HIPAA Compliance Checklist for 2025
The EU AI Act’s obligations for high-risk AI systems were due on 2 August 2026. On 27 July, six days out, Regulation (EU) 2026/1744 entered into force and moved them to 2 December 2027.
The reason matters more than the date. The harmonised standards and conformity assessment infrastructure the Act relies on were not ready, so the law waited for them.
That is the backdrop for any ISO 42001 vs NIST AI RMF vs EU AI Act decision: all three have moved in the last fourteen months. Below is what changed, how the three differ, which to adopt first, and the one prerequisite all three share but none supplies.
1. What Changed in the EU AI Act, NIST AI RMF, and ISO 42001 in 2025–2026?
A. The EU AI Act Deferred High-Risk Deadlines to December 2027
Negotiators reached provisional agreement on 7 May 2026; Parliament endorsed the package on 16 June and the Council gave final approval on 29 June. The new timeline splits cleanly into what moved and what did not.
The deferral bought time on documentation and conformity assessment. It bought nothing on disclosure, prohibitions or general-purpose models; our EU AI Act compliance checklist covers the full obligation set.
B. The NIST AI RMF Is Being Revised Under the AI Action Plan
America’s AI Action Plan, published in July 2025, directs NIST to revise the framework and strip out references to misinformation, DEI and climate change. As of September 2026, NIST’s own page still lists AI RMF 1.0 as current and notes the revision is underway.
Treat this as a version-stability point, not a political one. A voluntary framework can be rewritten by executive direction, with no legislative vote or standards ballot in between; if you chose NIST as the neutral, technical option, that premise now carries a footnote.
For how the current version maps to tools your teams already use, see how the NIST AI RMF applies to your AI tools.
C. ISO 42001 Got Its Certifier Accreditation Standard 18 Months Late
ISO/IEC 42001 was published in December 2023. ISO/IEC 42006, which sets requirements for the bodies that audit and certify against it, followed on 7 July 2025; until then, accreditation bodies worked from drafts.
As of August 2026, fifteen certification bodies hold verifiable accreditation to certify against ISO 42001, across ANAB, UKAS, RvA, JAS-ANZ, SAC and IAS. Two things follow:
- A certificate from an unaccredited body is not equivalent to an accredited one, and enterprise buyers increasingly ask which body issued it
- With fifteen accredited bodies serving global demand, “we will just get certified” is a capacity question before it is a budget question
Our breakdown of what ISO 42001 requires covers the controls buyers are now asking about.
2. How Are ISO 42001, NIST AI RMF, and the EU AI Act Different?
Most comparisons line them up as competing products. They are three different kinds of object: a law, a certifiable standard and a voluntary method.
- The EU AI Act attaches duties to a system’s risk tier, not its technology; Annex III is the list that catches most enterprises
- ISO 42001 follows the ISO 27001 model, a documented cycle of policy, roles, risk assessment, controls, audit and review that an external body attests to; it does not judge whether a model is safe
- The NIST AI RMF organises work into Govern, Map, Measure and Manage, with Govern running through the other three; there is nothing to pass and nobody to pass it with
The €35 million figure appears in every comparison, and it flatters the decision. It applies to a narrow set of banned uses; most organisations reading this are not doing social scoring.
The distinction that drives the choice is quieter: each framework produces a different kind of evidence, and evidence is only worth what the person asking will accept.
3. Which AI Governance Framework Should You Start With?
Start with who is asking for proof. Regulators, enterprise buyers and your own engineers each want a different artefact, and none accepts the others.

A certificate does not substitute for a conformity file, and a NIST-aligned risk register substitutes for neither. NIST is also the only one of the three built to be used weekly rather than annually, which makes it the cheapest place to start.
4. How ISO 27001 Certification Shortens the Path to ISO 42001
ISO 42001 shares its skeleton with ISO 27001. An organisation already certified to 27001 can usually extend its existing management system rather than stand up a second one.
That turns a multi-quarter programme into an extension of an audit cycle you already run. It is the biggest cost variable in the whole decision, and it is settled by what you already hold, not by any judgement about the frameworks. The phase-by-phase work is in our ISO 42001 implementation checklist.
5. What Do the EU AI Act, ISO 42001, and NIST AI RMF All Require First?
An accurate inventory of the AI systems you run. Every one of the three assumes you already have it:
- The EU AI Act attaches duties per system: providers owe technical documentation (Article 11 and Annex IV), automatic logging (Article 12) and post-market monitoring (Article 72); deployers owe human oversight and log retention under Article 26
- ISO 42001’s Annex A has 38 controls; A.4 covers the resources behind each AI system, including data, tooling and compute, and A.6 covers the system life cycle
- The NIST AI RMF’s Map function exists to establish context and categorise AI systems; Measure and Manage sit downstream of it by design
Three documents, three legal statuses, one prerequisite. None of them tells you how to find AI that was never procured, a gap that widens with autonomous agents, as we cover in why most AI governance frameworks ignore agents.
A. Why Procurement Records Miss Most Enterprise AI
Standards bodies write requirements; they do not ship discovery. In 2026 that matters, because most enterprise AI arrives through channels that leave no procurement trail:
- Free-tier tools signed up for with a work email
- AI features switched on inside approved SaaS, where the contract predates the capability, including vendor-embedded agents that can reach your data
- Agents, model integrations and MCP servers spun up by engineering with an API key and no ticket
None of that appears in a vendor register, and your identity provider only sees what sits behind single sign-on (see five ways shadow AI slips past SSO and CASB logs). Procurement can produce a list of purchases, not a list of AI systems.
B. How Large Is the Enterprise AI Inventory Gap?
These organisations did not pick the wrong framework; most of them picked one. They could not populate it.
CloudEagle.ai works at that step. It maintains a proprietary catalogue of AI applications, agents and MCP servers, then correlates SSO, finance, firewall and browser signals against it to surface the AI nobody filed a ticket for; EagleIQ correlates seven discovery sources to do it.
Discovered tools are risk-scored so teams know what to review first, and non-human identities sit in the same system as human ones. The result is the auditable AI inventory every framework on this page assumes you have, feeding the access reviews and audit evidence in CloudEagle.ai’s SaaS security and compliance workflows.
6. In What Order Should You Implement AI Governance Frameworks?
The frameworks will keep moving. Build in an order that does not care:
- Build the inventory: discover every AI application, agent, model integration and MCP server actually in use, not just what procurement bought; it is the only step every framework depends on, and nobody sells a certificate for it
- Classify by exposure: for each system, check whether it touches EU users, sits in an Annex III category, processes personal or regulated data, or can take actions rather than produce text; that separates a legal problem from a hygiene problem
- Name the audience: regulator, buyer or your own engineers; satisfy whoever is asking first and accept that the other two can wait a quarter, with clear decision rights on who makes that call
- Then adopt the matching framework: one adopted before steps one and two produces a binder, not a control
- Own your control set: define controls in your own terms, version-pin them and map them outward, so an amendment to a framework mid-revision or mid-deferral does not become a re-scoping project and audit readiness survives it
The mapping work is smaller than most comparisons imply, because the three overlap heavily on substance. Where they differ is the artefact at the end, and that is a business decision, not a compliance one.
7. Conclusion
Organisations that spent 2026 building toward 2 August had that date pulled six days out; those that had done nothing were handed sixteen extra months.
That is the case for treating framework selection as reversible and inventory as permanent. Deadlines move, standards get rewritten, accreditation schemes arrive late, and US state AI laws keep adding to the list.
The list of AI systems you actually run holds its value across all three frameworks, every amendment to them, and whatever replaces them. Start there, and which framework comes first stops being urgent.
8. FAQs
1. Doesn't CloudEagle.ai only help once you've already chosen a framework?
CloudEagle.ai works at the step that comes before any framework choice. The EU AI Act, ISO 42001, and the NIST AI RMF all assume you hold an accurate AI inventory. CloudEagle.ai builds that inventory, so whichever framework you adopt first has something real to govern.
2. Can't CloudEagle.ai only find the AI tools that procurement bought?
CloudEagle.ai finds the AI that never reached procurement. It correlates SSO, finance, firewall, and browser signals against its proprietary catalogue of AI applications, agents, and MCP servers, surfacing free-tier sign-ups, AI features switched on inside approved SaaS, and tools engineering spun up with an API key.
3. Doesn't CloudEagle.ai leave teams to sort through hundreds of AI tools by hand?
CloudEagle.ai risk-scores every AI tool it discovers, so teams know what to review first. That gives your classification work a starting order, which helps you separate systems that need regulatory attention from those that only need basic hygiene.
4. Isn't CloudEagle.ai's inventory missing the agents and service accounts frameworks now care about?
CloudEagle.ai includes agents, MCP servers, and non-human identities in the same system as human users. As frameworks catch up on autonomous agents, your inventory already covers the service accounts and API keys that agents create.
5. Isn't an AI inventory from CloudEagle.ai just a list, not audit evidence?
CloudEagle.ai turns the inventory into evidence. It feeds directly into access reviews and audit evidence workflows, so the artefact you hand a regulator, certification body, or enterprise buyer is built from systems you've actually discovered and reviewed.





.avif)




.avif)
.avif)




.png)




.avif)
.avif)
.avif)

