1 August 2024 — entered into force (European Commission, digital-strategy.ec.europa.eu).
2 February 2025 — prohibited practices banned; AI-literacy obligations apply.
2 August 2025 — governance rules and general-purpose AI (GPAI) obligations apply.
2 August 2026 — the Act's main application date (now reached; the core regime applies).
2 December 2027 / 2 August 2028 — extended dates for certain sensitive-area and regulated-product high-risk systems.
The risk architecture does the sorting: banned practices, high-risk systems with pre-market obligations, transparency-risk systems (disclose that a human is talking to AI), and a minimal-risk tier the Act deliberately leaves alone. Classification is therefore the first real governance task — most of the Act's weight lands only if your use case is high-risk, and knowing that requires the inventory this site keeps returning to.
NIST AI RMF, as an operating system
Released 26 January 2023 and explicitly voluntary, the framework organizes trustworthy-AI work into four functions: Govern (policies, accountability, culture), Map (context and risk identification per system), Measure (evaluate and track those risks), and Manage (act on them, monitor, respond). Its genius is being jurisdiction-neutral scaffolding: an RMF-shaped program can produce EU AI Act evidence, customer-questionnaire answers, and internal audit artifacts from the same inventory and controls.
What both imply for tooling
Every obligation above reduces to registries and evidence: which systems exist, their classification, their owners, their evaluations, their incidents. That is database-and-workflow work — which is why the software category exists, and why a disciplined spreadsheet beats an empty platform. See the software page for that market's honest shape.
Framework questions
What does the EU AI Act prohibit outright?
The unacceptable-risk tier — practices the Act deems a clear threat to safety, livelihoods, and rights — is banned entirely, with nine listed practices (the Commission's summary includes examples like social scoring and certain manipulative or exploitative systems). These bans have applied since 2 February 2025, the Act's earliest applicable obligations, alongside AI-literacy requirements.
What makes a system "high-risk" under the AI Act?
Use cases posing serious risk to health, safety, or fundamental rights — the Commission's categories cover areas like critical infrastructure, education, employment, essential services, law enforcement, and justice, plus AI embedded in regulated products. High-risk systems face pre-market obligations: risk management, data governance, documentation, human oversight, robustness. Application dates stagger: the core regime applies from 2 August 2026, with sensitive-area and regulated-product extensions to 2 December 2027 and 2 August 2028.
Is NIST AI RMF mandatory?
No — NIST states it is intended for voluntary use. Its pull is practical rather than legal: it is the shared vocabulary US enterprises, auditors, and procurement teams reach for, and its four functions (Govern, Map, Measure, Manage) structure most governance programs regardless of jurisdiction. Voluntary frameworks become de facto mandatory when your biggest customer's security questionnaire is built on one.