The Regulatory Landscape at a Glance: EU AI Act, GDPR, NIST AI RMF, and ISO/IEC 42001
Deliberate Academy Editorial Team
Reviewed for accuracy and professional relevance
You're 3 lessons in — don't lose your progress.
Sign up free to save where you are and earn a verified certificate when you pass.
- Name the four reference points a compliance professional working on AI is most likely to encounter, and describe what each one actually is at an orientation level
- Distinguish a binding legal regulation from a voluntary standard, and explain why that distinction changes how each is used
- Explain, at a high level, what each of the four frameworks is designed to answer, and how they relate to and complement one another
- Apply appropriate hedging when discussing implementation timelines and specifics for frameworks that are still evolving
New compliance professionals in this field often encounter all four of these names — the EU AI Act, GDPR, the NIST AI Risk Management Framework, ISO/IEC 42001 — in the same meeting, sometimes in the same sentence, with little explanation of how they relate. This lesson is your map, not your destination: it gives you enough orientation to recognize which framework is relevant to a given conversation and why, so that a dedicated governance course's deeper mechanics build on a real foundation rather than four unfamiliar acronyms.
The Four Reference Points
The EU AI Act. A binding regulation from the European Union — the first comprehensive, horizontal AI-specific law from a major regulatory body. It applies a risk-tiered structure: the regulatory burden a system carries scales with its potential for harm, not with how advanced its underlying technology is. It entered into force in August 2024, with its obligations applying on a phased timeline over the following years. Because a regulation phasing in over time will continue to be clarified by guidance from EU institutions, treat any specific deadline or definitional boundary you encounter as something to verify against current official sources before relying on it in a real decision — this lesson is an orientation map, not a substitute for that verification.
GDPR, and specifically Article 22. The EU's General Data Protection Regulation is a binding data protection law that predates the AI Act by several years, but one specific provision — Article 22 — is directly and frequently relevant to AI systems: it gives individuals the right not to be subject to a decision based solely on automated processing that produces a legal or similarly significant effect on them, such as a hiring rejection, a credit denial, or an insurance decision. Article 22 is covered in its own dedicated lesson next, because it is one of the most frequently and specifically tested compliance concepts in this field.
The NIST AI Risk Management Framework (AI RMF). A voluntary, process-oriented framework published by the U.S. National Institute of Standards and Technology (AI RMF 1.0, released in January 2023), widely adopted by U.S. federal agencies and referenced by private-sector organizations globally as a baseline for structuring AI risk management, independent of any specific binding law. It organizes AI governance work into four continuous functions: Govern (accountability, policy, and culture), Map (identifying context and risks), Measure (assessing and tracking risk with metrics), and Manage (prioritizing and responding to risk). Because it is voluntary and framework-based rather than a specific legal rule, organizations use it as a structuring tool for their own governance program, not as a compliance checklist with binding legal deadlines attached.
ISO/IEC 42001. A voluntary, certifiable international management-system standard for AI, published in 2023, structured around the same plan-do-check-act continuous improvement cycle used by other ISO management-system standards. It specifies how an organization should structure its AI governance processes — not specific technical performance thresholds for individual systems — and is increasingly requested by enterprise customers as evidence of structured AI governance, independent of which specific regulation applies to the organization.
A useful orientation distinction: the EU AI Act and GDPR are binding law with legal enforcement consequences. The NIST AI RMF and ISO/IEC 42001 are voluntary frameworks and standards that organizations adopt to structure their own governance work — but "voluntary" does not mean unimportant: enterprise customers, insurers, and increasingly regulators themselves treat alignment with these frameworks as meaningful evidence of a mature AI governance posture, sometimes ahead of what any specific law strictly requires.
A colleague says, 'our organization needs to comply with the NIST AI RMF the same way we comply with the EU AI Act.' What is the correct correction, based on this lesson?
Select one answer.
How the Four Fit Together in Practice
These four are complementary, not competing, and a compliance professional will typically use more than one at the same time on the same system. A single AI-powered hiring tool deployed by an EU-based organization might need EU AI Act risk-tier classification (because it operates in an enumerated high-risk domain — employment), a GDPR Article 22 assessment (because it may make or influence an automated decision about a specific individual), and sit inside an organization-wide AI management system structured along NIST AI RMF or ISO/IEC 42001 lines (because the organization has adopted one or both as its overall governance structure). None of the four frameworks replaces the others — each answers a related but distinct question.
Untangling Four Frameworks for One System — Multinational Retailer
Context
A compliance analyst was asked to assess a new AI-powered customer-service chatbot being rolled out across both EU and US markets, and initially treated the assessment as a single undifferentiated 'AI compliance check.'
Action
Working through the orientation framework from this lesson, she separated the assessment into its actual components: an EU AI Act risk-tier check (the chatbot interacts directly with individuals, which is relevant to the Act's transparency-obligation tier), a GDPR Article 22 check (the chatbot did not make automated decisions with legal effect, so Article 22 was not triggered), and an internal governance-structure check against the company's existing ISO/IEC 42001-aligned management system (confirming the deployment followed the company's established AI intake and review process).
Outcome
Separating the single vague task into three distinct, correctly scoped questions took less time than the team's previous undifferentiated approach and produced a clearer, more defensible record of which framework was checked and why. The compliance analyst's manager adopted this separation approach as the standard first step for every new AI system review going forward.
Why does this lesson recommend applying appropriate hedging when discussing EU AI Act implementation timelines and specific deadlines?
Select one answer.
Exercise
Your Task
Take an AI system your organization uses or is evaluating (or a plausible one). For each of the four frameworks in this lesson, write one sentence on whether and why it is potentially relevant to that system: EU AI Act (does it operate in an enumerated high-risk domain, or interact directly with people?), GDPR Article 22 (does it make or influence an automated decision about a specific individual?), NIST AI RMF (does your organization use or plan to use it as a governance structure?), ISO/IEC 42001 (does your organization hold or plan to pursue this certification, or does a customer request it?).
Your reflection
Did you complete this exercise? What did you find? (Saved locally in your browser)
- The EU AI Act and GDPR are binding law with legal enforcement consequences; the NIST AI RMF and ISO/IEC 42001 are voluntary frameworks and standards organizations adopt to structure their own governance work.
- The EU AI Act applies a risk-tiered structure that scales regulatory burden to potential harm, entered into force in August 2024, and phases in its obligations over time.
- GDPR Article 22 gives individuals the right not to be subject to a decision based solely on automated processing with a legal or similarly significant effect — covered in depth in the next lesson.
- The NIST AI RMF organizes governance work into four functions — Govern, Map, Measure, Manage — and ISO/IEC 42001 structures an AI management system around a plan-do-check-act cycle; both are increasingly requested by enterprise customers regardless of which binding law applies.
- These four frameworks are complementary, not competing — a single AI system commonly needs to be assessed against more than one at the same time, each answering a distinct question.