Framework Crosswalk · pack v2026.07.30
EU AI Act vs NIST AI RMF: what actually carries over
26 requirement-level mappings connect EU AI Act and NIST AI RMF: 1 strong (completing one substantially satisfies the other) and 25 partial (it contributes, but more is needed). Neither framework substitutes for the other — this page shows exactly what carries over, requirement by requirement.
What carries over between EU AI Act and NIST AI RMF?
Strong mappings: completing one requirement substantially satisfies the other.
| EU AI Act | NIST AI RMF | Why |
|---|---|---|
| EU AI Act: AI literacy duty | NIST AI RMF GOVERN-2.2 | Both produce role-based AI training for staff and relevant partners with completion records — the same literacy evidence. |
What only partly carries over?
Partial mappings: work on one contributes to the other, but more is needed. Shieldra deliberately does not count these as coverage — the "why" column is what's still missing.
| EU AI Act | NIST AI RMF | Why (and what’s missing) |
|---|---|---|
| EU AI Act: AI literacy duty | NIST AI RMF MAP-3.4 | Operator proficiency requirements and qualification records cover the operator slice of Art. 4 literacy. |
| EU AI Act: Prohibited practices | NIST AI RMF GOVERN-1.1 | A maintained register of AI legal obligations is how a prohibited practice gets caught, but ceasing or redesigning it is a separate substantive act. |
| EU AI Act: AI interaction disclosure | NIST AI RMF MEASURE-2.8 | MEASURE 2.8 examines whether users can tell they are interacting with AI; Art. 50(1) requires actually building that disclosure into the product. |
| EU AI Act: Machine-readable marking | NIST AI RMF MEASURE-2.8 | Machine-readable provenance marking is one transparency control the 2.8 examination covers; the RMF does not itself require marking synthetic content. |
| EU AI Act: Deep fake disclosure | NIST AI RMF MEASURE-2.8 | Deep-fake labelling is transparency evidence for the 2.8 examination, but the disclosure duty and its exemptions are EU-specific. |
| EU AI Act: Public-interest text disclosure | NIST AI RMF MEASURE-2.8 | Disclosing AI-generated public-interest text feeds the transparency examination; the publication duty itself has no RMF counterpart. |
| EU AI Act: Emotion & biometric notification | NIST AI RMF MEASURE-2.8 | Notifying exposed persons that the system operates is transparency work 2.8 examines but does not mandate. |
| EU AI Act: Emotion & biometric notification | NIST AI RMF MEASURE-2.10 | Privacy-risk examination of emotion and biometric data supports, but does not establish, lawful processing under EU data-protection law. |
| EU AI Act: GPAI technical documentation | NIST AI RMF MAP-2.1 | Documenting the model's tasks and methods supplies part of the Annex XI model description. |
| EU AI Act: GPAI technical documentation | NIST AI RMF MAP-2.2 | Documented knowledge limits and output-use guidance overlap with the downstream-provider information Art. 53 requires. |
| EU AI Act: GPAI technical documentation | NIST AI RMF MEASURE-2.1 | Documented test sets, metrics, and evaluation tooling feed the evaluation-results sections of the required model documentation. |
| EU AI Act: GPAI copyright & training summary | NIST AI RMF MAP-4.1 | A documented IP-risk approach covering training-data provenance underpins, but does not constitute, the copyright policy and the public training summary. |
| EU AI Act: Systemic-risk GPAI duties | NIST AI RMF MEASURE-2.6 | Regular safety evaluation against mapped risks with residual-risk demonstration contributes to the systemic-risk assessment and mitigation duty. |
| EU AI Act: Systemic-risk GPAI duties | NIST AI RMF MEASURE-2.7 | Adversarial-robustness and jailbreak evaluation is the same practice as Art. 55 adversarial testing and cybersecurity assurance, but not at the depth or cadence the Act mandates. |
| EU AI Act: Systemic-risk GPAI duties | NIST AI RMF MANAGE-4.3 | Documented incident tracking and communication supports serious-incident reporting, but Art. 55 fixes the recipients and deadlines. |
| EU AI Act: High-risk provider obligations | NIST AI RMF MAP-1.1 | Documented intended purpose, context, assumptions, and limitations supplies core Annex IV technical-documentation content, one piece of the package. |
| EU AI Act: High-risk provider obligations | NIST AI RMF MAP-3.5 | Defined and assessed human-oversight processes map directly to Art. 14, one element of the conformity bundle. |
| EU AI Act: High-risk provider obligations | NIST AI RMF MEASURE-2.3 | Performance measurement under deployment-like conditions evidences Art. 15 accuracy and robustness, without the conformity-assessment wrapper. |
| EU AI Act: High-risk provider obligations | NIST AI RMF MANAGE-4.1 | A post-deployment monitoring plan with incident response is the substance of Art. 72 post-market monitoring, one piece of the bundle. |
| EU AI Act: High-risk deployer duties | NIST AI RMF GOVERN-3.2 | Defined human-AI oversight roles with override authority cover the oversight-assignment element of Art. 26. |
| EU AI Act: High-risk deployer duties | NIST AI RMF MAP-3.5 | Documented, assessed oversight processes give the trained-human-oversight duty substance; log retention, input-data checks, and worker notification remain. |
| EU AI Act: High-risk deployer duties | NIST AI RMF MEASURE-2.4 | Production monitoring of system behavior is the Art. 26 monitoring duty in RMF terms; log retention and notification duties are extra. |
| EU AI Act: Fundamental rights impact assessment | NIST AI RMF MAP-5.1 | A documented likelihood-and-magnitude assessment of harms to affected people is the analytical core of a FRIA, but Art. 27 prescribes processes, affected-person categories, oversight, and mitigation content. |
| EU AI Act: Importer duties for high-risk AI | NIST AI RMF GOVERN-6.1 | Third-party AI due-diligence policy supports verifying provider conformity before market placement, but the CE-marking and documentation checks are EU-specific. |
| EU AI Act: Distributor duties for high-risk AI | NIST AI RMF GOVERN-6.1 | Third-party due-diligence procedures support the distributor verification duties, which remain EU-specific market-surveillance obligations. |
Frequently asked questions
Does EU AI Act cover NIST AI RMF?
Not by itself. Of the 26 requirement-level mappings between them, only 1 are strong; the other 25 are partial, meaning work on one contributes evidence toward the other but does not satisfy it. Shieldra deliberately does not count partial mappings as coverage.
What is the difference between a strong and a partial mapping?
Requirement-level crosswalk among the AI frameworks. strength=strong means completing one substantially satisfies the other; partial means it contributes but more is needed.
Should you do EU AI Act or NIST AI RMF first?
They answer different demands: a regulation binds by law, a management-system standard or risk framework is what enterprise buyers ask for. The overlap table on this page shows which requirements you only have to build once — start from whichever one a customer or regulator is actually asking you for.