Skip to main content

EU AI Act vs NIST AI RMF vs ISO 42001: the difference, explained

Verified July 31, 2026. Sources listed at the end.

The EU AI Act is a binding law that regulates AI by risk tier for anyone reaching the EU market. The NIST AI RMF is a voluntary US framework for managing AI risk. ISO/IEC 42001 is a certifiable international standard for an AI management system. One is a law, one is a method, one is a certificate, and mature programs use all three.

The three at a glance

EU AI ActNIST AI RMFISO/IEC 42001
What it isA comprehensive, risk-based LAW for AI placed on the EU marketA voluntary FRAMEWORK for managing AI riskA certifiable STANDARD for an AI management system
Legal statusBinding and mandatoryVoluntary, not lawVoluntary, but third-party certifiable
Issued byEuropean Union (Regulation (EU) 2024/1689)US NIST (AI 100-1)ISO and IEC (42001:2023)
ReachThe EU market, including providers outside the EU whose output is used thereGlobal, adopted voluntarilyGlobal, adopted voluntarily
How it is structuredRisk tiers (prohibited, high-risk, transparency, minimal) with duties by roleFour functions: Govern, Map, Measure, ManageA management system (Plan, Do, Check, Act) with Annex A controls
Can you be certified?No org certificate; high-risk systems need conformity assessment and CE markingNo, it is a frameworkYes, an organization can be certified against it
Best used forMeeting a legal obligation if you touch the EU marketOperationalizing AI risk management, flexiblyProving governance with an auditable, certifiable system

What is the difference between the EU AI Act, the NIST AI RMF, and ISO 42001?

The EU AI Act is binding law that regulates AI by risk tier for anyone placing AI on the EU market. The NIST AI RMF is a voluntary US framework that helps any organization manage AI risk through four functions. ISO/IEC 42001 is a voluntary international standard you can be certified against, describing an AI management system. One is a law, one is a method, one is a certificate.

Is the NIST AI RMF mandatory?

No. The NIST AI Risk Management Framework is voluntary guidance. It carries no penalties on its own, though US agencies and contracts increasingly reference it, and it is a common way to operationalize the risk management other regimes expect.

Can you get certified against the EU AI Act?

Not as an organization the way you can against ISO/IEC 42001. The EU AI Act requires high-risk systems to pass a conformity assessment and carry CE marking, and it requires organizations to ensure staff AI literacy. It is compliance with a law, not a badge you earn.

Do the three overlap or compete?

They stack. The EU AI Act is the obligation you must meet if you reach the EU market. The NIST AI RMF is a practical way to run the risk management that meeting it takes. ISO/IEC 42001 gives you a certifiable system that evidences the whole thing to an auditor or a customer. Most mature programs use all three: the law as the requirement, the framework as the method, the standard as the proof.

Which one should your organization start with?

Start with the one that is not optional. If any AI you build, sell, or use reaches the EU market, the EU AI Act is a legal requirement, not a choice, so scope it first. Use the NIST AI RMF to run the risk work it takes, and pursue ISO/IEC 42001 when you need a certificate that proves your governance to an auditor or a buyer.

To see exactly where a given AI system lands under the EU AI Act, use our free Scope Wizard, read any provision in full in the EU AI Act Explorer, or compare the EU, US and China regimes side by side in the Governance Arena. For the current phased dates, which move, see our deadline page, kept current.

Turn this into capability you can prove

Knowing the difference is the start. AI Governance: Applied Mastery has you run a real organization through the AI era, decision by decision, and leave with a verifiable credential. Not sure where you stand? Take the free capability check first.

Sources

  • EU AI Act: Regulation (EU) 2024/1689, the Official Journal of the European Union (EUR-Lex), as amended.
  • NIST AI RMF: NIST AI Risk Management Framework (AI 100-1), National Institute of Standards and Technology.
  • ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, ISO and IEC.

Verified July 31, 2026. GAGE is not affiliated with, or endorsed by, the EU, NIST, ISO or IEC. This guide is general information, not legal advice.