Skip to reading
AI.Governance AI / Modern ML

Governance — EU AI Act, NIST AI RMF, US AISI

Node 7 of 12 in AI

Objectives

  • Identify the key rules and §§ that apply to governance — eu ai act, nist ai rmf, us aisi.
  • Apply the AI.Governance knowledge element in a typical exam scenario.
  • Recognize common distractors and partial-credit answers.

Read

AI.Governance

Governance — EU AI Act, NIST AI RMF, US AISI

AI Era · Law and Governance EU AI Act, NIST, US AISI

**EU AI Act (Regulation 2024/1689, in force Aug 2024, staggered applicability through Aug 2026):**

• **Prohibited** (Art. 5, applied Feb 2025) — social scoring by public authorities, real-time remote biometric ID in public spaces for law enforcement (narrow exceptions), emotion recognition at work/school, subliminal manipulation causing harm, vulnerability exploitation, untargeted scraping for facial recognition DBs.

• **High-risk** (Annex III, applied Aug 2026) — AI in safety components of regulated products + standalone use cases like biometric ID, critical infrastructure, education/vocational, employment, essential services (credit scoring, insurance, benefits), law enforcement, migration/border, justice. Requires conformity assessment, QMS, data governance, human oversight, robustness, accuracy + cybersecurity, logging, transparency, FRIA (fundamental rights impact assessment).

• **GPAI models** (Chapter V) — technical documentation, training-data summary, copyright policy, compliance with EU copyright. **GPAI with systemic risk** (>10²⁵ FLOPs training compute or designated): evals, adversarial testing, incident reporting, cybersecurity.

• **Transparency** (Art. 50) — deepfakes must be labeled; AI-generated text on matters of public interest disclosed unless human-reviewed.

• **Penalties** — up to €35M or 7% global turnover for prohibited; €15M/3% for other violations.

**NIST AI RMF 1.0 (2023) + GenAI Profile (2024):** voluntary framework. Four functions — **GOVERN, MAP, MEASURE, MANAGE** — cross-cutting through the AI lifecycle. Complements ISO/IEC 42001 (AI management systems standard).

**US AI Safety Institute (AISI) at NIST** — established 2024. Pre-deployment evaluations (MOUs with Anthropic, OpenAI), red-teaming, methodology publications. Companion institutes in UK AISI, Japan AISI, and network via AISI Consortium.

**Sector rules (US):** FDA on AI/ML medical devices (predetermined change control plans), EEOC on hiring AI, CFPB on adverse-action notices in credit, NIST AI RMF expected in federal procurement (OMB M-24-10 / NIST SP 800-218A for secure AI development).

EU AI Act (Regulation 2024/1689) Art. 5, 6, 50 NIST AI RMF 1.0 Core US AISI Mandate

Check yourself

3 quick questions — no score kept, just formative feedback.

  1. Q1 · AI.Governance

    Under the EU AI Act (Regulation 2024/1689), a general-purpose AI model is classified as having SYSTEMIC RISK when trained with cumulative compute of:

    Answer choices
  2. Q2 · AI.Governance

    The EU AI Act's risk pyramid treats the following as UNACCEPTABLE (prohibited) practices:

    Answer choices
  3. Q3 · AI.Governance

    The NIST AI RMF Playbook maps which high-level phases of AI lifecycle?

    Answer choices

Tutor

Scoped to AI.Governance .

  1. Ask questions about this passage. Answers cite the specific corpus chunk and regulation. The tutor will never reproduce real exam items.