Last updated: September 1, 2026
The EU AI Act is binding law with fines attached. ISO/IEC 42001 is a voluntary international standard you can be certified against. The Act says what you must do for particular AI systems placed on the EU market or used in the EU. ISO 42001 says how to run an AI management system that makes those duties repeatable and auditable. They are not alternatives: certifying to ISO 42001 does not make you AI Act compliant, and complying with the Act does not earn you a certificate.
This comparison is part of our AI governance guide. If the regulation itself is new to you, start with our overview of EU AI Act compliance for GRC teams.
Key takeaways
- The EU AI Act is regulation. ISO 42001 is a certifiable management system standard. Only one of them can fine you.
- The Act is risk-tiered and applies per AI system. ISO 42001 applies to the organization as a whole.
- ISO 42001 covers a large share of what the Act expects on governance, risk management, documentation, human oversight and supplier control, but none of its product-specific conformity duties.
- Prohibited practices, AI literacy, general purpose AI rules and the Article 50 transparency duties already apply. Standalone high-risk obligations now apply from December 2, 2027 following the Digital Omnibus deferral.
- The practical sequence for most companies: classify your systems against the Act first, then build the ISO 42001 management system so the evidence is produced by default rather than assembled in a panic.
What is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the first comprehensive AI law of its kind. It regulates AI systems by risk rather than by technology. A small set of practices is prohibited outright. A defined set of use cases is classified as high-risk and carries heavy obligations on risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness. General purpose AI models carry their own transparency and, above a compute threshold, systemic risk duties. Everything else is largely unregulated apart from the Article 50 transparency rules that apply when people interact with AI or see synthetic content.
Two things make it awkward for compliance teams. First, obligations attach to roles rather than to companies, so the same business can be a provider for one system and a deployer for another. Our guide to who the EU AI Act applies to walks through that split. Second, the timeline has moved. The Digital Omnibus on AI entered into force in July 2026 and pushed the standalone high-risk deadline from August 2, 2026 to December 2, 2027, with AI embedded in products already covered by EU product safety law moving to August 2, 2028. Fine levels did not change: prohibited practices still reach 35 million euros or 7 percent of global annual turnover, whichever is higher.
What is ISO 42001?
ISO/IEC 42001:2023 is the international standard for an artificial intelligence management system, or AIMS. It follows the same harmonized structure as ISO 27001, so Clauses 4 to 10 set the certifiable requirements (context, leadership, planning, support, operation, performance evaluation and improvement) and Annex A offers a reference set of 38 controls across nine control areas, from AI policy and roles through impact assessment, the AI life cycle, data, and third-party relationships. You select Annex A controls through a risk assessment and justify what you leave out, exactly as you would with ISO 27001. Our breakdown of ISO 42001 requirements covers each clause in detail.
The standard is deliberately generic. It does not tell you that facial recognition in recruitment is off limits, or that a CE mark is needed. It tells you to define your context, set objectives, assess AI risks and impacts on individuals and society, control the life cycle, manage suppliers, measure, audit and improve.
EU AI Act vs ISO 42001: side by side
| Dimension | EU AI Act | ISO/IEC 42001 |
|---|---|---|
| Type | Binding regulation | Voluntary certifiable standard |
| Issuer | European Union | ISO and IEC |
| Scope | Per AI system, by risk tier and by role (provider, deployer, importer, distributor) | Organization-wide management system, scoped by you |
| Geographic reach | EU market and EU-used outputs, wherever you are established | Global, no jurisdictional trigger |
| Enforcement | National market surveillance authorities and the AI Office | Accredited certification bodies |
| Consequence of failure | Fines up to 35 million euros or 7 percent of global turnover; products withdrawn from market | Nonconformity, suspended or withdrawn certificate |
| Key dates | Prohibitions and AI literacy since February 2025; GPAI since August 2025; transparency duties from August 2026; standalone high-risk from December 2, 2027 | Published December 2023; certify whenever you are ready |
| Evidence produced | Technical documentation, conformity assessment, EU declaration of conformity, registration in the EU database | Statement of Applicability, risk and impact assessments, internal audit, management review |
| Buyer signal | Table stakes if you sell into the EU | Differentiator in security reviews and RFPs anywhere |
Where do the two overlap?
More than most teams expect. The Act’s Article 9 risk management system, its data governance expectations, its record keeping and logging duties, its human oversight requirement and its post-market monitoring loop all have close analogues in ISO 42001 clauses and Annex A controls. If you run a working AIMS, you will already have an AI system inventory, documented owners, a risk and impact assessment method, supplier due diligence, incident handling and a corrective action process. Those are the same artifacts an EU regulator or a notified body will ask to see for a system in one of the EU AI Act high-risk categories.
This is why ISO 42001 is often described as a compliance accelerator. It does not satisfy the law, but it produces most of the raw material the law wants, and it produces it continuously rather than as a one-off project.
Where does ISO 42001 fall short of EU AI Act compliance?
Four gaps matter most.
- Classification. Nothing in ISO 42001 makes you decide whether a system is prohibited, high-risk, limited-risk or minimal-risk under Annex I and Annex III. That legal analysis is yours to do.
- Conformity assessment and CE marking. The Act requires a formal conformity route, an EU declaration of conformity, and in some biometric and Annex I cases a notified body. An AIMS certificate is not a substitute.
- Prescribed content. Annex IV technical documentation, Article 50 disclosure wording, registration in the EU database and the fundamental rights impact assessment have specific required contents. ISO 42001 asks for documentation but not that documentation.
- Prohibitions. A certified AIMS will happily wrap around a practice the Act bans outright. Screening against Article 5 is a legal control, not a management system control.
The reverse gap is real too. A company that does only the minimum for the Act has no certificate to show a US or UK buyer, and no organization-wide discipline for the AI systems that sit outside the high-risk tier, which is where most shadow AI actually lives.
Which should you do first?
Start with scope, because it is cheap and it drives everything else. Build an inventory of AI systems, assign a role to each one, and screen against the prohibitions. Our EU AI Act compliance checklist is a reasonable running order for that work.
Then choose based on exposure. If you have systems that will land in Annex III, the December 2027 date is your hard constraint and the Act should lead, with ISO 42001 built alongside it so the documentation has a home. If your EU exposure is limited to transparency duties, or you are mostly selling to enterprises who are asking hard AI questions in security reviews, ISO 42001 is the better first investment. It answers the questionnaire, it is recognized outside Europe, and it leaves you a short step from the Act’s governance requirements if your risk profile changes. Teams already holding ISO 27001 usually find the incremental effort modest, as our comparison of ISO 42001 vs ISO 27001 explains.
Frequently asked questions
Does ISO 42001 certification prove EU AI Act compliance?
No. It is strong supporting evidence of governance maturity and it produces much of the documentation the Act expects, but it does not cover classification, conformity assessment, CE marking or the Act’s prescribed documentation contents. Treat it as a foundation, not a defense.
Will ISO 42001 become a harmonized standard under the AI Act?
Not as it stands. The European Commission mandated CEN and CENELEC to develop harmonized European standards for the Act, and those are being drafted with ISO 42001 as an input rather than as a direct adoption. Conformity with a harmonized standard, once published and cited in the Official Journal, gives a presumption of conformity. An ISO 42001 certificate does not.
Do I need both if I am a deployer rather than a provider?
Deployer duties under the Act are lighter but real: human oversight, input data quality within your control, logging, worker notification and in some cases a fundamental rights impact assessment. ISO 42001 maps onto those well, and for many deployers it is the more useful of the two because it also covers the internal AI use that the Act ignores.
How much do the two cost to implement?
ISO 42001 has a knowable price: readiness work plus a two-stage audit, with certification body fees typically in the low tens of thousands of dollars for a mid-sized scope. See our breakdown of ISO 42001 certification cost. AI Act cost depends entirely on how many high-risk systems you own, since each one carries its own documentation and conformity burden.
Did the Digital Omnibus reduce what I have to do?
It bought time, not relief. The high-risk application dates moved and some administrative points were softened, but the substantive requirements and the penalty tiers are materially unchanged. Our post on EU AI Act penalties covers the fine structure as it stands.
Can one set of controls satisfy both?
Largely, yes, if you design for it. Build the ISO 42001 management system with the Act’s Annex IV documentation fields and Article 9 risk management steps mapped into your control set from the start, so one risk assessment and one evidence trail serves both audiences.
Running both without running two programs
The failure mode is treating these as separate projects with separate spreadsheets. They share an inventory, a risk register, a control set and an evidence trail, and maintaining them twice is where the cost comes from. Compyl gives GRC teams one place to hold that shared layer: map ISO 42001 controls and EU AI Act obligations to the same evidence, automate the collection, and see in one view which systems are covered and which are not. If you are scoping either program this year, we are happy to walk through what that mapping looks like for your environment.