Framework Crosswalk · pack v2026.07.30

EU AI Act vs NIST AI RMF: what actually carries over

26 requirement-level mappings connect EU AI Act and NIST AI RMF: 1 strong (completing one substantially satisfies the other) and 25 partial (it contributes, but more is needed). Neither framework substitutes for the other — this page shows exactly what carries over, requirement by requirement.

What carries over between EU AI Act and NIST AI RMF?

Strong mappings: completing one requirement substantially satisfies the other.

EU AI ActNIST AI RMFWhy
EU AI Act: AI literacy dutyNIST AI RMF GOVERN-2.2Both produce role-based AI training for staff and relevant partners with completion records — the same literacy evidence.

What only partly carries over?

Partial mappings: work on one contributes to the other, but more is needed. Shieldra deliberately does not count these as coverage — the "why" column is what's still missing.

EU AI ActNIST AI RMFWhy (and what’s missing)
EU AI Act: AI literacy dutyNIST AI RMF MAP-3.4Operator proficiency requirements and qualification records cover the operator slice of Art. 4 literacy.
EU AI Act: Prohibited practicesNIST AI RMF GOVERN-1.1A maintained register of AI legal obligations is how a prohibited practice gets caught, but ceasing or redesigning it is a separate substantive act.
EU AI Act: AI interaction disclosureNIST AI RMF MEASURE-2.8MEASURE 2.8 examines whether users can tell they are interacting with AI; Art. 50(1) requires actually building that disclosure into the product.
EU AI Act: Machine-readable markingNIST AI RMF MEASURE-2.8Machine-readable provenance marking is one transparency control the 2.8 examination covers; the RMF does not itself require marking synthetic content.
EU AI Act: Deep fake disclosureNIST AI RMF MEASURE-2.8Deep-fake labelling is transparency evidence for the 2.8 examination, but the disclosure duty and its exemptions are EU-specific.
EU AI Act: Public-interest text disclosureNIST AI RMF MEASURE-2.8Disclosing AI-generated public-interest text feeds the transparency examination; the publication duty itself has no RMF counterpart.
EU AI Act: Emotion & biometric notificationNIST AI RMF MEASURE-2.8Notifying exposed persons that the system operates is transparency work 2.8 examines but does not mandate.
EU AI Act: Emotion & biometric notificationNIST AI RMF MEASURE-2.10Privacy-risk examination of emotion and biometric data supports, but does not establish, lawful processing under EU data-protection law.
EU AI Act: GPAI technical documentationNIST AI RMF MAP-2.1Documenting the model's tasks and methods supplies part of the Annex XI model description.
EU AI Act: GPAI technical documentationNIST AI RMF MAP-2.2Documented knowledge limits and output-use guidance overlap with the downstream-provider information Art. 53 requires.
EU AI Act: GPAI technical documentationNIST AI RMF MEASURE-2.1Documented test sets, metrics, and evaluation tooling feed the evaluation-results sections of the required model documentation.
EU AI Act: GPAI copyright & training summaryNIST AI RMF MAP-4.1A documented IP-risk approach covering training-data provenance underpins, but does not constitute, the copyright policy and the public training summary.
EU AI Act: Systemic-risk GPAI dutiesNIST AI RMF MEASURE-2.6Regular safety evaluation against mapped risks with residual-risk demonstration contributes to the systemic-risk assessment and mitigation duty.
EU AI Act: Systemic-risk GPAI dutiesNIST AI RMF MEASURE-2.7Adversarial-robustness and jailbreak evaluation is the same practice as Art. 55 adversarial testing and cybersecurity assurance, but not at the depth or cadence the Act mandates.
EU AI Act: Systemic-risk GPAI dutiesNIST AI RMF MANAGE-4.3Documented incident tracking and communication supports serious-incident reporting, but Art. 55 fixes the recipients and deadlines.
EU AI Act: High-risk provider obligationsNIST AI RMF MAP-1.1Documented intended purpose, context, assumptions, and limitations supplies core Annex IV technical-documentation content, one piece of the package.
EU AI Act: High-risk provider obligationsNIST AI RMF MAP-3.5Defined and assessed human-oversight processes map directly to Art. 14, one element of the conformity bundle.
EU AI Act: High-risk provider obligationsNIST AI RMF MEASURE-2.3Performance measurement under deployment-like conditions evidences Art. 15 accuracy and robustness, without the conformity-assessment wrapper.
EU AI Act: High-risk provider obligationsNIST AI RMF MANAGE-4.1A post-deployment monitoring plan with incident response is the substance of Art. 72 post-market monitoring, one piece of the bundle.
EU AI Act: High-risk deployer dutiesNIST AI RMF GOVERN-3.2Defined human-AI oversight roles with override authority cover the oversight-assignment element of Art. 26.
EU AI Act: High-risk deployer dutiesNIST AI RMF MAP-3.5Documented, assessed oversight processes give the trained-human-oversight duty substance; log retention, input-data checks, and worker notification remain.
EU AI Act: High-risk deployer dutiesNIST AI RMF MEASURE-2.4Production monitoring of system behavior is the Art. 26 monitoring duty in RMF terms; log retention and notification duties are extra.
EU AI Act: Fundamental rights impact assessmentNIST AI RMF MAP-5.1A documented likelihood-and-magnitude assessment of harms to affected people is the analytical core of a FRIA, but Art. 27 prescribes processes, affected-person categories, oversight, and mitigation content.
EU AI Act: Importer duties for high-risk AINIST AI RMF GOVERN-6.1Third-party AI due-diligence policy supports verifying provider conformity before market placement, but the CE-marking and documentation checks are EU-specific.
EU AI Act: Distributor duties for high-risk AINIST AI RMF GOVERN-6.1Third-party due-diligence procedures support the distributor verification duties, which remain EU-specific market-surveillance obligations.

Frequently asked questions

Does EU AI Act cover NIST AI RMF?

Not by itself. Of the 26 requirement-level mappings between them, only 1 are strong; the other 25 are partial, meaning work on one contributes evidence toward the other but does not satisfy it. Shieldra deliberately does not count partial mappings as coverage.

What is the difference between a strong and a partial mapping?

Requirement-level crosswalk among the AI frameworks. strength=strong means completing one substantially satisfies the other; partial means it contributes but more is needed.

Should you do EU AI Act or NIST AI RMF first?

They answer different demands: a regulation binds by law, a management-system standard or risk framework is what enterprise buyers ask for. The overlap table on this page shows which requirements you only have to build once — start from whichever one a customer or regulator is actually asking you for.