Turn regulatory timelines into a usable executive view.
The EU AI Act, ISO/IEC 42001, and the NIST AI RMF answer different questions and don't map onto each other cleanly. This page separates what's active now from what's deferred, and shows where the standards genuinely help, and where they don't.
Last reviewed: 2026-07-29
What belongs on this page
EU AI Act timeline
The major dates, deferred obligations, and which rules are active now versus later.
Standards crosswalk
What ISO/IEC 42001 and the NIST AI RMF each actually answer, and where they overlap.
Gap analysis
Where the standards genuinely stop short of what the regulation requires.
What's active, what's deferred.
The 2026 Digital Omnibus amendments pushed several high-risk obligations back. Treat the dates below as the current picture, not a fixed one. The EU AI Act Service Desk timeline (linked in Resources) is the regulator's own live tracker and the one to check before relying on a date for a filing deadline.
| Date | Reference | Milestone | Impact |
|---|---|---|---|
| 2 Feb 2025 | Article 5 | Prohibited practices ban active | Social scoring, real-time public biometric ID, and manipulative systems become illegal. |
| 2 Aug 2025 | Chapter V | GPAI model obligations apply | Providers of general-purpose AI models must document training data and ensure copyright compliance. |
| 2 Aug 2026 | Article 50 | Transparency/disclosure rules enforced | Mandatory labelling of chatbots, deepfakes, and synthetic media. |
| 2 Dec 2026 | Art. 50(2) & 5 | Extended bans, watermarking deadlines | Systems live before Aug 2026 must implement machine-readable watermarks. |
| 2 Aug 2027 | N/A | Sandbox and testing structures active | Member states must provide at least one operational regulatory sandbox. |
| 2 Dec 2027 | Annex III (deferred) | Standalone high-risk system rules enforced | 16-month delay for standalone systems: employment, credit scoring, and similar. |
| 2 Aug 2028 | Annex I (deferred) | Embedded high-risk product rules enforced | 12-month delay for embedded safety components: medical devices, aviation software. |
Three frameworks, three different questions.
Treating these as interchangeable is the most common mistake in AI compliance planning. They're complementary, not redundant.
What am I legally obligated to do?
Binding, risk-tiered, enforceable. The only one of the three with actual penalties attached.
How do I run the management system that makes compliance provable?
Certifiable. The operating model: see /governance for the clause-by-clause detail.
How should I think about AI risk, regardless of jurisdiction?
Voluntary, US-originated, but the Govern/Map/Measure/Manage structure is a genuinely useful mental model even under a UK/EU regulatory regime.
Where the standards stop short.
Two concrete examples where ISO/IEC 42001 and the NIST AI RMF give no direct coverage, not an exhaustive list, but the two that come up most often in practice.
Third-party conformity assessment (Article 44)
High-risk systems require assessment by an accredited notified body. Neither ISO/IEC 42001 certification nor a NIST AI RMF self-assessment satisfies this on its own. It is a distinct regulatory step.
EU database registration (Article 49)
Certain high-risk systems must be registered in the EU database before deployment. This is a procedural filing obligation with no standards-based equivalent. It has to be done directly.
Long-form analysis on this
Articles that work through the practice rather than catalogue it.
AI Governance in UK Financial Services: The Regimes That Already Apply
The UK has decided not to write an AI Act for financial services. That is not the relief it sounds like. Five existing regimes already bind AI in regulated firms, one of them has required a board-approved model risk appetite since May 2024, and UK lenders and insurers serving EU customers sit inside the EU AI Act whatever Westminster does.
AI Impact Assessments: DPIA, FRIA and AIA Compared
Three different assessments answer to the phrase "AI impact assessment", and only one of them may actually bind your organisation. The EU AI Act's fundamental rights impact assessment reaches a narrower set of deployers than most coverage suggests. For those inside it, completing the assessment is only half the obligation, because Article 27 also requires you to file it with a regulator.
Undisclosed AI Interaction: The Article 50 Obligation That Was Not Delayed
The Digital Omnibus deferred the AI Act's high-risk obligations by more than a year. It left Article 50 alone. The transparency duties that took effect on 2 August 2026 apply now, to almost every organisation running a chatbot, a synthetic voice agent, or a generative content pipeline, and they carry fines of up to €15 million or 3% of worldwide turnover.
Risks and controls in this domain.
Pulled live from the Risk Library and Control Library — every entry tagged Compliance in the full Risk & Control spine, not a hand-maintained duplicate.
20 risks
- AI literacy gap in the deploying organisation medium
- AI-driven social scoring critical
- Automated decision-making without safeguards critical
- Biometric categorisation of sensitive attributes critical
- Cross-border AI data transfer risk medium
- Disparate impact monitoring gap high
- Exploitation of vulnerable groups by AI critical
- Inadequate explainability for affected individuals high
- Inadequate fairness testing before deployment medium
- Individual criminal risk profiling critical
- Missing DPIA for high-risk AI processing high
- Proxy discrimination via correlated features high
- Real-time public biometric identification critical
- Sensitive information disclosure critical
- Subliminal or manipulative AI techniques critical
- Training data bias and discriminatory outcomes high
- Undisclosed AI interaction medium
- Unlawful or undocumented training data basis high
- Untargeted facial recognition scraping critical
- Workplace and education emotion recognition high
Frequently asked questions
When do the EU AI Act's prohibited-practice bans take effect?
2 February 2025 (Article 5): social scoring, real-time public biometric identification, and manipulative systems become illegal.
When do EU AI Act obligations for general-purpose AI (GPAI) models apply?
2 August 2025 (Chapter V): providers of general-purpose AI models must document training data and ensure copyright compliance.
When do the EU AI Act's high-risk system rules apply to standalone systems?
2 December 2027 (Annex III, deferred): a 16-month delay applies to standalone high-risk systems such as employment and credit-scoring tools.
What is the difference between the EU AI Act, ISO/IEC 42001, and the NIST AI RMF?
The EU AI Act answers "what am I legally obligated to do?" and is binding, risk-tiered, and enforceable. ISO/IEC 42001 answers "how do I run the management system that makes compliance provable?" and is certifiable. The NIST AI RMF answers "how should I think about AI risk, regardless of jurisdiction?" and is voluntary, but its Govern/Map/Measure/Manage structure is a useful mental model even under a UK/EU regime.
Does ISO/IEC 42001 certification satisfy the EU AI Act's Article 44 conformity assessment?
No. High-risk systems require assessment by an accredited notified body under Article 44. Neither ISO/IEC 42001 certification nor a NIST AI RMF self-assessment satisfies this on its own; it is a distinct regulatory step.
This is one of the areas Andrew advises on.
EU AI Act & Regulatory Compliance Advisory is one of five areas of expertise on the services page, grounded in exactly this timeline and crosswalk.