AI governance frameworks: Compare

A learning aid, not legal advice.

Depth, from 0 (least) to 3 (most)0123Under review
Frameworks to compare

Pick two or three frameworks.

Dimension
EU AI Act (Regulation (EU) 2024/1689)
binding law
Nature
Depth 3 of 3.

A regulation that applies directly in every Member State, backed by administrative fines.

Reg. (EU) 2024/1689, Art. 99
Where and to whom it applies
Depth 3 of 3.

Reaches providers placing AI on the EU market wherever they are established, deployers in the EU, and importers and distributors.

Art. 2 (Scope)
Roles addressed
Depth 3 of 3.

Defines provider, deployer, importer and distributor, and gives each its own list of duties (for example Art. 16 for providers and Art. 26 for deployers of high-risk systems).

Art. 3 (Definitions); Art. 16; Art. 26
Risk approach
Depth 3 of 3.

Tiers: prohibited practices, high-risk systems (Annex I products and Annex III uses), transparency duties for certain systems, and separate rules for general-purpose AI models.

Art. 5; Art. 6 and Annex III; Art. 50; Art. 53
Inventory and documentation
Depth 3 of 3.

High-risk providers draw up technical documentation before market placement, keep automatic logs, and register Annex III systems in the EU database; public-body deployers register their use.

Art. 11 and Annex IV; Art. 12; Art. 49; Art. 71
Risk or impact assessment
Depth 3 of 3.

Providers run a risk management system across the life cycle; public bodies and certain private deployers carry out a fundamental rights impact assessment before use and notify the authority.

Art. 9; Art. 27(1) to (3)
Human oversight
Depth 3 of 3.

High-risk systems are designed so people can understand, override or stop them; deployers assign oversight to competent people with authority.

Art. 14(1) to (4); Art. 26(2)
Transparency and notices
Depth 3 of 3.

Instructions for use to deployers; telling people they deal with AI; machine-readable marking of synthetic content; deepfake disclosure; a right to an explanation of certain decisions.

Art. 13; Art. 50(1) to (4); Art. 86
Data governance
Depth 3 of 3.

Training, validation and testing data for high-risk systems must follow data governance practices and be relevant and sufficiently representative; special-category data may be used for bias correction under safeguards.

Art. 10(2) to (5)
Testing, robustness and security
Depth 3 of 3.

High-risk systems must reach appropriate accuracy, robustness and cybersecurity, including measures against data and model poisoning and adversarial examples; testing is part of risk management.

Art. 15(1) to (5); Art. 9
Monitoring and incident reporting
Depth 3 of 3.

Providers run post-market monitoring and report serious incidents within 15 days, 10 days where a person died, 2 days for widespread infringement or critical infrastructure; deployers inform the provider immediately.

Art. 72; Art. 73(2) to (4); Art. 26(5)
Assurance and enforcement
Depth 3 of 3.

Conformity assessment before market placement for high-risk systems; market surveillance authorities; fines up to EUR 35 million or 7% of turnover for prohibited practices, EUR 15 million or 3% for other duties.

Art. 43; Art. 99(3) to (5)
Effort to implement
Depth 3 of 3.

Heavy for providers of high-risk systems (documentation, quality management, testing, conformity assessment); lighter for deployers of minimal-risk systems, who still carry AI literacy and transparency duties.

Art. 4; Art. 16; Art. 17; Art. 26
Key dates
Depth 3 of 3.

In force 2024-08-01; prohibitions and AI literacy 2025-02-02; general-purpose AI rules 2025-08-02; general application, incl. Art. 50, 2026-08-02; new prohibitions 2026-12-02; Annex III high-risk 2027-12-02; Annex I 2028-08-02.

Art. 113 and Art. 111(2) and (4) of Reg. (EU) 2024/1689, as amended by Reg. (EU) 2026/1744

A learning aid, not legal advice. Where AI SENTINEL is mentioned, it supports or maps to the dimension; it does not certify anything. Dates are those the official texts state on the date shown.