EU AI Act vs NIST AI RMF Binding duties and voluntary risk management
Use the EU AI Act for the binding legal decision and NIST AI RMF 1.0 for voluntary AI risk management. RMF adoption does not establish AI Act compliance.
Map AI Act roles and duties to GOVERN, MAP, MEASURE, and MANAGE outcomes, while keeping required legal artifacts and regulator-facing decisions separate.
Use the EU AI Act for the legal answer and for the risk-management method. The Act creates binding EU rules for covered AI systems and general-purpose AI models. NIST AI RMF 1.0 is a voluntary, non-sector-specific framework whose Core contains four functions: GOVERN, MAP, MEASURE, and MANAGE. The functions are not a compliance checklist or a required sequence. They can improve context, testing, monitoring, accountability, and risk decisions, but they do not replace AI Act role classification, required records, conformity assessment, registration, transparency, or enforcement duties. NIST states that AI RMF 1.0 is being revised, so record the version used in every crosswalk.
Side-by-side comparison
EU AI Act vs NIST AI RMF: what each one controls
Use the rows to keep binding EU obligations separate from voluntary risk-management practices while still reusing evidence where the cited duty allows it.
Binding EU legal regime for covered AI systems and general-purpose AI models, with role-specific duties, risk tiers, conformity routes, transparency duties, governance, and enforcement.
Second framework
NIST AI RMF
Voluntary AI risk-management framework that can structure governance, mapping, measurement, management, and assurance evidence but does not create EU legal compliance by itself.
is a voluntary, rights-preserving, non-sector-specific, and use-case-agnostic framework for organisations designing, developing, deploying, or using AI systems.
Treat AI Act compliance as the legal baseline. Use NIST AI RMF to organise risk work, but do not present RMF adoption as proof that AI Act duties are met.
Allocates duties by legal role, including provider, deployer, importer, distributor, authorised representative, product manufacturer, and GPAI model provider.
Triggered by AI Act scope facts: placing on the EU market, putting into service, use in the Union, outputs used in the Union, operator role, AI system risk tier, or GPAI model status.
Run the AI Act scope test first. An RMF-covered system can still be minimal risk under the AI Act, and an AI Act-covered system can require legal duties even if no RMF program exists.
The AI Act is organised by legal scope, definitions, risk categories, operator roles, requirements, conformity routes, transparency duties, governance, and enforcement. Its sequence follows the applicable legal provision, not an RMF function.
The AI RMF Core uses four functions: GOVERN is cross-cutting; MAP establishes context and identifies risks; MEASURE analyses, assesses, benchmarks, and monitors risks; MANAGE prioritises and acts on risks. The functions are iterative, and their actions are not a checklist or mandatory sequence.
Map each legal duty to useful RMF outcomes, but do not assume all RMF subcategories apply or that completing selected outcomes closes the legal duty. Record omissions, rationale, owners, and the AI Act evidence still required.
Requires high-risk provider and deployer work such as risk management, dataset governance, logging, technical documentation, information for deployers, human oversight, robustness, accuracy, cybersecurity, monitoring, and serious-incident processes.
Can support those duties by defining control objectives, test plans, evaluations, risk acceptance decisions, monitoring metrics, and governance reviews.
Use RMF evidence to explain the risk method, but check completion against AI Act artifacts and procedures required for the specific high-risk system and role.
May require technical documentation, conformity assessment, EU database registration, EU declaration of conformity, CE marking, post-market monitoring, and authority-facing records depending on the system and role.
Produces useful risk and assurance artifacts, but RMF artifacts are not the same as AI Act conformity assessment, declaration, registration, or CE marking.
Keep an evidence crosswalk: one column for AI Act required artifacts and one column for RMF artifacts that support the rationale, test results, and monitoring record.
Structures risk management through GOVERN, MAP, MEASURE, and MANAGE. These functions support context, risk identification, measurement, prioritisation, treatment, monitoring, and governance across the AI lifecycle.
Do not translate RMF risk severity into AI Act high-risk status. High-risk status depends on AI Act criteria, intended purpose, annex coverage, and legal role.
Enforced through AI Act governance, market-surveillance, national competent authority, AI Office, and Commission routes depending on the duty and actor, including GPAI supervision by the Commission.
Escalate AI Act gaps as legal compliance gaps. Escalate RMF gaps as risk-governance or assurance gaps unless a contract or policy makes them mandatory.
AI Act evidence must prove the applicable legal duty: role classification, risk classification, high-risk requirements, GPAI duties, Article 50 disclosures, conformity evidence, and monitoring.
Reuse evidence only when the record names both the AI Act obligation and the RMF function it supports. If the AI Act requires a specific artifact, produce that artifact.
Creates GPAI model-provider obligations, including technical documentation, downstream information, copyright-policy duties, public training-content summaries, and added systemic-risk duties for qualifying models.
Can help model teams record model context, evaluations, risk treatment, downstream-use assumptions, and monitoring, but does not decide GPAI provider status or systemic-risk classification.
Keep GPAI model evidence separate from application-level RMF evidence, especially where downstream providers need information to comply with the AI Act.
is a voluntary, rights-preserving, non-sector-specific, and use-case-agnostic framework for organisations designing, developing, deploying, or using AI systems.
Treat AI Act compliance as the legal baseline. Use NIST AI RMF to organise risk work, but do not present RMF adoption as proof that AI Act duties are met.
Allocates duties by legal role, including provider, deployer, importer, distributor, authorised representative, product manufacturer, and GPAI model provider.
Triggered by AI Act scope facts: placing on the EU market, putting into service, use in the Union, outputs used in the Union, operator role, AI system risk tier, or GPAI model status.
Run the AI Act scope test first. An RMF-covered system can still be minimal risk under the AI Act, and an AI Act-covered system can require legal duties even if no RMF program exists.
The AI Act is organised by legal scope, definitions, risk categories, operator roles, requirements, conformity routes, transparency duties, governance, and enforcement. Its sequence follows the applicable legal provision, not an RMF function.
The AI RMF Core uses four functions: GOVERN is cross-cutting; MAP establishes context and identifies risks; MEASURE analyses, assesses, benchmarks, and monitors risks; MANAGE prioritises and acts on risks. The functions are iterative, and their actions are not a checklist or mandatory sequence.
Map each legal duty to useful RMF outcomes, but do not assume all RMF subcategories apply or that completing selected outcomes closes the legal duty. Record omissions, rationale, owners, and the AI Act evidence still required.
Requires high-risk provider and deployer work such as risk management, dataset governance, logging, technical documentation, information for deployers, human oversight, robustness, accuracy, cybersecurity, monitoring, and serious-incident processes.
Can support those duties by defining control objectives, test plans, evaluations, risk acceptance decisions, monitoring metrics, and governance reviews.
Use RMF evidence to explain the risk method, but check completion against AI Act artifacts and procedures required for the specific high-risk system and role.
May require technical documentation, conformity assessment, EU database registration, EU declaration of conformity, CE marking, post-market monitoring, and authority-facing records depending on the system and role.
Produces useful risk and assurance artifacts, but RMF artifacts are not the same as AI Act conformity assessment, declaration, registration, or CE marking.
Keep an evidence crosswalk: one column for AI Act required artifacts and one column for RMF artifacts that support the rationale, test results, and monitoring record.
Structures risk management through GOVERN, MAP, MEASURE, and MANAGE. These functions support context, risk identification, measurement, prioritisation, treatment, monitoring, and governance across the AI lifecycle.
Do not translate RMF risk severity into AI Act high-risk status. High-risk status depends on AI Act criteria, intended purpose, annex coverage, and legal role.
Enforced through AI Act governance, market-surveillance, national competent authority, AI Office, and Commission routes depending on the duty and actor, including GPAI supervision by the Commission.
Escalate AI Act gaps as legal compliance gaps. Escalate RMF gaps as risk-governance or assurance gaps unless a contract or policy makes them mandatory.
AI Act evidence must prove the applicable legal duty: role classification, risk classification, high-risk requirements, GPAI duties, Article 50 disclosures, conformity evidence, and monitoring.
Reuse evidence only when the record names both the AI Act obligation and the RMF function it supports. If the AI Act requires a specific artifact, produce that artifact.
Creates GPAI model-provider obligations, including technical documentation, downstream information, copyright-policy duties, public training-content summaries, and added systemic-risk duties for qualifying models.
Can help model teams record model context, evaluations, risk treatment, downstream-use assumptions, and monitoring, but does not decide GPAI provider status or systemic-risk classification.
Keep GPAI model evidence separate from application-level RMF evidence, especially where downstream providers need information to comply with the AI Act.
First classify the AI Act role, risk tier, GPAI status, transparency duty, and required legal artifacts.
Then map AI RMF 1.0 functions and outcomes to the AI Act evidence pack as supporting material; record the RMF version because NIST is revising it.
Keep conformity, registration, declaration, CE marking, transparency, FRIA, GPAI, monitoring, and serious-incident records tied to AI Act sources.
Use RMF records for governance quality: risk context, control rationale, tests, monitoring metrics, residual risk, and reassessment triggers.
Do not treat the Playbook as a mandatory checklist. Select relevant actions, document omissions, and keep the legal completion test in the AI Act crosswalk.
The AI Act is a Regulation with binding rules for operators in scope. It uses a risk-based legal structure: prohibited practices, high-risk AI systems, transparency obligations for certain AI systems, rules for general-purpose AI models, and operator-specific duties.
NIST AI RMF does not set EU market-access rules. NIST describes AI RMF 1.0 as voluntary and intended to improve how organisations incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems. It is useful for governance, risk reviews, and evidence planning, but it does not decide whether an AI Act obligation applies.
Version control matters. NIST says AI RMF 1.0 is being revised. A crosswalk should identify AI RMF 1.0, the date of the mapping, any profile or Playbook material used, and the AI Act provision in force for the relevant system or model.
AI Act provisions apply on different dates. Regulation (EU) 2026/1744 was published on 24 July 2026 and enters into force on 27 July 2026. It keeps 2 August 2026 as the general application date but applies Chapter III Sections 1-3 from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Article 6(1) product-linked systems. Record the legal text and application date used in the same crosswalk as the NIST AI RMF version.
Use the AI Act to decide whether the product, model, role, market activity, or output is legally in scope.
Use to structure governance, context mapping, measurement, risk treatment, monitoring, and reassessment records.
Do not mark an AI Act requirement complete only because an RMF control exists; tie completion to the specific AI Act article, annex, or official guidance source.
Classify AI Act role and risk before reusing RMF artifacts
The AI Act comparison starts with legal classification: provider, deployer, importer, distributor, authorised representative, product manufacturer, GPAI model provider, and whether a downstream modifier has become a provider. It then asks whether the system is prohibited, high-risk, subject to transparency duties, or connected to a GPAI model.
NIST AI RMF can help document context, intended use, affected groups, risks, measurements, and risk treatment decisions. Those records support an AI Act file only when they are mapped to the relevant duty: for example, high-risk technical documentation, provider instructions, deployer human oversight, a fundamental rights impact assessment (FRIA), GPAI documentation, or transparency notices.
Do not convert an RMF risk score into an AI Act category. The Act's high-risk tests depend on Article 6, Annex I or Annex III, intended purpose, operator role, and any applicable exception. RMF severity, likelihood, or risk-tolerance decisions answer a different question.
Keep an AI Act role/risk register separate from the RMF risk register, even if both link to the same product inventory.
For high-risk systems, connect RMF evaluation and monitoring evidence to AI Act requirements such as risk management, data governance, logging, documentation, human oversight, accuracy, robustness, and cybersecurity.
For GPAI, separate model-provider documentation, downstream information, copyright policy, training-content summary, systemic-risk assessment, and serious-incident handling from generic model-risk notes.
The AI Act has evidence boundaries that the RMF does not create: technical documentation, EU declaration of conformity, CE marking where applicable, EU database registration for relevant high-risk systems, deployer FRIA records, GPAI model documentation, downstream information, public training-content summaries, transparency disclosures, post-market monitoring, and serious-incident records.
NIST AI RMF artifacts can support those records by documenting the method, assumptions, measurements, residual risks, owners, and reassessment triggers. They do not create a presumption of conformity. Under the AI Act, that legal effect attaches only to the requirements covered by a relevant harmonised standard or common specification under the conditions in Article 40 or 41.
Keep RMF companion resources distinct. The Core states the functions, categories, and subcategories; the Playbook offers optional suggested actions; profiles adapt outcomes to a sector, technology, or use context. Record which resource and version produced each artifact so a later reviewer can reproduce the mapping.
Label each evidence item with its AI Act duty and its RMF function, such as Govern, Map, Measure, or Manage.
Use RMF outputs to explain why controls were chosen, how risks were measured, and how monitoring will continue.
Use AI Act sources to prove market-access steps, conformity assessment, disclosures, registration, and authority-facing evidence.
Separate legal duties from risk-management controls
Sorena can help map AI Act roles, risk tiers, GPAI duties, transparency notices, and conformity evidence to reusable RMF controls without treating the RMF as a replacement for EU legal compliance.