| EU AI Act: AI literacy duty | NIST AI RMF MAP-3.4 | Operator proficiency requirements and qualification records cover the operator slice of Art. 4 literacy. |
| EU AI Act: Prohibited practices | NIST AI RMF GOVERN-1.1 | A maintained register of AI legal obligations is how a prohibited practice gets caught, but ceasing or redesigning it is a separate substantive act. |
| EU AI Act: AI interaction disclosure | NIST AI RMF MEASURE-2.8 | MEASURE 2.8 examines whether users can tell they are interacting with AI; Art. 50(1) requires actually building that disclosure into the product. |
| EU AI Act: Machine-readable marking | NIST AI RMF MEASURE-2.8 | Machine-readable provenance marking is one transparency control the 2.8 examination covers; the RMF does not itself require marking synthetic content. |
| EU AI Act: Deep fake disclosure | NIST AI RMF MEASURE-2.8 | Deep-fake labelling is transparency evidence for the 2.8 examination, but the disclosure duty and its exemptions are EU-specific. |
| EU AI Act: Public-interest text disclosure | NIST AI RMF MEASURE-2.8 | Disclosing AI-generated public-interest text feeds the transparency examination; the publication duty itself has no RMF counterpart. |
| EU AI Act: Emotion & biometric notification | NIST AI RMF MEASURE-2.8 | Notifying exposed persons that the system operates is transparency work 2.8 examines but does not mandate. |
| EU AI Act: Emotion & biometric notification | NIST AI RMF MEASURE-2.10 | Privacy-risk examination of emotion and biometric data supports, but does not establish, lawful processing under EU data-protection law. |
| EU AI Act: GPAI technical documentation | NIST AI RMF MAP-2.1 | Documenting the model's tasks and methods supplies part of the Annex XI model description. |
| EU AI Act: GPAI technical documentation | NIST AI RMF MAP-2.2 | Documented knowledge limits and output-use guidance overlap with the downstream-provider information Art. 53 requires. |
| EU AI Act: GPAI technical documentation | NIST AI RMF MEASURE-2.1 | Documented test sets, metrics, and evaluation tooling feed the evaluation-results sections of the required model documentation. |
| EU AI Act: GPAI copyright & training summary | NIST AI RMF MAP-4.1 | A documented IP-risk approach covering training-data provenance underpins, but does not constitute, the copyright policy and the public training summary. |
| EU AI Act: Systemic-risk GPAI duties | NIST AI RMF MEASURE-2.6 | Regular safety evaluation against mapped risks with residual-risk demonstration contributes to the systemic-risk assessment and mitigation duty. |
| EU AI Act: Systemic-risk GPAI duties | NIST AI RMF MEASURE-2.7 | Adversarial-robustness and jailbreak evaluation is the same practice as Art. 55 adversarial testing and cybersecurity assurance, but not at the depth or cadence the Act mandates. |
| EU AI Act: Systemic-risk GPAI duties | NIST AI RMF MANAGE-4.3 | Documented incident tracking and communication supports serious-incident reporting, but Art. 55 fixes the recipients and deadlines. |
| EU AI Act: High-risk provider obligations | NIST AI RMF MAP-1.1 | Documented intended purpose, context, assumptions, and limitations supplies core Annex IV technical-documentation content, one piece of the package. |
| EU AI Act: High-risk provider obligations | NIST AI RMF MAP-3.5 | Defined and assessed human-oversight processes map directly to Art. 14, one element of the conformity bundle. |
| EU AI Act: High-risk provider obligations | NIST AI RMF MEASURE-2.3 | Performance measurement under deployment-like conditions evidences Art. 15 accuracy and robustness, without the conformity-assessment wrapper. |
| EU AI Act: High-risk provider obligations | NIST AI RMF MANAGE-4.1 | A post-deployment monitoring plan with incident response is the substance of Art. 72 post-market monitoring, one piece of the bundle. |
| EU AI Act: High-risk deployer duties | NIST AI RMF GOVERN-3.2 | Defined human-AI oversight roles with override authority cover the oversight-assignment element of Art. 26. |
| EU AI Act: High-risk deployer duties | NIST AI RMF MAP-3.5 | Documented, assessed oversight processes give the trained-human-oversight duty substance; log retention, input-data checks, and worker notification remain. |
| EU AI Act: High-risk deployer duties | NIST AI RMF MEASURE-2.4 | Production monitoring of system behavior is the Art. 26 monitoring duty in RMF terms; log retention and notification duties are extra. |
| EU AI Act: Fundamental rights impact assessment | NIST AI RMF MAP-5.1 | A documented likelihood-and-magnitude assessment of harms to affected people is the analytical core of a FRIA, but Art. 27 prescribes processes, affected-person categories, oversight, and mitigation content. |
| EU AI Act: Importer duties for high-risk AI | NIST AI RMF GOVERN-6.1 | Third-party AI due-diligence policy supports verifying provider conformity before market placement, but the CE-marking and documentation checks are EU-specific. |
| EU AI Act: Distributor duties for high-risk AI | NIST AI RMF GOVERN-6.1 | Third-party due-diligence procedures support the distributor verification duties, which remain EU-specific market-surveillance obligations. |