AI governance frameworks: Which frameworks?

A learning aid, not legal advice.

Depth, from 0 (least) to 3 (most)0123Under review

Answer seven questions. The page lists the frameworks that apply or fit, ranked, each with its reasoning, and suggests a stack: the binding laws, one management system, one risk method and, if you have AI agents, a certification for agents.

Jurisdictions
Role
Sector
Risk level
Certificate or external assurance needed
Organization size
AI agents

Tick at least one jurisdiction.

A learning aid, not legal advice. The selector points at what to check first; it does not decide whether a law applies. Laws outside this aid (for example data protection, sector and anti-discrimination law) may also apply.

Why this result

Each rule adds its score to a framework when every listed condition matches (any of the listed values). Binding laws rank first, then by score. The stack takes the first matching rule in each list. Rules that matched your answers are marked.

  • EU AI Act +100 (binding) when jurisdictions is EU: Applies to providers placing AI on the EU market and to deployers in the EU (Art. 2); which duties apply depends on the risk category.
  • EU AI Act +20 when jurisdictions is EU, and risk level is High or Not yet known: High-risk (or not yet classified) systems may carry the full high-risk duties from 2027-12-02; classify first.
  • EU AI Act +10 when jurisdictions is EU, and sector is Employment or Education or Finance or Public sector or Health: This sector includes Annex III or Annex I high-risk uses (for example recruitment, education, credit scoring, access to public services, medical devices).
  • Colorado +100 (binding) when jurisdictions is Colorado, and sector is Employment or Health or Finance or Education or Public sector: Colorado's law covers technology that materially influences consequential decisions in this sector, from 2027-01-01 (enforcement currently barred by a federal court order).
  • Colorado +20 when jurisdictions is Colorado, and sector is General: Only consequential decisions are covered (education, employment, real estate, finance, insurance, health care, government services); check whether any use is one.
  • Texas TRAIGA +100 (binding) when jurisdictions is Texas: TRAIGA applies to anyone developing or deploying AI in Texas since 2026-01-01 (intent-based prohibitions).
  • Texas TRAIGA +10 when jurisdictions is Texas, and sector is Health or Public sector: Health care providers and government agencies also carry disclosure duties (§ 552.051).
  • California ADMT +100 (binding) when jurisdictions is California, and sector is Employment or Health or Finance or Education: The CPPA rules give pre-use notice, opt-out and access rights where the technology makes significant decisions in this sector, from 2027-01-01 for existing uses.
  • California ADMT +30 when jurisdictions is California, and sector is General: Risk assessments can be required even without a significant decision (for example selling or sharing personal information); check the six triggers.
  • NYC LL 144 +100 (binding) when jurisdictions is New York City, and sector is Employment, and role is Deployer or Both: Employers and employment agencies using automated tools for hiring or promotion in New York City need a yearly bias audit and notices.
  • NYC LL 144 +30 when jurisdictions is New York City, and sector is Employment, and role is Provider or developer: Tool vendors are not the regulated party, but employer customers will ask for bias audit data.
  • NIST AI RMF +50 when jurisdictions is US federal or Colorado or Texas or California or New York City: The reference voluntary risk framework in the United States; Texas links a liability bar to substantial compliance with its Generative AI Profile.
  • NIST AI RMF +20 when jurisdictions is Other or Singapore: Free, modular and widely mapped to other frameworks.
  • NIST AI RMF +10 when organization size is Small or Medium: No certification cost; adopt the subcategories that fit.
  • ISO/IEC 42001 +60 when certificate or external assurance needed is Yes: The international management system standard that an accredited certification body can certify (AIUC-1 certifies agents, not the organisation's management system).
  • ISO/IEC 42001 +20 when organization size is Large: A management system suits organisations with several AI systems and teams.
  • ISO/IEC 42001 +15 when jurisdictions is EU, and role is Provider or developer or Both, and risk level is High or Not yet known: A management system helps organise the provider's quality management duty (Art. 17), though it gives no presumption of conformity.
  • ISO/IEC 23894 +25 when risk level is High or Not yet known: Guidance on building AI risk into the organisation's existing risk management process.
  • ISO/IEC 23894 +15 when jurisdictions is EU or UK or Singapore or Other: International guidance that works across jurisdictions and alongside ISO/IEC 42001.
  • UK approach +60 when jurisdictions is UK: UK regulators apply the five principles within their remits; UK data protection law adds binding rules on automated decisions.
  • Singapore +60 when jurisdictions is Singapore: Singapore's voluntary framework, with AI Verify for testing; the PDPA is the binding backdrop.
  • Singapore +10 when risk level is High or Not yet known, and jurisdictions is Singapore or Other: Its human-involvement area helps decide how much review each decision needs.
  • CoE Convention +25 when jurisdictions is EU or UK: The treaty binds the states that ratify it and reaches organisations through national law (in the EU, largely the AI Act).
  • CoE Convention +20 when sector is Public sector: Public authorities are the treaty's first concern.
  • OECD Principles +10 always: The shared baseline vocabulary adopted by 47 adherents; most other frameworks build on it.
  • AIUC-1 +40 when ai agents is We deploy or build AI agents: The certification standard written for AI agents: an accredited audit of the controls plus technical evals repeated at least every three months.
  • AIUC-1 +20 when ai agents is We deploy or build AI agents, and certificate or external assurance needed is Yes: Where a certificate is needed for an agent, AIUC-1 tests the agent itself; ISO/IEC 42001 certifies the management system around it.
  • One management system, rule 1 ISO/IEC 42001 when certificate or external assurance needed is Yes: Certification needs a certifiable standard.
  • One management system, rule 2 ISO/IEC 42001 when organization size is Large: Several systems and teams benefit from a formal management system, certified or not.
  • One management system, rule 3 ISO/IEC 42001 when jurisdictions is EU or UK: Use its structure even without certifying; it is the international reference in Europe.
  • One management system, rule 4 NIST AI RMF always: The Govern function gives a light management layer without certification cost.
  • One risk method, rule 1 NIST AI RMF when jurisdictions is US federal or Colorado or Texas or California or New York City: Map, Measure and Manage are the method US regulators and Texas law refer to.
  • One risk method, rule 2 Singapore when jurisdictions is Singapore, and certificate or external assurance needed is No: Its human-involvement model and AI Verify testing give a practical, local method.
  • One risk method, rule 3 ISO/IEC 23894 always: International risk guidance that fits inside an ISO/IEC 42001 management system.
  • Certification for agents, rule 1 AIUC-1 when ai agents is We deploy or build AI agents: It certifies the agent itself, with testing; it sits alongside the management system above, not in place of it.

Related guide: Cross-border regimes tab (system page)

A learning aid, not legal advice. Where AI SENTINEL is mentioned, it supports or maps to the dimension; it does not certify anything. Dates are those the official texts state on the date shown.