EU AI Act vs NIST AI RMF vs ISO 42001: the difference, explained
Verified July 31, 2026. Sources listed at the end.
The EU AI Act is a binding law that regulates AI by risk tier for anyone reaching the EU market. The NIST AI RMF is a voluntary US framework for managing AI risk. ISO/IEC 42001 is a certifiable international standard for an AI management system. One is a law, one is a method, one is a certificate, and mature programs use all three.
The three at a glance
| EU AI Act | NIST AI RMF | ISO/IEC 42001 | |
|---|---|---|---|
| What it is | A comprehensive, risk-based LAW for AI placed on the EU market | A voluntary FRAMEWORK for managing AI risk | A certifiable STANDARD for an AI management system |
| Legal status | Binding and mandatory | Voluntary, not law | Voluntary, but third-party certifiable |
| Issued by | European Union (Regulation (EU) 2024/1689) | US NIST (AI 100-1) | ISO and IEC (42001:2023) |
| Reach | The EU market, including providers outside the EU whose output is used there | Global, adopted voluntarily | Global, adopted voluntarily |
| How it is structured | Risk tiers (prohibited, high-risk, transparency, minimal) with duties by role | Four functions: Govern, Map, Measure, Manage | A management system (Plan, Do, Check, Act) with Annex A controls |
| Can you be certified? | No org certificate; high-risk systems need conformity assessment and CE marking | No, it is a framework | Yes, an organization can be certified against it |
| Best used for | Meeting a legal obligation if you touch the EU market | Operationalizing AI risk management, flexibly | Proving governance with an auditable, certifiable system |
What is the difference between the EU AI Act, the NIST AI RMF, and ISO 42001?
The EU AI Act is binding law that regulates AI by risk tier for anyone placing AI on the EU market. The NIST AI RMF is a voluntary US framework that helps any organization manage AI risk through four functions. ISO/IEC 42001 is a voluntary international standard you can be certified against, describing an AI management system. One is a law, one is a method, one is a certificate.
Is the NIST AI RMF mandatory?
No. The NIST AI Risk Management Framework is voluntary guidance. It carries no penalties on its own, though US agencies and contracts increasingly reference it, and it is a common way to operationalize the risk management other regimes expect.
Can you get certified against the EU AI Act?
Not as an organization the way you can against ISO/IEC 42001. The EU AI Act requires high-risk systems to pass a conformity assessment and carry CE marking, and it requires organizations to ensure staff AI literacy. It is compliance with a law, not a badge you earn.
Do the three overlap or compete?
They stack. The EU AI Act is the obligation you must meet if you reach the EU market. The NIST AI RMF is a practical way to run the risk management that meeting it takes. ISO/IEC 42001 gives you a certifiable system that evidences the whole thing to an auditor or a customer. Most mature programs use all three: the law as the requirement, the framework as the method, the standard as the proof.
Which one should your organization start with?
Start with the one that is not optional. If any AI you build, sell, or use reaches the EU market, the EU AI Act is a legal requirement, not a choice, so scope it first. Use the NIST AI RMF to run the risk work it takes, and pursue ISO/IEC 42001 when you need a certificate that proves your governance to an auditor or a buyer.
To see exactly where a given AI system lands under the EU AI Act, use our free Scope Wizard, read any provision in full in the EU AI Act Explorer, or compare the EU, US and China regimes side by side in the Governance Arena. For the current phased dates, which move, see our deadline page, kept current.
Turn this into capability you can prove
Knowing the difference is the start. AI Governance: Applied Mastery has you run a real organization through the AI era, decision by decision, and leave with a verifiable credential. Not sure where you stand? Take the free capability check first.
Sources
- EU AI Act: Regulation (EU) 2024/1689, the Official Journal of the European Union (EUR-Lex), as amended.
- NIST AI RMF: NIST AI Risk Management Framework (AI 100-1), National Institute of Standards and Technology.
- ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, ISO and IEC.
Verified July 31, 2026. GAGE is not affiliated with, or endorsed by, the EU, NIST, ISO or IEC. This guide is general information, not legal advice.