AI at Work

    AI Risk Management in 2026: How to Own Your AI Risk (NIST AI RMF, EU AI Act)

    Published August 17, 2026·11 min read

    TL;DR

    The rules just moved: the EU's Digital Omnibus package (Council approval June 29, 2026) deferred standalone high-risk AI obligations from August 2, 2026 to December 2, 2027 — but Article 50 transparency duties still land August 2, 2026. Here is the corrected 2026 compliance calendar plus a runnable AI risk register, quantification rubric, and RACI ownership model built on NIST AI RMF, ISO/IEC 42001, and the OWASP LLM Top 10.

    Summarize with AIChatGPTClaude

    How do you manage AI risk in 2026?

    Managing AI risk in 2026 means running one operating loop across four layers: the EU AI Act tells you what you must do (the law), the NIST AI Risk Management Framework tells you how (the method), ISO/IEC 42001 lets you prove you did it (the certificate), and the OWASP Top 10 for LLM Applications tells you what attackers actually do (the threat list). The single most important 2026 update: the EU's Digital Omnibus simplification package — given final Council approval on June 29, 2026deferred standalone high-risk (Annex III) obligations from August 2, 2026 to December 2, 2027, with high-risk systems embedded in Annex I regulated products pushed to August 2, 2028 (Gibson Dunn / DLA Piper analyses). Most guides on the web still say high-risk hits August 2026. That is now wrong, and it changes your program roadmap.

    This piece gives you the corrected compliance calendar, a concrete AI risk taxonomy, and the operational machinery — a risk register template, a likelihood x impact scoring rubric, and a RACI ownership model — that framework summaries skip.

    Key facts and the data

    • NIST AI RMF 1.0 was released January 26, 2023, built around four core functions — Govern, Map, Measure, Manage (NIST).
    • NIST published the Generative AI Profile (NIST.AI.600-1) on July 26, 2024, extending the RMF to GenAI-specific risks (NIST).
    • The RMF's Measure function evaluates AI against seven trustworthiness characteristics: valid & reliable; safe; secure & resilient; accountable & transparent; explainable & interpretable; privacy-enhanced; and fair with harmful bias managed (NIST AIRC, AI 100-1).
    • The EU AI Act entered into force August 1, 2024 — the first comprehensive AI law (Software Improvement Group).
    • Article 5 prohibitions (unacceptable-risk practices) have been enforceable since February 2, 2025; GPAI model-provider obligations applied from August 2, 2025 (DataGuard timeline).
    • ISO/IEC 42001 — the first global standard for an AI Management System (AIMS) — was published December 2023 (EC-Council).
    • The OWASP Top 10 for LLM Applications (2025) ranks prompt injection (LLM01) #1 for the second consecutive edition (OWASP GenAI Security Project, via Kodem Security).
    • Enterprise reality check: Deloitte's State of AI in the Enterprise 2026 reports 73% cite data privacy/security as their top AI risk, 50% cite legal/IP/regulatory exposure, 46% cite governance oversight — yet only about 21% have mature governance for autonomous AI agents (Deloitte, via secondary summaries).
    ⚠️If your 2026 AI-risk plan assumes high-risk obligations begin August 2, 2026, it is built on a stale date. The Digital Omnibus deferred those to **December 2, 2027**. But do not over-relax: **Article 50 transparency duties still apply on the original August 2, 2026 schedule** (see the corrected calendar below).

    The AI risk taxonomy: what you are actually managing

    "AI risk" is not one thing. A workable program decomposes it into seven categories, each mapping to a specific control layer and framework.

    Risk category What it looks like Primary framework anchor
    Bias / fairness Discriminatory outcomes in hiring, lending, scoring NIST RMF "fair with harmful bias managed"; EU AI Act high-risk duties
    Safety Physical or operational harm from AI-driven decisions NIST RMF "safe"; EU AI Act Annex I product safety
    Security Prompt injection, data poisoning, model theft OWASP LLM Top 10; NIST RMF "secure & resilient"
    Privacy Training-data leakage, sensitive-info disclosure NIST RMF "privacy-enhanced"; OWASP LLM02
    IP / copyright Model output infringing or leaking protected content NIST GenAI Profile (NIST.AI.600-1)
    Hallucination / misinformation Confident false outputs, fabricated citations NIST GenAI Profile; OWASP LLM09
    Compliance / regulatory Missing EU AI Act, sector, or disclosure obligations EU AI Act; ISO/IEC 42001

    The OWASP Top 10 for LLM Applications (2025) is the sharpest tool for the security and privacy columns. Its list — LLM01 Prompt Injection, LLM02 Sensitive Information Disclosure, LLM03 Supply Chain, LLM04 Data & Model Poisoning, LLM05 Improper Output Handling, LLM06 Excessive Agency, LLM07 System Prompt Leakage, LLM08 Vector & Embedding Weaknesses, LLM09 Misinformation, LLM10 Unbounded Consumption — gives you concrete, testable threats to drop straight into a risk register (OWASP GenAI Security Project, via Kodem Security).

    The three frameworks, disentangled

    Searchers keep conflating three different things. They are not competitors — they stack.

    Framework What it is Status Released
    EU AI Act Binding law with four risk tiers and penalties Mandatory (in the EU) In force Aug 1, 2024
    NIST AI RMF 1.0 Voluntary risk-management method (Govern/Map/Measure/Manage) Voluntary Jan 26, 2023
    ISO/IEC 42001 Certifiable AI Management System (AIMS) standard Certifiable Dec 2023
    💡Remember it as one sentence: **EU AI Act = what you MUST do. NIST AI RMF = HOW you do it. ISO/IEC 42001 = PROVE you did it. OWASP LLM Top 10 = what attackers DO.** The law sets obligations, the RMF gives you the operating loop to meet them, the ISO standard gives you an auditable management system, and OWASP feeds your threat model.

    The EU AI Act risk tiers

    The Act classifies every system into one of four tiers, and the tier determines your obligations (JAGGAER).

    Tier Meaning Obligation level
    Unacceptable Prohibited practices (Article 5) Banned outright
    High Systems in sensitive domains (Annex III), e.g. hiring, credit, biometrics Full compliance obligations
    Limited Systems that interact with people or generate content Transparency / disclosure only (Article 50)
    Minimal Everything else (spam filters, most game AI) No specific obligations

    Penalties scale by violation type under Article 99 — the higher of a fixed amount or a percentage of global annual turnover: up to EUR 35M or 7% for prohibited practices, up to EUR 15M or 3% for other obligation breaches, and up to EUR 7.5M or 1% for supplying incorrect information (artificialintelligenceact.eu, Article 99).

    The corrected 2026 EU AI Act compliance calendar

    This is where most ranking guides are now factually stale. Here is the timeline after the Digital Omnibus.

    Date What applies Status
    Aug 1, 2024 EU AI Act enters into force In force (Software Improvement Group)
    Feb 2, 2025 Article 5 prohibitions enforceable Applicable (DataGuard)
    Aug 2, 2025 GPAI model-provider obligations apply Applicable (DataGuard)
    Aug 2, 2026 Article 50 transparency duties apply (disclose AI interaction, label AI-generated content) On original schedule (Secure Privacy)
    Dec 2, 2026 Article 50(2) watermarking/marking of AI-generated output becomes required (deferred from Aug 2, 2026), with four-month grandfathering for systems deployed before Aug 2026 Deferred by Digital Omnibus (ComplianceHub)
    Dec 2, 2027 Standalone high-risk (Annex III) obligations — deferred from Aug 2, 2026 Deferred by Digital Omnibus (Gibson Dunn)
    Aug 2, 2028 High-risk embedded in Annex I regulated products Deferred by Digital Omnibus (Gibson Dunn)

    The takeaway: transparency duties still land in 2026, high-risk obligations do not. The Council gave final approval to the Digital Omnibus package on June 29, 2026, deferring the standalone high-risk deadlines to December 2, 2027 while leaving Article 50 transparency on its original August 2, 2026 date (Gibson Dunn / DLA Piper; Secure Privacy).

    Dexity Intel · free newsletter

    Liking this? Get the next one in your inbox.

    JD-backed career reads, AI market signals, and field-tested tool guides — a few times a month. No fluff, no spam.

    NIST AI RMF as the operating backbone

    The Act tells you what; NIST AI RMF tells you how. Run its four functions as a continuous loop, not a one-time project (NIST).

    • Govern — Establish ownership, policy, and accountability. This is where your RACI and risk-appetite decisions live.
    • Map — Inventory every AI system, its context, and its risk-taxonomy exposure. Map each system to its EU AI Act tier here.
    • Measure — Assess systems against the seven trustworthiness characteristics and quantify likelihood x impact.
    • Manage — Prioritize, treat, monitor, and retire risks; feed results back into Govern.

    For generative systems, layer in the Generative AI Profile (NIST.AI.600-1, July 2024), which extends the RMF to GenAI-specific risks like hallucination, IP leakage, and prompt injection (NIST).

    Building an AI risk register: the machinery no one shows

    A risk register is where the frameworks stop being theory. Every row is one identified risk. Use these columns:

    Column Example entry
    Risk ID AIR-014
    Taxonomy category Bias / fairness
    Affected system Resume-screening model (candidate ranking)
    Threat / OWASP mapping Historical-data bias; LLM04 Data & Model Poisoning
    Likelihood (1–5) 4
    Impact (1–5) 5
    Score (L x I) 20
    Owner Model owner (Talent Data Science)
    Control Fairness testing pre-deploy + quarterly drift audit
    Framework mapping EU AI Act high-risk (Annex III); NIST "fair, bias managed"; ISO/IEC 42001 clause evidence
    Status Open / mitigating

    Quantify and prioritize with a real scoring rubric

    NIST frames risk as a function of likelihood x magnitude of harm. Turn that into a runnable rubric:

    • Likelihood (1–5): 1 = rare / strong controls in place; 3 = plausible under normal use; 5 = expected without intervention.
    • Impact (1–5): 1 = negligible; 3 = material harm to individuals or the business; 5 = severe (rights violation, regulatory breach, safety event).
    • Priority score = Likelihood x Impact (1–25). Triage: 20–25 = critical (treat now), 12–19 = high, 6–11 = medium, 1–5 = monitor.

    Weight impact toward affected individuals, not just the business — regulators and the EU AI Act's high-risk logic care about harm to people, and so should your scoring.

    Who owns AI risk? A RACI and three-lines-of-defense model

    "Everyone owns it" means no one does. Assign it explicitly.

    Role Responsibility
    Board / Chief AI Officer Accountable for AI risk appetite and governance (NIST "Govern")
    Model / product owners Responsible for identifying and treating risks in their systems (first line)
    Risk & compliance Independent challenge, register oversight, EU AI Act tiering (second line)
    Security Owns the OWASP LLM Top 10 threat surface; red-teaming
    Legal Owns regulatory obligations, IP, and disclosure duties
    Internal audit Independent assurance and ISO/IEC 42001 evidence (third line)

    This maps cleanly onto the three lines of defense: model owners (first) do the work, risk/compliance and security (second) set standards and challenge, audit (third) provides independent assurance. The Deloitte 2026 data shows why this matters — 46% flag governance oversight as a top concern, yet only ~21% have mature governance for autonomous agents (Deloitte). The gap is ownership, not awareness.

    Worked example: one hiring model across the whole stack

    Take a resume-screening model and run it through all four layers:

    • EU AI Act (the law): Recruitment/hiring is an Annex III high-risk category — full obligations apply, but on the deferred December 2, 2027 timeline post-Digital Omnibus (Gibson Dunn).
    • NIST AI RMF (the method): Map it as high-risk, Measure it against "fair, with harmful bias managed," Manage it with pre-deploy fairness testing and drift monitoring.
    • ISO/IEC 42001 (the certificate): Document the control, the testing cadence, and the accountable owner as auditable AIMS evidence.
    • OWASP LLM Top 10 (the threats): Guard against LLM04 (data poisoning) in the training set and LLM02 (sensitive info disclosure) in candidate data.

    One risk, four coordinated controls, one register row.

    Frequently asked questions

    What is the difference between the EU AI Act, NIST AI RMF, and ISO/IEC 42001?

    The EU AI Act (in force August 1, 2024) is binding law with four risk tiers and Article 99 penalties. NIST AI RMF 1.0 (January 26, 2023) is a voluntary method built on Govern/Map/Measure/Manage. ISO/IEC 42001 (December 2023) is a certifiable standard for an AI Management System. Law, method, certificate — you use all three together, not one instead of another (EC-Council).

    When do EU AI Act high-risk obligations actually take effect?

    After the Digital Omnibus package (Council approval June 29, 2026), standalone high-risk (Annex III) obligations are deferred to December 2, 2027, and high-risk systems embedded in Annex I regulated products to August 2, 2028 — not the previously cited August 2, 2026 (Gibson Dunn / DLA Piper).

    Do any EU AI Act obligations still apply in 2026?

    Yes. Article 50 transparency duties — disclosing AI interaction and labeling AI-generated content — still apply on August 2, 2026, though the Article 50(2) watermarking/marking obligation for AI-generated output is itself deferred to December 2, 2026, with a four-month grandfathering for systems deployed before August 2026 (ComplianceHub). Article 5 prohibitions (since February 2, 2025) and GPAI obligations (since August 2, 2025) remain in force (DataGuard).

    What are the seven characteristics of trustworthy AI in NIST AI RMF?

    Valid & reliable; safe; secure & resilient; accountable & transparent; explainable & interpretable; privacy-enhanced; and fair with harmful bias managed. The RMF's Measure function evaluates systems against these seven (NIST AIRC, AI 100-1).

    What are the biggest LLM security risks to put in a risk register?

    Start with the OWASP Top 10 for LLM Applications (2025), led by prompt injection (LLM01), followed by sensitive information disclosure, supply chain, data & model poisoning, improper output handling, excessive agency, system prompt leakage, vector & embedding weaknesses, misinformation, and unbounded consumption (OWASP GenAI Security Project, via Kodem Security).

    How do you quantify and prioritize AI risk?

    Score each risk as likelihood x impact on a 1–5 scale (NIST frames risk as likelihood x magnitude of harm), giving a 1–25 priority score. Treat 20–25 as critical, 12–19 as high, and weight impact toward harm to affected individuals, not just business cost.

    Own your AI risk

    Frameworks are easy to summarize and hard to operate. If you want to build the actual machinery — a live risk register, a quantification rubric, and a defensible ownership model mapped to NIST, the EU AI Act, ISO/IEC 42001, and OWASP — start the Own Your AI Risk sprint.

    Sources: NIST (AI RMF 1.0; Generative AI Profile NIST.AI.600-1; AIRC AI 100-1); EC-Council (framework comparison); artificialintelligenceact.eu (Article 99); DataGuard (EU AI Act timeline); Software Improvement Group (EU AI Act summary); Gibson Dunn and DLA Piper (Digital Omnibus analyses); Secure Privacy (Digital Omnibus deadlines); ComplianceHub (Article 50(2) watermarking timing); JAGGAER (EU AI Act risk categories); OWASP GenAI Security Project via Kodem Security (Top 10 for LLM Applications 2025); Deloitte (State of AI in the Enterprise 2026).

    Go from reading to doing · Dexity Sprint

    Own Your AI Risk

    Most teams shipping LLM apps, RAG pipelines, and AI agents have no structured risk assessment behind them — until legal, a regulator, or an incident forces the conversation. This sprint gives security architects, GRC professionals, and engineering managers a repeatable process to identify, score, and document AI risk against NIST AI RMF and EU AI Act requirements.

    4 Weeks
    Live instruction
    3 Projects
    Real deliverables
    30 Seats
    Per cohort, capped
    Nahid Farady, PhD
    Nahid Farady, PhD
    Principal Tech Lead, AI Security & Privacy · Microsoft
    Explore the sprint
    Anmol Gulwani

    Anmol Gulwani

    Dexity

    Connect on LinkedIn
    Questions or suggestions?hello@dexity.com