Copyright i3solutions. All Rights Reserved.
Email aski3@i3solutions.com, Phone 703.652.8966
Privacy Policy | Sitemap
Updated September 26, 2026
Which AI Governance Framework Should a Regulated Enterprise Adopt?
Quick answer. The AI governance framework a regulated enterprise should adopt depends on regulatory exposure, not preference. A US enterprise with no EU exposure typically uses the NIST AI RMF or ISO/IEC 42001, EU market exposure requires the EU AI Act, and federal agencies follow OMB Memorandum M-25-21.
The Four Real Candidates
NIST AI Risk Management Framework
If your enterprise has no EU market exposure and wants a voluntary baseline for managing AI risk, the NIST AI Risk Management Framework (AI RMF 1.0), paired with its Generative AI Profile (NIST-AI-600-1), is the framework built for that use. NIST’s own AI RMF description states the AI RMF “is intended for voluntary use and to improve the ability to incorporate trustworthiness considerations into the design, development, use, and evaluation of AI products, services, and systems.” It applies regardless of industry, and it is the natural starting point for a US organization that wants a recognized risk taxonomy without a certification audit attached.
Live caveat, checked at the time this page was last verified (2026-09-17): NIST’s own AI RMF overview page states that “the AI RMF 1.0 is being revised as part of the White House AI Action Plan.” The 1.0 text and the Generative AI Profile are both still the current published versions as of that check, but an enterprise adopting the AI RMF today is adopting a framework under active revision, not a finished one. Re-check nist.gov before finalizing a governance program built on the 1.0 text.
Where an enterprise’s AI use is generative (Copilot, custom agents, embedded model features), the practical adoption unit is AI RMF 1.0 plus the Generative AI Profile together, not the core framework alone.
ISO/IEC 42001:2023
If your enterprise needs a third-party-audited certificate to show a customer, a regulator, or a board, ISO/IEC 42001 is the only one of these four that is a certifiable management-system standard. ISO describes it as applicable to “organizations of any size involved in developing, providing, or using AI-based products or services,” across industries and sectors, and the standard uses a Plan-Do-Check-Act management-system structure rather than prescribing rules for any specific AI application, as ISO’s own material puts it, “rather than looking at the details of specific AI applications, it provides a practical way of managing AI-related risks and opportunities across an organization.”
That last distinction is the reason ISO/IEC 42001 pairs well with a risk taxonomy like the NIST AI RMF: the ISO standard governs the management system, not the AI system’s specific behavior. i3solutions does not perform ISO/IEC 42001 certification audits and does not guarantee a certification outcome; an enterprise pursuing certification engages an accredited certification body for the audit itself.
EU AI Act (Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744)
Of these four frameworks, the EU AI Act is the only one that is binding law, and only for enterprises with EU market exposure. The Regulation states its purpose as improving “the functioning of the internal market and promot[ing] the uptake of human-centric and trustworthy artificial intelligence,” while protecting health, safety, and fundamental rights.
Its reach is broader than a US headquarters address might suggest. The Act applies to “providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country,” and it extends to providers and deployers located in a third country “where the output produced by the AI system is used in the Union.” A US-only enterprise with no EU office can still fall under the Act if its AI’s output reaches people in the EU.
Adopting the EU AI Act is not a single yes-or-no switch. The Regulation classifies AI systems into risk tiers. An AI system that is a product, or a safety component of a product, covered by the EU legislation listed in Annex I “shall be considered to be high-risk where both of” two conditions “are fulfilled,” and the uses listed in Annex III are high-risk as well, unless they fall under the Regulation’s own derogation for systems that do not pose a significant risk of harm. Obligations scale with that classification rather than applying uniformly to every AI use, and the high-risk rules have their own start dates: as amended by Regulation (EU) 2026/1744, they apply from 2 December 2027 for Annex III uses and from 2 August 2028 for AI tied to Annex I products.
OMB Memorandum M-25-21 (federal agencies)
If your organization is a federal agency, OMB Memorandum M-25-21 (April 2025), “Accelerating Federal Use of AI through Innovation, Governance, and Public Trust,” sets the current federal AI governance baseline. M-25-21 rescinds and replaces the earlier M-24-10 (March 2024); any reference to “the OMB AI governance memo” that still points to M-24-10 is citing a superseded document.
M-25-21 directs agencies to implement minimum risk management practices for AI that could have significant impacts when deployed (“high-impact AI”), with practices proportionate to the anticipated risk from its intended use. The memorandum’s own scope line matters for a private regulated enterprise reading this page: M-25-21 is directed to the heads of Executive Branch departments and agencies, including independent regulatory agencies, and it does not bind a private company directly. A government contractor’s obligations under M-25-21 arrive through the contracting agency’s own flow-down clauses, never from the memorandum itself.
The Adoption Decision
| Your situation | Framework the criteria point to | Why |
|---|---|---|
| No EU market exposure, want a voluntary internal baseline | NIST AI RMF (+ Generative AI Profile) | Voluntary use, applicable to organizations in all sectors |
| Need a third-party-audited certificate to show a customer or regulator | ISO/IEC 42001 | The only certifiable management-system standard of the four |
| Place AI on the EU market, or its output reaches people in the EU | EU AI Act compliance program | Mandatory, not optional, once the Act’s scope conditions are met and the relevant provisions apply |
| Federal agency, or contractor under a flow-down clause | OMB M-25-21 minimum risk management practices | Current federal baseline; binds agencies, reaches contractors only by contract |
When two of these conditions are both true (for example, an enterprise that places AI on the EU market and also holds a federal contract), the mandatory frameworks set the floor and the voluntary ones fill the rest: apply the EU AI Act and any contract-driven OMB M-25-21 flow-down requirements first, because those are not optional, and then use NIST AI RMF and ISO/IEC 42001 as the operating model built around that floor rather than as a second, competing set of rules.
Is Your Copilot or Azure OpenAI Use High-Impact AI Under OMB M-25-21?
As of September 2026, OMB M-25-21 classifies the use case, not the product. Under the memorandum’s definition, a Microsoft 365 Copilot or Azure OpenAI deployment is high-impact AI only where its output “serves as a principal basis for decisions or actions with legal, material, binding, or significant effect on” one of six listed areas. Whether a given use meets that test is decided by the agency’s own process under its Chief AI Officer (CAIO), not by IT or a vendor.
Section 5 gives the definition in full: “High-Impact AI: AI with an output that serves as a principal basis for decisions or actions with legal, material, binding, or significant effect on: 1. an individual or entity’s civil rights, civil liberties, or privacy; or 2. an individual or entity’s access to education, housing, insurance, credit, employment, and other programs; 3. an individual or entity’s access to critical government resources or services; 4. human health and safety; 5. critical infrastructure or public safety; or 6. strategic assets or resources, including high-value property and information marked as sensitive or classified by the Federal Government.”
Three lines matter most for a Microsoft deployment. The requirements “apply to system functionality that implements or is reliant on AI, rather than to the entirety of an information system that incorporates AI.” So the question is asked of the Copilot feature or the Azure OpenAI call, not the whole tenant. Footnote 27 adds that “AI may be integrated in decision or activity pipelines in high-impact categories without meeting the definition of high-impact because the AI’s output does not actually “serve as a principal basis for” the relevant type of agency action or decision”, so what counts is the role the output plays in the decision. And “A high-impact determination is possible whether there is or is not human oversight for the decision or action.”
Section 3 gives the CAIO the job of “establishing a process for determining and documenting AI use cases as high-impact”. For the categories in Section 6, AI that serves as a principal basis for an agency decision or action “is presumed to be high-impact”, and an official who concludes otherwise “must submit written documentation to notify the CAIO when making a determination that a particular AI use case does not actually meet the definition of high-impact.” And “CAIOs may revisit any determinations made within their agency … at any time.” This page makes no determination for any use case.
Where a use is high-impact, Section 4(b) sets seven minimum practices:
- Conduct Pre-Deployment Testing
- Complete AI Impact Assessment
- Conduct Ongoing Monitoring for Performance and Potential Adverse Impacts
- Ensure Adequate Human Training and Assessment
- Provide Additional Human Oversight, Intervention, and Accountability
- Offer Consistent Remedies or Appeals
- Consult and Incorporate Feedback from End Users and the Public
Several of those practices call for evidence that IT produces. Where an agency does not have access to the underlying AI source code, models, or data, the testing practice calls for “alternative test methodologies, such as querying the AI service and observing the outputs or providing evaluation data to the vendor and obtaining results.” The impact assessment comes “before deploying any high-impact AI use case” and includes “the quality and appropriateness of the relevant data and model capability”, “results of independent review”, and “risk acceptance, supported by a signature from the individual accepting the risk.” Monitoring “must be designed to detect unforeseen circumstances, changes to an AI system after deployment, or changes to the context of use or associated data.” And “When practicable and consistent with existing agency practices, agencies must ensure that the AI functionality has an appropriate fail-safe that minimizes the risk of significant harm.”
On timing: “Within 365 days of the issuance of this memorandum, agencies must document implementation of the minimum practices in Section 4(b) of this memorandum for high-impact uses of AI”; 365 days after the April 3, 2025 issuance falls in April 2026. “If a particular high-impact use case is not compliant with the minimum practices then the agency must safely discontinue use of the AI functionality.” A pilot is exempt only where, among other conditions, “the agency CAIO has certified that the pilot may go forward”, and a waiver requires the CAIO to act “after making a written determination”.
Two kinds of use start somewhere else: “Sections 4(a) through (b) of this memorandum do not apply to elements of the Intelligence Community”, and the memorandum “does not cover AI when it is being used as a component of a National Security System.”
i3solutions is an SBA certified small business providing technical and professional services to US Federal Agencies, the DoD and the private sector. i3solutions implements whatever Microsoft technology a customer needs; the control-mapping work is described under What i3solutions Does at This Decision Point.
How This Fits the Operating Model You Already Run (or Are Building)
Choosing a framework answers which external standard your organization is adopting; it does not by itself tell you who inside your organization owns which governance decision day to day. Once a framework is chosen, Enterprise AI Governance for Microsoft Environments is the model that carries it out inside a Microsoft 365, Azure, and Power Platform estate; the domains, ownership options, and sequencing it describes are not repeated here.
What This Page Does Not Cover
This page stops at the adoption decision: which framework, and by what criteria. If your organization has already deployed Microsoft 365 Copilot and needs ongoing governance and support after that deployment, that is a different, later question, covered at Hire a Firm for Microsoft 365 Copilot Governance After Deployment.
What i3solutions Does at This Decision Point
Once a regulated enterprise has picked a framework, the work that follows is mapping that framework’s controls onto the Microsoft estate the AI actually runs in: Purview, Entra ID, Compliance Manager, and the platform’s own AI governance surfaces. i3solutions has been a Microsoft partner since 1997 and has delivered 600+ implementations across aerospace and defense, financial services, and health sciences.
i3solutions runs migrations against named control families across CMMC, HIPAA, SOC 2, and NIST 800-171, producing artifacts auditors can review. NIST 800-171 (which protects controlled unclassified information) is a different NIST publication from the NIST AI RMF discussed above, and this page does not claim AI-RMF-specific delivery experience from that control-family work. i3solutions has implemented governance frameworks for organizations managing 200+ integrations across Microsoft ecosystems. That is evidence of general governance-framework delivery at scale rather than an AI-framework-specific outcome. i3solutions does not perform ISO/IEC 42001 certification audits and does not offer a certification-outcome guarantee.
When This Framework Choice Is Not Your Next Move
If your organization has no AI system in production yet, or nobody has been named as the owner of AI governance decisions, a framework comparison is premature. The more useful first step is naming an owner and an inventory of where AI is already in use, informal or not, before comparing frameworks that assume a program already exists to govern.
Frequently Asked Questions
Is ISO/IEC 42001 mandatory?
No. ISO/IEC 42001 is voluntary; an organization chooses to pursue it, typically to obtain a third-party-audited certificate it can show to a customer, a regulator, or a board.
Does the EU AI Act apply to a US-only enterprise?
Only if that enterprise places AI on the EU market, deploys it from an EU establishment, or the AI’s output is used in the Union. A US company with none of those three conditions is outside the Act’s scope; a US company whose AI output reaches EU users is inside it, with no EU office required.
Is the NIST AI RMF being replaced?
It is under active revision as part of the White House AI Action Plan as of this page’s last check (2026-09-17); the published AI RMF text and the Generative AI Profile are both still the current versions as of that date. Re-check nist.gov for the current status before adopting it as a fixed baseline, since a framework under revision can change.
Do federal contractors have to follow OMB M-25-21 directly?
No. The memorandum is directed to Executive Branch departments and agencies, including independent regulatory agencies. A contractor’s obligations arrive through the contracting agency’s own flow-down clauses, never directly from the memorandum.
Is Microsoft 365 Copilot automatically high-impact AI under OMB M-25-21?
No. M-25-21 classifies the use case, not the product: a use is high-impact where its output serves as a principal basis for decisions or actions with legal, material, binding, or significant effect on the areas the memorandum lists, such as civil rights, access to critical government services, or human health and safety.
Can an enterprise adopt more than one framework?
Yes. Pairing a certifiable management system (ISO/IEC 42001) with a risk taxonomy (NIST AI RMF) is common market practice, since the two work at different levels: one governs the management system, and the other assesses AI-specific risk. This is stated as general practice, not as an i3solutions client outcome.
What does i3solutions do once a framework is chosen?
i3solutions maps the chosen framework’s controls onto the Microsoft estate the AI runs in (identity, data boundaries, and monitoring inside Purview, Entra ID, and Compliance Manager) as an architecture and control-mapping engagement. i3solutions does not perform certification audits for ISO/IEC 42001 or guarantee a certification outcome.
