Guide
ISO 42001 and the EU AI Act: what they require and how they relate to ISO 27001
What AI governance means, what ISO/IEC 42001 is, what the EU AI Act requires after the 2026 Digital Omnibus amendment, and how both connect to an existing ISMS.
Summary
The EU AI Act is law: it defines prohibited AI practices, obligations for providers and deployers, transparency duties and requirements for high-risk AI systems. ISO/IEC 42001 is a voluntary management system standard describing how to govern AI in an organization. The AI Act says what; ISO 42001 offers a structured way to organize how. Both fit naturally into an existing ISO 27001 ISMS.
Most organizations already use AI — in office tools, customer service, software development or analytics. AI governance is about knowing where, deciding under which rules, and being able to show it.
The EU AI Act in brief
The EU AI Act entered into force in August 2024 and applies in stages. It sorts AI uses by risk:
- Prohibited practices — for example certain forms of manipulation or social scoring — have been banned since February 2025.
- AI literacy — providers and deployers must take measures to support the AI literacy of their staff. The 2026 amendment reframed this as an obligation of effort rather than a guaranteed level.
- General-purpose AI models have their own obligations for model providers.
- Transparency obligations apply to certain AI systems, for example when people interact with AI or AI-generated content.
- High-risk AI systems — for example in employment, education, credit scoring or critical infrastructure — face extensive requirements. The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) deferred these to December 2027 (Annex III) and August 2028 (Annex I).
Which obligations apply depends on your role (provider, deployer, importer, distributor) and your use cases. Binding legal assessments belong with legal counsel.
ISO/IEC 42001 in brief
ISO/IEC 42001 is the international standard for AI management systems (AIMS). It requires, among other things:
- an AI policy and objectives,
- defined roles and responsibilities,
- AI risk assessment and AI system impact assessment,
- controls across the AI lifecycle (data, development, operation, monitoring),
- attention to transparency, human oversight and third parties,
- internal audit, management review and improvement.
How they relate
The AI Act says what is required. ISO/IEC 42001 offers a structured way to organize how.
ISO/IEC 42001 does not automatically make you AI Act compliant, but it creates the governance structure in which AI Act obligations can be implemented, documented and reviewed.
How ISO 42001 relates to ISO 27001
Both follow the same management system structure. If you run an ISO/IEC 27001 ISMS, you can reuse:
- document control, roles and competence management,
- risk management methods (extended with AI-specific impacts),
- supplier management (for AI providers),
- internal audit, management review and corrective actions.
What is new is AI-specific: the AI inventory, impact assessments, data governance for training and input data, and controls for transparency and human oversight.
A practical first step: the AI inventory
Start with an overview: Which AI tools and systems are used, by whom, for what, with which data? Who approved them? This inventory is the basis for every further decision — and often reveals quick wins, such as clear rules for using generative AI with confidential information.
Frequently asked questions
What is AI governance?
The rules, responsibilities and processes an organization uses to control how AI is selected, developed, used and monitored — so that its use is secure, lawful, transparent and aligned with the organization's goals.
Is ISO 42001 mandatory?
No. It is a voluntary, certifiable standard. It can help structure and evidence governance that the AI Act and customers expect.
When do the high-risk obligations of the AI Act apply?
Following the Digital Omnibus amendment (Regulation (EU) 2026/1744), obligations for stand-alone high-risk systems under Annex III apply from 2 December 2027, and for AI embedded in products regulated under Annex I from 2 August 2028. Check the current legal situation for your specific case.
