European Union AI rules mapped to NIST AI RMF
Each row is one legal duty recorded for European Union and the function of NIST AI Risk Management Framework 1.0 it corresponds to. Use it to find which duties your existing evidence already reaches.
Coverage of this crosswalk
43 of 44 recorded European Union duties carry a mapping
The denominator is the number of duties this platform has broken out for European Union, not the number of duties the law contains. Unmapped duties are ones no reviewer has crosswalked yet, not ones the standard fails to address.
The mapping
| Legal duty | Binding? | NIST AI RMF function | Why they correspond | Confidence |
|---|---|---|---|---|
| Do not deploy or provide AI for prohibited practices EU AI Act, Article 5 | Legal requirement | GOVERN 1.1, MAP 1.1 | Original editorial mapping to legal-requirement identification and context mapping. | medium |
| Ensure AI literacy of staff operating AI systems EU AI Act, Article 4 | Legal requirement | GOVERN 2.2 | Workforce training and awareness. | medium |
| Establish a risk management system for high-risk AI EU AI Act, Article 9 | Legal requirement | MAP, MEASURE and MANAGE functions | The AI RMF's core functions map closely to Article 9's iterative process. | high |
| Apply data governance and quality criteria to training, validation and testing data EU AI Act, Article 10 | Legal requirement | MAP 2.3, MEASURE 2.1, MEASURE 2.11 | Data quality and bias measurement. | medium |
| Draw up technical documentation before placing a high-risk system on the market EU AI Act, Article 11 and Annex IV | Legal requirement | GOVERN 1.4, MAP 3.x | Documentation practices. | medium |
| Design high-risk systems to log events automatically EU AI Act, Article 12; Article 26(6) for deployers | Legal requirement | MEASURE 2.x, MANAGE 4.1 | Monitoring and traceability. | medium |
| Provide deployers with clear instructions for use EU AI Act, Article 13 | Legal requirement | GOVERN 4.x, MAP 1.x | Transparency to downstream users. | medium |
| Enable and assign effective human oversight EU AI Act, Article 14; Article 26(2) for deployers | Legal requirement | GOVERN 3.2, MANAGE 2.x | Roles and human-AI configuration. | medium |
| Achieve appropriate accuracy, robustness and cybersecurity EU AI Act, Article 15 | Legal requirement | MEASURE 2.5, 2.6, 2.7 | Validity, safety, security and resilience measurement. | high |
| Operate a quality management system EU AI Act, Article 17 | Legal requirement | GOVERN function | Governance structures and policies. | medium |
| Use high-risk AI as instructed, monitor it and inform affected people EU AI Act, Article 26 | Legal requirement | MANAGE 3.x, GOVERN 5.x | Deployment management and stakeholder engagement. | medium |
| Carry out a fundamental rights impact assessment before deployment EU AI Act, Article 27 | Legal requirement | MAP 5.1, MAP 5.2 | Impacts on individuals, groups and society. | medium |
| Disclose AI interaction and label synthetic content EU AI Act, Article 50 | Legal requirement | GOVERN 4.x; NIST AI 600-1 content provenance suggestions | Generative AI profile guidance on provenance. | medium |
| Meet general-purpose AI model provider obligations EU AI Act, Article 53 and Annexes XI–XII | Legal requirement | NIST AI 600-1 (Generative AI profile) — intellectual property and data privacy risks | Original editorial mapping. | medium |
| Manage systemic risk for high-impact general-purpose models EU AI Act, Articles 51, 52 and 55 | Legal requirement | MEASURE 2.x; NIST AI 600-1 | Evaluation and red-teaming practices. | medium |
| Operate a post-market monitoring system EU AI Act, Article 72 | Legal requirement | MANAGE 4.1, MEASURE 3.x | Post-deployment monitoring. | high |
| Report serious incidents to market surveillance authorities EU AI Act, Article 73 | Legal requirement | MANAGE 4.3 | Incident response and communication. | high |
| Verify conformity before importing or distributing high-risk AI EU AI Act, Articles 23 and 24 | Legal requirement | GOVERN 6.1, GOVERN 6.2 | Third-party risk management. | high |
| Providers must meet the full set of provider duties for high-risk AI EU AI Act, Article 16 | Legal requirement | GOVERN 1.1, GOVERN 2.1 | Legal requirements identified and roles assigned. | medium |
| Providers must keep high-risk AI documentation for ten years EU AI Act, Article 18 | Legal requirement | GOVERN 1.4 | Documentation of governance and risk decisions retained. | medium |
| Providers must retain automatically generated logs under their control EU AI Act, Article 19 | Legal requirement | MEASURE 2.4, MANAGE 4.1 | Traceability data for monitoring. | medium |
| Providers must take corrective action and inform the supply chain about non-conforming high-risk AI EU AI Act, Article 20 | Legal requirement | MANAGE 2.4, MANAGE 4.3 | Mechanisms to deactivate or supersede systems and respond to incidents. | high |
| Providers must supply conformity evidence and log access to authorities on request EU AI Act, Article 21 | Legal requirement | GOVERN 1.4, GOVERN 4.2 | Transparency and accountability records. | medium |
| Non-EU providers must appoint an EU authorised representative for high-risk AI EU AI Act, Article 22 | Legal requirement | GOVERN 2.1, GOVERN 6.1 | Roles and third-party arrangements. | low |
| Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI EU AI Act, Article 25(1) and 25(2) | Legal requirement | GOVERN 6.1, MAP 1.1 | Roles across the AI supply chain and context of use. | medium |
| Providers of high-risk AI must have written agreements with suppliers of components, tools and services EU AI Act, Article 25(4) | Legal requirement | GOVERN 6.1 | Policies for third-party AI risks. | high |
| Providers must document and register a conclusion that an Annex III system is not high-risk EU AI Act, Article 6(4); Article 49(2) | Legal requirement | MAP 1.5, MAP 3.1 | Scoping and classification of the system's impact. | medium |
| Deployers must ensure input data they control is relevant and representative EU AI Act, Article 26(4) | Legal requirement | MAP 2.3, MEASURE 2.2 | Data representativeness in context. | medium |
| Deployers must monitor high-risk AI, suspend use on risk and report serious incidents EU AI Act, Article 26(5) | Legal requirement | MANAGE 2.4, MANAGE 4.1, MANAGE 4.3 | Deactivation mechanisms, post-deployment monitoring and incident response. | high |
| Employers must inform workers and their representatives before using high-risk AI at work EU AI Act, Article 26(7) | Legal requirement | GOVERN 5.1, MAP 1.6 | Engagement with affected groups. | medium |
| Public authorities must register their use of high-risk AI and must not use unregistered systems EU AI Act, Article 26(8); Article 49(3) and 49(4) | Legal requirement | GOVERN 1.6, MAP 1.1 | Inventory of deployed systems and context. | medium |
| Deployers must use the provider's transparency information in their data protection impact assessment EU AI Act, Article 26(9) | Legal requirement | MAP 3.1, MEASURE 2.10 | Privacy risk assessed with system information. | medium |
| Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually EU AI Act, Article 26(10) | Legal requirement | GOVERN 1.1, MANAGE 1.3 | Legal requirements and documented use decisions. | low |
| Deployers must tell natural persons that a high-risk AI system is used in decisions about them EU AI Act, Article 26(11) | Legal requirement | GOVERN 5.1, MANAGE 4.1 | Communication with affected individuals. | medium |
| Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way EU AI Act, Article 50(2) | Legal requirement | MEASURE 2.7, MANAGE 4.1 | Provenance mechanisms as recommended in NIST AI 600-1. | medium |
| Deployers of emotion recognition or biometric categorisation must inform exposed persons EU AI Act, Article 50(3) | Legal requirement | GOVERN 5.1, MEASURE 2.10 | Communication and privacy risk. | medium |
| Deployers must disclose deepfakes and AI-generated text published on matters of public interest EU AI Act, Article 50(4) | Legal requirement | GOVERN 5.1, MANAGE 4.1 | Transparency to end users; NIST AI 600-1 content provenance. | medium |
| Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold EU AI Act, Article 52(1) | Legal requirement | GOVERN 1.1, MAP 1.1 | Legal requirement tracking and system context. | medium |
| Providers of GPAI models must maintain technical documentation and inform downstream providers EU AI Act, Article 53(1)(a) and 53(1)(b); Annexes XI and XII | Legal requirement | GOVERN 1.4, MAP 2.2, MEASURE 2.1 | Documentation of design, testing and evaluation. | medium |
| Non-EU providers of GPAI models must appoint an EU authorised representative EU AI Act, Article 54 | Legal requirement | GOVERN 2.1, GOVERN 6.1 | Roles and third-party arrangements. | low |
| Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office EU AI Act, Article 55(1)(c) | Legal requirement | MANAGE 4.3, MEASURE 3.1 | Incident response and tracking of emergent risks. | high |
| Providers of systemic-risk GPAI models must secure the model and its infrastructure EU AI Act, Article 55(1)(d) | Legal requirement | MEASURE 2.7, MANAGE 2.2 | Security and resilience of the system. | medium |
| Deployers must explain individual decisions taken with high-risk AI on request EU AI Act, Article 86 | Legal requirement | GOVERN 5.1, MANAGE 4.1 | Recourse and communication for affected individuals. | medium |
What a mapping means
The duty and the function ask for overlapping work, so evidence produced for one is likely to be reusable for the other. Confidence records how direct that overlap is.
What it does not mean
NIST AI RMF adoption does not discharge a legal duty and carries no force in European Union. A mapped row still has to be complied with on the statute's own terms.
Instruments in this crosswalk
- EU AI Act — European Union
All NIST AI RMF mappings across every jurisdiction →
NIST AI RMF vs the EU AI Act: turning a voluntary framework into legal evidence →
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Does NIST AI RMF adoption satisfy European Union AI rules?
- No. NIST AI RMF is a voluntary framework and carries no legal force in European Union. This crosswalk records that 43 of the 44 duties tracked here have a corresponding clause, which means the evidence may be reusable, not that the duty is discharged.
- How many European Union AI duties map to NIST AI RMF?
- 43 of 44 duties recorded for European Union carry a mapping to NIST AI Risk Management Framework 1.0.