Agent Governance Cloud Toolkit from $199

AI governance framework: what applies to you, and where to start

Three frameworks matter: the EU AI Act (law), the NIST AI Risk Management Framework (structure) and ISO/IEC 42001 (proof). They overlap more than they differ. Here's how they compare, what AI agents add, and the fastest way to put all three in place.

Want it done this month? The AI Governance Toolkit has the policy, AI inventory and risk register, EU AI Act risk assessment, ISO/IEC 42001 gap assessment and NIST AI RMF mapping, ready to fill in.

The three frameworks side by side

EU AI ActNIST AI RMFISO/IEC 42001
What it isEU law (Regulation (EU) 2024/1689)Voluntary US framework (AI RMF 1.0, January 2023)International management-system standard (2023)
Who it applies toProviders and deployers of AI placed on the market or used in the EU, and those whose AI output is used thereAnyone who chooses to use it; widely referenced by US agencies and buyersAny organisation that chooses to adopt it; can be certified by an accredited body
How it's organisedRisk classes: prohibited, high-risk, transparency, minimal; separate rules for general-purpose AI modelsFour functions (Govern, Map, Measure, Manage) and 19 categoriesManagement-system clauses 4–10 plus Annex A control areas A.2–A.10
Binding?Yes, with finesNoNo, unless a customer or contract requires certification
Key datesProhibitions since 2 Feb 2025; transparency from 2 Aug 2026; Annex III high-risk from 2 Dec 2027; Annex I from 2 Aug 2028In use now; generative AI profile (NIST AI 600-1) July 2024Certification available now
Best forKnowing what you must do in the EUStructuring AI risk work, especially for US buyersProving to customers and auditors that AI is governed

EU AI Act dates as amended by the Digital Omnibus on AI (in force 27 July 2026). Not legal advice.

Where to start: five steps that serve all three

  1. Approve an AI policy with named owners. (EU AI Act literacy duty · NIST GOVERN · ISO 5.2, A.2)
  2. Inventory every AI system and agent, including AI features inside tools you already pay for. (NIST MAP · ISO A.4, A.6)
  3. Screen each system for its EU AI Act class. Free screening tool.
  4. Assess and register the risks with owners, treatments and review dates. (NIST MEASURE, MANAGE · ISO 6.1, 8.2)
  5. Put AI terms in supplier contracts: no training on your data, model-change notice, incident notification. (NIST GOVERN 6, MANAGE 3 · ISO A.10)

What AI agent governance adds

An AI agent doesn't just suggest; it acts, with credentials. Governing agents means an owner for every agent, permissions limited to its task, approval before risky actions, and a record of what it did. Those controls live in your identity and runtime systems, not in a spreadsheet, which is what Agent Trust Cloud does: it discovers agents across your identity sources and governs what they're allowed to do.

AI Governance Toolkit

Word and Excel templates that put the five steps in place, with EU AI Act, NIST AI RMF and ISO/IEC 42001 built in. Workbooks score themselves; every file has a start-here guide.

Full contents and FAQ

Questions

What is an AI governance framework?

A set of rules, roles and processes for deciding which AI you use, how you check its risks, and who is accountable. In practice most organisations combine the EU AI Act (if they touch the EU), the NIST AI RMF (to structure risk work) and ISO/IEC 42001 (to prove it to others).

Which framework should we start with?

Start with an AI policy and an inventory of every AI system; all three frameworks need them. Then screen each system against the EU AI Act, and use the NIST AI RMF or ISO/IEC 42001 to organise the rest.

What is AI agent governance?

Governance for AI that takes actions with credentials: sending messages, changing records, calling tools. On top of normal AI governance it needs an owner per agent, least-privilege permissions, approval for risky actions and a log of what each agent did.

Do we need ISO/IEC 42001 certification?

Only if customers, contracts or your market expect it. Many organisations use the standard as a checklist first and decide on certification later.