Governance — EU AI Act, NIST AI RMF, US AISI
**EU AI Act (Regulation 2024/1689, in force Aug 2024, staggered applicability through Aug 2026):**
• **Prohibited** (Art. 5, applied Feb 2025) — social scoring by public authorities, real-time remote biometric ID in public spaces for law enforcement (narrow exceptions), emotion recognition at work/school, subliminal manipulation causing harm, vulnerability exploitation, untargeted scraping for facial recognition DBs.
• **High-risk** (Annex III, applied Aug 2026) — AI in safety components of regulated products + standalone use cases like biometric ID, critical infrastructure, education/vocational, employment, essential services (credit scoring, insurance, benefits), law enforcement, migration/border, justice. Requires conformity assessment, QMS, data governance, human oversight, robustness, accuracy + cybersecurity, logging, transparency, FRIA (fundamental rights impact assessment).
• **GPAI models** (Chapter V) — technical documentation, training-data summary, copyright policy, compliance with EU copyright. **GPAI with systemic risk** (>10²⁵ FLOPs training compute or designated): evals, adversarial testing, incident reporting, cybersecurity.
• **Transparency** (Art. 50) — deepfakes must be labeled; AI-generated text on matters of public interest disclosed unless human-reviewed.
• **Penalties** — up to €35M or 7% global turnover for prohibited; €15M/3% for other violations.
**NIST AI RMF 1.0 (2023) + GenAI Profile (2024):** voluntary framework. Four functions — **GOVERN, MAP, MEASURE, MANAGE** — cross-cutting through the AI lifecycle. Complements ISO/IEC 42001 (AI management systems standard).
**US AI Safety Institute (AISI) at NIST** — established 2024. Pre-deployment evaluations (MOUs with Anthropic, OpenAI), red-teaming, methodology publications. Companion institutes in UK AISI, Japan AISI, and network via AISI Consortium.
**Sector rules (US):** FDA on AI/ML medical devices (predetermined change control plans), EEOC on hiring AI, CFPB on adverse-action notices in credit, NIST AI RMF expected in federal procurement (OMB M-24-10 / NIST SP 800-218A for secure AI development).