Governing AI: the EU AI Act, ISO 42001, and the NIST AI RMF
The AI Act is the newest and fastest-moving layer of the compliance maze, so fast that its own deadlines shifted in mid-2026. That makes it the perfect case study for the two things this series keeps arguing: build on your existing controls, and never rely on a static answer.

Part of the pillar series Sovereign AI, Explained.
This is practical guidance for compliance teams, not legal advice. Current as of July 2026.
Why the AI Act exists
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive horizontal law for artificial intelligence. Its goal: safe, trustworthy AI that respects fundamental rights, with legal certainty and a single EU market for AI. In force 1 August 2024 (EUR-Lex).
It regulates by risk tier, not by technology:
| Tier | What it covers | Obligation |
|---|---|---|
| Unacceptable | Social scoring, manipulative techniques, untargeted facial scraping, most real-time public biometric ID | Prohibited (since Feb 2025) |
| High-risk | Annex III use-cases (e.g. employment, credit, essential services) + safety components of regulated products | Heaviest: risk management, data governance, documentation, logging, human oversight, robustness, QMS |
| Limited / transparency | Chatbots, deepfakes, AI-generated content | Disclosure/marking (Article 50) |
| Minimal | Most systems | No mandatory obligations |
General-purpose AI models carry their own duties (Articles 51–56): technical documentation, downstream information, an EU copyright-compliance policy, and a public summary of training content, with extra obligations for systemic-risk models.
Fines run to €35M or 7% of global turnover for prohibited practices, and €15M or 3% for most other breaches (Article 99).
The timeline that just moved: the live proof point
Here is why a static AI compliance explainer is dangerous. The AI Act's high-risk obligations were originally scheduled for August 2026 and 2027. In mid-2026, through the "Digital Omnibus," the EU formally delayed them, because the supporting harmonized standards and national authorities weren't ready. Council gave final adoption on 29 June 2026.
| Date | Provision | Status |
|---|---|---|
| 2 Feb 2025 | Prohibited practices + AI literacy | In force |
| 2 Aug 2025 | GPAI obligations | In force |
| 2 Aug 2026 | Transparency (Art. 50); enforcement begins | Still applies |
| 2 Dec 2027 | High-risk (Annex III) obligations | Delayed (was Aug 2026) |
| 2 Aug 2028 | Product-embedded high-risk (Annex I) | Delayed (was Aug 2027) |
Source: Council of the EU, 29 June 2026. Confirm the Official Journal citation of the amending regulation before relying on these dates for a filing.
Anyone who wrote "high-risk obligations apply August 2026" against the 2024 text is now wrong by more than a year. That is the timing-drift problem, live.
The frameworks that operationalize responsible AI
The AI Act tells you what. Two management frameworks tell you how. Usefully, they're built to sit on the governance and security systems you already have.
| Framework | What it is | Why for the AI Act |
|---|---|---|
| ISO/IEC 42001:2023 | The world's first certifiable AI management system (AIMS) | Operationalizes the high-risk duties (risk management, data governance, documentation, human oversight, QMS) as an auditable, certifiable system. Uses the same harmonized structure as ISO 27001. |
| NIST AI RMF 1.0 | Voluntary; functions Govern, Map, Measure, Manage | Structures trustworthy-AI practice; the Generative AI Profile (2024) adds ~12 GenAI-specific risks |
One honest caveat: the AI Act's harmonized standards (which grant a presumption of conformity) are being developed by CEN-CENELEC and are delayed, and the Commission has asked for an AI-Act-specific quality-management standard rather than adopting ISO 42001 wholesale. So treat ISO 42001 as the best available way to operationalize and demonstrate AI governance today, not as automatic legal conformity.
AI governance is an overlay, not a greenfield
The most reassuring finding: the AI Act doesn't start from scratch. Its obligations overlap heavily with laws you already handle.
- GDPR: AI Act human-oversight (Art. 14) ↔ GDPR automated-decision rules (Art. 22); AI Act technical documentation and logging ↔ GDPR records and DPIAs; AI Act training-data governance (Art. 10) ↔ GDPR data-protection principles.
- NIS2 / security: AI Act robustness, vulnerability monitoring, and cybersecurity (Art. 15) and serious-incident reporting (Art. 73) mirror NIS2 risk management and reporting.
So responsible-AI governance is a management-system layer on top of your privacy and security controls: the same shared control domains, applied to a new object. For the security side of AI specifically (prompt injection, data exfiltration), see our technical post, Securing AI the Way Attackers Break It.
Where Soveryne fits
The AI Act is where the two Soveryne jobs are most obviously needed.
Because the rules move, coverage intelligence is not optional here. Counsel answers "is this system high-risk?" and "what's the current deadline?" from the AI Act text and official sources (with citations, and current) rather than from an explainer that predates the June 2026 delay. For a law that literally changed its own dates this year, a living, grounded answer is the only safe one. Counsel is itself a governed AI assistant (grounded, cited, EU-sovereign), which is to say, governance you can actually use.
Then Command turns the AI Act into mapped controls alongside GDPR and NIS2, so your AI inventory, risk assessments, documentation, and human-oversight measures are evidenced in the same control library, reusing the privacy and security work you've already done. AI governance stops being a separate program and becomes an overlay on the one you run.
FAQ
When do the AI Act's high-risk obligations apply? As of the June 2026 "Digital Omnibus," Annex III high-risk obligations apply from 2 December 2027 and Annex I (product-embedded) from 2 August 2028, pushed back from the original 2026/2027 dates. Transparency obligations still apply from 2 August 2026.
What framework should we adopt for the AI Act? ISO/IEC 42001 (the first certifiable AI management system) is the strongest tool to operationalize and demonstrate AI governance, complemented by the NIST AI RMF. Note the AI Act's own harmonized standards are still in development.
Does the AI Act replace our GDPR obligations for AI? No. They're cumulative and overlapping. An AI-Act-compliant system can still breach GDPR (e.g. on automated decisions or training data), so AI governance layers on top of your privacy controls.
Why did the AI Act deadlines change? The supporting harmonized standards and national authorities weren't ready, so the EU formally delayed the high-risk obligations, a reminder that AI compliance dates must be checked against current sources, not static summaries.
The AI Act moves, so your answers must too. Get current, cited answers on AI Act scope and deadlines from Counsel, and evidence AI governance alongside GDPR and NIS2 in Command.
Sources
- AI Act (EUR-Lex): https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Council of the EU, final adoption of the AI Act simplification (Digital Omnibus), 29 June 2026: https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/
- ISO/IEC 42001:2023: https://www.iso.org/standard/42001
- NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework
- CEN-CENELEC JTC 21 (harmonized AI standards): https://jtc21.eu/




