Turn regulatory timelines into a usable executive view.
The EU AI Act, ISO/IEC 42001, and the NIST AI RMF answer different questions and don't map onto each other cleanly. This page separates what's active now from what's deferred, and shows where the standards genuinely help — and where they don't.
What belongs on this page
EU AI Act timeline
The major dates, deferred obligations, and which rules are active now versus later.
Standards crosswalk
What ISO/IEC 42001 and the NIST AI RMF each actually answer, and where they overlap.
Gap analysis
Where the standards genuinely stop short of what the regulation requires.
What's active, what's deferred.
The 2026 Digital Omnibus amendments pushed several high-risk obligations back. Treat the dates below as the current picture, not a fixed one — the EU AI Act Service Desk timeline (linked in Resources) is the regulator's own live tracker and the one to check before relying on a date for a filing deadline.
| Date | Reference | Milestone | Impact |
|---|---|---|---|
| 2 Feb 2025 | Article 5 | Prohibited practices ban active | Social scoring, real-time public biometric ID, and manipulative systems become illegal. |
| 2 Aug 2025 | Chapter V | GPAI model obligations apply | Providers of general-purpose AI models must document training data and ensure copyright compliance. |
| 2 Aug 2026 | Article 50 | Transparency/disclosure rules enforced | Mandatory labelling of chatbots, deepfakes, and synthetic media. |
| 2 Dec 2026 | Art. 50(2) & 5 | Extended bans, watermarking deadlines | Systems live before Aug 2026 must implement machine-readable watermarks. |
| 2 Aug 2027 | — | Sandbox and testing structures active | Member states must provide at least one operational regulatory sandbox. |
| 2 Dec 2027 | Annex III (deferred) | Standalone high-risk system rules enforced | 16-month delay for standalone systems — employment, credit scoring, and similar. |
| 2 Aug 2028 | Annex I (deferred) | Embedded high-risk product rules enforced | 12-month delay for embedded safety components — medical devices, aviation software. |
Three frameworks, three different questions.
Treating these as interchangeable is the most common mistake in AI compliance planning. They're complementary, not redundant.
What am I legally obligated to do?
Binding, risk-tiered, enforceable. The only one of the three with actual penalties attached.
How do I run the management system that makes compliance provable?
Certifiable. The operating model — see /governance for the clause-by-clause detail.
How should I think about AI risk, regardless of jurisdiction?
Voluntary, US-originated, but the Govern/Map/Measure/Manage structure is a genuinely useful mental model even under a UK/EU regulatory regime.
Where the standards stop short.
Two concrete examples where ISO/IEC 42001 and the NIST AI RMF give no direct coverage — not an exhaustive list, but the two that come up most often in practice.
Third-party conformity assessment (Article 44)
High-risk systems require assessment by an accredited notified body. Neither ISO/IEC 42001 certification nor a NIST AI RMF self-assessment satisfies this on its own — it is a distinct regulatory step.
EU database registration (Article 49)
Certain high-risk systems must be registered in the EU database before deployment. This is a procedural filing obligation with no standards-based equivalent — it has to be done directly.
See how this becomes an engagement.
EU AI Act & Regulatory Compliance Advisory is scoped against exactly this timeline and crosswalk.