EU AI Act + ISO 42001
A strong foundation for compliance, not a presumption of conformity
Bottom line
ISO 42001 builds most of the machinery the EU AI Act expects: risk management, data governance, documentation, logging, human oversight, monitoring and incident handling. It is not enough on its own. The Commission states that ISO 42001's goals are not aligned with the Act's quality management system and ISO 42001 carries no presumption of conformity, which comes only from harmonised standards cited in the Official Journal, Commission common specifications or certain Article 42 certificates. After the 2026 Digital Omnibus, high-risk obligations apply from December 2, 2027 (Annex III) and August 2, 2028 (Annex I products), which leaves time to build on a certified AIMS.[2][3][6]
The EU AI Act in brief
Regulation (EU) 2024/1689 regulates AI by risk tier. A short list of practices is prohibited. High-risk systems, in the product areas of Annex I and the use cases of Annex III such as employment, credit, education and essential services, carry the heaviest obligations for providers and deployers. Certain systems carry transparency duties, and general-purpose AI models have their own chapter.[1]
The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on July 27, 2026. It replaced the original high-risk dates with fixed later ones, softened the AI literacy duty to supporting staff literacy, and extended SME relief to small mid-caps.[3][4][9]
Harmonised standards are arriving. EN 18286, the quality management system standard for Article 17, was approved in July 2026. At this review no AI Act harmonised standard has been cited in the Official Journal, so none yet gives a presumption of conformity.[7][8]
- Instrument
- Regulation (EU) 2024/1689, amended by (EU) 2026/1744
- Applies to
- Providers placing AI on the EU market; deployers in the EU; non-EU providers and deployers whose output is used in the EU; importers, distributors
- Prohibited practices
- Up to €35M or 7% of worldwide turnover
- Most other obligations
- Up to €15M or 3% of worldwide turnover
- Misleading information
- Up to €7.5M or 1% of worldwide turnover
- ISO 42001 status
- Not a harmonised standard; no presumption of conformity
Key dates
- Aug 1, 2024AI Act enters into force[1]
- Feb 2, 2025Prohibited practices and AI literacy apply[2]
- Aug 2, 2025General-purpose AI model obligations, governance and penalties apply (Commission fines on GPAI providers under Art. 101 from Aug 2, 2026)[2]
- Jul 27, 2026Digital Omnibus (Regulation (EU) 2026/1744) enters into force[3]
- Aug 2, 2026General application, including Article 50 transparency obligations[2]
- Dec 2, 2026New prohibitions on non-consensual intimate imagery and child sexual abuse material apply; deadline for Article 50(2) content marking by generative systems placed on the market before Aug 2, 2026[2][12]
- Dec 2, 2027High-risk obligations for Annex III systems apply (originally Aug 2026)[2]
- Aug 2, 2028High-risk obligations for Annex I product systems apply (originally Aug 2027)[2]
Where they overlap
Each row is an AI Act obligation and where ISO 42001 produces the process or evidence. Articles 9 to 17, 43 to 49, 72 and 73 bind providers; deployers carry Articles 26, 27 and 50(3) to (4); Article 4 binds both. Article numbers refer to Regulation (EU) 2024/1689 as amended.[2][10]
| EU AI Act | ISO 42001 | Coverage |
|---|---|---|
| Art. 4 AI literacy | 7.2, 7.3 Competence and awareness for everyone working on or with AI systems in scope. | Strong |
| Art. 9 Risk management system | 6.1.2, 6.1.3, 8.2, 8.3 Lifecycle AI risk assessment and treatment. The Act focuses on risks to health, safety and fundamental rights and requires testing against them. | Partial |
| Art. 10 Data and data governance | A.7.2–A.7.6 Data quality, provenance and preparation. The Act adds representativeness and bias examination (special-category data for bias detection is now Art. 4a). | Partial |
| Art. 11 Technical documentation (Annex IV) | A.6.2.7, 7.5 Technical documentation exists, but Annex IV prescribes specific content you must map to. | Partial |
| Art. 12 Record-keeping | A.6.2.8 Event logging is a control; the Act requires automatic logging capability over the system's lifetime. | Partial |
| Art. 13 Transparency to deployers | A.8.2 A.8.2 produces user information; Art. 13(3) prescribes specific content for the instructions for use. | Partial |
| Art. 14 Human oversight | A.9.2, A.9.3, A.6.2.2 Responsible use and requirements. The Act requires oversight measures designed into the system. | Partial |
| Art. 15 Accuracy, robustness, cybersecurity | A.6.2.4, A.6.2.6 Verification, validation and monitoring. Declared accuracy levels and cybersecurity need more, often ISO 27001. | Partial |
| Art. 17 Quality management system | Cl. 4–10 A management system to build on, but the Commission says its goals differ from Art. 17. EN 18286:2026 is the CEN-CENELEC QMS standard written for Art. 17; it gives a presumption of conformity only once cited in the Official Journal. | Partial |
| Art. 26 Deployer obligations | A.9, A.10.2, A.10.3, A.8.5, A.6.2.6 Use per instructions, oversight and monitoring. Log retention and worker information are statutory specifics. | Partial |
| Art. 27 Fundamental rights impact assessment | 6.1.4, A.5.2–A.5.5 The AI system impact assessment is the natural home; the FRIA's scope and content are defined by the Act. | Partial |
| Art. 43, 47–49 Conformity assessment, CE marking, registration | None Regulatory procedures with no ISO 42001 equivalent. Certification is not conformity assessment. | Gap |
| Art. 50 Transparency for certain AI systems | A.8.2, A.8.5 Disclosure processes exist; marking AI-generated content needs technical implementation. | Partial |
| Art. 72 Post-market monitoring | A.6.2.6, 9.1 Monitoring processes exist; the Act requires a plan on the Commission template, inside the technical documentation. | Partial |
| Art. 73 Serious incident reporting | A.8.4, 10.2 Incident communication and corrective action; regulator reporting and deadlines are statutory. | Partial |
| Art. 53–55 General-purpose AI model obligations | A.6.2.7, A.7.5 Model documentation, copyright policy and training-content summaries are outside what 42001 was built for. The GPAI Code of Practice is the recognized route; models on the market before Aug 2, 2025 have until Aug 2, 2027. | Gap |
Coverage reflects how directly ISO 42001 produces the evidence or process the requirement asks for. It is an editorial assessment, not a legal opinion or a presumption of conformity.
What ISO 42001 won't cover
Certification to ISO 42001 is a voluntary third-party audit. The AI Act is a product-safety regulation with its own procedures.
No presumption of conformity
Presumption of conformity comes from harmonised standards cited in the Official Journal (Art. 40), Commission common specifications (Art. 41) or, for some requirements, Art. 42 certificates. ISO 42001 is none of these.[6][11]
Conformity assessment and CE marking
High-risk systems need a conformity assessment, EU declaration of conformity, CE marking and registration. An ISO certificate replaces none of them.[1]
QMS alignment
Article 17's QMS has a product-compliance focus. Plan to extend the AIMS toward EN 18286 rather than assume 42001 satisfies it.[6][7]
Prescribed content
Annex IV documentation, logging capability, accuracy declarations and incident-reporting deadlines are specified by the Act, not by 42001.[2]
Using ISO 42001 to get there
- 1
Classify every AI system
Use the AIMS inventory to tag each system as prohibited, high-risk (Annex I or III), transparency-only or minimal, and your role as provider or deployer. Track the Commission's high-risk classification guidelines, still in draft at this review.
- 2
Extend risk and impact assessment
Add health, safety and fundamental-rights criteria to 6.1.2 and 6.1.4 so one assessment feeds Article 9 and, for deployers, the FRIA.
- 3
Map Annex IV to your documentation
Restructure A.6.2.7 technical documentation so each Annex IV item has an owner and a source record.
- 4
Engineer logging and oversight in
Turn A.6.2.8 and A.9 into design requirements: automatic event logs and human-oversight measures built into high-risk systems.
- 5
Bridge the QMS to EN 18286
Gap the AIMS against EN 18286 and add product-compliance processes: conformity assessment, declaration, CE marking, registration.
- 6
Prepare for conformity assessment
Consider certifying the AIMS, and plan conformity assessment ahead of December 2027 or August 2028.
Frequently asked questions
Does ISO 42001 certification mean we comply with the EU AI Act?
No. ISO 42001 covers much of the operational work, but it is not a harmonised standard and gives no presumption of conformity. High-risk systems still need conformity assessment, CE marking and registration.
When do the high-risk requirements apply?
After the 2026 Digital Omnibus, from December 2, 2027 for Annex III systems such as employment, credit and education, and from August 2, 2028 for AI in products covered by Annex I. These are fixed dates.
What is EN 18286?
The first harmonised European standard developed for the AI Act, covering the quality management system required by Article 17. It was approved in July 2026. Once its reference is published in the Official Journal it will give a presumption of conformity for the requirements it covers.
Is ISO 42001 still worth it for the EU AI Act?
For many organizations, yes, as a foundation. It earns no regulatory credit on its own. The risk, data, documentation, monitoring and incident processes it requires are the ones the Act builds on, and a certified AIMS shows customers you are organized ahead of the deadlines.
What are the penalties?
Up to €35 million or 7% of worldwide annual turnover for prohibited practices, €15 million or 3% for most other obligations, and €7.5 million or 1% for supplying incorrect or misleading information. SMEs pay the lower of the two amounts in every tier; small mid-caps pay the lower amount except for prohibited practices.
Related frameworks
This page is general information, not legal advice. Laws change; confirm obligations with counsel.