This is commentary by a product-design practitioner, not a lawyer. Dates and obligations move — the EU high-risk deadline moved twice in the twelve months before this was written. Verify anything here against the current text and your own counsel before relying on it.
1. What the frameworks currently require
The EU AI Act
Regulation (EU) 2024/1689 · binding law · risk-tiered
The one with teeth. Obligations scale with the risk tier a system falls into, and the timetable has been amended.
2 August 2026 — live now. The Article 50 transparency duties apply: telling people they are interacting with an AI system, marking synthetic content as machine-generated, and identifying deepfakes. These were not postponed.
2 December 2026. End of the four-month grace period reported for the Article 50(2) watermarking duty on systems already on the market.
2 December 2027 / 2 August 2028. The substantive high-risk obligations, deferred by the Digital Omnibus agreement — standalone Annex III systems to December 2027, AI embedded in regulated products under Annex I to August 2028.
The deferral is the part most commentary got wrong in the first weeks: high-risk duties moved, transparency did not. If you sell or deploy a general-purpose assistant in the EU, the live date already passed.
NIST AI Risk Management Framework 1.0
Voluntary · United States · process-shaped
Four functions: GOVERN across the organisation, then MAP, MEASURE and MANAGE as a loop you run on each system. It tells you to establish measurement rather than telling you what to measure, which is deliberate and is also where the room is.
The Generative AI Profile (NIST AI 600-1, July 2024) names twelve risk categories for generative systems. Two sit closest to this page’s subject: human-AI configuration — which covers over-reliance and automation bias — and information integrity.
ISO/IEC 42001:2023
Certifiable management-system standard · published December 2023
The first certifiable AI management system standard, structured like ISO 27001: context, leadership, planning, support, operation, evaluation, improvement — with an AI-specific control set in Annex A, reported as 38 controls across nine areas, selected through a Statement of Applicability.
It governs how you manage AI. It does not tell you whether a particular product is well designed, and it does not claim to.
2. The question none of them asks
All three ask whether a system is risky, lawful, documented and managed.
None asks whether it is designed so that a user’s reliance on it is earned rather than extracted.
Those are different questions, and the gap between them is not academic. A product can be fully compliant on every one of these and still be built to hold attention rather than to deserve it:
- Article 50 requires you to tell someone they are talking to an AI. It does not require you to tell them what that AI is optimised for, or that a third party paid to influence what it recommends.
- NIST tells you to establish measurement. It does not tell you that session time is an anti-metric for an assistant, or that a rising engagement number can be a trust drawdown rather than a win.
- ISO 42001 asks whether you have a process. A well-run process can produce, document, review and certify a product whose growth depends on interrupting people.
This is not a criticism of the frameworks. They are doing their job. Their job is not product design, and the failure this instrument describes is a design failure that leaves no compliance trace.
3. Where a conferral review genuinely connects
Not as a control, and not as evidence of compliance. As an input that produces something these processes ask you to have and do not tell you how to make.
| Framework element | What it asks for | What a conferral review can feed into it |
|---|---|---|
| NIST MEASURE | Evaluations, monitoring, thresholds and owners — without prescribing the measures | A repeatable ten-criterion score with an evidence tag on every item, re-runnable quarterly, that produces a trend rather than an assertion |
| NIST — human-AI configuration (AI 600-1) | Risks of over-reliance and automation bias | The calibration and failure-conduct criteria address exactly this: does the product push back when the user is wrong, and what happens to reliance when it turns out to have been |
| ISO 42001 impact assessment | Assessment of consequences for affected parties | An outside-in reading of what the product does to the people relying on it, with the evidence basis of each judgement stated |
| ISO 42001 — information for interested parties | What you tell people about the system | The disclosure and provenance criteria test whether that information arrives where the decision is made rather than in a policy document |
| EU AI Act Article 50 | Disclosure that content or interaction is AI-generated | Nothing, for compliance. But a product that satisfies Article 50 and still hides commercial influence has met the law and failed the user — and that is visible on this rubric and nowhere in the file |
| Vendor due diligence | Varies; usually security, data and legal | The buy-side scorecard asks what the product needs from your people in order to succeed, and how much of what you were told is in the contract |
4. What this is not, stated plainly
It is not a compliance product
Running the Conferral Design Scorecard does not satisfy any obligation, does not map to any control as evidence of conformity, does not reduce a risk tier, and will not help in an audit. Anyone selling you a design rubric as a compliance shortcut is selling you something that does not exist.
It is also not a security review, a model evaluation, a safety audit, a bias assessment or a DPIA. It does not require model internals, because the failures it describes do not live there.
The reason to be this blunt is self-interested as well as honest. A governance lead who arrives expecting a compliance tool leaves disappointed and correct. One who arrives with a working governance process and a nagging sense that it does not capture whether the product is good for the people using it has found the right page.
On whether the rubric is reliable: a study of whether independent raters produce the same scores from the same evidence is pre-registered here, with the threshold fixed in advance and a commitment to publish the result either way. Until it reports, treat any score as one informed reading.
5. If you want to use it
Everything is published and free. The rubric — ten criteria, the 0/2/4 anchors, the per-criterion fixes, five red flags that override the arithmetic, four bands — is at the Conferral Design Scorecard, and it will not be put behind a door. The methodology it comes from is at Conferral by Design; the measures are defined at the Conferral Metrics Standard.
Three routes, depending on where you sit:
- You build the product. Run the 45-minute review with your own team, then score it properly.
- You are buying one. Use the vendor scorecard before signature, while you still have leverage.
- You want it done from outside. That is the Conferral Design Review — the same rubric applied by someone who is not on the team, which is the half a self-assessment structurally cannot supply. The first three are $2,500, in exchange for permission to publish the review.
Start with the free instrument, not the conversation. If it tells you what you needed, the review is unnecessary — which is also the point.
Score a product →Sources
Regulatory position verified 31 August 2026. This page cites secondary legal commentary rather than primary legislative text; where a date matters to a decision you are making, check the current official source.
- Gibson Dunn, on the Digital Omnibus agreement, the postponed high-risk deadlines and what was not postponed — gibsondunn.com
- Holland & Knight, on the August 2026 compliance position for US companies — hklaw.com
- NIST, AI Risk Management Framework — nist.gov
- NIST AI 600-1, Generative AI Profile (July 2024), for the twelve risk categories including human-AI configuration
- ISO/IEC 42001:2023, for the management-system structure and the Annex A control set
Reported dates for the Digital Omnibus differ between sources — the trilogue agreement and Council confirmation are cited above from Gibson Dunn; other reporting gives later dates for formal adoption steps. The substantive point that Article 50 was not deferred is consistent across the sources checked.
Conferral Theory and the Conferral Design Scorecard are the work of Clint Miller. This page is commentary and is not legal advice, a compliance assessment, or a statement about any specific product or organisation.