Skip to main content
We have begun the founding chapter. Be among the first
+1 (888) 885-5991|[email protected]
The AI LabFor compliance, risk and trust teamsControl by control

Aligned with ISO 42001, the NIST AI RMF, the EU AI Act and Australia's AI Ethics Principles

Every one of these frameworks asks for the same evidence: who made a piece of content, whether AI was involved, and a record that cannot be quietly changed. The Trust Identity Protocol® provides that evidence as open infrastructure. This page maps it to each framework, control by control, and says plainly where it stops.

At a glance

What each framework asks for, and how TIP helps

FrameworkWhat it asks forHow TIP helpsWhere TIP stops
ISO/IEC 42001:2023An AI management system, with Annex A controls on data provenance, event logs and information for users and interested parties.Signed, timestamped provenance records and origin labels that serve as evidence for those controls.Not a management system. Certification is issued to your organisation by an accredited body.
NIST AI RMF 1.0 and AI 600-1Govern, Map, Measure and Manage AI risk; for generative AI, address information integrity and intellectual property, with content provenance as a primary consideration.Content provenance and labelling infrastructure with a public audit trail, mapped in whitepaper Appendix E.3.A voluntary framework with no certification. TIP covers content provenance, not model testing.
EU AI Act, Article 50Machine-readable marking of AI-generated content (50(2)) and disclosure of deepfakes and AI-generated text on public-interest matters (50(4)), from 2 August 2026.A signed, machine-readable origin label that survives copying, and a verification link anyone can open.The duty stays with providers and deployers. Not a conformity assessment for high-risk systems.
Australia's AI Ethics Principles and Voluntary AI Safety StandardTransparency, contestability and accountability; guardrails on provenance, informing users, challenge, supply chains and records.Origin labels, identifiable verified authors, a dispute process and a public record.Both are voluntary. TIP does not assess fairness, safety testing or wellbeing.

The honest version

TIP does not make you compliant on its own, and nothing does. What it does is give you the provenance, labelling and audit-trail evidence that each framework asks for, in a form an auditor can verify without trusting you or us.

ISO/IEC 42001:2023

ISO 42001: the Annex A controls TIP supports

ISO/IEC 42001 is the international standard for an AI management system. Its Annex A lists 38 controls. TIP supplies evidence for the controls that concern where content came from, what happened to it, and what people are told about it.

Annex A controlWhat TIP provides
A.7.5 Data provenanceA Content Trust ID for each piece of content, recording its verified author, time of creation, origin label and content fingerprint.
A.6.2.8 AI system recording of event logsAn append-only public record of every signing, label change and retraction, which cannot be edited after the fact.
A.8.2 System documentation and information for usersOrigin labels (Original Human, AI-Assisted, AI-Generated, Mixed) shown to users wherever the content appears.
A.8.3 External reportingThe public AI Trust Registry, where any record can be looked up by anyone.
A.8.5 Information for interested partiesA free verification page for every record, with no account needed.
A.10.3 SuppliersA way to check the origin of content you receive from vendors and partners before you rely on it.

NIST AI RMF 1.0 and NIST AI 600-1

NIST AI RMF: the published crosswalk

The NIST AI Risk Management Framework organises guidance into four functions: Govern, Map, Measure and Manage. The TIP whitepaper publishes this crosswalk in Appendix E.3.

NIST AI RMF subcategoryTIP architectural support
GOVERN 1.1 Legal and regulatory requirements understood and managedPart IX and Appendix E of the whitepaper
GOVERN 1.2 Characteristics of trustworthy AI integrated into organizational policiesTIPCL-1.0 and the AI Trust Council Charter
GOVERN 1.4 Risk management process and outcomes established through transparent policiesTIPCL-1.0 published; AI Trust Council transparency report
GOVERN 1.6 Mechanisms to inventory AI systemsPublic record of Verification Providers and Node Operators
MEASURE 3.2 Risk tracking approachesTrust Score evolution recorded on the public record
MANAGE 1.2 Treatment of documented AI risksSuspension, revocation and dispute pathways
MANAGE 2.2 Mechanisms for sustaining the value of deployed AI systemsApache 2.0 conversion provision; AI Trust Council Charter
MANAGE 2.4 Mechanisms for superseding, disengaging or deactivating AI systemsVerification Provider accreditation revocation
MANAGE 4.1 Post-deployment monitoring plansAnnual Verification Provider audit; AI Trust Council transparency report

For generative AI, NIST AI 600-1 (the Generative AI Profile, July 2024) names information integrity and intellectual property among its risks and treats content provenance as a primary consideration. TIP is content provenance and labelling infrastructure, so it speaks to those directly.

EU AI Act, Regulation (EU) 2024/1689

EU AI Act Article 50: machine-readable labels, from 2 August 2026

  1. Article 50(2), providers. Outputs of generative AI must be marked in a machine-readable format and detectable as artificially generated. A TIP origin label is signed, machine-readable, and survives screenshots, re-encoding and copying.
  2. Article 50(4), deployers. Deepfakes, and AI-generated text published to inform the public on matters of public interest, must be disclosed. A TIP verification link shows the reader the label and who signed it.
  3. Evidence. Every label sits on a public, append-only record, so you can show a regulator when content was labelled and by whom.

The full guide is on our EU AI Act page.

Australia

Australia's AI Ethics Principles and the Voluntary AI Safety Standard

Principle or guardrailHow TIP supports it
Principle: Transparency and explainabilityPeople can see whether content was made by a human, with AI help, or by AI, and who signed it.
Principle: ContestabilityAny record can be disputed through a published process with a bonded jury.
Principle: AccountabilityEvery record is signed by an identifiable, verified author.
Principle: Privacy protection and securityRaw biometric data is never stored; signatures are post-quantum (ML-DSA-65, NIST FIPS 204).
Guardrail 3: data governance and provenanceA provenance record for every piece of content.
Guardrail 6: inform end users about AI-generated contentOrigin labels readers can check in one tap.
Guardrail 7: processes to challenge use or outcomesThe dispute and jury process.
Guardrail 8: transparency across the AI supply chainVerifiable origin for content passed between organisations.
Guardrail 9: records for third-party assessmentA public, append-only record any assessor can check.

Put it to work

How to use TIP as evidence, in four steps

  1. Verify your authors. Each person who publishes gets a TIP-ID from an accredited Verification Provider.
  2. Sign and label content. Through the browser extension, the WordPress plugin, or the API, with one of four origin labels.
  3. Show the label. Readers and regulators open the verification link; nothing to install.
  4. Point auditors at the record. The public registry is the evidence, and they can check it themselves.
Talk to us about your framework Read the whitepaper crosswalk

Questions

What compliance teams ask, answered plainly

Is the Trust Identity Protocol aligned with ISO 42001, the NIST AI RMF, the EU AI Act and Australia's AI Ethics Principles?

Yes. TIP is aligned with ISO/IEC 42001:2023, the NIST AI Risk Management Framework (AI RMF 1.0) and its Generative AI Profile (NIST AI 600-1), Article 50 of the EU AI Act, and Australia's AI Ethics Principles and Voluntary AI Safety Standard. In each case TIP supplies the same evidence those frameworks ask for: who made a piece of content, whether AI was involved, and a tamper-evident record that anyone can verify. TIP is infrastructure that supports your compliance. It does not certify your organisation.

Does using TIP make my organisation ISO/IEC 42001 certified?

No. ISO/IEC 42001 certification is issued to an organisation's AI management system by an accredited certification body, after an audit. TIP supplies evidence for specific Annex A controls, including A.7.5 data provenance, A.6.2.8 recording of event logs, A.8.2 information for users and A.8.5 information for interested parties. That evidence helps an audit. It is not the certification.

How does TIP help with ISO/IEC 42001?

Every piece of content signed with TIP receives a Content Trust ID that records its author, time of creation, origin label (Original Human, AI-Assisted, AI-Generated or Mixed) and a content fingerprint. That gives you provenance for content your AI systems use or produce (A.7.5), an append-only log of signing, label changes and retractions (A.6.2.8), user-facing origin labels (A.8.2), and a free public verification page for interested parties (A.8.5).

How does TIP map to the NIST AI Risk Management Framework?

The TIP whitepaper publishes a crosswalk to the NIST AI RMF in Appendix E.3, covering GOVERN 1.1, 1.2, 1.4 and 1.6, MEASURE 3.2, and MANAGE 1.2, 2.2, 2.4 and 4.1. For generative AI, NIST AI 600-1 names information integrity and intellectual property among its risks and treats content provenance as a primary consideration. TIP is content provenance and labelling infrastructure, so it addresses those directly. It does not replace model testing or evaluation.

Does TIP satisfy EU AI Act Article 50?

TIP gives providers and deployers the infrastructure Article 50 calls for: a machine-readable, signed label on AI-generated content (Article 50(2)) and a clear, verifiable disclosure for deepfakes and AI-generated text on matters of public interest (Article 50(4)). Article 50 applies from 2 August 2026. The legal duty stays with the provider or deployer, and TIP is not a conformity assessment for high-risk AI systems.

How does TIP support Australia's AI Ethics Principles and the Voluntary AI Safety Standard?

Of Australia's eight AI Ethics Principles, TIP directly supports transparency and explainability (people can see when content is AI-generated), contestability (a dispute and jury process for any record), accountability (every record is signed by an identifiable, verified author) and privacy protection (raw biometric data is never stored). Of the Voluntary AI Safety Standard's ten guardrails, it supports guardrail 3 (data provenance), 6 (informing end users about AI-generated content), 7 (challenging outcomes), 8 (supply-chain transparency) and 9 (records for third-party assessment).

What evidence can I show an auditor or regulator?

For each signed piece of content: its Content Trust ID, the verified author, the timestamp, the declared origin label, the content fingerprint and the full history of changes, all on a public, append-only record that the auditor can check themselves, free and without an account. They do not have to trust The AI Lab or you to confirm it.

Is TIP free to use for compliance?

The specification is open under CC BY 4.0 and verification is free for everyone. Signing is free for individuals, nonprofits, education, government, journalism and businesses under USD 100,000 in annual revenue. Larger organisations use a published commercial tier, listed at theailab.org/tip-license. The reference implementation converts irrevocably to the Apache License 2.0 on 1 January 2031.

Who governs the Trust Identity Protocol?

TIP is published by The AI Lab Intelligence Unobscured, Inc. and governed by the AI Trust Council, an independent body with five constituencies holding equal votes: Creators, Institutions, Publishers, Operators and Partners. The public record is kept by independent node operators in multiple countries, so no single company, including The AI Lab, can alter it.

Who is behind this

An open standard, governed in the open

The Trust Identity Protocol® is published by The AI Lab Intelligence Unobscured, Inc. and governed by the AI Trust Council. The specification is open under CC BY 4.0, and the reference implementation converts to the Apache License 2.0 on 1 January 2031. Read the whitepaper, the licence, or the protocol overview.