dates verified against ec.europa.eu and nist.gov

The two frameworks that anchor everything

The EU AI Act, as a compliance calendar

The risk tiers do the sorting. There are banned practices, and high-risk systems with pre-market obligations. There are transparency-risk systems, which must disclose that a human is talking to AI, and a minimal-risk tier the Act leaves alone on purpose. So the first real governance task is working out which tier you are in. Most of the Act's weight lands only if your use case is high-risk, and knowing that requires the inventory this site keeps returning to.

NIST AI RMF, as an operating system

Released 26 January 2023, and explicitly voluntary, the framework sorts trustworthy-AI work into four functions. Govern covers policies, accountability, and culture, and Map finds the context and risks of each system. Measure tests and tracks those risks, and Manage acts on them, monitors, and responds. Its genius is that it works in any jurisdiction. One RMF-shaped program can produce EU AI Act evidence, customer-questionnaire answers, and internal audit artifacts — all from the same inventory and controls.

What both imply for tooling

Every obligation above reduces to registries and evidence: which systems exist, how each one is classed, who owns it, what its tests showed, and what incidents it had. That is database-and-workflow work. It is why the software category exists, and why a disciplined spreadsheet beats an empty platform. See the software page for that market's honest shape.

Framework questions

What does the EU AI Act prohibit outright?

The Act bans the unacceptable-risk tier outright. These are practices the Act deems a clear threat to safety, livelihoods, and rights, and nine are listed. The Commission's summary includes examples like social scoring and certain manipulative or exploitative systems. These bans have applied since 2 February 2025 — the Act's earliest applicable obligations — alongside AI-literacy requirements.

What makes a system "high-risk" under the AI Act?

A use case that poses serious risk to health, safety, or fundamental rights. The Commission's categories cover areas like critical infrastructure, education, employment, essential services, law enforcement, and justice, and also AI embedded in regulated products. High-risk systems face pre-market obligations: risk management, data governance, documentation, human oversight, robustness. The dates stagger: the core regime applies from 2 August 2026. Extensions for sensitive-area and regulated-product systems run to 2 December 2027 and 2 August 2028.

Is NIST AI RMF mandatory?

No — NIST states it is intended for voluntary use. Its pull is practical, not legal: it is the shared language that US firms, auditors, and procurement teams reach for. Its four functions (Govern, Map, Measure, Manage) shape most governance programs in any jurisdiction. And a voluntary framework becomes mandatory in practice when your biggest customer's security questionnaire is built on it.