Compliance

Turn regulatory timelines into a usable executive view.

The EU AI Act, ISO/IEC 42001, and the NIST AI RMF answer different questions and don't map onto each other cleanly. This page separates what's active now from what's deferred, and shows where the standards genuinely help — and where they don't.

What belongs on this page

EU AI Act timeline

The major dates, deferred obligations, and which rules are active now versus later.

Standards crosswalk

What ISO/IEC 42001 and the NIST AI RMF each actually answer, and where they overlap.

Gap analysis

Where the standards genuinely stop short of what the regulation requires.

EU AI Act

What's active, what's deferred.

The 2026 Digital Omnibus amendments pushed several high-risk obligations back. Treat the dates below as the current picture, not a fixed one — the EU AI Act Service Desk timeline (linked in Resources) is the regulator's own live tracker and the one to check before relying on a date for a filing deadline.

DateReferenceMilestoneImpact
2 Feb 2025Article 5Prohibited practices ban activeSocial scoring, real-time public biometric ID, and manipulative systems become illegal.
2 Aug 2025Chapter VGPAI model obligations applyProviders of general-purpose AI models must document training data and ensure copyright compliance.
2 Aug 2026Article 50Transparency/disclosure rules enforcedMandatory labelling of chatbots, deepfakes, and synthetic media.
2 Dec 2026Art. 50(2) & 5Extended bans, watermarking deadlinesSystems live before Aug 2026 must implement machine-readable watermarks.
2 Aug 2027Sandbox and testing structures activeMember states must provide at least one operational regulatory sandbox.
2 Dec 2027Annex III (deferred)Standalone high-risk system rules enforced16-month delay for standalone systems — employment, credit scoring, and similar.
2 Aug 2028Annex I (deferred)Embedded high-risk product rules enforced12-month delay for embedded safety components — medical devices, aviation software.
Standards crosswalk

Three frameworks, three different questions.

Treating these as interchangeable is the most common mistake in AI compliance planning. They're complementary, not redundant.

EU AI Act

What am I legally obligated to do?

Binding, risk-tiered, enforceable. The only one of the three with actual penalties attached.

ISO/IEC 42001

How do I run the management system that makes compliance provable?

Certifiable. The operating model — see /governance for the clause-by-clause detail.

NIST AI RMF

How should I think about AI risk, regardless of jurisdiction?

Voluntary, US-originated, but the Govern/Map/Measure/Manage structure is a genuinely useful mental model even under a UK/EU regulatory regime.

Gap analysis

Where the standards stop short.

Two concrete examples where ISO/IEC 42001 and the NIST AI RMF give no direct coverage — not an exhaustive list, but the two that come up most often in practice.

Third-party conformity assessment (Article 44)

High-risk systems require assessment by an accredited notified body. Neither ISO/IEC 42001 certification nor a NIST AI RMF self-assessment satisfies this on its own — it is a distinct regulatory step.

EU database registration (Article 49)

Certain high-risk systems must be registered in the EU database before deployment. This is a procedural filing obligation with no standards-based equivalent — it has to be done directly.

Next

See how this becomes an engagement.

EU AI Act & Regulatory Compliance Advisory is scoped against exactly this timeline and crosswalk.

Axiom Verity

Board-level AI governance advisory built on 25+ years of regulated technology risk, cyber, and cryptography leadership.