EU AI Act vs the NIST AI RMF
By Sam Rivera, Founder, SentinelPanda · August 6, 2026 · 3 min read · AI Governance
A regulation you can be fined 7% of global turnover under, and a framework nobody can penalise you for ignoring. They are not the same kind of object at all.
Law versus framework
Regulation (EU) 2024/1689 — the AI Act — entered into force on 1 August 2024 and applies in stages. Prohibitions on unacceptable-risk practices applied from February 2025, general-purpose AI model obligations from August 2025, and the bulk of the high-risk obligations under Annex III from 2 August 2026, with product-embedded high-risk systems under Annex I following in 2027. Penalties reach 35 million euros or 7% of worldwide annual turnover for prohibited practices, with lower tiers for other breaches.
The NIST AI Risk Management Framework 1.0, published January 2023, is voluntary guidance from a US standards body. There is no penalty for ignoring it, no deadline, and no authority that enforces it. It is influential because it is useful, not because it is binding.
The Act also applies extraterritorially: a US company placing an AI system on the EU market, or whose system's output is used in the EU, can be in scope regardless of where it is established.
Risk tiers versus risk process
The AI Act tells you what category your system falls into and what follows from that. Unacceptable-risk practices are prohibited outright. High-risk systems carry the heavy obligations — risk management system, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness, conformity assessment, CE marking, and registration. Limited-risk systems carry transparency duties. Minimal-risk systems carry essentially none.
The AI RMF makes no such determination. Its four functions — GOVERN, MAP, MEASURE, MANAGE — describe a process for identifying and managing AI risk in context, organised around trustworthiness characteristics: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed. You decide what your risk is; nobody hands you a tier.
Using the RMF toward the Act
- The Act's high-risk risk-management-system obligation maps naturally onto MAP and MEASURE.
- Its data governance requirements align with the RMF's treatment of data quality and representativeness.
- Its human oversight article corresponds to oversight practices the RMF describes under GOVERN and MANAGE.
- Its accuracy, robustness, and cybersecurity requirements track the RMF's validity, safety, and security characteristics.
- But no amount of AI RMF alignment produces a conformity assessment, a CE mark, or an EU database registration. Those are legal artefacts with legal processes.
What to actually do
Determine exposure first. If you place AI systems on the EU market or their output is used in the EU, the Act may apply regardless of where you sit, and classification is the gating question — everything else follows from whether you are high-risk.
If you are in scope, treat the Act as the requirement and use the AI RMF and ISO 42001 as the means: the RMF to structure the risk process, ISO 42001 to give it a certifiable management-system shell that maps well onto what the Act expects. If you are not in scope, the RMF alone is a perfectly reasonable way to govern AI without inheriting an EU regulatory structure you have no obligation to.