What are the three frameworks?
ISO/IEC 42001 sets requirements for an AI management system, in the same management system family as ISO 27001, so teams with an ISMS often find the structure familiar. The EU AI Act is a regulation that places obligations on providers and deployers of AI systems according to risk. The NIST AI Risk Management Framework is voluntary guidance for identifying and managing AI risks.
Which platforms name them?
On the pages we reviewed: ISO 42001 is named by Scytale, Vanta, Drata, Comp AI and Delve. The EU AI Act is named by Scytale (on its AI agent page) and Vanta. NIST AI RMF is named by Vanta and Drata. Sprinto lists AI governance as a product and states 200+ frameworks but did not name individual frameworks on the pages we read. Scytale also lists ISO 42001 among its own certifications.
Why do AI frameworks arrive as framework three?
A company that ships AI features often starts with SOC 2 or ISO 27001 for security, then gets asked by enterprise buyers how it governs its models. ISO 42001 and EU AI Act questions then appear in security questionnaires before anyone plans an audit. Cross-mapping matters here because many AI governance controls (access, change management, supplier management) overlap with security controls you already have.
What should you ask?
Ask whether the AI framework is pre-built or a custom framework, whether its controls map to your existing ISMS, and whether the vendor's own AI features are covered by its own governance, for example by an ISO 42001 certificate of its own.
How do AI frameworks change who does the work?
AI governance adds tasks that are hard to automate: deciding which systems count as AI, classifying their risk, documenting training data sources and model changes, and assigning human oversight. Evidence for these is often written documentation rather than a configuration export, so it leans on policy drafting and human review more than on integrations. That makes the agents vs humans split more important for framework three than for framework one. Ask whether the vendor's agents can draft AI impact assessments or model documentation, and whether a human expert reviews them before an auditor sees them.