Module 6.3 · Topic 1
Global Governance Frameworks
Bottom Line Up Front: Three major frameworks—the EU AI Act (binding by August 2026), NIST AI Risk Management Framework (voluntary but industry-standard), and ISO/IEC 42001 (certifiable)—converge around governance, risk…
1.1 The EU AI Act: Risk Classification and Compliance
| Risk Tier | Scope | Deadline | Penalty |
|---|---|---|---|
| Unacceptable | Social scoring, real-time biometric surveillance | February 2025 | €35M / 7% revenue |
| High | Credit, hiring, benefits decisions | August 2026 | €15M / 3% revenue |
| Limited | Chatbots, AI-generated content | Transparency required | €7.5M / 1% revenue |
| Minimal | Spam filters, recommendations | No restrictions | None |
1.2 NIST AI Risk Management Framework
- Govern: Establish policies, assign accountability, define risk tolerance
- Map: Identify and categorize AI risks in business context
- Measure: Assess risk severity and evaluate mitigation effectiveness
- Manage: Implement controls, monitor performance, respond to incidents
Unlike the EU Act's prescriptive requirements, NIST is flexibly applied. A March 2025 update added model provenance and data integrity guidance.
1.3 ISO/IEC 42001 and International Standards
- Assess current state: Evaluate existing AI practices against ISO 42001 requirements and identify gaps
- Build the management system: Document AI risks, implement controls, establish policies using Plan-Do-Check-Act methodology
- Integrate with ISO 27001: Leverage existing information security infrastructure for faster certification
- Certify: Engage accredited certification body for Stage 1 and Stage 2 audits (6-12 months, $15K-$200K depending on size)
Gartner projects 70% of enterprises will adopt ISO 42001 by 2026.
1.4 How Frameworks Converge and Where They Differ
| Dimension | EU AI Act | NIST AI RMF | ISO/IEC 42001 |
|---|---|---|---|
| Nature | Binding regulation | Voluntary framework | Certifiable standard |
| Focus | Risk-tier compliance | Governance methodology | Management system |
| Geography | EU (mandatory) | Global (US-centric) | Global (ISO) |
| Certification | Conformity assessment | None (profiles exist) | Third-party audit |
Organizations typically start with NIST for governance design, implement ISO 42001 for certification, and monitor EU obligations separately (see Module 6.1 for architecture concepts).