LawQi

Module 6.3 · Topic 1

Global Governance Frameworks

Bottom Line Up Front: Three major frameworks—the EU AI Act (binding by August 2026), NIST AI Risk Management Framework (voluntary but industry-standard), and ISO/IEC 42001 (certifiable)—converge around governance, risk…

1.1 The EU AI Act: Risk Classification and Compliance

Risk Tier Scope Deadline Penalty
Unacceptable Social scoring, real-time biometric surveillance February 2025 €35M / 7% revenue
High Credit, hiring, benefits decisions August 2026 €15M / 3% revenue
Limited Chatbots, AI-generated content Transparency required €7.5M / 1% revenue
Minimal Spam filters, recommendations No restrictions None

1.2 NIST AI Risk Management Framework

  • Govern: Establish policies, assign accountability, define risk tolerance
  • Map: Identify and categorize AI risks in business context
  • Measure: Assess risk severity and evaluate mitigation effectiveness
  • Manage: Implement controls, monitor performance, respond to incidents

Unlike the EU Act's prescriptive requirements, NIST is flexibly applied. A March 2025 update added model provenance and data integrity guidance.

1.3 ISO/IEC 42001 and International Standards

  1. Assess current state: Evaluate existing AI practices against ISO 42001 requirements and identify gaps
  2. Build the management system: Document AI risks, implement controls, establish policies using Plan-Do-Check-Act methodology
  3. Integrate with ISO 27001: Leverage existing information security infrastructure for faster certification
  4. Certify: Engage accredited certification body for Stage 1 and Stage 2 audits (6-12 months, $15K-$200K depending on size)

Gartner projects 70% of enterprises will adopt ISO 42001 by 2026.

1.4 How Frameworks Converge and Where They Differ

Dimension EU AI Act NIST AI RMF ISO/IEC 42001
Nature Binding regulation Voluntary framework Certifiable standard
Focus Risk-tier compliance Governance methodology Management system
Geography EU (mandatory) Global (US-centric) Global (ISO)
Certification Conformity assessment None (profiles exist) Third-party audit

Organizations typically start with NIST for governance design, implement ISO 42001 for certification, and monitor EU obligations separately (see Module 6.1 for architecture concepts).