---
title: "NIST AI RMF vs EU AI Act: differences, overlap and mapping"
description: "NIST AI RMF vs the EU AI Act: voluntary US framework and binding EU law, compared on scope, dates and duties, with a topic-by-topic clause mapping."
canonical: https://aigovernanceengineer.com/resources/crosswalk/nist-ai-rmf-vs-eu-ai-act
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-27
---

# NIST AI RMF vs EU AI Act: differences, overlap and mapping

> The EU AI Act is binding law, directly applicable in every Member State; it reaches providers, deployers, importers and distributors whose AI systems are placed on the EU market or whose output is used there. The NIST AI RMF 1.0 is a voluntary, US-origin framework that any organisation may adopt; it has no legal force and no certification scheme.

**In short**

The EU AI Act is binding law and the NIST AI RMF is voluntary guidance. The Act reaches providers placing AI systems or GPAI models on the EU market wherever they are established, and providers and deployers in third countries whose output is used in the Union, so it can apply to US companies. It fines prohibited practices up to EUR 35 million or 7% of worldwide annual turnover, and its Annex III high-risk duties apply from 2 December 2027. The NIST AI RMF 1.0 (NIST AI 100-1) is US-origin and use-case agnostic, with no penalties and no certification scheme. It gives no presumption of conformity with the Act, but its four functions, Govern, Map, Measure and Manage, organise the risk management, testing and monitoring the Act's high-risk articles require. In this crosswalk both file clauses under 23 of 25 topics, 14 of them strongly, so one set of evidence can serve both.

## At a glance

The two instruments side by side, as the Body of Knowledge states them, each cell with the primary source it rests on.

| Attribute | NIST AI RMF | EU AI Act (post-Omnibus) |
|---|---|---|
| Type | Framework: NIST AI Risk Management Framework 1.0 (NIST AI 100-1). Its companion Generative AI Profile (NIST AI 600-1, 2024) is not mapped on these pages. (Sources: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1), [NIST AI 600-1](https://doi.org/10.6028/NIST.AI.600-1)) | Law: Regulation (EU) 2024/1689, as amended by the Digital Omnibus, Regulation (EU) 2026/1744 (Sources: [Regulation (EU) 2024/1689, consolidated text](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng), [Regulation (EU) 2026/1744 (Digital Omnibus)](https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng)) |
| Issuer | NIST (United States) (Source: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)) | European Union (Source: [Regulation (EU) 2024/1689, consolidated text](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng)) |
| Legal force | Voluntary and US-origin. It describes itself as voluntary, rights-preserving, non-sector-specific and use-case agnostic. (Source: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)) | Binding and directly applicable in every Member State. Fines reach EUR 35 million or 7% of worldwide annual turnover, whichever is higher, for prohibited practices, and EUR 15 million or 3% for operator obligations. (Sources: [Art. 99](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_99), [Art. 113](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_113)) |
| Scope and reach | Any organisation, in any sector and for any use case. GOVERN applies across the whole process; MAP, MEASURE and MANAGE apply per system and per lifecycle stage. (Source: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)) | Risk-tiered: prohibited practices, high-risk systems (Annex I products, Annex III uses), transparency cases and GPAI models. It reaches providers placing AI systems or GPAI models on the EU market wherever they are established, deployers in the Union, third-country providers and deployers whose output is used in the Union, importers and distributors. (Sources: [Art. 2](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_2), [Art. 5](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_5), [Art. 6](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_6), [Art. 50](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_50), [Art. 51](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_51)) |
| Certifiable | No. There is no certification scheme for it: NIST AI 100-1 presents the RMF as voluntary guidance. (Source: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)) | No certificate of the Act as a whole. A high-risk system passes a conformity assessment (internal control, or a notified body where required), then the provider draws up an EU declaration of conformity, affixes the CE marking and registers the system in the EU database. (Sources: [Art. 43](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_43), [Art. 47](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_47), [Art. 48](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_48), [Art. 49](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_49)) |
| Key artefacts | Four functions (Govern, Map, Measure, Manage) in 19 categories and their subcategories, used as control metadata; a current and a target profile, with the gap between them as the action plan. (Source: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)) | Risk classification, risk management system, technical documentation, quality management system, logs, human oversight, fundamental rights impact assessment, serious-incident reports. (Sources: [Art. 6](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_6), [Art. 9](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_9), [Art. 11](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_11), [Art. 12](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_12), [Art. 14](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_14), [Art. 17](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_17), [Art. 27](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_27), [Art. 73](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_73)) |
| Dates | 1.0 published 2023-01-26; there is no 2.0. A formal review was foreseen by 2028, and as of 2026-09-24 NIST states that 1.0 is being revised, with no revised version published. (Sources: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1), [NIST: AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)) | In force 2024-08-01. Prohibitions and AI literacy from 2025-02-02; GPAI obligations from 2025-08-02; Omnibus in force 2026-07-27; high-risk Annex III from 2027-12-02 and Annex I from 2028-08-02. (Sources: [Art. 113](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_113), [Regulation (EU) 2026/1744 (Digital Omnibus)](https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng)) |
| In the Body of Knowledge | [22. NIST AI RMF 1.0 in depth](https://aigovernanceengineer.com/bok/principles-and-standards#nist-ai-rmf-10-in-depth) · [13. NIST AI RMF and ISO/IEC 23894 on the stack](https://aigovernanceengineer.com/bok/risk-management#nist-ai-rmf-and-isoiec-23894-on-the-stack) | [18. The EU AI Act in one pass](https://aigovernanceengineer.com/bok/eu-ai-act) · [08. The regulatory map: EU AI Act](https://aigovernanceengineer.com/bok/regulatory-map#eu-ai-act-post-omnibus) |

## Where they overlap, topic by topic

The crosswalk maps 25 AI governance topics. Both instruments file clauses under 23 of them, 14 strongly (a core clause on each side). 0 topics have a core clause only in the NIST AI RMF and 2 only in the EU AI Act; 0 are reached by neither. A shared topic means the two deal with the same thing, not that meeting one meets the other.

Strong: both file a core clause. Partial: both file a clause, at least one only in passing. Only, in passing: one side files a related clause and the other none. The last column names a pattern only where it serves a core clause on both sides: the register entry of that clause lists it and the pattern's own "Maps to" line names the clause.

| Topic | What NIST AI RMF asks for | What EU AI Act asks for | Overlap | Patterns for both |
|---|---|---|---|---|
| [Risk management](https://aigovernanceengineer.com/resources/crosswalk#topic-risk-management) | [MAP 1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Context is established and understood; [MAP 5](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Impacts to individuals, groups, communities, organizations, and society are characterized; [MANAGE 1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) AI risks based on assessments and other analytical output are prioritized, responded to, and managed; [GOVERN 1.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Processes, procedures, and practices are in place to determine the needed level of risk management activities based on the organization's risk tolerance; [MAP 1.5](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Organizational risk tolerances are determined and documented; [MANAGE 1.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Responses to the AI risks deemed high priority, as identified by the MAP function, are developed, planned, and documented; [MANAGE 1.4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Negative residual risks to both downstream acquirers of AI systems and end users are documented; [MEASURE 3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Mechanisms for tracking identified AI risks over time are in place; [MEASURE 2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) AI systems are evaluated for trustworthy characteristics | [Art. 9](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9) Risk management system; Art. 3 Definitions | Strong | [Downstream Use Register](https://aigovernanceengineer.com/patterns/downstream-use-register) |
| [Governance and accountability](https://aigovernanceengineer.com/resources/crosswalk#topic-governance-accountability) | [GOVERN 1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Policies, processes, procedures, and practices across the organization related to the mapping, measuring, and managing of AI risks are in place, transparent, and implemented effectively; [GOVERN 2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Accountability structures are in place so that the appropriate teams and individuals are empowered, responsible, and trained; [GOVERN 4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Organizational teams are committed to a culture that considers and communicates AI risk; [GOVERN 5](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Processes are in place for robust engagement with relevant AI actors | [Art. 17](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art17) Quality management system; [Art. 4](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4) AI literacy; Art. 87 Reporting of infringements and protection of reporting persons | Strong |  |
| [Impact assessment](https://aigovernanceengineer.com/resources/crosswalk#topic-impact-assessment) | [MAP 3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) AI capabilities, targeted usage, goals, and expected benefits and costs are understood; [MAP 5](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Impacts to individuals, groups, communities, organizations, and society are characterized | [Art. 27](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art27) Fundamental rights impact assessment for high-risk AI systems; [Art. 9](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9) Risk management system | Strong |  |
| [Data governance](https://aigovernanceengineer.com/resources/crosswalk#topic-data-governance) | [MAP 2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Categorization of the AI system is performed; [MEASURE 2.10](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Privacy risk of the AI system is examined and documented; [MEASURE 2.11](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Fairness and bias are evaluated and results are documented | [Art. 10](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10) Data and data governance; [Art. 10(2)(f)–(g)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10) Examination for possible biases; measures to detect, prevent and mitigate them; [Art. 4a](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a) Special-category data for bias detection; Art. 53 Obligations for providers of general-purpose AI models; Art. 53(1)(c) Copyright policy, including rights reservations; Art. 5(1)(e) Prohibited: untargeted scraping of facial images | Partial |  |
| [Documentation and transparency](https://aigovernanceengineer.com/resources/crosswalk#topic-documentation-transparency) | [MAP 1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Context is established and understood; [MEASURE 2.8](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Risks associated with transparency and accountability are examined and documented; [MAP 1.6](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) System requirements are elicited from and understood by relevant AI actors. Design decisions take socio-technical implications into account to address AI risks; [MEASURE 2.9](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance | [Art. 11](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art11) Technical documentation; [Art. 13](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13) Transparency and provision of information to deployers; [Art. 53](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53) Obligations for providers of general-purpose AI models; [Art. 50](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50) Transparency obligations for providers and deployers of certain AI systems; Art. 86 Right to explanation of individual decision-making; Art. 18 Documentation keeping; Art. 43 Conformity assessment; Art. 53(1)(d) Public summary of the content used for training; [Art. 50(2), 50(4)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50) Machine-readable marking of synthetic content; disclosure of deep fakes | Partial |  |
| [Inventory and registration](https://aigovernanceengineer.com/resources/crosswalk#topic-inventory-registration) | [GOVERN 1.6](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities; [GOVERN 1.7](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness | [Art. 49](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art49-71) Registration; [Art. 71](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art49-71) EU database for high-risk AI systems; [Art. 6](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art6) Classification rules for high-risk AI systems; Art. 3(1) Definition of an AI system; Art. 52 Procedure | Strong | [Use-Case Intake & Risk Tiering](https://aigovernanceengineer.com/patterns/use-case-intake-risk-tiering) |
| [Logging and traceability](https://aigovernanceengineer.com/resources/crosswalk#topic-logging-traceability) | [MANAGE 4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored; [MEASURE 3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Mechanisms for tracking identified AI risks over time are in place | [Art. 12](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art12) Record-keeping; [Art. 26(6)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Deployers keep the automatically generated logs; [Art. 26](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Obligations of deployers of high-risk AI systems; Art. 19 Automatically generated logs | Partial |  |
| [Human oversight](https://aigovernanceengineer.com/resources/crosswalk#topic-human-oversight) | [MANAGE 2.4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use; [MAP 3.5](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Processes for human oversight are defined, assessed, and documented in accordance with organizational policies from the GOVERN function; [GOVERN 3.2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems | [Art. 14](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14) Human oversight; [Art. 26](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Obligations of deployers of high-risk AI systems; [Art. 14(4)(b)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14) Awareness of automation bias | Strong |  |
| [Runtime guardrails](https://aigovernanceengineer.com/resources/crosswalk#topic-runtime-guardrails) | [MANAGE 2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Strategies to maximize AI benefits and minimize negative impacts are planned, prepared, implemented, documented, and informed by relevant AI actors | [Art. 5](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5) Prohibited AI practices; [Art. 15](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15) Accuracy, robustness and cybersecurity; [Art. 5(1)(a)–(b)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5) Manipulative techniques; exploitation of vulnerabilities | Partial |  |
| [Robustness, security and evaluations](https://aigovernanceengineer.com/resources/crosswalk#topic-robustness-security-evals) | [MEASURE 2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) AI systems are evaluated for trustworthy characteristics; [MEASURE 2.7](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) AI system security and resilience as identified in the MAP function are evaluated and documented; [MEASURE 2.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Test sets, metrics, and details about the tools used during TEVV are documented; [MEASURE 1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Appropriate methods and metrics are identified and applied | [Art. 15](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15) Accuracy, robustness and cybersecurity; [Art. 55](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55) Obligations for providers of general-purpose AI models with systemic risk; [Art. 60](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art60) Testing of high-risk AI systems in real-world conditions outside AI regulatory sandboxes; [Art. 15(3)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art15) Declared accuracy levels and metrics; [Art. 9](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art9) Risk management system; Art. 42(3) Presumption of conformity for cybersecurity (Cyber Resilience Act) | Strong | [AI Threat Model](https://aigovernanceengineer.com/patterns/ai-threat-model); [Model Artefact Integrity](https://aigovernanceengineer.com/patterns/model-artefact-integrity) |
| [Incident response and monitoring](https://aigovernanceengineer.com/resources/crosswalk#topic-incident-monitoring) | [MANAGE 4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Risk treatments, including response and recovery, and communication plans for the identified and measured AI risks are documented and monitored; [MANAGE 4.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Incidents and errors are communicated to relevant AI actors, including affected communities. Processes for tracking, responding to, and recovering from incidents and errors are followed and documented; [MANAGE 2.4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use; [GOVERN 4.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Organizational practices are in place to enable AI testing, identification of incidents, and information sharing | [Art. 72](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art72) Post-market monitoring by providers and post-market monitoring plan; [Art. 73](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art73) Reporting of serious incidents; [Art. 26(5)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Deployer monitoring, informing the provider and suspending use; [Art. 55](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55) Obligations for providers of general-purpose AI models with systemic risk; Art. 3(49) Definition of serious incident; Art. 20 Corrective actions and duty of information | Strong | [Disclosure & Notification Pipeline](https://aigovernanceengineer.com/patterns/disclosure-notification-pipeline) |
| [Supply chain and third parties](https://aigovernanceengineer.com/resources/crosswalk#topic-supply-chain) | [GOVERN 6](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Policies and procedures are in place to address AI risks and benefits arising from third-party software and data and other supply chain issues; [MAP 4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Risks and benefits are mapped for all AI system components including third-party software and data; [MANAGE 3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) AI risks and benefits from third-party entities are managed; [MANAGE 3.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) AI risks and benefits from third-party resources are regularly monitored, and risk controls are applied and documented; [GOVERN 6.2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Contingency processes are in place to handle failures or incidents in third-party data or AI systems deemed to be high-risk | [Art. 25](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25) Responsibilities along the AI value chain; [Art. 25(4)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25) Written agreement with third-party suppliers; [Art. 26](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Obligations of deployers of high-risk AI systems; Art. 22 Authorised representatives of providers of high-risk AI systems; Art. 23 Obligations of importers; Art. 24 Obligations of distributors; Art. 54 Authorised representatives of providers of general-purpose AI models | Strong |  |
| [Prohibited practices](https://aigovernanceengineer.com/resources/crosswalk#topic-prohibited-practices) | [GOVERN 1.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Legal and regulatory requirements involving AI are understood, managed, and documented | [Art. 5](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art5) Prohibited AI practices | Partial |  |
| [Fairness and non-discrimination](https://aigovernanceengineer.com/resources/crosswalk#topic-fairness-non-discrimination) | [MEASURE 2.11](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Fairness and bias as identified in the MAP function are evaluated and results are documented; [GOVERN 3.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Decision-making related to mapping, measuring, and managing AI risks throughout the lifecycle is informed by a diverse team | [Art. 10(2)(f)–(g)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10) Examination for possible biases; measures to detect, prevent and mitigate them; [Art. 4a](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a) Special-category data for bias detection | Strong | [Fairness Eval Suite](https://aigovernanceengineer.com/patterns/fairness-eval-suite); [Drift & Fairness Monitor](https://aigovernanceengineer.com/patterns/drift-fairness-monitor) |
| [Privacy and data protection](https://aigovernanceengineer.com/resources/crosswalk#topic-privacy-data-protection) | [MEASURE 2.10](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Privacy risk of the AI system as identified in the MAP function is examined and documented | Art. 59 Further processing of personal data in the AI regulatory sandbox; [Art. 4a](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4a) Special-category data for bias detection | Partial |  |
| [Explainability and right to explanation](https://aigovernanceengineer.com/resources/crosswalk#topic-explainability) | [MEASURE 2.9](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) The AI model is explained, validated, and documented, and AI system output is interpreted within its context as identified in the MAP function to inform responsible use and governance; [MEASURE 2.8](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Risks associated with transparency and accountability as identified in the MAP function are examined and documented | Art. 86 Right to explanation of individual decision-making; [Art. 13(3)(b)(iv)–(v)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art13) Information relevant to explain output; performance for specific persons or groups | Strong |  |
| [AI literacy and competence](https://aigovernanceengineer.com/resources/crosswalk#topic-ai-literacy) | [GOVERN 2.2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) The organization's personnel and partners receive AI risk management training to enable them to perform their duties and responsibilities consistent with related policies, procedures, and agreements; [MAP 3.4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Processes for operator and practitioner proficiency with AI system performance and trustworthiness, and relevant technical standards and certifications, are defined, assessed, and documented | [Art. 4](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4) AI literacy; [Art. 26(2)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Oversight by people with the competence, training and authority it needs; Art. 95(2)(c) Codes of conduct: promoting AI literacy | Strong | [Sanctioned AI Gateway](https://aigovernanceengineer.com/patterns/sanctioned-ai-gateway) |
| [Conformity assessment and certification](https://aigovernanceengineer.com/resources/crosswalk#topic-conformity-assessment) | [MEASURE 1.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Internal experts who did not serve as front-line developers for the system and/or independent assessors are involved in regular assessments and updates | [Art. 43](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art43) Conformity assessment; [Art. 47](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art47) EU declaration of conformity; Art. 48 CE marking; Art. 40 Harmonised standards and standardisation deliverables | Partial |  |
| [GPAI and foundation models](https://aigovernanceengineer.com/resources/crosswalk#topic-gpai-foundation-models) | Not mapped | [Art. 53](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53) Obligations for providers of general-purpose AI models; [Art. 55](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art55) Obligations of providers of general-purpose AI models with systemic risk; Art. 51 Classification of general-purpose AI models as general-purpose AI models with systemic risk; Art. 56 Codes of practice | EU AI Act only |  |
| [IP and copyright](https://aigovernanceengineer.com/resources/crosswalk#topic-ip-copyright) | [GOVERN 6.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party's intellectual property or other rights; [MAP 4.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-map) Approaches for mapping AI technology and legal risks of its components, including the use of third-party data or software, are in place, followed, and documented, as are risks of infringement of a third party's intellectual property or other rights | [Art. 53(1)(c)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53) Copyright policy, including rights reservations; Art. 53(1)(d) Public summary of the content used for training | Strong |  |
| [Agent identity and autonomy](https://aigovernanceengineer.com/resources/crosswalk#topic-agent-identity-autonomy) | [GOVERN 3.2](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Policies and procedures are in place to define and differentiate roles and responsibilities for human-AI configurations and oversight of AI systems | [Art. 14](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14) Human oversight | Partial |  |
| [Content provenance and deepfakes](https://aigovernanceengineer.com/resources/crosswalk#topic-content-provenance) | Not mapped | [Art. 50(2)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50) Machine-readable marking of synthetic content; [Art. 50(4)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art50) Disclosure of deep fakes; Art. 3(60) Definition of deep fake | EU AI Act only |  |
| [Sandboxes and real-world testing](https://aigovernanceengineer.com/resources/crosswalk#topic-sandboxes-real-world-testing) | [MEASURE 2.3](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) AI system performance or assurance criteria are measured qualitatively or quantitatively and demonstrated for conditions similar to deployment setting(s) | Art. 57 AI regulatory sandboxes; [Art. 60](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art60) Testing of high-risk AI systems in real world conditions outside AI regulatory sandboxes; Art. 58 Detailed arrangements for, and functioning of, AI regulatory sandboxes; Art. 59 Further processing of personal data in the AI regulatory sandbox; Art. 61 Informed consent to participate in testing in real world conditions | Partial |  |
| [Environmental impact](https://aigovernanceengineer.com/resources/crosswalk#topic-environmental-impact) | [MEASURE 2.12](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-measure) Environmental impact and sustainability of AI model training and management activities as identified in the MAP function are assessed and documented | [Annex XI 1(2)(e)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53) Known or estimated energy consumption of the GPAI model; Art. 40(2) Standardisation deliverables on energy and resource performance; Art. 95(2)(b) Codes of conduct: environmental sustainability | Strong |  |
| [Deployment, change and decommissioning](https://aigovernanceengineer.com/resources/crosswalk#topic-deployment-change-decommissioning) | [MANAGE 2.4](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Mechanisms are in place and applied, and responsibilities are assigned and understood, to supersede, disengage, or deactivate AI systems that demonstrate performance or outcomes inconsistent with intended use; [MANAGE 4.1](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage) Post-deployment AI system monitoring plans are implemented, including mechanisms for capturing and evaluating input from users and other relevant AI actors, appeal and override, decommissioning, incident response, recovery, and change management; [GOVERN 1.7](https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-govern) Processes and procedures are in place for decommissioning and phasing out AI systems safely and in a manner that does not increase risks or decrease the organization's trustworthiness | [Art. 26](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art26) Obligations of deployers of high-risk AI systems; [Art. 25](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art25) Responsibilities along the AI value chain; [Art. 43(4)](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art43) New conformity assessment on substantial modification; Art. 20 Corrective actions and duty of information; Art. 79 Procedure at national level for dealing with AI systems presenting a risk; Art. 86 Right to explanation of individual decision-making | Strong | [Decision Notice & Contest Path](https://aigovernanceengineer.com/patterns/decision-notice-contest-path); [Staged Rollout with Rollback Criteria](https://aigovernanceengineer.com/patterns/staged-rollout-rollback-criteria); [Drift & Fairness Monitor](https://aigovernanceengineer.com/patterns/drift-fairness-monitor); [Deactivation, Localisation & Retirement Runbook](https://aigovernanceengineer.com/patterns/deactivation-localisation-retirement-runbook) |

## Can you use the NIST AI RMF to comply with the EU AI Act?

Not by itself. Only harmonised standards cited in the Official Journal (Article 40) and the Commission's common specifications (Article 41) give a presumption of conformity, and the RMF, voluntary US guidance, is neither. It is still scaffolding: its four functions organise the risk management, testing and monitoring the Act's high-risk articles require, and one set of evidence can serve both.

## Which should you start with?

If your AI systems reach the EU market or their output is used there, start with the Act: its scope and risk tiers decide which duties apply and from when. Use the NIST AI RMF alongside it as the working method for risk management; it is use-case agnostic, and its functions map onto the Act's risk, testing and monitoring duties.

## Next step

Put the comparison to work on your own systems, in the browser.

- [Check where your system falls under the EU AI Act](https://aigovernanceengineer.com/toolkit/ai-act-triage): The EU AI Act risk classification checker: indicative roles and risk classes, each with its article, and a decision record to file.
- [List the EU AI Act obligations and deadlines that bind you](https://aigovernanceengineer.com/toolkit/obligations-planner): The obligations planner: the register rows for your roles, the artefact that evidences each and the date it applies.
- [Write a FRIA or an AI system impact assessment as one record](https://aigovernanceengineer.com/toolkit/impact-assessment): The impact assessment builder: every risk linked to the measure and pattern that mitigate it, and the triggers that reopen it.

Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser.

## Frequently asked questions

### Does the EU AI Act apply to US companies?

Yes, when they are in its scope. Article 2(1) reaches providers placing AI systems or GPAI models on the EU market wherever they are established, and providers and deployers in third countries whose system's output is used in the Union. The scope question is where the output is used, not where the system is hosted.

Source: [Art. 2](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_2)

### What are the penalties under each?

The Act fines prohibited practices up to EUR 35 million or 7% of worldwide annual turnover, and breaches of operator obligations up to EUR 15 million or 3%, whichever is higher; SMEs pay the lower of the two. The NIST AI RMF carries no penalties: it is voluntary.

Sources: [Art. 99](https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_99), [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1)

### Is there a NIST AI RMF 2.0?

No. AI RMF 1.0 (NIST AI 100-1, 26 January 2023) remains the citable text. As of 2026-09-24 NIST's framework page states that 1.0 is being revised as part of the White House AI Action Plan, but no revised version is published. Pin the version in control metadata.

Sources: [NIST AI 100-1](https://doi.org/10.6028/NIST.AI.100-1), [NIST: AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework)

### What does the EU AI Act cover that the NIST AI RMF does not?

In this crosswalk, 2 of the 25 topics have a core EU AI Act clause and no NIST AI RMF clause mapped: GPAI and foundation models; Content provenance and deepfakes. A topic with no NIST AI RMF clause here is one this mapping does not reach, not one the NIST AI RMF is shown to leave out. The overlap table on this page lists the clauses; mappings are illustrative, not a claim of conformity. The NIST column maps AI RMF 1.0 (NIST AI 100-1) only: its companion Generative AI Profile (NIST AI 600-1) adds suggested actions for 12 risks that generative AI creates or exacerbates, among them information integrity and intellectual property, and is not mapped here.

Source: [NIST AI 600-1](https://doi.org/10.6028/NIST.AI.600-1)

## Illustrative mapping, not a conformity assessment

Mappings are illustrative, not a claim of conformity. A mapping cell is not evidence; see the [Framework Crosswalk pattern](https://aigovernanceengineer.com/patterns/framework-crosswalk) for what turns a crosswalk into an auditable control.

## Sources

- NIST AI RMF: https://www.nist.gov/itl/ai-risk-management-framework
- NIST AI RMF: https://airc.nist.gov/airmf-resources/airmf/
- EU AI Act (post-Omnibus): https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng
- NIST AI 100-1: https://doi.org/10.6028/NIST.AI.100-1
- NIST AI 600-1: https://doi.org/10.6028/NIST.AI.600-1
- Regulation (EU) 2026/1744 (Digital Omnibus): https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng

Every clause on this page, with its note and verification status, is in the [topic × framework crosswalk](https://aigovernanceengineer.com/resources/crosswalk) and its [JSON download](https://aigovernanceengineer.com/resources/crosswalk.json). Other comparisons: [ISO 42001 vs EU AI Act](https://aigovernanceengineer.com/resources/crosswalk/iso-42001-vs-eu-ai-act) · [NIST AI RMF vs ISO 42001](https://aigovernanceengineer.com/resources/crosswalk/nist-ai-rmf-vs-iso-42001). The wider field: [AI governance, explained](https://aigovernanceengineer.com/ai-governance).
