Aligned with ISO 42001, the NIST AI RMF, the EU AI Act and Australia's AI Ethics Principles
Every one of these frameworks asks for the same evidence: who made a piece of content, whether AI was involved, and a record that cannot be quietly changed. The Trust Identity Protocol® provides that evidence as open infrastructure. This page maps it to each framework, control by control, and says plainly where it stops.
At a glance
What each framework asks for, and how TIP helps
| Framework | What it asks for | How TIP helps | Where TIP stops |
|---|---|---|---|
| ISO/IEC 42001:2023 | An AI management system, with Annex A controls on data provenance, event logs and information for users and interested parties. | Signed, timestamped provenance records and origin labels that serve as evidence for those controls. | Not a management system. Certification is issued to your organisation by an accredited body. |
| NIST AI RMF 1.0 and AI 600-1 | Govern, Map, Measure and Manage AI risk; for generative AI, address information integrity and intellectual property, with content provenance as a primary consideration. | Content provenance and labelling infrastructure with a public audit trail, mapped in whitepaper Appendix E.3. | A voluntary framework with no certification. TIP covers content provenance, not model testing. |
| EU AI Act, Article 50 | Machine-readable marking of AI-generated content (50(2)) and disclosure of deepfakes and AI-generated text on public-interest matters (50(4)), from 2 August 2026. | A signed, machine-readable origin label that survives copying, and a verification link anyone can open. | The duty stays with providers and deployers. Not a conformity assessment for high-risk systems. |
| Australia's AI Ethics Principles and Voluntary AI Safety Standard | Transparency, contestability and accountability; guardrails on provenance, informing users, challenge, supply chains and records. | Origin labels, identifiable verified authors, a dispute process and a public record. | Both are voluntary. TIP does not assess fairness, safety testing or wellbeing. |
The honest version
ISO/IEC 42001:2023
ISO 42001: the Annex A controls TIP supports
ISO/IEC 42001 is the international standard for an AI management system. Its Annex A lists 38 controls. TIP supplies evidence for the controls that concern where content came from, what happened to it, and what people are told about it.
| Annex A control | What TIP provides |
|---|---|
| A.7.5 Data provenance | A Content Trust ID for each piece of content, recording its verified author, time of creation, origin label and content fingerprint. |
| A.6.2.8 AI system recording of event logs | An append-only public record of every signing, label change and retraction, which cannot be edited after the fact. |
| A.8.2 System documentation and information for users | Origin labels (Original Human, AI-Assisted, AI-Generated, Mixed) shown to users wherever the content appears. |
| A.8.3 External reporting | The public AI Trust Registry, where any record can be looked up by anyone. |
| A.8.5 Information for interested parties | A free verification page for every record, with no account needed. |
| A.10.3 Suppliers | A way to check the origin of content you receive from vendors and partners before you rely on it. |
NIST AI RMF 1.0 and NIST AI 600-1
NIST AI RMF: the published crosswalk
The NIST AI Risk Management Framework organises guidance into four functions: Govern, Map, Measure and Manage. The TIP whitepaper publishes this crosswalk in Appendix E.3.
| NIST AI RMF subcategory | TIP architectural support |
|---|---|
| GOVERN 1.1 Legal and regulatory requirements understood and managed | Part IX and Appendix E of the whitepaper |
| GOVERN 1.2 Characteristics of trustworthy AI integrated into organizational policies | TIPCL-1.0 and the AI Trust Council Charter |
| GOVERN 1.4 Risk management process and outcomes established through transparent policies | TIPCL-1.0 published; AI Trust Council transparency report |
| GOVERN 1.6 Mechanisms to inventory AI systems | Public record of Verification Providers and Node Operators |
| MEASURE 3.2 Risk tracking approaches | Trust Score evolution recorded on the public record |
| MANAGE 1.2 Treatment of documented AI risks | Suspension, revocation and dispute pathways |
| MANAGE 2.2 Mechanisms for sustaining the value of deployed AI systems | Apache 2.0 conversion provision; AI Trust Council Charter |
| MANAGE 2.4 Mechanisms for superseding, disengaging or deactivating AI systems | Verification Provider accreditation revocation |
| MANAGE 4.1 Post-deployment monitoring plans | Annual Verification Provider audit; AI Trust Council transparency report |
For generative AI, NIST AI 600-1 (the Generative AI Profile, July 2024) names information integrity and intellectual property among its risks and treats content provenance as a primary consideration. TIP is content provenance and labelling infrastructure, so it speaks to those directly.
EU AI Act, Regulation (EU) 2024/1689
EU AI Act Article 50: machine-readable labels, from 2 August 2026
- Article 50(2), providers. Outputs of generative AI must be marked in a machine-readable format and detectable as artificially generated. A TIP origin label is signed, machine-readable, and survives screenshots, re-encoding and copying.
- Article 50(4), deployers. Deepfakes, and AI-generated text published to inform the public on matters of public interest, must be disclosed. A TIP verification link shows the reader the label and who signed it.
- Evidence. Every label sits on a public, append-only record, so you can show a regulator when content was labelled and by whom.
The full guide is on our EU AI Act page.
Australia
Australia's AI Ethics Principles and the Voluntary AI Safety Standard
| Principle or guardrail | How TIP supports it |
|---|---|
| Principle: Transparency and explainability | People can see whether content was made by a human, with AI help, or by AI, and who signed it. |
| Principle: Contestability | Any record can be disputed through a published process with a bonded jury. |
| Principle: Accountability | Every record is signed by an identifiable, verified author. |
| Principle: Privacy protection and security | Raw biometric data is never stored; signatures are post-quantum (ML-DSA-65, NIST FIPS 204). |
| Guardrail 3: data governance and provenance | A provenance record for every piece of content. |
| Guardrail 6: inform end users about AI-generated content | Origin labels readers can check in one tap. |
| Guardrail 7: processes to challenge use or outcomes | The dispute and jury process. |
| Guardrail 8: transparency across the AI supply chain | Verifiable origin for content passed between organisations. |
| Guardrail 9: records for third-party assessment | A public, append-only record any assessor can check. |
Put it to work
How to use TIP as evidence, in four steps
- Verify your authors. Each person who publishes gets a TIP-ID from an accredited Verification Provider.
- Sign and label content. Through the browser extension, the WordPress plugin, or the API, with one of four origin labels.
- Show the label. Readers and regulators open the verification link; nothing to install.
- Point auditors at the record. The public registry is the evidence, and they can check it themselves.
Questions
What compliance teams ask, answered plainly
Is the Trust Identity Protocol aligned with ISO 42001, the NIST AI RMF, the EU AI Act and Australia's AI Ethics Principles?
Yes. TIP is aligned with ISO/IEC 42001:2023, the NIST AI Risk Management Framework (AI RMF 1.0) and its Generative AI Profile (NIST AI 600-1), Article 50 of the EU AI Act, and Australia's AI Ethics Principles and Voluntary AI Safety Standard. In each case TIP supplies the same evidence those frameworks ask for: who made a piece of content, whether AI was involved, and a tamper-evident record that anyone can verify. TIP is infrastructure that supports your compliance. It does not certify your organisation.
Does using TIP make my organisation ISO/IEC 42001 certified?
No. ISO/IEC 42001 certification is issued to an organisation's AI management system by an accredited certification body, after an audit. TIP supplies evidence for specific Annex A controls, including A.7.5 data provenance, A.6.2.8 recording of event logs, A.8.2 information for users and A.8.5 information for interested parties. That evidence helps an audit. It is not the certification.
How does TIP help with ISO/IEC 42001?
Every piece of content signed with TIP receives a Content Trust ID that records its author, time of creation, origin label (Original Human, AI-Assisted, AI-Generated or Mixed) and a content fingerprint. That gives you provenance for content your AI systems use or produce (A.7.5), an append-only log of signing, label changes and retractions (A.6.2.8), user-facing origin labels (A.8.2), and a free public verification page for interested parties (A.8.5).
How does TIP map to the NIST AI Risk Management Framework?
The TIP whitepaper publishes a crosswalk to the NIST AI RMF in Appendix E.3, covering GOVERN 1.1, 1.2, 1.4 and 1.6, MEASURE 3.2, and MANAGE 1.2, 2.2, 2.4 and 4.1. For generative AI, NIST AI 600-1 names information integrity and intellectual property among its risks and treats content provenance as a primary consideration. TIP is content provenance and labelling infrastructure, so it addresses those directly. It does not replace model testing or evaluation.
Does TIP satisfy EU AI Act Article 50?
TIP gives providers and deployers the infrastructure Article 50 calls for: a machine-readable, signed label on AI-generated content (Article 50(2)) and a clear, verifiable disclosure for deepfakes and AI-generated text on matters of public interest (Article 50(4)). Article 50 applies from 2 August 2026. The legal duty stays with the provider or deployer, and TIP is not a conformity assessment for high-risk AI systems.
How does TIP support Australia's AI Ethics Principles and the Voluntary AI Safety Standard?
Of Australia's eight AI Ethics Principles, TIP directly supports transparency and explainability (people can see when content is AI-generated), contestability (a dispute and jury process for any record), accountability (every record is signed by an identifiable, verified author) and privacy protection (raw biometric data is never stored). Of the Voluntary AI Safety Standard's ten guardrails, it supports guardrail 3 (data provenance), 6 (informing end users about AI-generated content), 7 (challenging outcomes), 8 (supply-chain transparency) and 9 (records for third-party assessment).
What evidence can I show an auditor or regulator?
For each signed piece of content: its Content Trust ID, the verified author, the timestamp, the declared origin label, the content fingerprint and the full history of changes, all on a public, append-only record that the auditor can check themselves, free and without an account. They do not have to trust The AI Lab or you to confirm it.
Is TIP free to use for compliance?
The specification is open under CC BY 4.0 and verification is free for everyone. Signing is free for individuals, nonprofits, education, government, journalism and businesses under USD 100,000 in annual revenue. Larger organisations use a published commercial tier, listed at theailab.org/tip-license. The reference implementation converts irrevocably to the Apache License 2.0 on 1 January 2031.
Who governs the Trust Identity Protocol?
TIP is published by The AI Lab Intelligence Unobscured, Inc. and governed by the AI Trust Council, an independent body with five constituencies holding equal votes: Creators, Institutions, Publishers, Operators and Partners. The public record is kept by independent node operators in multiple countries, so no single company, including The AI Lab, can alter it.
Who is behind this
An open standard, governed in the open
The Trust Identity Protocol® is published by The AI Lab Intelligence Unobscured, Inc. and governed by the AI Trust Council™. The specification is open under CC BY 4.0, and the reference implementation converts to the Apache License 2.0 on 1 January 2031. Read the whitepaper, the licence, or the protocol overview.