Short answer
ISO 42001 vs EU AI Act is a comparison of a voluntary standard and a binding law. ISO/IEC 42001:2023 sets requirements for an AI management system and can be certified. The EU AI Act, Regulation (EU) 2024/1689, sets legal duties by risk class, with fines. Certification supports compliance with the Act but does not prove it.
Key takeaways
- ISO 42001 is voluntary and certifies an organisation; the EU AI Act is law and regulates each AI system by risk class.
- ISO 42001 has 38 Annex A controls alongside clauses 4 to 10.
- An ISO 42001 certificate does not give a presumption of conformity with the Act.
- High-risk obligations under the Act apply from 2 December 2027, after the 2026 Digital Omnibus.
The short version
ISO/IEC 42001:2023 is a management system standard. It asks an organisation to set an AI policy, assess AI risks and impacts, apply controls across the AI system life cycle, and review how it all performs. An accredited body can certify it. The EU AI Act is a regulation. It applies to anyone who places an AI system on the EU market, puts one into service there or uses one there, and it sets duties by how risky the system is.
| ISO 42001 | EU AI Act | |
|---|---|---|
| What it is | Requirements for an AI management system (AIMS) | A law regulating AI systems placed on or used in the EU market |
| Reference | ISO/IEC 42001:2023 | Regulation (EU) 2024/1689, amended by the 2026 Digital Omnibus |
| Binding? | Voluntary | Mandatory for those in scope |
| Who it applies to | Any organisation that develops, provides or uses AI | Providers, deployers, importers and distributors, including those outside the EU |
| Approach | Management system: policy, risk, controls, review | Risk classes, plus rules for general-purpose AI models |
| Structure | Clauses 4 to 10, plus 38 Annex A controls | Chapters, articles and annexes |
| How you show it | Certificate from an accredited body | Conformity assessment, CE marking and registration for high-risk systems |
| Penalties | None; a certificate can be withdrawn | Up to €35 million or 7% of worldwide turnover for prohibited practices |
| Enforced by | Certification bodies, through audits | National authorities and the EU AI Office |
How the EU AI Act sorts AI systems
The Act uses four levels. Some practices are prohibited outright. High-risk systems, such as AI used in recruitment, credit scoring or as a safety component of a regulated product, carry the heaviest duties. Systems that interact with people or generate content have transparency duties. Everything else is minimal risk, with no specific obligations. General-purpose AI models have their own set of rules.
Timeline
EU AI Act: when each part applies
- In forceRegulation (EU) 2024/1689
- Prohibitions applyProhibited practices and AI literacy
- General-purpose AIDuties for providers of general-purpose AI models
- Transparency dutiesArticle 50
- High-risk obligationsAfter the 2026 Digital Omnibus
How ISO 42001 is built
ISO 42001 follows the same structure as ISO 27001. Clauses 4 to 10 set the management system: context, leadership, planning, support, operation, performance evaluation and improvement. Two requirements are specific to AI: an AI risk assessment and an AI system impact assessment, which looks at the effect on individuals and society. Annex A then lists 38 controls under nine objectives, from AI policies and internal organisation to data for AI systems, information for interested parties, use of AI systems and third-party relationships.
A certificate is not conformity
Under the Act, following a harmonised European standard gives a presumption of conformity with the requirements it covers. ISO/IEC 42001 is not a harmonised standard under the Act, so holding a certificate does not give that presumption. European standards written for this purpose are being developed. What ISO 42001 does give you is the working machinery: named owners, a risk process, records and reviews that an authority or a customer can inspect.
Where ISO 42001 and the EU AI Act overlap
An AI management system supplies most of the working parts the Act expects from providers of high-risk systems. The mapping below shows where work can be reused. It is indicative and does not show legal equivalence.
Clause 6.1AI risk assessment and treatmentArticle 9Risk management system6.1.4, A.5AI system impact assessmentArticle 27Fundamental rights impact assessmentA.7Data for AI systemsArticle 10Data and data governance7.5, A.6Documented information, AI life cycleArticles 11–12Technical documentation and record-keepingA.8Information for interested partiesArticles 13, 50TransparencyA.9Use of AI systemsArticles 14, 26Human oversight and deployer dutiesClauses 4–10The management systemArticle 17Quality management system7.2, 7.3Competence and awarenessArticle 4AI literacy
Do you need one, the other, or both?
Start with the law. Work out whether the Act applies to you, in which role (provider, deployer, importer or distributor) and in which risk class. Then decide how to meet those duties. ISO 42001 is a sound way to build the management system behind them, and it is also what customers increasingly ask for as proof of responsible AI. If you already hold ISO 27001, the two standards share a structure, so the same management system can be extended to AI.
Checklist
Preparing for both
0 of 6 done
This article is general information, not legal advice. Dates reflect the Act as amended in 2026; check the current text before relying on them.
Put this into practice on QULDEX
Frequently asked questions
Does ISO 42001 certification make me EU AI Act compliant?
No. It supports compliance by putting risk management, documentation and oversight in place, but it is not a harmonised standard under the Act and does not prove conformity.
Is ISO 42001 mandatory under the EU AI Act?
No. The Act does not require ISO 42001. Providers of high-risk systems need a quality management system, which ISO 42001 can help deliver.
Should we start with ISO 42001 or the EU AI Act?
First work out whether the Act applies to you and in which risk class. Then use ISO 42001 to build the management system that meets those duties.
How many controls does ISO 42001 have?
38 Annex A controls, alongside the requirements in clauses 4 to 10.
When do the EU AI Act's high-risk rules apply?
From 2 December 2027, after the 2026 Digital Omnibus. Prohibitions have applied since 2 February 2025.