AI Governance Frameworks

Overview

Multiple frameworks exist for governing AI risk. No single framework covers everything — most organizations need a composite approach.

Framework Comparison

FrameworkScopeMandatory?Best For
NIST AI RMFComprehensive AI risk managementVoluntary (mandatory for US federal)Enterprise risk programs
EU AI ActRisk-based regulatory frameworkMandatory in EU (2024-2026 rollout)Compliance for EU-facing orgs
ISO 42001AI management system standardVoluntary (certification available)Formal AIMS implementation
OWASP LLM Top 10Technical vulnerability taxonomyVoluntarySecurity engineering teams
MITRE ATLASAdversarial threat frameworkVoluntaryRed teams, threat modeling

Subsections