ISO 42001 vs the EU AI Act

A standard is voluntary and a regulation is not, and conformity with one is not compliance with the other. Both can be worth doing, for different reasons.

ISO 42001 is a voluntary AI management system standard; the EU AI Act is a binding law. Certifying to the standard does not satisfy the Act, and the two ask for different things.

Standard vs regulation

This is the sentence neither SERP writes plainly: conformity with ISO 42001 is not compliance with the EU AI Act. They are different instruments doing different jobs, and an organisation in EU scope can need both for different reasons (Cloud Security Alliance research note on prEN 18286). This page bridges the two clusters; it names the instruments and does not reproduce either one's text.

What is each one?

ISO/IEC 42001 is a voluntary management system standard: it sets out how an organisation governs the AI it develops and uses, and adopting it is a choice you make (ISO/IEC 42001:2023). The EU AI Act is a binding regulation that treats AI as a matter of product safety and applies to anyone within its scope (Regulation (EU) 2024/1689).

One is organisational and elective; the other is per-system and mandatory where it reaches you. That difference runs through everything below.

Does certification satisfy the Act?

No. The EU AI Office determined in May 2024 that ISO 42001 is not fully aligned with the Act and is not part of its harmonisation process, so certifying to it does not establish compliance (Cloud Security Alliance research note on prEN 18286). A certificate is useful evidence of good governance, but it is not a defence to an obligation the Act places on you.

The AI-specific harmonised standard is EN 18286. CEN-CENELEC ratified it on 12 July 2026 (CEN-CENELEC on the publication of EN 18286), the first European standard published to support the Act, and BSI has issued it in the UK as BS EN 18286:2026 (BSI on BS EN 18286:2026). It is written around the quality management system the Act requires at Article 17. Publication is not the same thing as citation, though: Article 40 gives a presumption of conformity only to standards whose references have appeared in the Official Journal, and EN 18286's has not. The Commission is expected to publish it later in 2026, and until then there is no presumption here to rely on.

What overlaps, and what does neither cover?

They overlap on governance discipline: both want you to know what AI you run, to manage its risks, and to keep humans able to oversee it. Doing ISO 42001 well makes the Act's organisational expectations easier to meet, and the work is not wasted.

Neither, on its own, is the whole picture. The standard does not make you compliant with a law, and the Act does not give you a running management system. An organisation that only certifies can still miss a binding duty; one that only reacts to the Act can lack the system to keep doing so.

Laid side by side, the gaps are the useful part. Two clauses have nothing in the Act to point at, and one of the Act's live duties has no clause behind it at all.

ISO 42001 clauses against the nearest duty in the Act. A reading aid, not a conformity mapping: neither document was written against the other.
ISO 42001Nearest in the ActWhere they meet, and where they do not
Clause 4Context, scope and your roleArticle 2, Article 3The closest fit in the table. Both start by asking what AI you run and which hat you wear for each system, and both make that answer decide everything after it.
Clause 5Leadership and policyNo direct counterpartThe Act binds roles, not policies. It never asks for an approved AI policy, which is one reason certifying does not discharge a duty.
Clause 6Risk, objectives and impact on peopleArticle 6 classification, then the duties that followThe standard asks you to run a risk process. The Act decides, by classification, whether a heavier set of obligations attaches at all.
Clause 7Competence and AI literacyArticle 4The one place the two nearly say the same thing, and it is live today whatever your risk tier.
Clause 8Operational controls and data governanceArticle 14 human oversight, and the data duties on high-risk systemsBoth want a documented way of working that someone follows. The Act is prescriptive about oversight where the standard leaves the design to you.
Clauses 9 and 10Monitoring, audit, review and improvementPost-market monitoring and incident duties on high-risk systemsThe standard makes this a cycle you run forever. The Act attaches it to particular systems.
Annex AReference controlsNo direct counterpartControls to consider, not duties owed. Nothing in the Act asks for them by name.
No clauseTransparency to the people affectedArticle 50The row that runs the other way. This duty has applied since 2 August 2026 and no clause puts it on you, so a certified organisation can still be in breach of it.

How do you sequence work across both?

Start with the Act's scope, because it is the one that can bind you: a UK organisation with no EU customers, users or outputs used in the EU is not bound today (Article 2). The UK scope guide and the EU AI Act check settle that.

Then use ISO 42001 as the system that carries the governance, whether or not you certify. The readiness check shows where your management system stands, or work through the gap sheet offline, and the ISO 42001 hub and the EU AI Act hub hold the rest of each cluster.

Common questions

Does ISO 42001 certification satisfy the EU AI Act?
No. ISO 42001 is a voluntary management system standard; the EU AI Act is a binding regulation. The EU AI Office determined in May 2024 that ISO 42001 is not fully aligned with the Act and is not part of its harmonisation process, so certifying to it does not establish compliance with the Act.
What is the difference between the standard and the Act?
ISO 42001 governs how an organisation manages AI, and adopting it is a choice. The EU AI Act regulates AI as a matter of product safety and binds anyone within its scope. Conformity with the standard is not compliance with the law, and the two ask for different things.
Which harmonised standard will carry the Act’s presumption of conformity?
Not ISO 42001. It is EN 18286, ratified by CEN-CENELEC in July 2026 and the first European standard published to support the Act. It hasn't been cited in the Official Journal yet, so there is no presumption to claim from it. Once it is cited, Article 40 is the provision that turns conformity with the standard into a presumption of conformity with the Article 17 duty it was written around.