Open almost any guide to running AI governance on both sides of the Atlantic and the first artifact you meet is a crosswalk: a table with the NIST Risk Management Framework’s four functions down one side and the EU AI Act’s articles down the other, each cell claiming a correspondence. The pitch is always the same — maintain one control library, collect evidence once, satisfy several auditors. For most of the table it holds. The risk-management language lines up, the documentation duties overlap, the same test results travel between columns. That convergence is real, and it is the reason the table is worth keeping. It is also the reason the few rows where it breaks are so easy to walk past — and those rows, this reading argues, are where the actual comparison lives.
What the table actually maps
Begin with the part that works, because it works well enough to be persuasive.
The NIST AI RMF — the U.S. National Institute of Standards and Technology’s voluntary risk framework — is organised into four functions: GOVERN, MAP, MEASURE, and MANAGE. GOVERN sets policy and accountability; MAP fixes context and intended use; MEASURE tests performance, bias, and uncertainty; MANAGE acts on what the other three surface. Set those beside the EU AI Act’s obligations for high-risk systems and the parallels are immediate.
Article 9’s continuous risk management reads like MAP and MANAGE in legal dress. Article 10 on data governance maps to MEASURE’s bias and representativeness work. Article 11’s technical documentation is the paper trail GOVERN and MAP already generate.
So the same artifacts recur on both sides. An evaluation report that closes a MEASURE subcategory is also the evidence an Article 10 file wants. A monitoring log produced under MANAGE is most of what Article 15’s post-market duties ask for. This is the honest core of the crosswalk: a U.S. team that already runs the RMF has, without trying, drafted much of a European technical file.
One caution about provenance. NIST’s own crosswalk — the one in the framework’s appendix — maps the proposed 2021 Act, and does so at the level of broad trustworthiness characteristics, not the binding 2024 articles. The granular, article-by-article maps people actually use are mostly built by vendors selling the “one program, three audits” promise. Useful, but not neutral, and not law.
Where the columns run out
Keep reading down the table. A few rows in, the right-hand column starts to thin, then goes blank.
The breakage is not random. It clusters at exactly the obligations that turn documentation into a duty owed to someone. The clearest is Article 43 — conformity assessment, the pre-market check by a notified third party that a high-risk system meets the Act’s requirements before it ships. There is no NIST cell for it, because there is nothing to map: the RMF is self-attested. You assert your own alignment; no independent body signs off, and nothing is withheld from the market if you do not.
The same blank appears below it. CE marking, enforced transparency toward the person a decision affects (Article 13), human oversight that must be built in rather than asserted (Article 14), penalties that reach up to seven percent of worldwide turnover — none has a NIST equivalent. The crosswalk maps the evidence-production machinery faithfully and then stops at the machinery of enforcement, because the second machine was never built on the American side.
This is the hinge, so it is worth stating slowly. The crosswalk is a map of evidence. It is not a map of standing. It can show that a NIST file and a European file ask for the same test, the same log, the same documented decision. It cannot show that the affected person can see any of it, contest it, or force a response. The RMF never promised that, and a table can only align what both sides contain.
A crosswalk aligns the evidence two regimes collect. It cannot align who is allowed to argue with it.— the thesis the crosswalk implies
Even the Act’s own escape hatch confirms the asymmetry. Article 40 lets harmonised European standards presumptively satisfy parts of the Act — but the NIST AI RMF is not a harmonised standard. Alignment with it buys familiarity and a head start on paperwork. It does not buy a presumption of conformity.
Why this is a claim, not a table
The missing rows are not a gap to be filled by a better spreadsheet. They are the finding.
Read the crosswalk literally and it invites a tidy conclusion: get to NIST alignment and you are most of the way to European compliance. The blank rows say otherwise. A U.S. federal agency can run the RMF cleanly: publish its evaluations, log its monitoring, assign its owners. It can still sit nowhere near substantive conformity with the Act. The obligations it cannot satisfy are precisely the ones that give an outside person a foothold.
NIST already produces the demographic-bias metrics a European file would want; the United States has had face-recognition error rates broken out by race since 2019. Producing the number was never the hard part. Being bound to act on it, in a way the affected person can invoke, is.
The compliance-engineering literature names the same problem from the formal side. Two regimes can require overlapping evidence and still impose non-equivalent duties. A static table that marks each cell “covered” mistakes overlap for sufficiency. The point is not that crosswalks are wrong. It is that they answer a narrower question than they appear to — what evidence transfers — and leave the load-bearing one untouched: what is owed, and to whom.
PATTERN is where that abstraction becomes a person waiting on a release date, which is why N° 32 spent a whole reading there. The crosswalk is the frame around it. Walk the table top to bottom and it quietly teaches its own thesis: documented compliance and contestable compliance are different things, and the distance between them is the column the American side does not have.