ISO 42001 vs EU AI Act: how they complement each other
By Sam Rivera, Founder, SentinelPanda · May 30, 2026 · 3 min read · ISO 42001
Two different instruments answering related questions. Confusing them costs time and money; treating them as complementary is how mature programs use both.
Different instruments, different audiences
The EU AI Act is binding law in the European Union, enacted in 2024 with a phased application running through 2026 and 2027. It applies extraterritorially: providers and deployers of AI systems whose output is used in the EU are in scope, regardless of where the provider is established. Penalties for non-compliance reach into the tens of millions of euros or a percentage of global turnover, depending on the violation.
ISO 42001 is a voluntary international standard. It carries no fines; non-conformity affects your certificate, not your bank account. Its audience is buyers, partners, auditors, and regulators looking for evidence of a defensible AI governance programme.
What the AI Act requires
The AI Act takes a risk-based approach. It prohibits a narrow set of AI practices outright (social scoring, real-time biometric identification in public spaces with limited exceptions, and others). It classifies a defined set of use cases as high-risk and imposes specific obligations on providers and deployers of those systems: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity. General-purpose AI models carry their own set of obligations, with additional rules for systemic-risk models.
The Act is procedural. It tells you what conformity must look like (CE-marked high-risk systems, accessible technical documentation, post-market monitoring) but not in detail how to implement the underlying governance. That gap is where standards — including ISO 42001 — come in.
How ISO 42001 helps with AI Act compliance
Implementing ISO 42001 puts you in a strong position to demonstrate AI Act conformity, but it does not substitute for it. The Act explicitly anticipates harmonised standards — once published in the Official Journal, conformity with a harmonised standard creates a presumption of conformity with the corresponding requirements of the Act. ISO 42001 is widely expected to underpin some of those standards.
Even before formal harmonisation, an ISO 42001 AIMS gives you the documented programme that AI Act regulators will want to see — risk management, data governance, technical documentation, post-market monitoring, human oversight processes. You will still need to prove conformity to the Act specifically (especially for high-risk systems), but the work of building it is mostly the same work.
Where they differ in scope
The AI Act covers prohibited practices, high-risk classification with specific obligations, general-purpose AI model obligations, and transparency obligations for deepfakes and AI-generated content. ISO 42001 covers the management system: the policies, processes, and controls you use to govern AI development and deployment, irrespective of risk class.
Practically: the Act tells you which use cases are prohibited and which need additional safeguards; ISO 42001 tells you how to run the programme that produces those safeguards. Compliance with the Act for a specific high-risk system requires the conformity assessment the Act prescribes — your ISO 42001 certificate is not a substitute, but it is supporting evidence.
A pragmatic approach
- Map your AI systems against the AI Act risk classifications first — do any sit in prohibited or high-risk categories?
- Build the AIMS scaffolding (ISO 42001 clauses 4–10) as the operating system for whatever obligations the Act imposes.
- Run the AI Act-specific conformity assessment for each high-risk system, using the AIMS evidence wherever it applies.
- Track the publication of harmonised standards in the Official Journal of the EU — once published, they create the presumption of conformity that simplifies the Act's evidentiary burden.