NIST AI RMF — Generative AI Profile published
Companion profile mapping GenAI-specific risks to the Govern/Map/Measure/Manage functions.
The same obligation themes, side by side, from the catalogue that powers the rest of this site — 19 catalogued requirements across 16 themes. Expand any requirement to read it. Free, no login.
Comparing 2 of 38 regulations we track. This URL is the comparison — send it to anyone.
Every theme below appears in exactly one group, so these account for all 16 of them. Sharing a theme means both regimes legislate in that area — it does not mean complying with one discharges the other.
NIST AI RMF · EU AI Act
EU AI Actnot: NIST AI RMF
NIST AI RMFnot: EU AI Act
A dash means we have not catalogued a requirement for that regulation under that theme — a summary of our catalogue, not a finding that the law is silent. Always check the official text, linked from each regulation's page.
| Theme | NIST AI RMF | EU AI Act |
|---|---|---|
| What is forbidden outright | ||
| Outright bans Are some uses forbidden regardless of safeguards? | — | Art. 5 Prohibited AI practices mustPractices such as social scoring, manipulative/subliminal techniques, exploitation of vulnerabilities, untargeted facial scraping, and (most) real-time remote biometric identification are banned and cannot be placed on the EU market. Read it in context → |
| What you must assess first | ||
| Risk management system Must you run a documented, continuous risk process? | MAP Map: context & risks shouldEstablish the context and identify risks for the AI system and its intended/foreseeable uses. Read it in context → | Art. 9 Risk-management system mustEstablish, document and maintain a continuous risk-management system across the AI lifecycle. Read it in context → |
| Rights impact assessment Must you assess the impact on people before deploying? | — | Art. 27 Fundamental Rights Impact Assessment mustCertain deployers must perform a Fundamental Rights Impact Assessment before putting the system into use. Read it in context → |
| What you owe the data | ||
| Data & training data Are there duties on the data the system learns from? | — | Art. 10 Data & data governance mustTraining, validation and testing data must meet quality criteria and be examined for bias; document provenance and representativeness. Read it in context → |
| What you must build and prove | ||
| Accuracy, robustness & security Must you hit and evidence performance targets? | MEASURE Measure: analyse & track shouldUse quantitative/qualitative methods to assess trustworthiness — bias, robustness, security, drift — continuously. Read it in context → | Art. 15 Accuracy, robustness & cybersecurity mustAchieve appropriate accuracy, robustness and cybersecurity, and declare metrics. Read it in context → |
| Technical documentation Must a technical file exist before deployment? | — | Art. 11 / Annex IV Technical documentation mustDraw up and keep up-to-date technical documentation demonstrating conformity (the Annex IV technical file). Read it in context → |
| Conformity assessment Must someone certify it before it goes to market? | — | Art. 43 Conformity assessment mustUndergo the relevant conformity-assessment procedure and draw up an EU declaration of conformity before market entry. Read it in context → |
| Registration & public listing Must the system be registered or published somewhere? | — | Art. 49 EU database registration mustRegister the high-risk system in the EU database before placing it on the market. Read it in context → |
| What you must tell people | ||
| Transparency & explanation Must you explain how it works, and to whom? | — | Art. 13 Transparency & instructions for use mustProvide deployers with clear instructions: capabilities, limitations, and required human oversight. Read it in context → |
| Telling people AI was used Must people be told an AI was involved? | — | Art. 50 Transparency for certain systems mustInform people they are interacting with an AI system (chatbots) and label AI-generated/manipulated content. Read it in context → |
| Labelling AI-generated content Must generated output be marked or watermarked? | — | Art. 50(2) Marking of synthetic content mustMark AI-generated audio, image, video or text in a machine-readable, detectable way. Read it in context → |
| What you must do while it runs | ||
| Human oversight & override Must a person be able to intervene, review or stop it? | — | Art. 14 Human oversight mustDesign the system so humans can effectively oversee it, intervene, and stop it. Read it in context → |
| Logging & records Must the system keep records of what it did? | — | Art. 12 Record-keeping (logging) mustAutomatically record events (logs) over the system lifetime to ensure traceability. Read it in context → |
| Monitoring after deployment Must you keep watching it once it is live? | MANAGE Manage: prioritise & respond shouldPrioritise, treat and monitor identified risks; plan responses and recovery. Read it in context → | Art. 72 Post-market monitoring mustOperate a post-market monitoring system to collect and review performance data after deployment. Read it in context → |
| Incident reporting Must failures be reported, and to whom? | — | Art. 73 Serious-incident reporting mustReport serious incidents and malfunctioning to the competent market-surveillance authority. Read it in context → |
| What the organisation must carry | ||
| AI policy, roles & governance Must the organisation itself be governed, not just the system? | GOVERN Govern: culture & accountability shouldCultivate a risk-management culture: policies, roles, accountability and oversight across the organisation. Read it in context → | — |
Every dated obligation attached to these regulations, merged into one timeline.
Companion profile mapping GenAI-specific risks to the Govern/Map/Measure/Manage functions.
Eight unacceptable-risk practices (social scoring, manipulative AI, untargeted face-scraping, most real-time biometric ID) are banned.
The final GPAI Code of Practice (Transparency, Copyright, Safety & Security chapters) gives providers a voluntary route to demonstrate compliance ahead of harmonised standards.
National competent authorities and fines (up to 7% of global turnover for prohibited use) become enforceable.
GPAI providers owe transparency, technical documentation, copyright policy, and systemic-risk duties for capable models.
Now live. Chatbots must disclose they are AI; deepfakes and emotion-recognition/biometric-categorisation uses must be disclosed. The Commission adopted final Art. 50 guidelines on 20 July 2026, and the AI Office's enforcement powers over GPAI providers (fines up to €15M or 3% of turnover) became applicable the same day. Providers' machine-readable marking of synthetic content under Art. 50(2) has a grace period to 2 Dec 2026.
The Digital Omnibus adds a prohibition on AI systems for non-consensual intimate imagery/CSAM and ends the synthetic-content marking grace period for pre-existing systems.
Providers of high-risk systems must report serious incidents to authorities within 15 days (10 days on a death; 2 days for widespread infringement or critical-infrastructure disruption).
Full high-risk regime (risk management, data governance, logging, human oversight, accuracy, conformity assessment, registration). Moved from Aug 2026 to 2 Dec 2027 by the Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026 and in force since 27 July 2026, so this date is settled law.
High-risk AI embedded in regulated products (machinery, medical devices, vehicles) must comply. Moved from Aug 2027 to 2 Aug 2028 by the Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026.