On this page
EU regulation

EU AI Act + ISO 42001

A strong foundation for compliance, not a presumption of conformity

Reviewed by the ISO42k editorial team · Last reviewed October 9, 2026

Bottom line

ISO 42001 builds most of the machinery the EU AI Act expects: risk management, data governance, documentation, logging, human oversight, monitoring and incident handling. It is not enough on its own. The Commission states that ISO 42001's goals are not aligned with the Act's quality management system and ISO 42001 carries no presumption of conformity, which comes only from harmonised standards cited in the Official Journal, Commission common specifications or certain Article 42 certificates. After the 2026 Digital Omnibus, high-risk obligations apply from December 2, 2027 (Annex III) and August 2, 2028 (Annex I products), which leaves time to build on a certified AIMS.[2][3][6]

Interactive toolDoes the AI Act apply to your system?Up to eight questions to screen scope, risk tier, transparency and GPAI duties, with Omnibus dates.Start →

The EU AI Act in brief

Regulation (EU) 2024/1689 regulates AI by risk tier. A short list of practices is prohibited. High-risk systems, in the product areas of Annex I and the use cases of Annex III such as employment, credit, education and essential services, carry the heaviest obligations for providers and deployers. Certain systems carry transparency duties, and general-purpose AI models have their own chapter.[1]

The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on July 27, 2026. It replaced the original high-risk dates with fixed later ones, softened the AI literacy duty to supporting staff literacy, and extended SME relief to small mid-caps.[3][4][9]

Harmonised standards are arriving. EN 18286, the quality management system standard for Article 17, was approved in July 2026. At this review no AI Act harmonised standard has been cited in the Official Journal, so none yet gives a presumption of conformity.[7][8]

Instrument
Regulation (EU) 2024/1689, amended by (EU) 2026/1744
Applies to
Providers placing AI on the EU market; deployers in the EU; non-EU providers and deployers whose output is used in the EU; importers, distributors
Prohibited practices
Up to €35M or 7% of worldwide turnover
Most other obligations
Up to €15M or 3% of worldwide turnover
Misleading information
Up to €7.5M or 1% of worldwide turnover
ISO 42001 status
Not a harmonised standard; no presumption of conformity

Key dates

  1. Aug 1, 2024
    AI Act enters into force[1]
  2. Feb 2, 2025
    Prohibited practices and AI literacy apply[2]
  3. Aug 2, 2025
    General-purpose AI model obligations, governance and penalties apply (Commission fines on GPAI providers under Art. 101 from Aug 2, 2026)[2]
  4. Jul 27, 2026
    Digital Omnibus (Regulation (EU) 2026/1744) enters into force[3]
  5. Aug 2, 2026
    General application, including Article 50 transparency obligations[2]
  6. Dec 2, 2026
    New prohibitions on non-consensual intimate imagery and child sexual abuse material apply; deadline for Article 50(2) content marking by generative systems placed on the market before Aug 2, 2026[2][12]
  7. Dec 2, 2027
    High-risk obligations for Annex III systems apply (originally Aug 2026)[2]
  8. Aug 2, 2028
    High-risk obligations for Annex I product systems apply (originally Aug 2027)[2]

Where they overlap

Each row is an AI Act obligation and where ISO 42001 produces the process or evidence. Articles 9 to 17, 43 to 49, 72 and 73 bind providers; deployers carry Articles 26, 27 and 50(3) to (4); Article 4 binds both. Article numbers refer to Regulation (EU) 2024/1689 as amended.[2][10]

Strong(1)Partial(13)Gap(2)
EU AI ActISO 42001Coverage
Art. 4 AI literacy
7.2, 7.3
Competence and awareness for everyone working on or with AI systems in scope.
Strong
Art. 9 Risk management system
6.1.2, 6.1.3, 8.2, 8.3
Lifecycle AI risk assessment and treatment. The Act focuses on risks to health, safety and fundamental rights and requires testing against them.
Partial
Art. 10 Data and data governance
A.7.2–A.7.6
Data quality, provenance and preparation. The Act adds representativeness and bias examination (special-category data for bias detection is now Art. 4a).
Partial
Art. 11 Technical documentation (Annex IV)
A.6.2.7, 7.5
Technical documentation exists, but Annex IV prescribes specific content you must map to.
Partial
Art. 12 Record-keeping
A.6.2.8
Event logging is a control; the Act requires automatic logging capability over the system's lifetime.
Partial
Art. 13 Transparency to deployers
A.8.2
A.8.2 produces user information; Art. 13(3) prescribes specific content for the instructions for use.
Partial
Art. 14 Human oversight
A.9.2, A.9.3, A.6.2.2
Responsible use and requirements. The Act requires oversight measures designed into the system.
Partial
Art. 15 Accuracy, robustness, cybersecurity
A.6.2.4, A.6.2.6
Verification, validation and monitoring. Declared accuracy levels and cybersecurity need more, often ISO 27001.
Partial
Art. 17 Quality management system
Cl. 4–10
A management system to build on, but the Commission says its goals differ from Art. 17. EN 18286:2026 is the CEN-CENELEC QMS standard written for Art. 17; it gives a presumption of conformity only once cited in the Official Journal.
Partial
Art. 26 Deployer obligations
A.9, A.10.2, A.10.3, A.8.5, A.6.2.6
Use per instructions, oversight and monitoring. Log retention and worker information are statutory specifics.
Partial
Art. 27 Fundamental rights impact assessment
6.1.4, A.5.2–A.5.5
The AI system impact assessment is the natural home; the FRIA's scope and content are defined by the Act.
Partial
Art. 43, 47–49 Conformity assessment, CE marking, registration
None
Regulatory procedures with no ISO 42001 equivalent. Certification is not conformity assessment.
Gap
Art. 50 Transparency for certain AI systems
A.8.2, A.8.5
Disclosure processes exist; marking AI-generated content needs technical implementation.
Partial
Art. 72 Post-market monitoring
A.6.2.6, 9.1
Monitoring processes exist; the Act requires a plan on the Commission template, inside the technical documentation.
Partial
Art. 73 Serious incident reporting
A.8.4, 10.2
Incident communication and corrective action; regulator reporting and deadlines are statutory.
Partial
Art. 53–55 General-purpose AI model obligations
A.6.2.7, A.7.5
Model documentation, copyright policy and training-content summaries are outside what 42001 was built for. The GPAI Code of Practice is the recognized route; models on the market before Aug 2, 2025 have until Aug 2, 2027.
Gap

Coverage reflects how directly ISO 42001 produces the evidence or process the requirement asks for. It is an editorial assessment, not a legal opinion or a presumption of conformity.

What ISO 42001 won't cover

Certification to ISO 42001 is a voluntary third-party audit. The AI Act is a product-safety regulation with its own procedures.

No presumption of conformity

Presumption of conformity comes from harmonised standards cited in the Official Journal (Art. 40), Commission common specifications (Art. 41) or, for some requirements, Art. 42 certificates. ISO 42001 is none of these.[6][11]

Conformity assessment and CE marking

High-risk systems need a conformity assessment, EU declaration of conformity, CE marking and registration. An ISO certificate replaces none of them.[1]

QMS alignment

Article 17's QMS has a product-compliance focus. Plan to extend the AIMS toward EN 18286 rather than assume 42001 satisfies it.[6][7]

Prescribed content

Annex IV documentation, logging capability, accuracy declarations and incident-reporting deadlines are specified by the Act, not by 42001.[2]

Using ISO 42001 to get there

  1. 1

    Classify every AI system

    Use the AIMS inventory to tag each system as prohibited, high-risk (Annex I or III), transparency-only or minimal, and your role as provider or deployer. Track the Commission's high-risk classification guidelines, still in draft at this review.

  2. 2

    Extend risk and impact assessment

    Add health, safety and fundamental-rights criteria to 6.1.2 and 6.1.4 so one assessment feeds Article 9 and, for deployers, the FRIA.

  3. 3

    Map Annex IV to your documentation

    Restructure A.6.2.7 technical documentation so each Annex IV item has an owner and a source record.

  4. 4

    Engineer logging and oversight in

    Turn A.6.2.8 and A.9 into design requirements: automatic event logs and human-oversight measures built into high-risk systems.

  5. 5

    Bridge the QMS to EN 18286

    Gap the AIMS against EN 18286 and add product-compliance processes: conformity assessment, declaration, CE marking, registration.

  6. 6

    Prepare for conformity assessment

    Consider certifying the AIMS, and plan conformity assessment ahead of December 2027 or August 2028.

Frequently asked questions

Does ISO 42001 certification mean we comply with the EU AI Act?

No. ISO 42001 covers much of the operational work, but it is not a harmonised standard and gives no presumption of conformity. High-risk systems still need conformity assessment, CE marking and registration.

When do the high-risk requirements apply?

After the 2026 Digital Omnibus, from December 2, 2027 for Annex III systems such as employment, credit and education, and from August 2, 2028 for AI in products covered by Annex I. These are fixed dates.

What is EN 18286?

The first harmonised European standard developed for the AI Act, covering the quality management system required by Article 17. It was approved in July 2026. Once its reference is published in the Official Journal it will give a presumption of conformity for the requirements it covers.

Is ISO 42001 still worth it for the EU AI Act?

For many organizations, yes, as a foundation. It earns no regulatory credit on its own. The risk, data, documentation, monitoring and incident processes it requires are the ones the Act builds on, and a certified AIMS shows customers you are organized ahead of the deadlines.

What are the penalties?

Up to €35 million or 7% of worldwide annual turnover for prohibited practices, €15 million or 3% for most other obligations, and €7.5 million or 1% for supplying incorrect or misleading information. SMEs pay the lower of the two amounts in every tier; small mid-caps pay the lower amount except for prohibited practices.

This page is general information, not legal advice. Laws change; confirm obligations with counsel.