ISO 42001 or the EU AI Act: What Do You Actually Need?

Zahed AshkaraAI & Legal Expert
9 minutesAI GovernanceAugust 24, 2026
ISO 42001 or the EU AI Act: What Do You Actually Need?

"Do we need ISO 42001?" Nearly every quality manager, CISO and compliance lead is now getting this question from a client, an auditor or their own board. The short answer: an ISO 42001 certificate and EU AI Act compliance are two different things that partly overlap, but neither replaces the other. ISO 42001 is a voluntary management system standard that organises how you run your AI processes. The AI Act is a law that imposes concrete obligations, tied to your role and to the risk class of each AI system. This piece explains what each framework covers and does not cover, what the European standardisation route means for organisations already certified, and in what order to resolve the question.

Two different things: a standard and a law

ISO/IEC 42001 was published in 2023 as the first international standard for an AI management system.4 A management system standard works like ISO 9001 or ISO 27001: it describes how an organisation should structure policy, roles, risk assessment, documentation and continuous improvement around AI. A certification body audits whether that process demonstrably works. The standard says little to nothing about what a specific AI system must actually do or be allowed to do.

The EU AI Act, Regulation (EU) 2024/1689 as amended by the Digital Omnibus (EU) 2026/1744, is legislation.12 The law imposes enforceable obligations on providers and deployers, broken down by the role you play and the risk class of each individual system. A supervisory authority can impose a fine for non-compliance, up to 35 million euros or 7% of global turnover for prohibited practices, and up to 15 million euros or 3% for most other infringements; for SMEs and start-ups, whichever of the two amounts is lower applies.1 No one accepts an ISO certificate as proof of legal compliance, simply because it was never built for that purpose.

The confusion arises because both frameworks address the same subject matter, and because certification bodies and consultants often sell ISO 42001 as "AI Act-proof". It is not.

Where they overlap

ISO 42001 and the AI Act touch on a number of the same areas, and that is exactly why organisations with an existing management system have a head start:

  • Risk management. ISO 42001 requires a structured process to identify and manage AI risks. The AI Act requires a comparable risk management system for high-risk systems, applied per system.
  • Documentation. Both frameworks expect you to record what you do: policy, procedures, decisions, changes.
  • Roles and responsibilities. ISO 42001 asks for clear internal accountability for AI governance. The AI Act has its own roles (provider, deployer, importer, distributor), each with distinct obligations.
  • Incident process. A working internal process to flag and follow up on AI-related incidents, as ISO 42001 requires, is the foundation you build the AI Act's statutory notification duties on top of.

This overlap is real and valuable. An organisation with a working ISO 42001 system does not have to start AI governance from zero. But overlap is not coverage.

What ISO 42001 does not cover

Four gaps that quality managers and CISOs consistently underestimate:

  1. Per-system classification. The AI Act requires you to assess each AI system individually: is it prohibited, high-risk, limited-risk or minimal-risk? ISO 42001 asks for a management process at organisational level, not a system-by-system classification against a statutory list.
  2. Concrete measures per role. Article 4 has required organisations, since 2 February 2025, to take measures that support AI literacy among staff and users; since the amendment of 27 July 2026 this is explicitly a duty to take measures, not a guarantee of any individual skill level. ISO 42001 mentions competence in general terms but does not translate it into this specific statutory obligation.
  3. Transparency toward end users. Article 50 has required, since 2 August 2026, that users be informed they are interacting with AI, for example with chatbots or synthetic content. For systems already on the market before that date, the machine-readable marking under paragraph 2 carries a transition period until 2 December 2026. ISO 42001 imposes no concrete disclosure duty toward end users.
  4. Registration duties. For high-risk systems under Annex III, enforceable from 2 December 2027, a registration duty in an EU database applies. That is a statutory formality no management system standard regulates.

An organisation that assumes an ISO 42001 certificate means it is ready for the AI Act is therefore missing four concrete, enforceable obligations.

Comparison table

| Aspect | ISO/IEC 42001 | EU AI Act | |---|---|---| | Nature | Voluntary management system standard | Binding legislation | | Scope | Organisation-wide process | Per AI system and per role | | Enforcement | Certification body, voluntary | National supervisory authority, mandatory | | Gives presumption of conformity under the AI Act? | No | N/A, it is the law itself | | Per-system classification | No | Yes, required | | AI literacy measures (Art. 4) | General, not legally tied | Required since 2 Feb 2025, revised 27 Jul 2026 | | End-user transparency (Art. 50) | Not covered | Required since 2 Aug 2026 | | High-risk system registration | Not covered | Required from 2 Dec 2027 | | Sanction for non-compliance | Certificate can be withdrawn | Fine up to 35m euros / 7% turnover for prohibited practices, 15m euros / 3% for most other breaches | | Value | Organises processes, credible toward clients | Legally required, not optional |

The European standardisation route: why ISO 42001 gives no presumption of conformity

This is the misunderstanding this piece exists to correct. Under the AI Act, harmonised European standards give a presumption of conformity: providers applying such a standard may assume they meet the corresponding statutory requirement. ISO 42001 is not a harmonised standard under the AI Act, and therefore does not give that presumption, no matter how often it is marketed as if it does.

The actual European standardisation route runs through CEN-CENELEC, the joint European standardisation body, under Joint Technical Committee 21 (JTC 21).5 The European Commission tasked JTC 21, through standardisation request M/613, with developing a set of harmonised standards specifically tailored to the AI Act, covering everything from risk management to technical documentation and data governance.3

On 12 July 2026, the first standard under that request was approved: EN 18286:2026, covering the quality management system for providers of high-risk AI systems. That is the first European standard that can formally give a presumption of conformity, once the Commission publishes the reference in the Official Journal. Further standards under M/613 are still in progress, including on risk management and technical documentation; those are not yet finalised at the time of writing.

What does this mean for organisations that already hold ISO 42001? Your work is not wasted. The processes you have built, risk management, documentation, role allocation, are a solid foundation and overlap substantively with what EN 18286 will require. But you need to actively map your ISO 42001 system against EN 18286 and the other M/613 standards as they appear, and close the gaps. Do not assume your certificate will automatically keep pace.

When ISO 42001 still makes sense

Not being a compliance route does not mean no value. Three situations where certification is genuinely worthwhile, independent of your statutory obligations:

  • Client procurement requirements. Large clients and public-sector buyers increasingly ask for an ISO 42001 certificate in tenders as evidence of mature AI governance. That is a commercial requirement, not a legal one.
  • International group structure. If you operate across multiple jurisdictions outside the EU, an international standard gives a consistent governance framework that does not stop at the EU border, unlike the AI Act.
  • Existing ISO culture. If you already run ISO 27001 or ISO 9001, the marginal cost of adding ISO 42001 is low: the audit structure, internal audits and management review already exist.

In these cases, certification is a deliberate, additional choice alongside your statutory AI Act track, not a substitute for it.

Decision order

For anyone facing this question now, in this order:

  1. Classify your AI systems first. Determine your role per system (provider, deployer, importer, distributor) and its risk class. This determines your statutory obligations, independent of any certification decision.
  2. Build the legally required pieces regardless. Article 4 measures, transparency where Article 50 applies, and for high-risk systems the Annex III obligations ahead of 2 December 2027. This is not optional.
  3. Check whether you already have a management system. Existing ISO 27001 or 9001 infrastructure makes ISO 42001 relatively cheap to add.
  4. Ask whether clients or procurement explicitly require the certificate. If so, plan certification alongside your compliance track, not as a replacement for it.
  5. Track the M/613 standards. Once EN 18286 and the other harmonised standards are finalised, map your existing system against them and close the gaps.

The core point stands: AI Act compliance is mandatory regardless of any certification decision. ISO 42001 is a tool that can support that compliance, never a substitute for it.

Frequently asked questions

Does ISO 42001 automatically give a presumption of conformity under the EU AI Act?

No. Only harmonised European standards give that presumption, and ISO 42001 is not one of them. The first harmonised standard under standardisation request M/613, EN 18286:2026 on the quality management system, was approved on 12 July 2026; further standards are still in progress.

Is an ISO 42001 certificate mandatory under the AI Act?

No, ISO 42001 remains a voluntary standard. The AI Act imposes its own obligations independent of certification, and those obligations apply whether or not you hold a certificate.

We already have ISO 27001. Does ISO 42001 still make sense alongside the AI Act?

Possibly, especially if clients or procurement ask for it, or if you operate internationally. The marginal cost is low because the audit structure already exists. It does not, however, replace any AI Act obligation.

What is the difference between ISO 42001 and the upcoming EN 18286?

ISO 42001 is an international, voluntary standard with no legal status under the AI Act. EN 18286:2026 is a European standard that, once its reference is published in the Official Journal, can give a presumption of conformity for the AI Act's quality management system requirement. They overlap substantively but have a different legal status.

Should we certify now or handle the AI Act obligations first?

Handle the statutory obligations first: classification, Article 4 measures, transparency, and where applicable the Annex III obligations. Certification is an additional, commercial decision you make afterward, not instead of it.

Can we reuse parts of our ISO 42001 system for AI Act compliance?

Yes, risk management processes, documentation structure, role allocation and incident processes from ISO 42001 are a solid foundation. You still need to add the system-specific classification and the concrete statutory obligations the standard does not cover.

Zahed Ashkara

Zahed Ashkara

AI & Legal Expert

Newsletter

Stay on top of the EU AI Act

Get practical updates on AI governance, compliance and the EU AI Act. No noise, only what you can use.

By subscribing you agree to our privacy policy.