NIST AI RMF vs EU AI Act
The EU AI Act is binding law, directly applicable in every Member State; it reaches providers, deployers, importers and distributors whose AI systems are placed on the EU market or whose output is used there. The NIST AI RMF 1.0 is a voluntary, US-origin framework that any organisation may adopt; it has no legal force and no certification scheme.
At a glance
The two instruments side by side, as the Body of Knowledge states them. Each cell names the primary source it rests on; the last row links the chapter sections each line comes from.
| Attribute | NIST AI RMF | EU AI Act (post-Omnibus) |
|---|---|---|
| Type | Framework: NIST AI Risk Management Framework 1.0 (NIST AI 100-1). Its companion Generative AI Profile (NIST AI 600-1, 2024) is not mapped on these pages. Sources: NIST AI 100-1, NIST AI 600-1 | Law: Regulation (EU) 2024/1689, as amended by the Digital Omnibus, Regulation (EU) 2026/1744 Sources: Regulation (EU) 2024/1689, consolidated text, Regulation (EU) 2026/1744 (Digital Omnibus) |
| Issuer | NIST (United States) Source: NIST AI 100-1 | European Union Source: Regulation (EU) 2024/1689, consolidated text |
| Legal force | Voluntary and US-origin. It describes itself as voluntary, rights-preserving, non-sector-specific and use-case agnostic. Source: NIST AI 100-1 | Binding and directly applicable in every Member State. Fines reach EUR 35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices, and EUR 15 million or 3% for operator obligations. Sources: Art. 99, Art. 113 |
| Scope and reach | Any organisation, in any sector and for any use case. GOVERN applies across the whole process; MAP, MEASURE and MANAGE apply per system and per lifecycle stage. Source: NIST AI 100-1 | Risk-tiered: prohibited practices, high-risk systems (Annex I products, Annex III uses), transparency cases and GPAI models. It reaches providers placing AI systems or GPAI models on the EU market wherever they are established, deployers in the Union, third-country providers and deployers whose output is used in the Union, importers and distributors. Sources: Art. 2, Art. 5, Art. 6, Art. 50, Art. 51 |
| Certifiable | No. There is no certification scheme for it: NIST AI 100-1 presents the RMF as voluntary guidance. Source: NIST AI 100-1 | No certificate of the Act as a whole. A high-risk system passes a conformity assessment (internal control, or a notified body where required), then the provider draws up an EU declaration of conformity, affixes the CE marking and registers the system in the EU database. Sources: Art. 43, Art. 47, Art. 48, Art. 49 |
| Key artefacts | Four functions (Govern, Map, Measure, Manage) in 19 categories and their subcategories, used as control metadata; a current and a target profile, with the gap between them as the action plan. Source: NIST AI 100-1 | Risk classification, risk management system, technical documentation, quality management system, logs, human oversight, fundamental rights impact assessment, serious-incident reports. Sources: Art. 6, Art. 9, Art. 11, Art. 12, Art. 14, Art. 17, Art. 27, Art. 73 |
| Dates | 1.0 published 2023-01-26; there is no 2.0. A formal review was foreseen by 2028, and as of 2026-09-24 NIST states that 1.0 is being revised, with no revised version published. Sources: NIST AI 100-1, NIST: AI Risk Management Framework | In force 2024-08-01. Prohibitions and AI literacy from 2025-02-02; GPAI obligations from 2025-08-02; Omnibus in force 2026-07-27; high-risk Annex III from 2027-12-02 and Annex I from 2028-08-02. Sources: Art. 113, Regulation (EU) 2026/1744 (Digital Omnibus) |
| In the Body of Knowledge |
Where they overlap, topic by topic
The crosswalk maps 25 AI governance topics. Both instruments file clauses under 23 of them, 14 strongly (a core clause on each side). 0 topics have a core clause only in the NIST AI RMF and 2 only in the EU AI Act; 0 are reached by neither. A shared topic means the two deal with the same thing, not that meeting one meets the other.
Strong: both file a core clause. Partial: both file a clause, at least one only in passing. Only, in passing: one side files a related clause and the other none. Clause ids link to their page in the obligation register where one exists. The last column names a pattern only where it serves a core clause on both sides: the crosswalk row's register entry lists it and the pattern's own "Maps to" line names that clause. Otherwise the cell is empty.
| Topic | What NIST AI RMF asks for | What EU AI Act asks for | Overlap | Patterns for both |
|---|---|---|---|---|
| Risk management |
|
| Strong | |
| Governance and accountability |
| Strong | ||
| Impact assessment | Strong | |||
| Data governance |
|
| Partial | |
| Documentation and transparency |
|
| Partial | |
| Inventory and registration |
|
| Strong | |
| Logging and traceability |
| Partial | ||
| Human oversight |
|
| Strong | |
| Runtime guardrails |
|
| Partial | |
| Robustness, security and evaluations |
|
| Strong | |
| Incident response and monitoring |
|
| Strong | |
| Supply chain and third parties |
|
| Strong | |
| Prohibited practices |
|
| Partial | |
| Fairness and non-discrimination |
|
| Strong | |
| Privacy and data protection |
|
| Partial | |
| Explainability and right to explanation |
|
| Strong | |
| AI literacy and competence |
|
| Strong | |
| Conformity assessment and certification |
|
| Partial | |
| GPAI and foundation models | Not mapped |
| EU AI Act only | |
| IP and copyright |
|
| Strong | |
| Agent identity and autonomy |
|
| Partial | |
| Content provenance and deepfakes | Not mapped |
| EU AI Act only | |
| Sandboxes and real-world testing |
|
| Partial | |
| Environmental impact |
|
| Strong | |
| Deployment, change and decommissioning |
|
| Strong |
Can you use the NIST AI RMF to comply with the EU AI Act?
Not by itself. Only harmonised standards cited in the Official Journal (Article 40) and the Commission's common specifications (Article 41) give a presumption of conformity, and the RMF, voluntary US guidance, is neither. It is still scaffolding: its four functions organise the risk management, testing and monitoring the Act's high-risk articles require, and one set of evidence can serve both.
Which should you start with?
If your AI systems reach the EU market or their output is used there, start with the Act: its scope and risk tiers decide which duties apply and from when. Use the NIST AI RMF alongside it as the working method for risk management; it is use-case agnostic, and its functions map onto the Act's risk, testing and monitoring duties.
Next step
Put the comparison to work on your own systems, in the browser.
Frequently asked questions
Does the EU AI Act apply to US companies?
Yes, when they are in its scope. Article 2(1) reaches providers placing AI systems or GPAI models on the EU market wherever they are established, and providers and deployers in third countries whose system's output is used in the Union. The scope question is where the output is used, not where the system is hosted.
Source: Art. 2
What are the penalties under each?
The Act fines prohibited practices up to EUR 35 million or 7% of worldwide annual turnover, and breaches of operator obligations up to EUR 15 million or 3%, whichever is higher; SMEs pay the lower of the two. The NIST AI RMF carries no penalties: it is voluntary.
Sources: Art. 99, NIST AI 100-1
Is there a NIST AI RMF 2.0?
No. AI RMF 1.0 (NIST AI 100-1, 26 January 2023) remains the citable text. As of 2026-09-24 NIST's framework page states that 1.0 is being revised as part of the White House AI Action Plan, but no revised version is published. Pin the version in control metadata.
What does the EU AI Act cover that the NIST AI RMF does not?
In this crosswalk, 2 of the 25 topics have a core EU AI Act clause and no NIST AI RMF clause mapped: GPAI and foundation models; Content provenance and deepfakes. A topic with no NIST AI RMF clause here is one this mapping does not reach, not one the NIST AI RMF is shown to leave out. The overlap table on this page lists the clauses; mappings are illustrative, not a claim of conformity. The NIST column maps AI RMF 1.0 (NIST AI 100-1) only: its companion Generative AI Profile (NIST AI 600-1) adds suggested actions for 12 risks that generative AI creates or exacerbates, among them information integrity and intellectual property, and is not mapped here.
Source: NIST AI 600-1
Both instruments sit inside a wider field: AI governance, explained, from the laws and standards to the engineering practice.
Sources
- NIST AI RMF: https://www.nist.gov/itl/ai-risk-management-framework
- NIST AI RMF: https://airc.nist.gov/airmf-resources/airmf/
- EU AI Act (post-Omnibus): https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng
- NIST AI 100-1: https://doi.org/10.6028/NIST.AI.100-1
- NIST AI 600-1: https://doi.org/10.6028/NIST.AI.600-1
- Regulation (EU) 2026/1744 (Digital Omnibus): https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
Every clause on this page, with its note and verification status, is in the topic × framework crosswalk and its JSON download.
Other comparisons: ISO 42001 vs EU AI Act · NIST AI RMF vs ISO 42001