Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How does ISO 42001 compare to the EU AI Act?

Last verified

ISO 42001 is a voluntary management-system standard. The EU AI Act is binding Union law where it applies. They overlap in governance themes but do not substitute for each other. Not legal advice.

Comparison, last verified 10 September 2026 against ISO/IEC 42001:2023 and Regulation (EU) 2024/1689 Articles 1–6, 50, 51–56, 99, 113. Harmonised-standard presumption for 42001 not verified as of this date. Not legal advice.

Comparison table

ISO 42001 vs EU AI Act (not YOUR applicability; not legal advice)
DimensionISO/IEC 42001EU AI Act (2024/1689)Kind of text
NatureVoluntary management-system standardBinding regulation where applicableStandard vs legal requirement
EnforcementMarket / contractual; CB surveillanceMember State authorities; Article 99 finesLegal requirement — Article 99
Scope triggerOrganisation chooses AIMS scopeArticles 2–3 — AI systems, GPAI, operatorsLegal requirement — if applicable
High-risk AIImpact assessment in Annex A — organisationalArticle 6, Annexes I/III — legal classificationLegal requirement vs standard control
DocumentationAIMS documented informationArticles 11, 53, Annex IV/XI — legal packsDifferent artifacts
CertificationAccredited CB certificateConformity assessment / notified bodies for some routesLegal requirement for listed routes
Harmonised standardNot verified as conferring presumption of conformity as of 10 September 2026Commission may cite harmonised standards when published in OJStatus — verify Commission/CEN-CENELEC sources

EU AI Act dates — Article 113 (from regulation text)

Last verified 10 September 2026 against Article 113 of Regulation (EU) 2024/1689: entry into force 1 August 2024; Chapters I–II from 2 February 2025; GPAI and penalties from 2 August 2025; general application 2 August 2026; Article 6(1) Annex I product-embedded high-risk from 2 August 2027 in the original text. Regulation (EU) 2026/1744 amended Annex III and Annex I high-risk dates — Commission page presents 2 December 2027 and 2 August 2028. Counsel reads the amending regulation. This page does not determine YOUR dates.

  • Article 99 maxima: up to EUR 35 000 000 or 7 % turnover for Article 5 prohibitions — statutory ceiling, not typical fine.
  • ISO 42001 surveillance audits are CB contractual cycles — not Union penalties.

What to do now

  • Run EU AI Act applicability with counsel — use /docs/eu-ai-act/overview, not this page alone.
  • If pursuing 42001, map AIMS artifacts to Act duties separately — see iso-42001-eu-ai-act-compliance page.
  • Do not cite ISO 42001 certificate as EU AI Act conformity without legal analysis.

Checklist

  • ☐ Legal track (Act) and voluntary track (42001) documented separately?
  • ☐ Article 113 dates sourced from EUR-Lex, not vendor blogs?
  • ☐ Harmonised-standard status checked on current Commission list?

Where this shows up in ShipReady Metrics

The bundled eu_ai_act and ISO 42001 entries in the 24-framework crosswalk are separate framework keys. Marking either in-scope on the obligation map is not a legal determination. AI inventory and AI risk register support both tracks as recorded posture — not filings with authorities.

Frequently asked questions