Resources · Briefing

AI regulation for engineering programs: EU AI Act, NIST AI RMF and ISO 42001

Tymeline · · 4 min read

In short

Three frameworks matter most. The EU AI Act is law, in force since August 2024 with obligations phasing in. The NIST AI Risk Management Framework, published in January 2023, is voluntary guidance widely used in the United States. ISO/IEC 42001, published in December 2023, is a certifiable management-system standard for AI. All three ask for the same practical things: know what your AI does, keep humans accountable, and keep records.

What is the EU AI Act?

A regulation that classifies AI systems by risk and sets obligations accordingly. It entered into force in August 2024, and its requirements apply in stages over the following years. It applies to organisations that place or use AI systems in the EU.

What is the NIST AI RMF?

A voluntary framework from the US National Institute of Standards and Technology, first published in January 2023. It organises AI risk management into four functions: govern, map, measure and manage.

What is ISO/IEC 42001?

An international standard, published in December 2023, for an AI management system. Like ISO 27001 for information security, an organisation can be audited and certified against it.

What do they ask for in common?

In practice, four things:

  • An inventory: which AI systems are in use, and for what.
  • Human oversight: a person accountable for consequential decisions.
  • Records: what the system did, on what data, and who approved it.
  • Control: the ability to limit and stop it.

What does that mean on an engineering program?

Agents that inherit the access of whoever deployed them cannot meet these. Each needs an identity, a scope, an approver and a record. Tymeline is aligned to the NIST AI RMF and ISO 42001-ready; this article is a summary, not legal advice.

See a slip caught on a program like yours.

45 minutes. No slide deck.

Independently attested. Renewed annually.