The compliance surface
The standards and regulation agents are measured against. The EU AI Act is the binding one: its high-risk obligations arrive Aug 2026.
Aug 2026: high-risk obligations land, the deadline that matters most for production agents.
| name | issuing body | region | scope | status | status label | src |
|---|---|---|---|---|---|---|
| ISO/IEC 42001 | ISO/IEC | International | AI management systems | published | Published Dec 2023 | ↗ T1 |
| NIST AI RMF 1.0 | NIST | US | AI risk management framework | published | Published Jan 2023 | ↗ T1 |
| EU AI Act | European Union | EU | Risk-based AI regulation | in_force | In force Aug 2024; phased enforcement 2025-27 | ↗ T1 |
| OWASP Top 10 for LLM Apps | OWASP | Global | LLM application security risks | published | 2025 edition | ↗ T1 |
| ISO/IEC 23894 | ISO/IEC | International | AI risk management guidance | published | Published 2023 | ↗ T1 |
| IEEE 7000-2021 | IEEE | International | Ethical system design process | published | Published 2021 | ↗ T1 |
Binding regulation and voluntary frameworks: what an agent is measured against
Six standards cover the formal frameworks now being applied to agents: NIST AI RMF, ISO 42001 and the regulatory instruments arriving alongside them.
Show more
They were written for AI systems generally, not for agents specifically, so the gap shows up around autonomy, delegated action and tool access. Expect agent-specific guidance to arrive as amendments to these frameworks rather than as new ones, which means the obligations land sooner than a new standard would suggest.
The EU AI Act is the binding one to watch. It classifies systems by risk and loads the heaviest duties, risk management, data governance, transparency, human oversight and conformity assessment, onto high-risk uses, which is exactly where many enterprise agents land. The obligations reach anyone placing such a system on the EU market regardless of where they are based. The timeline above plots the enforcement milestones, and the date that matters most for production agents is August 2026, when the high-risk obligations take effect. The table below catalogues the standards and regulations in scope, each linked to its issuing body.
What regulations apply to AI agents?
The EU AI Act is the binding one, and it reaches anyone placing a system on the EU market regardless of where they are based. Alongside it sit voluntary frameworks: ISO/IEC 42001 for AI management systems and the NIST AI Risk Management Framework for risk (NIST). Sector rules, such as financial and medical regulation, still apply on top.
What is the EU AI Act?
The first comprehensive, binding AI law. It sorts systems by risk and puts the heaviest duties on high-risk uses: risk management, data governance, transparency, human oversight and conformity assessment. A small number of practices are banned outright. Many enterprise agent deployments land in the high-risk band.
When does the EU AI Act take effect?
It phases in. The Act entered into force in 2024, with the prohibitions and AI-literacy duties first and general-purpose model obligations following. The date that matters most for production agents is August 2026, when the high-risk obligations land. The timeline above plots the milestones in order.
What is ISO 42001?
ISO/IEC 42001 is the international management-system standard for AI, published in December 2023. It gives you a certifiable framework of policies, risk controls, defined roles and continual improvement, in the same shape as ISO 27001 for information security. It is voluntary, but certification is increasingly asked for in enterprise procurement.
What is the NIST AI Risk Management Framework?
A voluntary US framework for identifying, measuring and managing AI risk across a system's life. It is organised around four functions: govern, map, measure and manage. It carries no legal force, but it is widely used as the shared vocabulary in policy and procurement (NIST).