overseen by national accreditation bodies. |
| Current timeline / status (as of September 2026) | Article 5 prohibited-practices rules have applied since 2 February 2025; GPAI provider obligations since 2 August 2025. Following the July 2026 Digital Omnibus (Regulation (EU) 2026/1744), high-risk obligations were deferred: Annex III standalone high-risk systems now apply from 2 December 2027, and Annex I product-embedded high-risk systems from 2 August 2028. Article 50 AI-generated-content transparency duties remained on the original 2 August 2026 schedule. | AI RMF 1.0 has been in effect since January 2023 and is unchanged in legal status; NIST continues to publish companion profiles (e.g. the Generative AI Profile) rather than amending the core framework's voluntary status. | In effect since publication in 2023; accredited certification bodies (e.g. through UKAS, ANAB and equivalent national accreditation bodies) have been issuing certificates since 2024, and adoption has grown alongside the EU AI Act's compliance deadlines as organizations look for external assurance mechanisms. |
Common questions
Common questions about EU AI Act vs NIST AI RMF vs ISO/IEC 42001
Does getting ISO/IEC 42001 certified satisfy the EU AI Act's conformity assessment requirements?
+
Not by itself. ISO/IEC 42001 certification is not a legal requirement under the AI Act and does not automatically satisfy the Act's conformity assessment, CE marking, or EU database registration obligations for high-risk systems. Many organizations use an ISO/IEC 42001 AI management system as the internal governance foundation that supports their AI Act compliance work, but the Act's specific conformity assessment procedure is a separate, mandatory step for providers of high-risk systems.
Can an organization use the NIST AI RMF instead of complying with the EU AI Act?
+
No. The NIST AI RMF is voluntary US guidance with no legal force in the EU or anywhere else. An organization placing an AI system on the EU market is subject to the AI Act's binding obligations regardless of whether it also follows the NIST framework. The two are not alternatives — organizations that must comply with the AI Act sometimes use the RMF's Govern-Map-Measure-Manage structure to organize the internal risk-management work the Act requires, but adopting the RMF does not discharge any legal obligation.
Do these three actually work together, or is picking one enough?
+
They address different questions, so most organizations operating in this space end up touching more than one: the EU AI Act determines whether an organization has binding legal obligations at all (and what they are), the NIST AI RMF offers a widely used internal structure for organizing AI risk-management activities regardless of jurisdiction, and ISO/IEC 42001 certification offers a way to demonstrate that internal governance to customers, partners, and auditors through independent, accredited assessment. None of the three is a drop-in substitute for either of the others.







