GovCompass

AI regulations & frameworks

AI regulations & frameworks

The law and the layers

By Michel Venniker· Last verified August 2026

The EU AI Act, ISO/IEC 42001, and the NIST AI RMF are not three options to choose between. The AI Act is the law and defines what you must do. ISO/IEC 42001 is the certifiable management system standard that gives your governance an auditable backbone. The NIST AI RMF is the risk method that runs inside it. They are complementary and layered, and this section covers each layer and how they connect.

Organizations meeting AI regulation for the first time tend to ask the wrong first question: which framework should we pick. The frameworks answer different questions, and mature programs use all three layers. The law sets the obligations and the deadlines. The management system standard turns obligations into an operating structure that a certification body can audit. The risk framework supplies the method for identifying and treating AI risk within that structure.

One connection between the layers deserves early attention, because it is widely assumed and legally false. ISO/IEC 42001 certification does not create a presumption of conformity with the AI Act. That presumption attaches only to harmonized European standards after the Commission cites them in the Official Journal, and the first candidates are only now reaching publication. Until then, every claim of AI Act compliance rests on your own documentation against the regulation text.

The law

The frameworks

Each framework page carries the same companion piece: the frameworks comparison, which sets the three layers side by side and shows where they overlap and where they do not.

Kept current

Time-bound facts on these pages carry a date stamp. The regulation changed in July 2026 and the first European AI standard reached publication the same month; where a page depends on a moving fact, the stamp tells you when it was last verified against the official source.