AI Compliance in 2026: EU AI Act, NIST AI RMF, and ISO 42001
TL;DR
- • The EU AI Act is the world's first comprehensive AI regulation — now enforceable in 2026
- • It classifies AI systems into Unacceptable, High, Limited, and Minimal risk tiers with different obligations
- • NIST AI RMF (2023) is the US voluntary framework for AI risk management — increasingly referenced in federal contracts
- • ISO 42001 is the new international AI management system standard, analogous to ISO 27001 for information security
- • Penalties under the EU AI Act reach €35M or 7% of global turnover for the most serious violations
In 2026, "we use AI responsibly" is no longer enough. Regulators, enterprise buyers, and board members increasingly demand documented evidence of how AI systems are governed, tested, and monitored. Three frameworks dominate the conversation: the EU AI Act (now in full enforcement), the NIST AI Risk Management Framework, and ISO 42001. Understanding all three — and which applies to your company — is now a foundational compliance question.
The EU AI Act: World's First Comprehensive AI Law
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force in August 2024, with obligations rolling out through 2026 and 2027. The Act applies to any provider or deployer of AI systems that affect people in the EU — regardless of where the company is incorporated.
The Four Risk Tiers
These AI systems are banned outright in the EU. Violations can result in fines up to €35M or 7% of global annual turnover.
- • Real-time biometric surveillance in public spaces by law enforcement (narrow exceptions apply)
- • Social scoring systems by public or private entities affecting fundamental rights
- • Manipulation of people's behavior exploiting subconscious biases or vulnerabilities
- • AI that infers sensitive characteristics (race, political opinions, sexual orientation) from biometric data
- • "Emotion recognition" in workplaces and educational institutions
High-risk AI systems face the most substantial compliance requirements. These are systems used in critical infrastructure, employment, education, essential services, law enforcement, migration, or administration of justice.
Key obligations for high-risk AI providers:
- • Register in the EU AI system database before market placement
- • Establish a risk management system covering the entire AI lifecycle
- • Implement data governance and management practices for training data
- • Prepare technical documentation explaining system design, purpose, and capabilities
- • Enable automatic logging of events during system operation
- • Provide human oversight mechanisms and override capabilities
- • Achieve accuracy, robustness, and cybersecurity standards
- • Undergo conformity assessment (third-party for some categories)
- • Apply CE marking before EU deployment
AI systems that interact with humans (chatbots, virtual assistants) must disclose that the user is interacting with AI. AI-generated content (deepfakes, synthetic media) must be labeled. This applies to most AI-powered SaaS features — even simple ones.
AI-powered spam filters, AI-enabled video games, inventory optimization systems, and most recommendation engines fall here. No mandatory compliance obligations, but the EU encourages voluntary adoption of AI codes of conduct.
General-Purpose AI (GPAI) Models
The EU AI Act also covers General-Purpose AI models — foundation models like GPT-4, Claude, Gemini, and Llama that can be adapted for many downstream tasks. Providers of GPAI models must:
- →Prepare and maintain technical documentation
- →Comply with EU copyright law regarding training data
- →Publish a summary of training data used
GPAI models with "systemic risk" (trained using compute exceeding 10^25 FLOPs) face additional obligations including adversarial testing, incident reporting to the European AI Office, and cybersecurity measures.
NIST AI Risk Management Framework
The NIST AI Risk Management Framework (AI RMF 1.0), released January 2023, is a voluntary US framework for managing risks associated with AI systems. Unlike the EU AI Act, it carries no legal penalties — but it's increasingly referenced in US federal procurement requirements, defense contractor obligations, and financial services guidance.
The AI RMF is organized around four core functions:
Establish organizational practices, culture, and accountability structures for AI risk. Includes policies, roles, training, and incentives. This is the "tone from the top" function.
Identify and classify AI risks based on context — who is affected, how the system will be used, and what failure modes exist. Requires cataloguing AI systems and their societal impact.
Quantify and prioritize AI risks using metrics, testing, bias assessments, and benchmarking. Includes performance evaluation across demographic groups and adversarial testing.
Allocate resources to mitigate prioritized risks, establish response plans for AI incidents, and continuously monitor deployed systems for drift, failure, or emerging harms.
For US companies, aligning with NIST AI RMF is increasingly important for selling to federal agencies and large enterprise customers with AI governance mandates. It also provides a useful internal structure regardless of regulatory requirements.
ISO 42001: The AI Management System Standard
ISO/IEC 42001:2023 is the international standard for AI Management Systems (AIMS), published in December 2023. If you're familiar with ISO 27001 for information security or ISO 9001 for quality management, ISO 42001 follows the same High-Level Structure (HLS) approach — making it compatible and integrable with those existing standards.
What ISO 42001 Covers
ISO 42001 requires organizations to establish, implement, maintain, and continuously improve an AI Management System. Key components:
ISO 42001 certification is still emerging — as of 2026, a relatively small number of companies are certified compared to ISO 27001. But it's gaining traction rapidly, particularly in Europe where the EU AI Act's requirements align closely with ISO 42001's management system approach. Organizations that are ISO 27001 certified have a significant head start since the frameworks share structure and many control concepts.
Which Framework Applies to Your Company?
| Company Profile | Priority Framework | Why |
|---|---|---|
| EU customers / EU market | EU AI Act (mandatory) | Legal requirement — non-compliance risks fines up to €35M |
| US federal/defense contracts | NIST AI RMF (de facto) | Increasingly required in federal procurement and DoD |
| Global enterprise sales | ISO 42001 | International certification demonstrates systematic AI governance |
| Already ISO 27001 certified | ISO 42001 (lowest lift) | Shared HLS structure means most governance infrastructure already exists |
| AI/ML in high-risk domains (HR, credit, healthcare, law enforcement) | EU AI Act (High-Risk) | Product likely classified as high-risk AI under Annex III |
Practical AI Compliance Steps for 2026
Step 1: Inventory your AI systems
List every AI/ML system your company uses or deploys — including vendor-provided AI features in your SaaS stack. Classify each by EU AI Act risk tier.
Step 2: Assess high-risk classification
Review EU AI Act Annex III and Annex I carefully. If your system affects employment, credit, education, essential services, or law enforcement decisions for EU residents, assume high-risk classification until you can definitively rule it out.
Step 3: Implement model governance
Document model purpose, training data sources, known limitations, and intended use cases. Establish version control and model cards for all production models.
Step 4: Run bias and fairness testing
Test model outputs across demographic subgroups for disparate impact. Document methodology and findings. For high-risk AI, this is mandatory. For all AI, it's increasingly expected by enterprise customers.
Step 5: Add AI transparency to user-facing features
If your product has a chatbot, virtual assistant, or AI-generated content feature, add clear disclosure that users are interacting with AI. This satisfies EU AI Act "limited risk" transparency requirements.
Step 6: Establish human oversight mechanisms
For consequential AI decisions, ensure a human can review, override, and opt out of AI-driven outcomes. Document these mechanisms. For high-risk AI, this is a legal obligation.
Step 7: Build an AI policy and governance structure
Assign an AI governance lead (could be your CISO or a VP Engineering). Draft an AI use policy covering acceptable use, prohibited use cases, and responsible development practices. This is the foundation for ISO 42001 alignment.
Ready to Simplify Your Compliance?
LowerPlane automates up to 80% of your compliance work across multiple frameworks.
Book a Demo