AI Governance Made Simple: NIST AI RMF, ISO 42001 and the EU AI Act
AI Governance Made Simple: NIST AI RMF, ISO 42001 and the EU AI Act
Manoj Sharma
Founder & Lead Coach · CISSP, CCSP, CISM, CRISC
Quick Answer
What is AI governance, and how do NIST AI RMF, ISO 42001 and the EU AI Act fit together?
AI governance is the set of policies, processes, roles and controls an organisation uses to manage the risks of the AI it builds or deploys. Three frameworks dominate: the NIST AI Risk Management Framework (voluntary guidance for thinking about AI risk), ISO/IEC 42001 (a certifiable AI management system), and the EU AI Act (binding law with penalties larger than GDPR's). They are complementary — NIST tells you how to think, ISO 42001 gives you a system to manage it, and the EU AI Act tells you what the law demands. The EU AI Act's heaviest high-risk deadlines were deferred by the Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 — to December 2027 and August 2028; these are now confirmed law, though the 2 August 2026 transparency rules did not move.
Key Highlights
- •AI governance is the security risk discipline you already know, pointed at systems that learn and change.
- •Three frameworks, three jobs: NIST AI RMF (how to think), ISO/IEC 42001 (a certifiable system), the EU AI Act (the law).
- •The Digital Omnibus on AI is now in force (Regulation (EU) 2026/1744) — high-risk deadlines are confirmed for 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
- •Article 50 transparency rules (chatbot disclosure, AI-content labelling) were not deferred — they still apply from 2 August 2026.
- •EU AI Act penalties reach €35M or 7% of global turnover, above GDPR's 4% ceiling.
Most articles on AI governance make it sound like a legal subject. It isn't — or at least, it isn't yours to worry about as a legal subject. It is a security subject wearing a compliance coat.
Think about what governance has always meant in security. You have a risk. You decide who owns it, how you measure it, what controls you put around it, and how you prove to someone else that you did. That is ISO 27001. That is every risk framework you have ever touched. AI governance is the same discipline pointed at a new kind of risk — one where the system learns, changes, and sometimes cannot fully explain itself.
So when you read the three big names — NIST AI RMF, ISO 42001, the EU AI Act — do not see three intimidating frameworks. See three tools that answer three different questions:
- How should I think about AI risk? → NIST
- How do I run a system to manage it? → ISO 42001
- What does the law actually require of me? → the EU AI Act
Get that mental model straight and the rest of this article is just detail. Let us go through each, and then I will show you how they stack — and I will give you the 2026 deadlines correctly, because most of what is published right now is out of date.
What is AI governance?
AI governance is the framework of policies, processes, roles and controls that an organisation uses to develop and deploy AI responsibly and to manage its risks. It covers the whole life of an AI system — from the data it learns on, to how it makes decisions, to who is accountable when it gets one wrong.
Here is why this landed on the security team's desk, and it is worth being honest about. Nobody planned for security to own AI risk. It arrived there the way most things do — because AI touches data, decisions, and trust, and those have always been security's territory. When a model leaks training data, that is a security incident. When a model can be manipulated into a harmful action, that is a security failure. When the board asks "are we allowed to use this, and can we prove we're using it safely," they ask the person who already answers that question for everything else.
That person is increasingly you. AI governance is not a new discipline you have to learn from scratch — it is the risk discipline you already know, pointed at a system that learns and changes. Which is a burden, but also a door — and I want you to see the door.
What is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework (AI RMF) is voluntary guidance from the US National Institute of Standards and Technology for identifying and managing the risks of AI systems. It is organised around four functions — Govern, Map, Measure and Manage — and it is designed to be flexible across industries rather than prescriptive.
If you have used any NIST framework before, this will feel like home. It is not a checklist you pass or fail. It is a structured way of thinking, and its four functions are genuinely intuitive:
- Govern — build the culture, roles and accountability for AI risk. This function runs through all the others.
- Map — understand the context. What is this AI system, where is it used, who does it affect, what could go wrong?
- Measure — assess and track the risks you mapped, using the right methods for each.
- Manage — act on them. Prioritise, treat, monitor, respond.
Govern, Map, Measure, Manage. You can hold that in your head, and that is the point. NIST built it to be a common language, not an exam. Because it is voluntary, its power is not enforcement — it is credibility. When you need to show a board, a customer, or a regulator that your AI risk process is deliberate rather than improvised, "we follow the NIST AI RMF" is a sentence that carries weight globally.
What is ISO/IEC 42001?
ISO/IEC 42001 is the international standard for an Artificial Intelligence Management System (AIMS). Unlike NIST's voluntary guidance, ISO 42001 is certifiable — an organisation can be independently audited and certified against it, the same way ISO 27001 works for information security.
This is the one that will feel most familiar to anyone who has lived through an ISO 27001 programme, because it is built on the exact same skeleton: management system, defined scope, risk assessment, controls, internal audit, management review, continual improvement. If you have run or supported a 27001 programme, you already understand most of how 42001 operates. What changes is the subject — AI-specific risks, model lifecycle, data governance for training, transparency, human oversight.
The reason 42001 matters strategically is that it turns "trust us, we're careful with AI" into "here is our independent certificate." That is a commercial asset. Vendors will increasingly be asked for it the way they are asked for ISO 27001 and SOC 2 today.
To answer the question every 27001 practitioner is already forming: no, 42001 does not replace 27001. It sits alongside it. 27001 secures your information; 42001 governs your AI. Many organisations will run both — and because the management-system machinery is shared, the second one is far cheaper to stand up than the first.
What is the EU AI Act — and when does it actually apply?
The EU AI Act is the world's first comprehensive, binding law regulating artificial intelligence. It classifies AI systems by risk — from prohibited practices, through high-risk systems that carry heavy obligations, down to limited and minimal risk — and it applies extraterritorially to any organisation placing AI on the EU market, wherever that organisation is based. If you have worked through a regulated-compliance regime before — the way PCI DSS 4.0 reshaped payment security — the shape of this will feel familiar: classify by risk, apply controls, prove compliance.
Now, the deadlines. Pay attention here, because this is where almost every article you will find is currently out of date, and getting it right is genuinely useful.
Through 2025 and into 2026, the standard published timeline said high-risk obligations would apply from 2 August 2026. That changed. A simplification package known as the Digital Omnibus on AI moved the heaviest deadlines. The European Parliament adopted it on 16 June 2026, the Council of the EU gave its final approval on 29 June 2026, the final act was signed on 8 July 2026, and it was published in the Official Journal as Regulation (EU) 2026/1744 on 24 July 2026, entering into force on 27 July 2026. Here is the corrected picture:
Obligation | Old date | Confirmed date |
|---|---|---|
Prohibited AI practices + AI literacy duty | 2 Feb 2025 | in force |
General-purpose AI (GPAI) model rules | 2 Aug 2025 | in force |
Article 50 transparency (chatbot disclosure, AI-content labelling) | 2 Aug 2026 | 2 Aug 2026 — unchanged |
Transparency for systems already on the market + new prohibitions | — | 2 Dec 2026 |
High-risk — Annex III (recruitment, credit, education, law enforcement) | 2 Aug 2026 | 2 Dec 2027 |
High-risk — Annex I (medical devices, machinery, toys) | 2 Aug 2027 | 2 Aug 2028 |
The Omnibus also introduced new Article 5 prohibitions — most notably on AI-generated non-consensual intimate imagery and child sexual abuse material — which fall under that 2 December 2026 date. Two things you must take from this table:
First, the delay is real but narrow. The heavy high-risk regime moved to December 2027 and August 2028. But the Article 50 transparency rules did not move — chatbot disclosure and AI-content labelling still land on 2 August 2026. Anyone who reads "the AI Act was delayed" and relaxes has misread it.
Until late July 2026, the correct posture was "the new dates are not legally binding until the amendment is published in the Official Journal — plan against them, but document your decisions against the possibility they slip." That window has now closed: the Omnibus published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. The 2 December 2027 and 2 August 2028 dates are confirmed, binding law, not a pending proposal. If you see an article — including an earlier version of this one — still hedging on "awaiting publication," that is your signal it was written before the last week of July 2026 and hasn't been checked since. That is the whole lesson: verify against the Official Journal date, not the signature date, before you quote AI Act deadlines to anyone.
How do NIST AI RMF, ISO 42001 and the EU AI Act fit together?
They operate at different levels and reinforce each other. NIST AI RMF gives you a way to think about and structure AI risk. ISO 42001 gives you a certifiable management system to operationalise it. The EU AI Act gives you a legal obligation that the other two help you meet. Using NIST and ISO 42001 is one of the most practical ways to demonstrate readiness for the EU AI Act.
NIST AI RMF | ISO/IEC 42001 | EU AI Act | |
|---|---|---|---|
What it is | Voluntary framework | Certifiable standard | Binding law |
Who issues it | US NIST | ISO / IEC | European Union |
Binds you? | No — you choose it | No — you choose it | Yes, if in scope |
What it gives you | A way to think about AI risk | A system to manage it | Legal requirements to meet |
Reach | Global, influential | Global, certifiable | EU market — extraterritorial |
Proof it produces | Credible process | Independent certificate | Legal compliance |
The way to say it in one line: NIST tells you how to think, ISO 42001 gives you the machine, the EU AI Act tells you what the law demands — and the first two are how you get ready for the third.
Where does India's DPDP Act intersect?
For organisations in India, AI governance does not sit only under global frameworks — it also runs straight into the Digital Personal Data Protection (DPDP) Act. AI systems are built on data, and the DPDP Act governs how personal data is collected, processed and protected, with implementation phasing in through 2026 and beyond.
I will not repeat the whole DPDP picture here — it deserves its own article, and you should read it once it is live — but understand the overlap. Almost every AI system your organisation deploys processes personal data. The moment it does, DPDP obligations attach: consent, purpose limitation, security safeguards, breach reporting. So for an Indian security professional, "AI governance" is really two conversations at once — the global frameworks above, and the domestic data-protection law underneath them. That intersection, incidentally, is where a lot of the new roles are being created.
How do you start an AI governance programme?
Start by building an inventory of the AI systems your organisation actually uses — including the ones nobody formally approved. Classify each by risk and by what data it touches. Then pick a framework to structure your response: NIST AI RMF to think, ISO 42001 if you need certification, mapped against the EU AI Act and DPDP obligations that apply to you.
The honest first step is almost always the same, and it is unglamorous: nobody knows what AI they are running. Marketing has a tool. Support has a chatbot. Three engineers are quietly using an API. Before you can govern anything, you have to find it. The organisation that can produce an accurate AI inventory is already ahead of most.
From there, a sensible sequence:
- Inventory — every AI system, sanctioned or not.
- Classify — by risk, and by the data each one touches.
- Map to obligations — which frameworks and laws actually apply to you? An Indian fintech and a German medical-device maker have very different answers.
- Structure with a framework — NIST to think, ISO 42001 to certify.
- Assign ownership — governance without an owner is a document, not a control.
- Review continually — the systems change and so does the law, as the 2026 timeline shift just proved.
Governance is where a lot of security careers are heading. AI risk is now a board-level question, and the professional who understands the frameworks and can explain them to leadership is rare and valuable. Dedicated AI-governance credentials are emerging alongside AI-security ones — and the people who learn this while it is still new are the ones who will be leading it. It maps directly onto some of the highest-paying security roles; if you are choosing a path, our certification decision guide can help once it is live.
"For twenty years, governance was the room technical people avoided. That has reversed. The security professional who understands AI risk and can sit in the boardroom and explain it is the most valuable person in the building. That is not a compliance job. That is a leadership one."
At Cybernous, the GenAI Expert (GAESP) programme treats governance not as paperwork but as the leadership layer of AI security — the same philosophy behind a 98.4% first-attempt CISSP pass rate across 793+ certified professionals: understand the why, and the frameworks stop being intimidating.
With that said — governance tells you what must be protected. The next question is how it gets attacked, and for AI systems that begins with prompt injection, and on the offensive side, AI red teaming (both topics have dedicated articles coming — link once live).
Build the leadership layer of AI security with GAESP
The Cybernous GenAI Expert (GAESP) programme treats governance as the leadership layer of AI security, connecting the frameworks to how AI systems are actually attacked and defended. Understand the why, and the compliance stops being intimidating.
Explore the GenAI Expert programme →Read the AI security hub
Frequently Asked Questions
You might also like
Ready to accelerate your certification journey?
Join Cybernous' structured programme with live mentoring, hands-on practice, and a proven track record.


