AI Act vs NIST AI RMF: what they share and how they differ
AI Act and NIST AI RMF share 14 of 24 control themes and 9 checks. 22% of NIST AI RMF requirements can be proven with checks AI Act already uses, 15% the other way round.
Phasing in
AI Act
How to make an AI system compliant with the EU AI Act
33 requirementsNext Aug 2, 2027
Voluntary
NIST AI RMF
How to apply the NIST AI RMF to your AI systems
72 requirementsNext Dec 2026
14/24shared control themes
9shared checks
22%of NIST AI RMF requirements covered by AI Act evidence
15%of AI Act requirements covered by NIST AI RMF evidence
At a glance
| AI Act | NIST AI RMF | |
|---|---|---|
| Jurisdiction | European Union | United States (federal) |
| Kind | Regulation | Voluntary framework |
| Status | Phasing in | Voluntary |
| Binding | Yes | No |
| Object analysed | AI system same | AI system same |
| Scope | Providers, deployers, importers and distributors of AI systems; providers of GPAI models. | Any organisation designing, deploying or using AI. |
| Territorial reach | Extraterritorial: applies when the system is placed on the EU market or its output is used in the EU. | No territorial scope; de facto reference for US public buyers. |
| Penalties | Up to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information). | None (voluntary). Leverage: safe harbour in state laws. |
| Qualification axes | AI Act risk level, Organisation role, General-purpose model | Internal risk tier (organisation-defined) |
| Roles | Provider, Deployer, GPAI provider | AI actor |
| Requirements | 33 | 72 |
| Next milestone | Aug 2, 2027, Annex I high risk (regulated products); GPAI placed on the market before Aug 2025 | Dec 2026, Expected RMF revision |
Theme by theme
requirements per theme
AI ActNIST AI RMF
Governance
Assessment
Build
People & use
Lifecycle & third parties
What they share: one piece of evidence, two frameworks
9
| Code | Check | Requirements AI Act | Requirements NIST AI RMF |
|---|---|---|---|
| VER-003-01 | Documented and up-to-date risk register | ||
| VER-008-01 | Documented escalation and emergency stop procedure | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | ||
| VER-008-03 | Competent overseers assigned to the system | ||
| VER-AUTO-05 | Accuracy monitoring in operation | ||
| VER-009-02 | Accuracy and robustness verified and documented | ||
| VER-021-F-01 | Operational monitoring plan | ||
| VER-022-F-01 | Risk and incident response procedure | ||
| VER-022-D-01 | Serious incident reporting procedure |
Differences: requirements specific to each framework
Requirements with no check serving the other framework: the extra work.
AI Act
28
EX-001
AI literacy Art. 4
EX-002
Prohibited practices Art. 5
EX-004
Data and data governance Art. 10
EX-005
Technical documentation Art. 11 + Annexe IV
EX-006
Record-keeping / logging Art. 12
EX-007
Transparency to deployers Art. 13
EX-010
QMS Art. 17
EX-011
10-year retention Art. 18
EX-012
Automatically generated logs Art. 19
EX-013
Corrective actions Art. 20
EX-014
Cooperation with authorities Art. 21 + Art. 26§12
EX-015
EU declaration of conformity Art. 47
EX-016
CE marking Art. 48
EX-017
EU database registration Art. 49
EX-018
Transparency for all systems Art. 50
EX-019
DPIA Art. 26§9
EX-020
FRIA Art. 27
EX-023
Accessibility Art. 16(l)
EX-024
Conformity assessment Art. 43
EX-025
EX-026
Value chain Art. 25
EX-027
Compliant use Art. 26§1
EX-028
Input data Art. 26§4
EX-029
Information to affected persons Art. 26§11
EX-030
Information to workers' representatives Art. 26§7
EX-031
GPAI obligations Art. 53
EX-032
EX-033
NIST AI RMF
56
GOVERN-1.1
GOVERN-1.2
GOVERN-1.3
GOVERN-1.6
GOVERN-2.3
MAP-1.3
MAP-3.1
MEASURE-2.2
MEASURE-2.7
MEASURE-2.8
MEASURE-2.10
MEASURE-2.11
MEASURE-2.12
MEASURE-2.13
MEASURE-3.3
MANAGE-1.2
MANAGE-1.4
MANAGE-3.1
MANAGE-3.2
Timelines
PastSet in the textPotentialTo verify
Apr 21, 2021AI Act · Commission proposal
Jan 26, 2023NIST AI RMF · AI RMF 1.0
Jul 12, 2024AI Act · Published in the Official Journal
Jul 26, 2024NIST AI RMF · Generative AI Profile (NIST AI 600-1)
Aug 1, 2024AI Act · Entry into force
Feb 2, 2025AI Act · Prohibited practices (Art. 5) and AI literacy (Art. 4)
Jul 10, 2025AI Act · GPAI Code of Practice published
Jul 23, 2025NIST AI RMF · AI Action Plan asks for a revision of the framework
Aug 2, 2025AI Act · GPAI obligations, governance, penalties, notified bodies
Nov 19, 2025AI Act · Digital Omnibus proposal: high-risk delay tied to standards
Aug 2, 2026AI Act · General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay)
Dec 2026NIST AI RMF · Expected RMF revision
Aug 2, 2027AI Act · Annex I high risk (regulated products); GPAI placed on the market before Aug 2025
Dec 2, 2027AI Act · Omnibus backstop for Annex III high risk
Aug 2, 2028AI Act · Omnibus backstop for Annex I high risk
Aug 2, 2030AI Act · High-risk systems of public authorities already in service (Art. 111)
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.