Compared: The Leading AI Governance Frameworks
With the leading AI governance frameworks compared side by side, the choice turns out to be less about which is best and more about which job you are doing. One of them is law and you do not get an opinion. One of them you can be certified against, which is what procurement actually asks for. One of them is a method for doing the risk work, and it is free. Firms waste months treating them as competing options when they operate at different layers.
| Framework | Status | Certifiable | Best for |
|---|---|---|---|
| EU AI Act Reg. (EU) 2024/1689 | Binding law, extraterritorial | No, conformity assessment for high risk | Anyone placing AI on the EU market |
| ISO/IEC 42001:2023 | International standard, Dec 2023 | Yes, third-party certification | Proving governance to customers and procurement |
| NIST AI RMF 1.0 | Voluntary framework, Jan 2023 | No | Structuring risk work, US market expectations |
| OECD AI Principles | Intergovernmental principles, 2019, updated 2024 | No | The shared vocabulary the others borrow |
| UK cross-sector principles | Non-statutory, regulator-led | No | UK-only firms working out who regulates them |
The EU AI Act: the only one that is law
Regulation (EU) 2024/1689 is risk-tiered. A short list of practices is prohibited outright. A larger set of uses listed in Annex III, covering employment, education, credit, essential services, law enforcement and biometrics, is classed as high risk and carries the heavy obligations: a risk management system, data governance, technical documentation, logging, human oversight, accuracy and robustness, and post-market monitoring. General-purpose AI models carry their own transparency and, above a compute threshold, systemic-risk duties. Everything else is largely untouched beyond the transparency rules.
The timetable moved this summer, and it moved late. The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July, six days before the original high-risk deadline. It defers the Annex III standalone high-risk obligations from 2 August 2026 to 2 December 2027, and the Annex I obligations for AI embedded in products already covered by EU product safety law to 2 August 2028. The European Parliament had endorsed the package on 16 June 2026 by 423 votes to 57, with the Council giving final approval on 29 June.
Two things did not move. The Article 50 transparency duties still bite: users must be told when they are interacting with an AI system, AI-generated content must be marked, and deepfakes must be labelled. And the Commission's enforcement powers over general-purpose AI models were not deferred. Reading the delay as a reprieve from the whole regulation is a mistake several boards are currently making. For the detail, see our EU AI Act guide for UK business and the compliance checklist.
ISO/IEC 42001:2023: the one you can certify against
Published in December 2023, ISO/IEC 42001 is an AI management system standard. If you have been through ISO 27001 it will feel familiar, because it uses the same high-level structure: context, leadership, planning, support, operation, performance evaluation and improvement, in clauses 4 to 10, with a set of controls in Annex A. There are 38 of those controls, grouped into nine areas covering things like AI policy, roles and responsibilities, resources for AI systems, impact assessment, the system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party relationships.
The reason organisations pick it over the alternatives is simple: it is the only one on this list where an accredited body will audit you and issue a certificate. That certificate is what closes out the AI section of a customer security questionnaire. The reason to be careful is equally simple: a management system certificate says your process exists and is followed. It says nothing about whether a given model is fair, and a badly scoped certificate can be worth very little.
NIST AI RMF 1.0: the method
The US National Institute of Standards and Technology published version 1.0 in January 2023. It is voluntary, free, and organised around four functions: Govern, which runs across everything, then Map (understand the context and what could go wrong), Measure (analyse and track it) and Manage (prioritise and act). Beneath those sit 72 subcategories, plus a companion playbook and a Generative AI Profile added in 2024.
Its strength is that it is the most usable of the three at the level of an individual system. Map in particular forces the question most AI projects skip: who is this for, what happens when it is wrong, and to whom. Its weakness is that nobody can hand you a certificate for it, and a voluntary framework with no audit tends to drift.
OECD AI Principles and the shared vocabulary
The OECD Principles on Artificial Intelligence, adopted in 2019 and updated in 2024, are where most of the language everyone else uses came from: inclusive growth and wellbeing, human rights and democratic values, transparency and explainability, robustness and safety, and accountability. They bind nobody directly, but the EU AI Act's definition of an AI system was aligned to the OECD's, and both the G7 and national strategies lean on them. Treat them as the dictionary rather than the rulebook.
The UK approach: five principles, no statute
The UK has not passed a cross-sector AI law. Instead it set out five principles, safety and robustness, appropriate transparency and explainability, fairness, accountability and governance, and contestability and redress, and asked existing regulators to apply them in their own domains. In practice that means an AI hiring tool is regulated by employment law and the ICO, an AI credit model by the FCA, and an AI diagnostic by the MHRA. The practical consequence for a UK business is that "are we compliant?" has no single answer; you have to identify your regulators first.
How they fit together
The frameworks are layered, not competing.
- The Act sets the floor if you touch the EU market, and it is the only layer with fines attached.
- ISO 42001 gives you the container: policy, roles, risk process, internal audit, management review, and an external auditor to keep you honest.
- NIST gives you the method for what actually happens inside the container when a team wants to deploy a model.
- The OECD principles give you the language for the policy at the top of the pile.
The Govern function in NIST and clauses 4 to 10 of ISO 42001 cover the same governance terrain in different words, which is why the sensible sequence is to build one evidence base, an AI inventory, an impact assessment per system, a documented risk process, logging and a human oversight model, and then map it to whichever framework is being asked about. Our guide to building an AI governance framework covers that build in order, and algorithmic bias covers the measurement problem the Measure function keeps running into.
Choosing, in one paragraph
EU market exposure means the AI Act, whatever else you do. Customers asking for evidence means ISO 42001. No external pressure yet, but AI in production, means NIST AI RMF now and ISO later. A UK-only firm with no EU sales and no procurement pressure should still write an AI use policy and keep an inventory, because the first regulator to ask will not accept "we were waiting for legislation".
Frequently Asked Questions
Which AI governance framework should we adopt?
If you sell into the EU, the AI Act is not a choice and everything else sits on top of it. If customers or procurement teams ask for proof, ISO/IEC 42001 is the only one of the three you can be certified against. If you want a way to structure the work without paying for an audit, start with the NIST AI Risk Management Framework. Most mature programmes end up running ISO 42001 as the management system and NIST as the risk method inside it.
What is the difference between ISO 42001 and the NIST AI RMF?
ISO/IEC 42001:2023 is a certifiable management system standard, built on the same clause structure as ISO 27001, with 38 controls in Annex A across nine control areas. The NIST AI Risk Management Framework 1.0 is a voluntary US framework with four functions, Govern, Map, Measure and Manage, and 72 subcategories beneath them. One proves you have a system; the other tells you how to run the risk work.
Is the EU AI Act still coming into force in August 2026?
Partly. The Digital Omnibus on AI entered into force on 27 July 2026 and deferred the standalone high-risk obligations in Annex III from 2 August 2026 to 2 December 2027, and the Annex I embedded-product obligations to 2 August 2028. The Article 50 transparency duties, covering chatbot disclosure, marking of AI-generated content and deepfake labelling, were not delayed.
Do UK businesses need an AI governance framework?
There is no UK statute requiring one. The UK has taken a regulator-led approach built on five cross-sector principles rather than a single AI law, so the duties reach you through the ICO, the FCA, the MHRA and the rest. In practice UK firms adopt a framework because their customers, insurers or EU market access require it, not because Parliament does.
How much does ISO 42001 certification cost?
There is no published price, because the cost is driven by scope, headcount and how many AI systems are in the management system. Budget for three things: the gap analysis, the internal work to build and evidence the controls, and the certification body's stage 1 and stage 2 audits plus annual surveillance. The internal work is almost always the largest of the three, and the cheapest way to reduce it is to narrow the scope.
Can one framework satisfy all of them?
No single document does, but they overlap heavily. The NIST Govern function and clauses 4 to 10 of ISO 42001 cover the same ground in different vocabulary, and both feed the risk management system, data governance and post-market monitoring the EU AI Act demands of high-risk providers. Build the evidence once and map it three ways rather than running three programmes.
Sources
- Regulation (EU) 2024/1689 (the AI Act): eur-lex.europa.eu
- Gibson Dunn on the EU AI Act Omnibus agreement and the postponed high-risk deadlines: gibsondunn.com
- ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system: iso.org
- NIST AI Risk Management Framework 1.0: nist.gov
- OECD AI Principles: oecd.ai
Deadlines checked on 18 August 2026. The EU timetable has moved once already; verify against the Official Journal before relying on a date.