Skip to main content
NIST AI RMF27 May 2026 · 5 min read

Using the NIST AI RMF as a bridge to the EU AI Act

The NIST AI Risk Management Framework is voluntary US guidance and not a certification. Its four functions provide a practical structure for building the risk management, testing and documentation that also support EU AI Act obligations.

What the NIST AI RMF is

The AI Risk Management Framework (NIST AI 100-1, AI RMF 1.0) was published by the US National Institute of Standards and Technology on 26 January 2023, mandated by the National AI Initiative Act of 2020. It is explicitly voluntary and not a certification: there is no seal and no assessment body, only a structured method for designing, developing and operating trustworthy AI.

The core of the framework is four functions. Govern anchors culture, roles and policies across the entire lifecycle and is the only function that spans the whole organisation. Map, Measure and Manage are applied per system and context, and can be run in any order.

  • Govern — governance, accountability and policies across the full lifecycle.
  • Map — capture context, stakeholders, system boundaries and potential harms.
  • Measure — analyse and monitor risks with quantitative and qualitative methods.
  • Manage — prioritise and treat risks, document residual risk and respond to incidents.

The Generative AI Profile (NIST-AI-600-1)

On 26 July 2024, NIST published the Generative AI Profile (NIST-AI-600-1) as a companion to the AI RMF, produced in response to US Executive Order 14110. A profile is an application of the RMF functions to a specific technology — here generative AI — along the requirements, risk tolerance and resources of the organisation.

The profile names twelve risk categories that are unique to or exacerbated by generative AI — among them confabulation (hallucination), data privacy, information integrity and information security — and maps concrete suggested actions back to the four functions Govern, Map, Measure and Manage.

From voluntary framework to AI Act obligations

The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024; its transparency obligations apply from 2 August 2026 and the core high-risk obligations from 2 December 2027 following the 2026 Digital Omnibus amendment. For high-risk AI, Article 9 requires a risk management system that is established, implemented, documented and maintained — a continuous, iterative process across the entire lifecycle. That very continuity is what the RMF functions Map, Measure and Manage already describe.

Article 11 requires technical documentation per Annex IV before a system is placed on the market. The evidence produced under the RMF — system inventory, risk records, measurement results and treatment decisions — can be reused as supporting material for that documentation and for a management system, rather than building parallel structures.

What it delivers — and what it does not

The boundary matters: adopting the NIST AI RMF does not produce conformity with the EU AI Act. The legal presumption of conformity runs, under Article 40, through harmonised European standards still being developed by CEN and CENELEC (JTC 21). Any crosswalks that map the RMF to the AI Act are community-submitted resources that NIST hosts without endorsing them — not an authoritative mapping to the final Regulation.

The practical value therefore lies in reuse: a risk management practice built once to the RMF, with robust testing and end-to-end documentation, provides the substance that Articles 9 and 11 demand. It shortens the path, but it replaces neither the conformity assessment procedure nor the authoritative check against the official text of the Regulation.

Key takeaway

Use the four NIST functions to build risk management, testing and documentation once, as reusable substance for Articles 9 and 11 — and keep verifying conformity through the harmonised standards and the official AI Act text.

Book a demo

Turn the regulation into a running system.

30 minutes, scoped to your frameworks and integrations. You leave with a concrete plan — not a sales loop.