Current as of August 2026. Each control in the framework maps to at least one of these instruments, and every mapping carries a dated source.
EU AI ActIn force 27 Jul 2026
Amended by the AI Omnibus
Regulation (EU) 2026/1744 moved core Annex III high-risk obligations to 2 Dec 2027 and Annex I product-embedded high-risk AI to 2 Aug 2028. Prohibitions and AI-literacy duties have applied since 2 Feb 2025; GPAI obligations since 2 Aug 2025; Article 50 transparency since 2 Aug 2026. Full roll-out is foreseen by 2 Aug 2028.
Commission implementation timeline →ISO/IEC 42001Published 2023
AI management system — certifiable
The certifiable AI management system standard: AI policy, roles, risk and impact treatment, lifecycle controls and continual improvement. ISO/IEC 42006 now sets the accreditation requirements for the bodies that certify against it, so certificates are becoming comparable.
ISO/IEC 42001 overview →ISO/IEC 23894 + 4200523894:2023 · 42005:2025
Risk and impact assessment
23894 adapts ISO 31000 risk management to AI; 42005 gives the process for AI system impact assessment — scope, affected individuals, benefits and harms, documentation and timing across the lifecycle. Together they underpin our Assess stage.
ISO/IEC 42005 overview →NIST AI RMFRMF 1.0 · GenAI Profile (AI 600-1)
Voluntary US framework
Govern, Map, Measure, Manage — plus the Generative AI Profile's risk actions for foundation-model use. We use it to structure evidence for US and multinational programmes that are not directly AI Act-scoped.
NIST AI RMF →ISO/IEC 27001:2022Amd 1:2024 (climate action)
Information security baseline
The 2022 revision's 93 Annex A controls — threat intelligence, secure development, cloud service security, data masking, monitoring — are the security floor beneath any AI control. ISO/IEC 27701 extends it to privacy; transition to the 2022 edition is complete.
ISO/IEC 27001 overview →AI security testingOWASP LLM Top 10 · NIST AI 100-2
Adversarial assurance
Prompt injection, insecure output handling, supply-chain and data-poisoning risks tested against the OWASP Top 10 for LLM applications, with NIST's adversarial ML taxonomy (AI 100-2e2025) framing evasion, poisoning and privacy attacks in evaluation scope.
OWASP LLM Top 10 →