---
title: "EU AI Act vs NIST AI RMF: legal duties, risk controls, and evidence boundaries"
canonical_url: "https://www.sorena.io/artifacts/eu/artificial-intelligence-act/eu-ai-act-vs-nist-ai-rmf"
source_url: "https://www.sorena.io/artifacts/eu/artificial-intelligence-act/eu-ai-act-vs-nist-ai-rmf"
author: "Sorena AI"
description: "Compare the binding EU AI Act with the voluntary NIST AI RMF, including role classification, high-risk duties, GPAI, transparency, conformity evidence, and reuse limits."
published_at: "2026-05-09"
updated_at: "2026-05-09"
keywords:
  - "EU AI Act"
  - "NIST AI RMF"
  - "high-risk AI"
  - "GPAI"
  - "Article 50 transparency"
  - "conformity assessment"
  - "AI risk management"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# EU AI Act vs NIST AI RMF: legal duties, risk controls, and evidence boundaries

Compare the binding EU AI Act with the voluntary NIST AI RMF, including role classification, high-risk duties, GPAI, transparency, conformity evidence, and reuse limits.

*Comparison* *EU*

## EU AI Act vs NIST AI RMF Binding duties and voluntary risk management

This comparison helps separate AI Act legal obligations from NIST AI RMF risk-management practices.

Map role, risk tier, high-risk controls, GPAI duties, transparency disclosures, conformity evidence, and the points where RMF artifacts can support but not replace AI Act compliance.

The EU AI Act and NIST AI RMF are often used in the same governance program, but they answer different questions. The AI Act creates binding EU rules for covered AI systems and general-purpose AI models. NIST AI RMF is a voluntary framework for identifying, measuring, managing, and governing AI risks. Treat the RMF as a control-design and assurance aid, not as a substitute for AI Act role classification, legal obligations, conformity assessment, registration, transparency, or enforcement duties.

## EU AI Act vs NIST AI RMF: what each one can and cannot do

Use the rows to keep binding EU obligations separate from voluntary risk-management practices while still reusing evidence where the cited duty allows it.

- **EU AI Act**: Binding EU legal regime for covered AI systems and general-purpose AI models, with role-specific duties, risk tiers, conformity routes, transparency duties, governance, and enforcement.
- **NIST AI RMF**: Voluntary AI risk-management framework that can structure governance, mapping, measurement, management, and assurance evidence but does not create EU legal compliance by itself.

| Dimension | EU AI Act | NIST AI RMF | Operational implication | Sources |
| --- | --- | --- | --- | --- |
| Scope boundary | A directly applicable EU Regulation with binding obligations for covered operators, AI systems, and general-purpose AI model providers. | A voluntary risk-management framework referenced in cited source material as intended to improve trustworthiness considerations in AI design, development, use, and evaluation. | Treat AI Act compliance as the legal baseline. Use NIST AI RMF to organise risk work, but do not present RMF adoption as proof that AI Act duties are met. | [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal text establishing binding harmonised AI rules.<br>[ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source that describes NIST AI RMF as intended for voluntary use.<br>[NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - External NIST AI RMF URL present in the cited source material.<br>[European Commission - Standardisation of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation?ref=sorena.io) - Commission source distinguishing voluntary standards from the legal effect of harmonised standards referenced in the Official Journal. |
| Covered actors | Allocates duties by legal role, including provider, deployer, importer, distributor, authorised representative, product manufacturer, and GPAI model provider. | Helps assign governance, risk, technical, operational, and assurance responsibilities, but those owners do not replace AI Act operator roles. | Maintain a role matrix that shows both columns: legal operator status for the AI Act and internal RMF control owner for risk-management execution. | [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for operator roles and role-specific obligations.<br>[NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - NIST source URL for AI risk-management framework use.<br>[Commission GPAI provider guidelines](https://ec.europa.eu/newsroom/dae/redirection/document/118340?ref=sorena.io) - Commission guidance on GPAI provider status and downstream-provider considerations. |
| Trigger | Triggered by AI Act scope facts: placing on the EU market, putting into service, use in the Union, outputs used in the Union, operator role, AI system risk tier, or GPAI model status. | Triggered by an organisation's decision to use the RMF for AI risk management across products, services, systems, suppliers, or governance processes. | Run the AI Act scope test first. An RMF-covered system can still be minimal risk under the AI Act, and an AI Act-covered system can require legal duties even if no RMF program exists. | [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for AI Act territorial scope, operator roles, AI systems, and GPAI model provisions.<br>[ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source for the voluntary-use nature and risk-management purpose of NIST AI RMF.<br>[European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission source for the AI Act risk-based approach and categories of risk. |
| Core obligations | Requires high-risk provider and deployer work such as risk management, dataset governance, logging, technical documentation, information for deployers, human oversight, robustness, accuracy, cybersecurity, monitoring, and serious-incident processes. | Can support those duties by defining control objectives, test plans, evaluations, risk acceptance decisions, monitoring metrics, and governance reviews. | Use RMF evidence to explain the risk method, but check completion against AI Act artifacts and procedures required for the specific high-risk system and role. | [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission source listing strict obligations for high-risk AI systems.<br>[NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - NIST source URL for risk-management support.<br>[Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for high-risk requirements, technical documentation, logging, oversight, and monitoring provisions. |
| Evidence record | May require technical documentation, conformity assessment, EU database registration, EU declaration of conformity, CE marking, post-market monitoring, and authority-facing records depending on the system and role. | Produces useful risk and assurance artifacts, but RMF artifacts are not the same as AI Act conformity assessment, declaration, registration, or CE marking. | Keep an evidence crosswalk: one column for AI Act required artifacts and one column for RMF artifacts that support the rationale, test results, and monitoring record. | [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission source for high-risk conformity workflow, EU database registration, declaration of conformity, CE marking, and post-market monitoring.<br>[Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for conformity procedures, declarations, technical documentation, and registration information.<br>[ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source describing NIST AI RMF as voluntary support for trustworthiness considerations.<br>[European Commission - Standardisation of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation?ref=sorena.io) - Commission source for voluntary standards and legal certainty from harmonised standards, clarifying that not every framework has conformity effect. |
| Risk classification and RMF lifecycle use | Classifies legal risk categories such as prohibited practices, high-risk systems, transparency-risk systems, minimal-risk systems, GPAI models, and GPAI models with systemic risk. | Structures risk management around identifying context, mapping risks, measuring risks, managing risks, and governing the AI lifecycle. | Do not translate RMF risk severity into AI Act high-risk status. High-risk status depends on AI Act criteria, intended purpose, annex coverage, and legal role. | [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission source for unacceptable, high, transparency, and minimal risk categories.<br>[ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source for RMF as voluntary trustworthiness and risk-management support.<br>[Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for high-risk classification and related annex structure. |
| Enforcement | Enforced through AI Act governance, market-surveillance, national competent authority, AI Office, and Commission routes depending on the duty and actor, including GPAI supervision by the Commission. | Assurance depends on voluntary adoption, internal policy, customer commitments, contract terms, procurement requirements, or regulator expectations outside the RMF itself. | Escalate AI Act gaps as legal compliance gaps. Escalate RMF gaps as risk-governance or assurance gaps unless a contract or policy makes them mandatory. | [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for supervision, enforcement, penalties, and GPAI enforcement provisions.<br>[ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source for the voluntary nature of NIST AI RMF.<br>[Commission GPAI provider guidelines](https://ec.europa.eu/newsroom/dae/redirection/document/118340?ref=sorena.io) - Commission guidance for GPAI supervision, investigation, enforcement, and monitoring under Chapter V. |
| Overlap and reuse | AI Act evidence must prove the applicable legal duty: role classification, risk classification, high-risk requirements, GPAI duties, Article 50 disclosures, conformity evidence, and monitoring. | RMF evidence can support the same evidence pack by documenting context, risks, controls, tests, residual risk, monitoring, and governance decisions. | Reuse evidence only when the record names both the AI Act obligation and the RMF function it supports. If the AI Act requires a specific artifact, produce that artifact. | [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal text for the AI Act artifacts and obligations that evidence must support.<br>[NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - NIST source URL for voluntary AI risk-management evidence.<br>[JRC/AI Watch - Harmonised standards for the European AI Act](https://ai-watch.ec.europa.eu/topics/ai-standards_en?ref=sorena.io) - JRC source for presumption of conformity from European harmonised standards published in the Official Journal. |
| Practical decision rule | Creates GPAI model-provider obligations, including technical documentation, downstream information, copyright-policy duties, public training-content summaries, and added systemic-risk duties for qualifying models. | Can help model teams record model context, evaluations, risk treatment, downstream-use assumptions, and monitoring, but does not decide GPAI provider status or systemic-risk classification. | Keep GPAI model evidence separate from application-level RMF evidence, especially where downstream providers need information to comply with the AI Act. | [Commission FAQ - Navigating the AI Act](https://digital-strategy.ec.europa.eu/en/faqs/navigating-ai-act?ref=sorena.io) - Commission FAQ for GPAI documentation, downstream information, copyright policy, training-content summaries, and systemic-risk obligations.<br>[Commission GPAI provider guidelines](https://ec.europa.eu/newsroom/dae/redirection/document/118340?ref=sorena.io) - Commission guidance for provider and downstream-modifier boundaries.<br>[NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - NIST source URL for the risk-management framework side of model governance. |

Sources for Scope boundary - EU AI Act:

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal text establishing binding harmonised AI rules.
  - Quote: "laying down harmonised rules on artificial intelligence"

Sources for Scope boundary - NIST AI RMF:

- [ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source that describes NIST AI RMF as intended for voluntary use.
  - Quote: "intended for voluntary use"
- [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - External NIST AI RMF URL present in the cited source material.
  - Quote: "AI Risk Management Framework"

Sources for Scope boundary - operational implication:

- [European Commission - Standardisation of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation?ref=sorena.io) - Commission source distinguishing voluntary standards from the legal effect of harmonised standards referenced in the Official Journal.
  - Quote: "The application of standards remains voluntary"

Sources for Covered actors - EU AI Act:

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for operator roles and role-specific obligations.
  - Quote: "obligations of providers"

Sources for Covered actors - NIST AI RMF:

- [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - NIST source URL for AI risk-management framework use.
  - Quote: "AI Risk Management Framework"

Sources for Covered actors - operational implication:

- [Commission GPAI provider guidelines](https://ec.europa.eu/newsroom/dae/redirection/document/118340?ref=sorena.io) - Commission guidance on GPAI provider status and downstream-provider considerations.
  - Quote: "providers placing on the market"

Sources for Trigger - EU AI Act:

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for AI Act territorial scope, operator roles, AI systems, and GPAI model provisions.
  - Quote: "providers and deployers"

Sources for Trigger - NIST AI RMF:

- [ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source for the voluntary-use nature and risk-management purpose of NIST AI RMF.
  - Quote: "AI products, services, and systems"

Sources for Trigger - operational implication:

- [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission source for the AI Act risk-based approach and categories of risk.
  - Quote: "defines 4 levels of risk"

Sources for Core obligations - EU AI Act:

- [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission source listing strict obligations for high-risk AI systems.
  - Quote: "strict obligations"

Sources for Core obligations - NIST AI RMF:

- [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - NIST source URL for risk-management support.
  - Quote: "AI Risk Management Framework"

Sources for Core obligations - operational implication:

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for high-risk requirements, technical documentation, logging, oversight, and monitoring provisions.
  - Quote: "technical documentation"

Sources for Evidence record - EU AI Act:

- [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission source for high-risk conformity workflow, EU database registration, declaration of conformity, CE marking, and post-market monitoring.
  - Quote: "declaration of conformity"
- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for conformity procedures, declarations, technical documentation, and registration information.
  - Quote: "EU declaration of conformity"

Sources for Evidence record - NIST AI RMF:

- [ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source describing NIST AI RMF as voluntary support for trustworthiness considerations.
  - Quote: "design, development, use, and evaluation"

Sources for Evidence record - operational implication:

- [European Commission - Standardisation of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation?ref=sorena.io) - Commission source for voluntary standards and legal certainty from harmonised standards, clarifying that not every framework has conformity effect.
  - Quote: "provide legal certainty"

Sources for Risk classification and RMF lifecycle use - EU AI Act:

- [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission source for unacceptable, high, transparency, and minimal risk categories.
  - Quote: "A Risk-based Approach"

Sources for Risk classification and RMF lifecycle use - NIST AI RMF:

- [ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source for RMF as voluntary trustworthiness and risk-management support.
  - Quote: "incorporate trustworthiness considerations"

Sources for Risk classification and RMF lifecycle use - operational implication:

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for high-risk classification and related annex structure.
  - Quote: "Classification of AI systems as high-risk"

Sources for Enforcement - EU AI Act:

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for supervision, enforcement, penalties, and GPAI enforcement provisions.
  - Quote: "supervise and enforce Chapter V"

Sources for Enforcement - NIST AI RMF:

- [ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source for the voluntary nature of NIST AI RMF.
  - Quote: "intended for voluntary use"

Sources for Enforcement - operational implication:

- [Commission GPAI provider guidelines](https://ec.europa.eu/newsroom/dae/redirection/document/118340?ref=sorena.io) - Commission guidance for GPAI supervision, investigation, enforcement, and monitoring under Chapter V.
  - Quote: "enforcement of the obligations"

Sources for Overlap and reuse - EU AI Act:

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal text for the AI Act artifacts and obligations that evidence must support.
  - Quote: "requirements for high-risk AI systems"

Sources for Overlap and reuse - NIST AI RMF:

- [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - NIST source URL for voluntary AI risk-management evidence.
  - Quote: "AI Risk Management Framework"

Sources for Overlap and reuse - operational implication:

- [JRC/AI Watch - Harmonised standards for the European AI Act](https://ai-watch.ec.europa.eu/topics/ai-standards_en?ref=sorena.io) - JRC source for presumption of conformity from European harmonised standards published in the Official Journal.
  - Quote: "presumption of conformity"

Sources for Practical decision rule - EU AI Act:

- [Commission FAQ - Navigating the AI Act](https://digital-strategy.ec.europa.eu/en/faqs/navigating-ai-act?ref=sorena.io) - Commission FAQ for GPAI documentation, downstream information, copyright policy, training-content summaries, and systemic-risk obligations.
  - Quote: "general-purpose AI models"
- [Commission GPAI provider guidelines](https://ec.europa.eu/newsroom/dae/redirection/document/118340?ref=sorena.io) - Commission guidance for GPAI model scope, provider status, systemic risk, and enforcement.
  - Quote: "scope of the obligations"

Sources for Practical decision rule - NIST AI RMF:

- [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - NIST source URL for the risk-management framework side of model governance.
  - Quote: "AI Risk Management Framework"

Sources for Practical decision rule - operational implication:

- [Commission GPAI provider guidelines](https://ec.europa.eu/newsroom/dae/redirection/document/118340?ref=sorena.io) - Commission guidance for provider and downstream-modifier boundaries.
  - Quote: "downstream providers"

### How should teams use both without confusing them?

- First classify the AI Act role, risk tier, GPAI status, transparency duty, and required legal artifacts.
- Then map RMF functions and controls to the AI Act evidence pack as support, not replacement.
- Keep conformity, registration, declaration, CE marking, transparency, FRIA, GPAI, monitoring, and serious-incident records tied to AI Act sources.
- Use RMF records for governance quality: risk context, control rationale, tests, monitoring metrics, residual risk, and reassessment triggers.

Sources for the practical decision rule:

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for the AI Act side of the decision rule.
  - Quote: "laying down harmonised rules on artificial intelligence"
- [ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source for the NIST AI RMF voluntary-use side of the decision rule.
  - Quote: "intended for voluntary use"
- [European Commission - Standardisation of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation?ref=sorena.io) - Commission source for why voluntary frameworks must be distinguished from harmonised standards and legal AI Act compliance.
  - Quote: "presumed to be compliant"

## Start with legal status before control mapping

The AI Act is a Regulation with binding rules for operators in scope. It uses a risk-based legal structure: prohibited practices, high-risk AI systems, transparency obligations for certain AI systems, rules for general-purpose AI models, and operator-specific duties.

NIST AI RMF is not an EU market-access regime. Grounding material describes it as intended for voluntary use and for improving how organisations incorporate trustworthiness considerations into AI products, services, and systems. That makes it useful for governance, risk reviews, and evidence planning, but it does not decide whether an AI Act obligation applies.

- Use the AI Act to decide whether the product, model, role, market activity, or output is legally in scope.
- Use NIST AI RMF to structure risk conversations, controls, evaluations, monitoring, and governance records.
- Do not mark an AI Act requirement complete only because an RMF control exists; tie completion to the specific AI Act article, annex, or official guidance source.

Sources for this answer:

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal text for binding AI Act scope, operator roles, high-risk requirements, GPAI duties, transparency duties, conformity evidence, and enforcement provisions.
- [ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source that references NIST AI RMF and states that the framework is intended for voluntary use.
- [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - External NIST AI RMF URL present in the cited source material as the risk-management framework source.

## Classify AI Act role and risk before reusing RMF artifacts

The AI Act comparison starts with legal classification: provider, deployer, importer, distributor, authorised representative, product manufacturer, GPAI model provider, and whether a downstream modifier has become a provider. It then asks whether the system is prohibited, high-risk, subject to transparency duties, or connected to a GPAI model.

NIST AI RMF can help document context, intended use, affected groups, risks, measurements, and risk treatment decisions. Those records are valuable only if they are labelled against the AI Act duty they support: for example, high-risk technical documentation, provider instructions, deployer human oversight, FRIA, GPAI documentation, or transparency notices.

- Keep an AI Act role/risk register separate from the RMF risk register, even if both link to the same product inventory.
- For high-risk systems, connect RMF evaluation and monitoring evidence to AI Act requirements such as risk management, data governance, logging, documentation, human oversight, accuracy, robustness, and cybersecurity.
- For GPAI, separate model-provider documentation, downstream information, copyright policy, training-content summary, systemic-risk assessment, and serious-incident handling from generic model-risk notes.

Sources for this answer:

- [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission page summarising the AI Act risk-based approach, high-risk obligations, transparency risk, conformity steps, and GPAI rules.
- [Commission FAQ - Navigating the AI Act](https://digital-strategy.ec.europa.eu/en/faqs/navigating-ai-act?ref=sorena.io) - Commission FAQ for GPAI obligations, systemic-risk concepts, voluntary GPAI Code of Practice, and Article 50 transparency context.
- [Commission GPAI provider guidelines](https://ec.europa.eu/newsroom/dae/redirection/document/118340?ref=sorena.io) - Commission guidelines on the scope of GPAI model obligations, provider status, systemic risk, documentation, and enforcement under Chapter V.

## Use RMF evidence as support, not legal proof by itself

The AI Act has evidence boundaries that the RMF does not create: technical documentation, EU declaration of conformity, CE marking where applicable, EU database registration for relevant high-risk systems, deployer FRIA records, GPAI model documentation, downstream information, public training-content summaries, transparency disclosures, post-market monitoring, and serious-incident records.

NIST AI RMF artifacts can make those records stronger by giving a repeatable risk-management method, but they do not create a presumption of conformity. Grounding material distinguishes voluntary frameworks from European harmonised standards: only harmonised standards referenced in the Official Journal can provide the AI Act presumption of conformity described by Commission sources.

- Label each evidence item with its AI Act duty and its RMF function, such as Govern, Map, Measure, or Manage.
- Use RMF outputs to explain why controls were chosen, how risks were measured, and how monitoring will continue.
- Use AI Act sources to prove market-access steps, conformity assessment, disclosures, registration, and authority-facing evidence.

Sources for this answer:

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for technical documentation, declaration of conformity, conformity assessment, registration, post-market monitoring, and enforcement provisions.
- [European Commission - Standardisation of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation?ref=sorena.io) - Commission source explaining that standards remain voluntary and that harmonised standards referenced in the Official Journal provide legal certainty.
- [JRC/AI Watch - Harmonised standards for the European AI Act](https://ai-watch.ec.europa.eu/topics/ai-standards_en?ref=sorena.io) - JRC source for the role of harmonised standards in presumption of conformity and the need to address health, safety, and fundamental-rights risks.

*Recommended next step*

*Placement: before sources*

## Separate legal duties from risk-management controls

Sorena can help map AI Act roles, risk tiers, GPAI duties, transparency notices, and conformity evidence to reusable RMF controls without treating the RMF as a replacement for EU legal compliance.

- [Open Research Copilot for EU AI Act](/solutions/research-copilot.md): Ask questions tied to cited sources about AI Act role classification, high-risk duties, GPAI, Article 50 transparency, and evidence boundaries.
- [Talk through implementation](/contact.md): Review where NIST AI RMF artifacts can support your AI Act evidence pack and where separate legal work is still required.

## Primary sources

- [Regulation (EU) 2024/1689 (AI Act)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689&ref=sorena.io) - Primary legal source for the AI Act side of the decision rule.
  - Quote: "laying down harmonised rules on artificial intelligence"
- [European Commission - AI Act regulatory framework](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai?ref=sorena.io) - Commission source for unacceptable, high, transparency, and minimal risk categories.
  - Quote: "A Risk-based Approach"
- [ETSI White Paper 52 - ETSI activities in the field of AI](https://www.etsi.org/images/files/ETSIWhitePapers/ETSI-WP52-ETSI-activities-in-the-field-of-AI.pdf?ref=sorena.io) - Source for the NIST AI RMF voluntary-use side of the decision rule.
  - Quote: "intended for voluntary use"
- [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework?ref=sorena.io) - NIST source URL for the risk-management framework side of model governance.
  - Quote: "AI Risk Management Framework"
- [European Commission - Standardisation of the AI Act](https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation?ref=sorena.io) - Commission source for why voluntary frameworks must be distinguished from harmonised standards and legal AI Act compliance.
  - Quote: "presumed to be compliant"
- [Commission GPAI provider guidelines](https://ec.europa.eu/newsroom/dae/redirection/document/118340?ref=sorena.io) - Commission guidance for provider and downstream-modifier boundaries.
  - Quote: "downstream providers"
- [JRC/AI Watch - Harmonised standards for the European AI Act](https://ai-watch.ec.europa.eu/topics/ai-standards_en?ref=sorena.io) - JRC source for presumption of conformity from European harmonised standards published in the Official Journal.
  - Quote: "presumption of conformity"
- [Commission FAQ - Navigating the AI Act](https://digital-strategy.ec.europa.eu/en/faqs/navigating-ai-act?ref=sorena.io) - Commission FAQ for GPAI documentation, downstream information, copyright policy, training-content summaries, and systemic-risk obligations.
  - Quote: "general-purpose AI models"

## Related Topic Guides

- [Are industry AI use cases high-risk under EU AI Act Annex III?](/artifacts/eu/artificial-intelligence-act/faq/annex-iii-industry-use-cases.md): FAQ answer on when an industry AI use case falls under EU AI Act Annex III, how Article 6 classification works, when Article 6(3) can support a non-high-risk conclusion, and what evidence providers should keep.
- [EU AI Act AI System Classification Edge Cases FAQ](/artifacts/eu/artificial-intelligence-act/faq/ai-system-classification-edge-cases.md): Answers for EU AI Act edge cases: AI system definition, inference versus simple rules, GPAI models, embedded products, territorial scope, roles, and classification evidence.
- [EU AI Act Applicability and Roles: Scope, Actor Map, and Evidence](/artifacts/eu/artificial-intelligence-act/applicability-and-roles.md): Determine whether the EU AI Act applies to an AI system or GPAI model, map provider, deployer, importer, distributor, and product manufacturer roles, and record evidence for classification.
- [EU AI Act applicability test: scope, role, and risk classification](/artifacts/eu/artificial-intelligence-act/applicability-test.md): Stepwise EU AI Act applicability test for AI-system status, exclusions, territorial scope, operator role, prohibited uses, high-risk systems, GPAI models, transparency duties, and evidence records.
- [EU AI Act Article 5 Prohibited AI Practices Screening Guide](/artifacts/eu/artificial-intelligence-act/prohibited-ai-practices.md): Screen AI systems against the EU AI Act Article 5 prohibitions, including manipulation, exploitation, social scoring, biometric and law-enforcement exceptions.
- [EU AI Act Article 50 transparency disclosures FAQ](/artifacts/eu/artificial-intelligence-act/faq/article-50-transparency-disclosures.md): Article 50 FAQ for EU AI Act transparency duties covering chatbot notices, synthetic content marking, biometric and emotion notices, deepfakes, public-interest text, timing, accessibility, and exceptions.
- [EU AI Act Article 50 transparency, labeling, and user disclosures](/artifacts/eu/artificial-intelligence-act/transparency-labeling-and-user-disclosures.md): Source-backed guide to EU AI Act Article 50 duties for user interaction notices, synthetic content marking, deepfake labels, emotion recognition notices, biometric categorisation notices, and related high-risk AI instructions for use.
- [EU AI Act Article 73 serious incident FAQ](/artifacts/eu/artificial-intelligence-act/faq/serious-incidents.md): FAQ on EU AI Act serious incident handling for high-risk AI systems, including Article 73 reporting, deployer escalation, corrective action, and GPAI systemic-risk distinctions.
- [EU AI Act Compliance Checklist by Risk Class](/artifacts/eu/artificial-intelligence-act/checklist.md): A practical EU AI Act checklist for classifying AI systems, assigning operator roles, screening prohibited practices, and collecting evidence for high-risk, GPAI, transparency, monitoring, and incident duties.
- [EU AI Act Compliance Program: roles, high-risk evidence, GPAI and incidents](/artifacts/eu/artificial-intelligence-act/compliance.md): Build an EU AI Act compliance program around provider, deployer, importer, distributor, high-risk, GPAI, transparency, monitoring, and incident evidence duties.
- [EU AI Act conformity assessment and notified bodies for high-risk AI](/artifacts/eu/artificial-intelligence-act/conformity-assessment-and-notified-bodies.md): Source-backed guide to EU AI Act high-risk AI conformity assessment routes, provider evidence, EU declaration of conformity, CE marking, and notified body involvement.
- [EU AI Act deadlines and compliance calendar | Article 113 dates](/artifacts/eu/artificial-intelligence-act/deadlines-and-compliance-calendar.md): EU AI Act compliance calendar for Article 113 staged application dates, Article 111 transitions, GPAI, prohibited practices, AI literacy, and high-risk AI planning.
- [EU AI Act FAQ: scope, roles, high-risk AI, GPAI, FRIA, and dates](/artifacts/eu/artificial-intelligence-act/faq.md): Source-backed EU AI Act FAQ covering scope, provider and deployer roles, prohibited practices, high-risk classification, GPAI duties, transparency notices, FRIAs, EU database registration, serious incidents, and staged application dates.
- [EU AI Act FRIA FAQ: Article 27 Scope, Contents, and Notification](/artifacts/eu/artificial-intelligence-act/faq/fria.md): Source-backed FAQ on when Article 27 requires a fundamental rights impact assessment, which deployers are covered, what the FRIA must contain, and how it relates to DPIAs and registration.
- [EU AI Act FRIA for high-risk AI systems: Article 27 scope and evidence](/artifacts/eu/artificial-intelligence-act/fria-and-high-risk-impact-assessments.md): Source-backed guide to EU AI Act Article 27 fundamental rights impact assessments: who must run a FRIA, Article 6(2) triggers, Annex III carveouts, DPIA overlap, notification, and registration evidence.
- [EU AI Act GPAI and Systemic-Risk Duties: Article 53 and 55 FAQ](/artifacts/eu/artificial-intelligence-act/faq/gpai-and-systemic-risk-duties.md): FAQ on EU AI Act duties for general-purpose AI model providers, including Article 53 documentation, copyright and training-summary duties, Article 55 systemic-risk duties, serious incidents, cybersecurity, and staged enforcement.
- [EU AI Act GPAI evidence pack checklist for Article 53 and 55](/artifacts/eu/artificial-intelligence-act/gpai-evidence-pack-workflow.md): Build a source-backed evidence pack for EU AI Act GPAI model obligations: technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk records where applicable.
- [EU AI Act GPAI Provider Obligations: Articles 53 and 55](/artifacts/eu/artificial-intelligence-act/gpai-and-foundation-model-obligations.md): Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls.
- [EU AI Act High-Risk AI Requirements: Articles 8-16 and 26](/artifacts/eu/artificial-intelligence-act/requirements.md): Map the EU AI Act requirements for high-risk AI systems: risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness, cybersecurity, and deployer duties.
- [EU AI Act high-risk AI use cases by industry | Article 6 and Annex III guide](/artifacts/eu/artificial-intelligence-act/high-risk-ai-use-cases-by-industry.md): Industry-by-industry guide to EU AI Act high-risk classification under Article 6, Annex III, Annex I product safety routes, exclusions, and provider/deployer boundaries.
- [EU AI Act high-risk conformity assessment route selector](/artifacts/eu/artificial-intelligence-act/high-risk-conformity-route-selector-workflow.md): Select the EU AI Act Article 43 conformity assessment route for a high-risk AI system, including Annex I product legislation, Annex III categories, notified body triggers, standards, declaration, CE marking, registration, and evidence.
- [EU AI Act high-risk requirements checklist: Articles 8-15](/artifacts/eu/artificial-intelligence-act/high-risk-requirements-checklist.md): Checklist for EU AI Act high-risk AI system requirements in Articles 8-15: risk management, data governance, documentation, logs, transparency, human oversight, accuracy, robustness, and cybersecurity.
- [EU AI Act penalties and fines: Article 99 tiers and GPAI exposure](/artifacts/eu/artificial-intelligence-act/penalties-and-fines.md): EU AI Act penalties explained: Article 99 fine tiers, prohibited-practice exposure, incorrect information, SME caps, Member State rules, and GPAI model fines.
- [EU AI Act post-market monitoring and serious incident reporting](/artifacts/eu/artificial-intelligence-act/post-market-monitoring-and-serious-incidents.md): Source-backed guide to EU AI Act Articles 72 and 73 for high-risk AI: monitoring plans, serious incident reporting, deployer escalation, corrective action, and GPAI distinctions.
- [EU AI Act post-market monitoring FAQ for high-risk AI systems](/artifacts/eu/artificial-intelligence-act/faq/post-market-monitoring.md): Answer to how providers and deployers should handle EU AI Act post-market monitoring for high-risk AI systems under Article 72, with serious-incident, log, corrective-action, and lifecycle-change triggers.
- [EU AI Act provider vs deployer role boundaries: Article 3 and Article 25 FAQ](/artifacts/eu/artificial-intelligence-act/faq/provider-and-deployer-role-boundaries.md): FAQ on EU AI Act provider, deployer, operator, importer, distributor, authorised representative, product manufacturer, downstream provider, and GPAI model provider boundaries.
- [EU AI Act risk classification intake workflow](/artifacts/eu/artificial-intelligence-act/risk-classification-intake-workflow.md): A source-based intake structure for classifying EU AI Act scope, prohibited practices, high-risk routes, Annex III use cases, GPAI model status, roles, and reassessment triggers.
- [EU AI Act serious incident reporting triage workflow: Article 73 and Article 55](/artifacts/eu/artificial-intelligence-act/serious-incident-reporting-triage-workflow.md): Triage EU AI Act serious incidents by definition, actor, reporting route, deadline, deployer escalation, corrective action, and separate GPAI systemic-risk reporting.
- [EU AI Act Technical Documentation and Provider Evidence Templates](/artifacts/eu/artificial-intelligence-act/technical-documentation-and-provider-evidence-templates.md): Build AI Act evidence templates for high-risk AI providers: Article 11 technical documentation, Annex IV fields, quality management, conformity, CE marking, registration, logs, and post-market monitoring.
- [EU AI Act technical documentation FAQ | Article 11 and Annex IV](/artifacts/eu/artificial-intelligence-act/faq/technical-documentation.md): What Article 11 and Annex IV require in high-risk AI technical documentation: system identity, intended purpose, architecture, data, testing, oversight, cybersecurity, conformity, and post-market monitoring.
- [EU AI Act Timeline and Phasing Roadmap: practical obligations and evidence guide](/artifacts/eu/artificial-intelligence-act/timeline-and-phasing-roadmap.md): Practical EU AI Act guide to Timeline and Phasing Roadmap: scope, owners, evidence, edge cases, checklist steps, and external citations.
- [EU AI Act vs ISO/IEC 42001: legal duties, controls, and evidence limits](/artifacts/eu/artificial-intelligence-act/eu-ai-act-vs-iso-42001.md): Compare the EU AI Act and ISO/IEC 42001 across legal status, risk classification, high-risk AI, GPAI, transparency, conformity, evidence, and assurance limits.
- [FAQ: EU AI Act conformity assessment procedures and notified body selection](/artifacts/eu/artificial-intelligence-act/faq/conformity-assessment-and-notified-bodies.md): cited FAQ on EU AI Act Article 43 conformity assessment routes, Annex VI internal control, Annex VII notified-body review, CE marking, declarations, and registration.


---

[Privacy Policy](https://www.sorena.io/privacy) | [Terms of Use](https://www.sorena.io/terms-of-use) | [DMCA](https://www.sorena.io/dmca) | [About Us](https://www.sorena.io/about-us)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/artificial-intelligence-act/eu-ai-act-vs-nist-ai-rmf
