Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
Does ISO 42001 certification make you EU AI Act compliant?
Last verifiedNo — not as a general rule. ISO 42001 certification does not make you EU AI Act compliant. A certificate attests an AIMS; the Act imposes separate legal duties. Not legal advice.
Compliance Q&A, last verified 10 September 2026 against Regulation (EU) 2024/1689 and ISO/IEC 42001:2023. Does not determine that the Act applies to YOU. Not legal advice.
The qualified answer
No — ISO/IEC 42001 certification does not, by itself, make an organisation EU AI Act compliant. Certification attests that an accredited body found YOUR AI management system conforming to ISO/IEC 42001:2023. The EU AI Act is Regulation (EU) 2024/1689 — a different instrument with operator-specific duties, conformity routes, and enforcement. A well-run AIMS may help YOU produce evidence for some Act themes, but that is support, not substitution. This is not legal advice. Counsel applies Articles 2–3 to YOUR facts.
Decision aid — 42001 coverage vs Act duties
| EU AI Act theme | 42001 may help with | Act still requires separately | Kind of text |
|---|---|---|---|
| Risk management — Art. 9 | AIMS risk assessment, Annex A lifecycle | High-risk system risk management per Chapter III | Legal requirement if applicable |
| Technical documentation — Art. 11 | AIMS documented information | Annex IV pack, provider duties | Legal requirement if applicable |
| GPAI — Chapter V | Governance structure | Articles 53–55, model-specific duties | Legal requirement if applicable |
| Transparency — Art. 50 | Information for interested parties control | Article 50 disclosure cases | Legal requirement if applicable |
| Conformity assessment | Internal audit discipline | Notified body / EU declaration where required | Legal requirement if applicable |
| Penalties — Art. 99 | Not applicable — standard has no fines | Member State enforcement | Legal requirement |
What the Act still requires
- Applicability test under Articles 2 and 3 — this page does not run it.
- Role classification: provider, deployer, importer, distributor.
- Product-specific conformity: CE marking routes, notified bodies, EU database registration where required.
- Article 113 phased dates — not one number; see EU AI Act requirements-in-force-2026 page.
- Harmonised standards: ISO 42001 not verified as presumption of conformity as of 10 September 2026.
What to do now
- Treat 42001 and EU AI Act as parallel tracks with explicit mapping workshops.
- Ask counsel for a written applicability memo before claiming compliance with the Act.
- Use AI inventory to list systems; counsel classifies — product does not classify.
Checklist
- ☐ Written legal applicability assessment for the Act?
- ☐ Gap list from Act duties not covered by SoA?
- ☐ No marketing claim equates certificate to Act conformity?
Where this shows up in ShipReady Metrics
Marking eu_ai_act or iso_42001 in-scope on the obligation map is not a compliance determination. Evidence collection and met-verdict overlay are preparation artifacts. The product does not issue CE marks, does not file with the AI Office, and does not satisfy the EU AI Act.