AI & Compliance

AI Compliance in 2026: EU AI Act, NIST AI RMF, and ISO 42001

LowerPlane Team10 min read

TL;DR

  • • The EU AI Act is the world's first comprehensive AI regulation — now enforceable in 2026
  • • It classifies AI systems into Unacceptable, High, Limited, and Minimal risk tiers with different obligations
  • • NIST AI RMF (2023) is the US voluntary framework for AI risk management — increasingly referenced in federal contracts
  • • ISO 42001 is the new international AI management system standard, analogous to ISO 27001 for information security
  • • Penalties under the EU AI Act reach €35M or 7% of global turnover for the most serious violations

In 2026, "we use AI responsibly" is no longer enough. Regulators, enterprise buyers, and board members increasingly demand documented evidence of how AI systems are governed, tested, and monitored. Three frameworks dominate the conversation: the EU AI Act (now in full enforcement), the NIST AI Risk Management Framework, and ISO 42001. Understanding all three — and which applies to your company — is now a foundational compliance question.

The EU AI Act: World's First Comprehensive AI Law

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) entered into force in August 2024, with obligations rolling out through 2026 and 2027. The Act applies to any provider or deployer of AI systems that affect people in the EU — regardless of where the company is incorporated.

The Four Risk Tiers

UNACCEPTABLE RISK
Prohibited — Effective February 2025

These AI systems are banned outright in the EU. Violations can result in fines up to €35M or 7% of global annual turnover.

  • • Real-time biometric surveillance in public spaces by law enforcement (narrow exceptions apply)
  • • Social scoring systems by public or private entities affecting fundamental rights
  • • Manipulation of people's behavior exploiting subconscious biases or vulnerabilities
  • • AI that infers sensitive characteristics (race, political opinions, sexual orientation) from biometric data
  • • "Emotion recognition" in workplaces and educational institutions
HIGH RISK
Heavy obligations — Full compliance required by August 2026

High-risk AI systems face the most substantial compliance requirements. These are systems used in critical infrastructure, employment, education, essential services, law enforcement, migration, or administration of justice.

Key obligations for high-risk AI providers:

  • • Register in the EU AI system database before market placement
  • • Establish a risk management system covering the entire AI lifecycle
  • • Implement data governance and management practices for training data
  • • Prepare technical documentation explaining system design, purpose, and capabilities
  • • Enable automatic logging of events during system operation
  • • Provide human oversight mechanisms and override capabilities
  • • Achieve accuracy, robustness, and cybersecurity standards
  • • Undergo conformity assessment (third-party for some categories)
  • • Apply CE marking before EU deployment
LIMITED RISK
Transparency obligations

AI systems that interact with humans (chatbots, virtual assistants) must disclose that the user is interacting with AI. AI-generated content (deepfakes, synthetic media) must be labeled. This applies to most AI-powered SaaS features — even simple ones.

MINIMAL RISK
No mandatory requirements (but voluntary codes encouraged)

AI-powered spam filters, AI-enabled video games, inventory optimization systems, and most recommendation engines fall here. No mandatory compliance obligations, but the EU encourages voluntary adoption of AI codes of conduct.

General-Purpose AI (GPAI) Models

The EU AI Act also covers General-Purpose AI models — foundation models like GPT-4, Claude, Gemini, and Llama that can be adapted for many downstream tasks. Providers of GPAI models must:

GPAI models with "systemic risk" (trained using compute exceeding 10^25 FLOPs) face additional obligations including adversarial testing, incident reporting to the European AI Office, and cybersecurity measures.

NIST AI Risk Management Framework

The NIST AI Risk Management Framework (AI RMF 1.0), released January 2023, is a voluntary US framework for managing risks associated with AI systems. Unlike the EU AI Act, it carries no legal penalties — but it's increasingly referenced in US federal procurement requirements, defense contractor obligations, and financial services guidance.

The AI RMF is organized around four core functions:

GOVERN

Establish organizational practices, culture, and accountability structures for AI risk. Includes policies, roles, training, and incentives. This is the "tone from the top" function.

MAP

Identify and classify AI risks based on context — who is affected, how the system will be used, and what failure modes exist. Requires cataloguing AI systems and their societal impact.

MEASURE

Quantify and prioritize AI risks using metrics, testing, bias assessments, and benchmarking. Includes performance evaluation across demographic groups and adversarial testing.

MANAGE

Allocate resources to mitigate prioritized risks, establish response plans for AI incidents, and continuously monitor deployed systems for drift, failure, or emerging harms.

For US companies, aligning with NIST AI RMF is increasingly important for selling to federal agencies and large enterprise customers with AI governance mandates. It also provides a useful internal structure regardless of regulatory requirements.

ISO 42001: The AI Management System Standard

ISO/IEC 42001:2023 is the international standard for AI Management Systems (AIMS), published in December 2023. If you're familiar with ISO 27001 for information security or ISO 9001 for quality management, ISO 42001 follows the same High-Level Structure (HLS) approach — making it compatible and integrable with those existing standards.

What ISO 42001 Covers

ISO 42001 requires organizations to establish, implement, maintain, and continuously improve an AI Management System. Key components:

Context & Scope: Define the boundaries of your AIMS, identify internal and external stakeholders, and understand how your AI use affects them
Leadership & Policy: Top management commitment to responsible AI, a formal AI policy, and clear roles and responsibilities
Risk & Opportunity Assessment: Identify and evaluate AI-specific risks (bias, explainability, safety, privacy) and opportunities throughout the AI lifecycle
Objectives & Planning: Set measurable AI objectives and plan how to achieve them — including fairness metrics, accuracy targets, and transparency goals
Support: Provide resources, competence, awareness, communication, and documented information for AI governance
Operational Controls: Establish controls across the AI system lifecycle: data management, model development, testing, deployment, and monitoring
Performance Evaluation: Monitor and measure AIMS performance, conduct internal audits, and review progress against objectives
Continuous Improvement: Address nonconformities, take corrective action, and continually improve the AIMS

ISO 42001 certification is still emerging — as of 2026, a relatively small number of companies are certified compared to ISO 27001. But it's gaining traction rapidly, particularly in Europe where the EU AI Act's requirements align closely with ISO 42001's management system approach. Organizations that are ISO 27001 certified have a significant head start since the frameworks share structure and many control concepts.

Which Framework Applies to Your Company?

Company ProfilePriority FrameworkWhy
EU customers / EU marketEU AI Act (mandatory)Legal requirement — non-compliance risks fines up to €35M
US federal/defense contractsNIST AI RMF (de facto)Increasingly required in federal procurement and DoD
Global enterprise salesISO 42001International certification demonstrates systematic AI governance
Already ISO 27001 certifiedISO 42001 (lowest lift)Shared HLS structure means most governance infrastructure already exists
AI/ML in high-risk domains (HR, credit, healthcare, law enforcement)EU AI Act (High-Risk)Product likely classified as high-risk AI under Annex III

Practical AI Compliance Steps for 2026

Step 1: Inventory your AI systems

List every AI/ML system your company uses or deploys — including vendor-provided AI features in your SaaS stack. Classify each by EU AI Act risk tier.

Step 2: Assess high-risk classification

Review EU AI Act Annex III and Annex I carefully. If your system affects employment, credit, education, essential services, or law enforcement decisions for EU residents, assume high-risk classification until you can definitively rule it out.

Step 3: Implement model governance

Document model purpose, training data sources, known limitations, and intended use cases. Establish version control and model cards for all production models.

Step 4: Run bias and fairness testing

Test model outputs across demographic subgroups for disparate impact. Document methodology and findings. For high-risk AI, this is mandatory. For all AI, it's increasingly expected by enterprise customers.

Step 5: Add AI transparency to user-facing features

If your product has a chatbot, virtual assistant, or AI-generated content feature, add clear disclosure that users are interacting with AI. This satisfies EU AI Act "limited risk" transparency requirements.

Step 6: Establish human oversight mechanisms

For consequential AI decisions, ensure a human can review, override, and opt out of AI-driven outcomes. Document these mechanisms. For high-risk AI, this is a legal obligation.

Step 7: Build an AI policy and governance structure

Assign an AI governance lead (could be your CISO or a VP Engineering). Draft an AI use policy covering acceptable use, prohibited use cases, and responsible development practices. This is the foundation for ISO 42001 alignment.

Ready to Simplify Your Compliance?

LowerPlane automates up to 80% of your compliance work across multiple frameworks.

Book a Demo