Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How does ISO 42001 compare to the EU AI Act?
Last verifiedISO 42001 is a voluntary management-system standard. The EU AI Act is binding Union law where it applies. They overlap in governance themes but do not substitute for each other. Not legal advice.
Comparison, last verified 10 September 2026 against ISO/IEC 42001:2023 and Regulation (EU) 2024/1689 Articles 1–6, 50, 51–56, 99, 113. Harmonised-standard presumption for 42001 not verified as of this date. Not legal advice.
Legal requirement vs voluntary standard
Regulation (EU) 2024/1689 imposes legal duties on providers, deployers, and other operators where Articles 2 and 3 apply — penalties up to Article 99 maxima. ISO/IEC 42001:2023 is a voluntary international standard certifiable under ISO/IEC 17021-1. Confusing them risks under-preparing for legal duties or over-claiming from a certificate.
Comparison table
| Dimension | ISO/IEC 42001 | EU AI Act (2024/1689) | Kind of text |
|---|---|---|---|
| Nature | Voluntary management-system standard | Binding regulation where applicable | Standard vs legal requirement |
| Enforcement | Market / contractual; CB surveillance | Member State authorities; Article 99 fines | Legal requirement — Article 99 |
| Scope trigger | Organisation chooses AIMS scope | Articles 2–3 — AI systems, GPAI, operators | Legal requirement — if applicable |
| High-risk AI | Impact assessment in Annex A — organisational | Article 6, Annexes I/III — legal classification | Legal requirement vs standard control |
| Documentation | AIMS documented information | Articles 11, 53, Annex IV/XI — legal packs | Different artifacts |
| Certification | Accredited CB certificate | Conformity assessment / notified bodies for some routes | Legal requirement for listed routes |
| Harmonised standard | Not verified as conferring presumption of conformity as of 10 September 2026 | Commission may cite harmonised standards when published in OJ | Status — verify Commission/CEN-CENELEC sources |
EU AI Act dates — Article 113 (from regulation text)
Last verified 10 September 2026 against Article 113 of Regulation (EU) 2024/1689: entry into force 1 August 2024; Chapters I–II from 2 February 2025; GPAI and penalties from 2 August 2025; general application 2 August 2026; Article 6(1) Annex I product-embedded high-risk from 2 August 2027 in the original text. Regulation (EU) 2026/1744 amended Annex III and Annex I high-risk dates — Commission page presents 2 December 2027 and 2 August 2028. Counsel reads the amending regulation. This page does not determine YOUR dates.
- Article 99 maxima: up to EUR 35 000 000 or 7 % turnover for Article 5 prohibitions — statutory ceiling, not typical fine.
- ISO 42001 surveillance audits are CB contractual cycles — not Union penalties.
What to do now
- Run EU AI Act applicability with counsel — use /docs/eu-ai-act/overview, not this page alone.
- If pursuing 42001, map AIMS artifacts to Act duties separately — see iso-42001-eu-ai-act-compliance page.
- Do not cite ISO 42001 certificate as EU AI Act conformity without legal analysis.
Checklist
- ☐ Legal track (Act) and voluntary track (42001) documented separately?
- ☐ Article 113 dates sourced from EUR-Lex, not vendor blogs?
- ☐ Harmonised-standard status checked on current Commission list?
Where this shows up in ShipReady Metrics
The bundled eu_ai_act and ISO 42001 entries in the 24-framework crosswalk are separate framework keys. Marking either in-scope on the obligation map is not a legal determination. AI inventory and AI risk register support both tracks as recorded posture — not filings with authorities.