What you will be measured against

Six instruments, one of which is law and the rest guidance. The distinction matters more than the overlap: only the EU AI Act carries penalties, only ISO/IEC 42001 is certifiable, and only MITRE ATLAS describes what an adversary does rather than what you should do. Reviewed 24 Sep 2026

EU AI Act

European Union · Regulation (EU) 2024/1689
Law

Binding regulation covering AI systems placed on the EU market. Risk-tiered: prohibited practices, high-risk systems, transparency obligations, and a separate regime for general-purpose AI models.

Why it matters: The only item on this page that is law rather than guidance. Obligations attach to providers and deployers, and apply extraterritorially where output is used in the EU.

58 days to Transparency obligations apply (Art. 50)
  • 01 Aug 2024Entered into force
  • 02 Feb 2025Prohibited practices and AI literacy obligations apply
  • 02 Aug 2025General-purpose AI model obligations apply (Arts. 51–56)
  • 02 Aug 2026High-risk system framework applies
  • 02 Dec 2026Transparency obligations apply (Art. 50)
  • 02 Dec 2027Annex III high-risk systems apply
  • 02 Aug 2028Annex I product-embedded systems apply
LLM01:2025LLM02:2025LLM06:2025

NIST AI Risk Management Framework

NIST (United States) · NIST AI 100-1
Voluntary framework

Voluntary framework organised around four functions — GOVERN, MAP, MEASURE, MANAGE — for identifying and managing risk across the AI lifecycle.

Why it matters: Supplies the vocabulary most enterprise AI risk programmes are assessed against, and the mapping target used throughout this research. Not certifiable, but widely referenced in contracts.

  • 26 Jan 2023AI RMF 1.0 released
  • 26 Jul 2024Generative AI Profile released (NIST AI 600-1)
LLM01:2025LLM02:2025LLM05:2025LLM06:2025LLM10:2025

OWASP Top 10 for LLM Applications

OWASP GenAI Security Project · v2.0 (2025)
Community taxonomy

Ranked list of the ten risks most commonly seen in production LLM applications, with mitigation guidance per entry.

Why it matters: The de facto shared vocabulary for LLM application risk. The 2025 revision renumbered several entries against the 2023 list, so citations must carry the year to be unambiguous.

  • 01 Aug 2023First release (v1.0)
  • 18 Nov 2024v2.0 published — entries renumbered
LLM01:2025LLM02:2025LLM05:2025LLM06:2025LLM10:2025

MITRE ATLAS

MITRE · Adversarial Threat Landscape for AI Systems
Threat knowledge base

ATT&CK-style matrix of tactics and techniques observed against AI systems, with case studies drawn from real incidents.

Why it matters: The only one of these that describes adversary behaviour rather than controls. Techniques are added as they are seen in the wild, so it moves continuously rather than in releases.

  • 01 Jun 2021Initial public release
LLM01:2025LLM02:2025LLM05:2025LLM06:2025LLM10:2025

ISO/IEC 42001

ISO / IEC · ISO/IEC 42001:2023
Certifiable standard

Management system standard for artificial intelligence (AIMS), structured like ISO 27001 — policy, roles, risk assessment, controls, continual improvement.

Why it matters: Certifiable, which is what distinguishes it from the frameworks above. Where a customer asks for evidence of AI governance rather than a description of it, this is usually the artefact they mean.

  • 18 Dec 2023Published
LLM06:2025

ISO/IEC 23894

ISO / IEC · ISO/IEC 23894:2023
Guidance

Guidance on AI risk management, aligning ISO 31000 risk practice to AI-specific concerns.

Why it matters: Bridges an existing enterprise risk function into AI without requiring a separate programme. Guidance only — not certifiable.

  • 01 Feb 2023Published

Dates are cited from the issuing body and were verified on the review date above. The EU AI Act timeline in particular has been amended since the regulation entered into force — confirm against the official text before relying on any date here for a compliance decision.