5 min read1,125 wordsv1.0.2.0Last Updated: 1 Aug 2026
Standards Comparison — Unified AI Security & Governance Landscape
Five instruments dominate enterprise AI security and governance in 2024–2025. This page maps their scope, legal status, structure, and cross-references to enable a single control framework.
Primary sources: NIST AI RMF (NIST AI 100-1), NIST AI 600-1, Regulation (EU) 2024/1689, ISO/IEC 42001:2023, OWASP LLM Top 10 (2025), MITRE ATLAS v2.3.
At a Glance
Standard
Type
Legal Status
Scope
Primary Audience
NIST AI RMF
Risk management framework
Voluntary (US); de facto for US federal
All AI systems; lifecycle risk
Risk officers, CISOs, engineers
NIST AI 600-1
Generative AI profile
Voluntary (US); companion to AI RMF
Generative AI specific
GenAI developers, red teams
EU AI Act
Regulation (law)
Mandatory in EU; extraterritorial
Providers/deployers in EU market
Legal, compliance, product
ISO/IEC 42001
Management system standard
Voluntary; certifiable
Organisational AI governance
Management, auditors, procurement
OWASP LLM Top 10
Awareness document
Voluntary; community
LLM application security
AppSec, developers, architects
MITRE ATLAS
Threat knowledge base
Voluntary; open
Adversarial ML threat modelling
Threat analysts, red teams
Scope & Applicability Matrix
Criterion
NIST AI RMF / 600-1
EU AI Act
ISO 42001
OWASP LLM
MITRE ATLAS
Geographic scope
Global (voluntary)
EU + extraterritorial
Global (voluntary)
Global
Global
AI system types
All AI
All AI (risk-tiered)
All AI
LLM applications
ML systems broadly
Lifecycle coverage
Full (design → retire)
Full (conformity assessment)
Full (PDCA)
Development/ops
Attack lifecycle
Mandatory?
No
Yes (phased 2025–2027)
No (certifiable)
No
No
Enforcement
N/A
Market surveillance, fines up to 7% global turnover
Certification bodies
Community
N/A
Certification path
N/A
CE marking + notified body
Accredited CB (ISO 17021)
N/A
N/A
Structural Comparison
NIST AI RMF (AI 100-1) — Four Functions
Function
Sub-functions
Purpose
Govern
1.1–1.6
Culture, policies, accountability, diversity
Map
2.1–2.3
Context, risk identification, stakeholders
Measure
3.1–3.3
Metrics, testing, monitoring, TEVV
Manage
4.1–4.3
Prioritisation, treatment, monitoring
AI 600-1 adds 12 GAI-specific risk areas (§2.1 to §2.12) with 400+ actions mapped to RMF functions.
EU AI Act — Risk Tiers & Obligations
Tier
Examples
Provider Obligations
Deployer Obligations
Prohibited (Art. 5)
Social scoring, real-time biometric ID in public, subliminal manipulation
Ban — cannot place on market
N/A
High-Risk (Art. 6, Annex III)
Recruitment, credit scoring, critical infra, medical devices, law enforcement