AIPolicyTracker

European Union AI rules mapped to NIST AI RMF

Each row is one legal duty recorded for European Union and the function of NIST AI Risk Management Framework 1.0 it corresponds to. Use it to find which duties your existing evidence already reaches.

Coverage of this crosswalk

43 of 44 recorded European Union duties carry a mapping

The denominator is the number of duties this platform has broken out for European Union, not the number of duties the law contains. Unmapped duties are ones no reviewer has crosswalked yet, not ones the standard fails to address.

The mapping

European Union AI duties mapped to NIST AI Risk Management Framework 1.0
Legal dutyBinding?NIST AI RMF functionWhy they correspondConfidence
Do not deploy or provide AI for prohibited practices EU AI Act, Article 5 Legal requirement GOVERN 1.1, MAP 1.1 Original editorial mapping to legal-requirement identification and context mapping. medium
Ensure AI literacy of staff operating AI systems EU AI Act, Article 4 Legal requirement GOVERN 2.2 Workforce training and awareness. medium
Establish a risk management system for high-risk AI EU AI Act, Article 9 Legal requirement MAP, MEASURE and MANAGE functions The AI RMF's core functions map closely to Article 9's iterative process. high
Apply data governance and quality criteria to training, validation and testing data EU AI Act, Article 10 Legal requirement MAP 2.3, MEASURE 2.1, MEASURE 2.11 Data quality and bias measurement. medium
Draw up technical documentation before placing a high-risk system on the market EU AI Act, Article 11 and Annex IV Legal requirement GOVERN 1.4, MAP 3.x Documentation practices. medium
Design high-risk systems to log events automatically EU AI Act, Article 12; Article 26(6) for deployers Legal requirement MEASURE 2.x, MANAGE 4.1 Monitoring and traceability. medium
Provide deployers with clear instructions for use EU AI Act, Article 13 Legal requirement GOVERN 4.x, MAP 1.x Transparency to downstream users. medium
Enable and assign effective human oversight EU AI Act, Article 14; Article 26(2) for deployers Legal requirement GOVERN 3.2, MANAGE 2.x Roles and human-AI configuration. medium
Achieve appropriate accuracy, robustness and cybersecurity EU AI Act, Article 15 Legal requirement MEASURE 2.5, 2.6, 2.7 Validity, safety, security and resilience measurement. high
Operate a quality management system EU AI Act, Article 17 Legal requirement GOVERN function Governance structures and policies. medium
Use high-risk AI as instructed, monitor it and inform affected people EU AI Act, Article 26 Legal requirement MANAGE 3.x, GOVERN 5.x Deployment management and stakeholder engagement. medium
Carry out a fundamental rights impact assessment before deployment EU AI Act, Article 27 Legal requirement MAP 5.1, MAP 5.2 Impacts on individuals, groups and society. medium
Disclose AI interaction and label synthetic content EU AI Act, Article 50 Legal requirement GOVERN 4.x; NIST AI 600-1 content provenance suggestions Generative AI profile guidance on provenance. medium
Meet general-purpose AI model provider obligations EU AI Act, Article 53 and Annexes XI–XII Legal requirement NIST AI 600-1 (Generative AI profile) — intellectual property and data privacy risks Original editorial mapping. medium
Manage systemic risk for high-impact general-purpose models EU AI Act, Articles 51, 52 and 55 Legal requirement MEASURE 2.x; NIST AI 600-1 Evaluation and red-teaming practices. medium
Operate a post-market monitoring system EU AI Act, Article 72 Legal requirement MANAGE 4.1, MEASURE 3.x Post-deployment monitoring. high
Report serious incidents to market surveillance authorities EU AI Act, Article 73 Legal requirement MANAGE 4.3 Incident response and communication. high
Verify conformity before importing or distributing high-risk AI EU AI Act, Articles 23 and 24 Legal requirement GOVERN 6.1, GOVERN 6.2 Third-party risk management. high
Providers must meet the full set of provider duties for high-risk AI EU AI Act, Article 16 Legal requirement GOVERN 1.1, GOVERN 2.1 Legal requirements identified and roles assigned. medium
Providers must keep high-risk AI documentation for ten years EU AI Act, Article 18 Legal requirement GOVERN 1.4 Documentation of governance and risk decisions retained. medium
Providers must retain automatically generated logs under their control EU AI Act, Article 19 Legal requirement MEASURE 2.4, MANAGE 4.1 Traceability data for monitoring. medium
Providers must take corrective action and inform the supply chain about non-conforming high-risk AI EU AI Act, Article 20 Legal requirement MANAGE 2.4, MANAGE 4.3 Mechanisms to deactivate or supersede systems and respond to incidents. high
Providers must supply conformity evidence and log access to authorities on request EU AI Act, Article 21 Legal requirement GOVERN 1.4, GOVERN 4.2 Transparency and accountability records. medium
Non-EU providers must appoint an EU authorised representative for high-risk AI EU AI Act, Article 22 Legal requirement GOVERN 2.1, GOVERN 6.1 Roles and third-party arrangements. low
Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI EU AI Act, Article 25(1) and 25(2) Legal requirement GOVERN 6.1, MAP 1.1 Roles across the AI supply chain and context of use. medium
Providers of high-risk AI must have written agreements with suppliers of components, tools and services EU AI Act, Article 25(4) Legal requirement GOVERN 6.1 Policies for third-party AI risks. high
Providers must document and register a conclusion that an Annex III system is not high-risk EU AI Act, Article 6(4); Article 49(2) Legal requirement MAP 1.5, MAP 3.1 Scoping and classification of the system's impact. medium
Deployers must ensure input data they control is relevant and representative EU AI Act, Article 26(4) Legal requirement MAP 2.3, MEASURE 2.2 Data representativeness in context. medium
Deployers must monitor high-risk AI, suspend use on risk and report serious incidents EU AI Act, Article 26(5) Legal requirement MANAGE 2.4, MANAGE 4.1, MANAGE 4.3 Deactivation mechanisms, post-deployment monitoring and incident response. high
Employers must inform workers and their representatives before using high-risk AI at work EU AI Act, Article 26(7) Legal requirement GOVERN 5.1, MAP 1.6 Engagement with affected groups. medium
Public authorities must register their use of high-risk AI and must not use unregistered systems EU AI Act, Article 26(8); Article 49(3) and 49(4) Legal requirement GOVERN 1.6, MAP 1.1 Inventory of deployed systems and context. medium
Deployers must use the provider's transparency information in their data protection impact assessment EU AI Act, Article 26(9) Legal requirement MAP 3.1, MEASURE 2.10 Privacy risk assessed with system information. medium
Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually EU AI Act, Article 26(10) Legal requirement GOVERN 1.1, MANAGE 1.3 Legal requirements and documented use decisions. low
Deployers must tell natural persons that a high-risk AI system is used in decisions about them EU AI Act, Article 26(11) Legal requirement GOVERN 5.1, MANAGE 4.1 Communication with affected individuals. medium
Providers of generative AI must mark synthetic output as artificially generated in a machine-readable way EU AI Act, Article 50(2) Legal requirement MEASURE 2.7, MANAGE 4.1 Provenance mechanisms as recommended in NIST AI 600-1. medium
Deployers of emotion recognition or biometric categorisation must inform exposed persons EU AI Act, Article 50(3) Legal requirement GOVERN 5.1, MEASURE 2.10 Communication and privacy risk. medium
Deployers must disclose deepfakes and AI-generated text published on matters of public interest EU AI Act, Article 50(4) Legal requirement GOVERN 5.1, MANAGE 4.1 Transparency to end users; NIST AI 600-1 content provenance. medium
Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold EU AI Act, Article 52(1) Legal requirement GOVERN 1.1, MAP 1.1 Legal requirement tracking and system context. medium
Providers of GPAI models must maintain technical documentation and inform downstream providers EU AI Act, Article 53(1)(a) and 53(1)(b); Annexes XI and XII Legal requirement GOVERN 1.4, MAP 2.2, MEASURE 2.1 Documentation of design, testing and evaluation. medium
Non-EU providers of GPAI models must appoint an EU authorised representative EU AI Act, Article 54 Legal requirement GOVERN 2.1, GOVERN 6.1 Roles and third-party arrangements. low
Providers of systemic-risk GPAI models must track and report serious incidents to the AI Office EU AI Act, Article 55(1)(c) Legal requirement MANAGE 4.3, MEASURE 3.1 Incident response and tracking of emergent risks. high
Providers of systemic-risk GPAI models must secure the model and its infrastructure EU AI Act, Article 55(1)(d) Legal requirement MEASURE 2.7, MANAGE 2.2 Security and resilience of the system. medium
Deployers must explain individual decisions taken with high-risk AI on request EU AI Act, Article 86 Legal requirement GOVERN 5.1, MANAGE 4.1 Recourse and communication for affected individuals. medium

What a mapping means

The duty and the function ask for overlapping work, so evidence produced for one is likely to be reusable for the other. Confidence records how direct that overlap is.

What it does not mean

NIST AI RMF adoption does not discharge a legal duty and carries no force in European Union. A mapped row still has to be complied with on the statute's own terms.

Instruments in this crosswalk

All NIST AI RMF mappings across every jurisdiction →

NIST AI RMF vs the EU AI Act: turning a voluntary framework into legal evidence →

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Does NIST AI RMF adoption satisfy European Union AI rules?
No. NIST AI RMF is a voluntary framework and carries no legal force in European Union. This crosswalk records that 43 of the 44 duties tracked here have a corresponding clause, which means the evidence may be reusable, not that the duty is discharged.
How many European Union AI duties map to NIST AI RMF?
43 of 44 duties recorded for European Union carry a mapping to NIST AI Risk Management Framework 1.0.