ISO 42001 vs the EU AI Act
A standard is voluntary and a regulation is not, and conformity with one is not compliance with the other. Both can be worth doing, for different reasons.
ISO 42001 is a voluntary AI management system standard; the EU AI Act is a binding law. Certifying to the standard does not satisfy the Act, and the two ask for different things.
This is the sentence neither SERP writes plainly: conformity with ISO 42001 is not compliance with the EU AI Act. They are different instruments doing different jobs, and an organisation in EU scope can need both for different reasons (Cloud Security Alliance research note on prEN 18286). This page bridges the two clusters; it names the instruments and does not reproduce either one's text.
What is each one?
ISO/IEC 42001 is a voluntary management system standard: it sets out how an organisation governs the AI it develops and uses, and adopting it is a choice you make (ISO/IEC 42001:2023). The EU AI Act is a binding regulation that treats AI as a matter of product safety and applies to anyone within its scope (Regulation (EU) 2024/1689).
One is organisational and elective; the other is per-system and mandatory where it reaches you. That difference runs through everything below.
Does certification satisfy the Act?
No. The EU AI Office determined in May 2024 that ISO 42001 is not fully aligned with the Act and is not part of its harmonisation process, so certifying to it does not establish compliance (Cloud Security Alliance research note on prEN 18286). A certificate is useful evidence of good governance, but it is not a defence to an obligation the Act places on you.
The AI-specific harmonised standard is EN 18286. CEN-CENELEC ratified it on 12 July 2026 (CEN-CENELEC on the publication of EN 18286), the first European standard published to support the Act, and BSI has issued it in the UK as BS EN 18286:2026 (BSI on BS EN 18286:2026). It is written around the quality management system the Act requires at Article 17. Publication is not the same thing as citation, though: Article 40 gives a presumption of conformity only to standards whose references have appeared in the Official Journal, and EN 18286's has not. The Commission is expected to publish it later in 2026, and until then there is no presumption here to rely on.
What overlaps, and what does neither cover?
They overlap on governance discipline: both want you to know what AI you run, to manage its risks, and to keep humans able to oversee it. Doing ISO 42001 well makes the Act's organisational expectations easier to meet, and the work is not wasted.
Neither, on its own, is the whole picture. The standard does not make you compliant with a law, and the Act does not give you a running management system. An organisation that only certifies can still miss a binding duty; one that only reacts to the Act can lack the system to keep doing so.
Laid side by side, the gaps are the useful part. Two clauses have nothing in the Act to point at, and one of the Act's live duties has no clause behind it at all.
| ISO 42001 | Nearest in the Act | Where they meet, and where they do not |
|---|---|---|
| Clause 4Context, scope and your role | Article 2, Article 3 | The closest fit in the table. Both start by asking what AI you run and which hat you wear for each system, and both make that answer decide everything after it. |
| Clause 5Leadership and policy | No direct counterpart | The Act binds roles, not policies. It never asks for an approved AI policy, which is one reason certifying does not discharge a duty. |
| Clause 6Risk, objectives and impact on people | Article 6 classification, then the duties that follow | The standard asks you to run a risk process. The Act decides, by classification, whether a heavier set of obligations attaches at all. |
| Clause 7Competence and AI literacy | Article 4 | The one place the two nearly say the same thing, and it is live today whatever your risk tier. |
| Clause 8Operational controls and data governance | Article 14 human oversight, and the data duties on high-risk systems | Both want a documented way of working that someone follows. The Act is prescriptive about oversight where the standard leaves the design to you. |
| Clauses 9 and 10Monitoring, audit, review and improvement | Post-market monitoring and incident duties on high-risk systems | The standard makes this a cycle you run forever. The Act attaches it to particular systems. |
| Annex AReference controls | No direct counterpart | Controls to consider, not duties owed. Nothing in the Act asks for them by name. |
| No clauseTransparency to the people affected | Article 50 | The row that runs the other way. This duty has applied since 2 August 2026 and no clause puts it on you, so a certified organisation can still be in breach of it. |
How do you sequence work across both?
Start with the Act's scope, because it is the one that can bind you: a UK organisation with no EU customers, users or outputs used in the EU is not bound today (Article 2). The UK scope guide and the EU AI Act check settle that.
Then use ISO 42001 as the system that carries the governance, whether or not you certify. The readiness check shows where your management system stands, or work through the gap sheet offline, and the ISO 42001 hub and the EU AI Act hub hold the rest of each cluster.