All articles
ComplianceAI

Governing AI: the EU AI Act, ISO 42001, and the NIST AI RMF

The AI Act is the newest and fastest-moving layer of the compliance maze, so fast that its own deadlines shifted in mid-2026. That makes it the perfect case study for the two things this series keeps arguing: build on your existing controls, and never rely on a static answer.

Ilke Tosunoğlu
Ilke TosunoğluJune 18, 20266 min readUpdated July 20, 2026
The EU AI Act risk pyramid, from prohibited and high-risk systems down to minimal-risk AI.

Part of the pillar series Sovereign AI, Explained.

This is practical guidance for compliance teams, not legal advice. Current as of July 2026.

Why the AI Act exists

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive horizontal law for artificial intelligence. Its goal: safe, trustworthy AI that respects fundamental rights, with legal certainty and a single EU market for AI. In force 1 August 2024 (EUR-Lex).

It regulates by risk tier, not by technology:

Tier What it covers Obligation
Unacceptable Social scoring, manipulative techniques, untargeted facial scraping, most real-time public biometric ID Prohibited (since Feb 2025)
High-risk Annex III use-cases (e.g. employment, credit, essential services) + safety components of regulated products Heaviest: risk management, data governance, documentation, logging, human oversight, robustness, QMS
Limited / transparency Chatbots, deepfakes, AI-generated content Disclosure/marking (Article 50)
Minimal Most systems No mandatory obligations

General-purpose AI models carry their own duties (Articles 51–56): technical documentation, downstream information, an EU copyright-compliance policy, and a public summary of training content, with extra obligations for systemic-risk models.

Fines run to €35M or 7% of global turnover for prohibited practices, and €15M or 3% for most other breaches (Article 99).

The timeline that just moved: the live proof point

Here is why a static AI compliance explainer is dangerous. The AI Act's high-risk obligations were originally scheduled for August 2026 and 2027. In mid-2026, through the "Digital Omnibus," the EU formally delayed them, because the supporting harmonized standards and national authorities weren't ready. Council gave final adoption on 29 June 2026.

Date Provision Status
2 Feb 2025 Prohibited practices + AI literacy In force
2 Aug 2025 GPAI obligations In force
2 Aug 2026 Transparency (Art. 50); enforcement begins Still applies
2 Dec 2027 High-risk (Annex III) obligations Delayed (was Aug 2026)
2 Aug 2028 Product-embedded high-risk (Annex I) Delayed (was Aug 2027)

Source: Council of the EU, 29 June 2026. Confirm the Official Journal citation of the amending regulation before relying on these dates for a filing.

Anyone who wrote "high-risk obligations apply August 2026" against the 2024 text is now wrong by more than a year. That is the timing-drift problem, live.

The frameworks that operationalize responsible AI

The AI Act tells you what. Two management frameworks tell you how. Usefully, they're built to sit on the governance and security systems you already have.

Framework What it is Why for the AI Act
ISO/IEC 42001:2023 The world's first certifiable AI management system (AIMS) Operationalizes the high-risk duties (risk management, data governance, documentation, human oversight, QMS) as an auditable, certifiable system. Uses the same harmonized structure as ISO 27001.
NIST AI RMF 1.0 Voluntary; functions Govern, Map, Measure, Manage Structures trustworthy-AI practice; the Generative AI Profile (2024) adds ~12 GenAI-specific risks

One honest caveat: the AI Act's harmonized standards (which grant a presumption of conformity) are being developed by CEN-CENELEC and are delayed, and the Commission has asked for an AI-Act-specific quality-management standard rather than adopting ISO 42001 wholesale. So treat ISO 42001 as the best available way to operationalize and demonstrate AI governance today, not as automatic legal conformity.

AI governance is an overlay, not a greenfield

The most reassuring finding: the AI Act doesn't start from scratch. Its obligations overlap heavily with laws you already handle.

  • GDPR: AI Act human-oversight (Art. 14) ↔ GDPR automated-decision rules (Art. 22); AI Act technical documentation and logging ↔ GDPR records and DPIAs; AI Act training-data governance (Art. 10) ↔ GDPR data-protection principles.
  • NIS2 / security: AI Act robustness, vulnerability monitoring, and cybersecurity (Art. 15) and serious-incident reporting (Art. 73) mirror NIS2 risk management and reporting.

So responsible-AI governance is a management-system layer on top of your privacy and security controls: the same shared control domains, applied to a new object. For the security side of AI specifically (prompt injection, data exfiltration), see our technical post, Securing AI the Way Attackers Break It.

Governance overlay for the AI Act
AI Act risk tiersUnacceptable · High · Limited · Minimal
Management systemsISO/IEC 42001 (AIMS)
NIST AI RMF 1.0Govern · Map · Measure · Manage
Evidenced overlayon GDPR + NIS2 controls

Where Soveryne fits

The AI Act is where the two Soveryne jobs are most obviously needed.

Because the rules move, coverage intelligence is not optional here. Counsel answers "is this system high-risk?" and "what's the current deadline?" from the AI Act text and official sources (with citations, and current) rather than from an explainer that predates the June 2026 delay. For a law that literally changed its own dates this year, a living, grounded answer is the only safe one. Counsel is itself a governed AI assistant (grounded, cited, EU-sovereign), which is to say, governance you can actually use.

Then Command turns the AI Act into mapped controls alongside GDPR and NIS2, so your AI inventory, risk assessments, documentation, and human-oversight measures are evidenced in the same control library, reusing the privacy and security work you've already done. AI governance stops being a separate program and becomes an overlay on the one you run.

FAQ

When do the AI Act's high-risk obligations apply? As of the June 2026 "Digital Omnibus," Annex III high-risk obligations apply from 2 December 2027 and Annex I (product-embedded) from 2 August 2028, pushed back from the original 2026/2027 dates. Transparency obligations still apply from 2 August 2026.

What framework should we adopt for the AI Act? ISO/IEC 42001 (the first certifiable AI management system) is the strongest tool to operationalize and demonstrate AI governance, complemented by the NIST AI RMF. Note the AI Act's own harmonized standards are still in development.

Does the AI Act replace our GDPR obligations for AI? No. They're cumulative and overlapping. An AI-Act-compliant system can still breach GDPR (e.g. on automated decisions or training data), so AI governance layers on top of your privacy controls.

Why did the AI Act deadlines change? The supporting harmonized standards and national authorities weren't ready, so the EU formally delayed the high-risk obligations, a reminder that AI compliance dates must be checked against current sources, not static summaries.


The AI Act moves, so your answers must too. Get current, cited answers on AI Act scope and deadlines from Counsel, and evidence AI governance alongside GDPR and NIS2 in Command.

Sources