Corpus Agentis
The field book to agent ecosystems
The field book to agent ecosystems
Security · Standards

The compliance surface

The standards and regulation agents are measured against. The EU AI Act is the binding one: its high-risk obligations arrive Aug 2026.

EU AI Act · enforcement timeline Live data
2024-08In force2025-02Prohibited AI banned2025-08GPAI obligations2026-08High-risk obligations2027-08Product-legislation2025-01Signed2023-01Released2023-12Published2024-05Signed

Aug 2026: high-risk obligations land, the deadline that matters most for production agents.

6 rows Live data · click a row for its full spec
nameissuing bodyregionscopestatusstatus labelsrc
ISO/IEC 42001ISO/IECInternationalAI management systemspublishedPublished Dec 2023↗ T1
NIST AI RMF 1.0NISTUSAI risk management frameworkpublishedPublished Jan 2023↗ T1
EU AI ActEuropean UnionEURisk-based AI regulationin_forceIn force Aug 2024; phased enforcement 2025-27↗ T1
OWASP Top 10 for LLM AppsOWASPGlobalLLM application security riskspublished2025 edition↗ T1
ISO/IEC 23894ISO/IECInternationalAI risk management guidancepublishedPublished 2023↗ T1
IEEE 7000-2021IEEEInternationalEthical system design processpublishedPublished 2021↗ T1
Field notes

Binding regulation and voluntary frameworks: what an agent is measured against

Six standards cover the formal frameworks now being applied to agents: NIST AI RMF, ISO 42001 and the regulatory instruments arriving alongside them.

Show more

They were written for AI systems generally, not for agents specifically, so the gap shows up around autonomy, delegated action and tool access. Expect agent-specific guidance to arrive as amendments to these frameworks rather than as new ones, which means the obligations land sooner than a new standard would suggest.

The EU AI Act is the binding one to watch. It classifies systems by risk and loads the heaviest duties, risk management, data governance, transparency, human oversight and conformity assessment, onto high-risk uses, which is exactly where many enterprise agents land. The obligations reach anyone placing such a system on the EU market regardless of where they are based. The timeline above plots the enforcement milestones, and the date that matters most for production agents is August 2026, when the high-risk obligations take effect. The table below catalogues the standards and regulations in scope, each linked to its issuing body.

From the corpus, curated by Brandon Chaplin
Common questions
What regulations apply to AI agents?

The EU AI Act is the binding one, and it reaches anyone placing a system on the EU market regardless of where they are based. Alongside it sit voluntary frameworks: ISO/IEC 42001 for AI management systems and the NIST AI Risk Management Framework for risk (NIST). Sector rules, such as financial and medical regulation, still apply on top.

What is the EU AI Act?

The first comprehensive, binding AI law. It sorts systems by risk and puts the heaviest duties on high-risk uses: risk management, data governance, transparency, human oversight and conformity assessment. A small number of practices are banned outright. Many enterprise agent deployments land in the high-risk band.

When does the EU AI Act take effect?

It phases in. The Act entered into force in 2024, with the prohibitions and AI-literacy duties first and general-purpose model obligations following. The date that matters most for production agents is August 2026, when the high-risk obligations land. The timeline above plots the milestones in order.

What is ISO 42001?

ISO/IEC 42001 is the international management-system standard for AI, published in December 2023. It gives you a certifiable framework of policies, risk controls, defined roles and continual improvement, in the same shape as ISO 27001 for information security. It is voluntary, but certification is increasingly asked for in enterprise procurement.

What is the NIST AI Risk Management Framework?

A voluntary US framework for identifying, measuring and managing AI risk across a system's life. It is organised around four functions: govern, map, measure and manage. It carries no legal force, but it is widely used as the shared vocabulary in policy and procurement (NIST).

Next in the learning path