ISO42001 and The EU AI Act

[featured_image]
  • Version
  • Download 0
  • File Size 408.00 KB
  • File Count 1
  • Create Date September 5, 2026
  • Last Updated September 5, 2026

ISO42001 and The EU AI Act

ISO42001 and the EU AI Act: A Practical Compliance Guide ISO42001 and the EU AI Act comparison whitepaper cover, SAM Charter

ISO42001 and the EU AI Act are the two frameworks dominating every conversation about AI governance in Europe. However, the two are frequently confused. One is a voluntary management-system standard. The other is binding EU law, backed by fines of up to 7% of global turnover. This free SAM Charter whitepaper explains what each instrument actually does. It also shows where they converge, and why ISO42001 certification does not yet grant automatic AI Act compliance.

What ISO42001 Actually Covers

ISO/IEC 42001 is the world's first international standard for an AI Management System. It follows the same Harmonized Structure as ISO9001 and ISO27001, so certified organisations will recognise its shape immediately. Consequently, it sets out policies, roles, a risk process and a continual-improvement cycle. It does not, however, prescribe specific AI techniques or legal thresholds. Certification remains entirely voluntary, everywhere in the world.

Why the EU AI Act Is a Different Kind of Instrument

The EU AI Act, in contrast, is directly applicable law across all 27 member states. It classifies AI systems into fixed risk tiers, from prohibited practices to minimal risk. Each tier carries specific, non-negotiable obligations. As a result, an organisation cannot simply opt out, the way it can opt out of ISO certification. Furthermore, the Act applies extraterritorially, catching many UK and US organisations that have no EU legal entity at all.

The Compliance Gap Most Sales Conversations Skip

Here is the nuance that matters most: ISO42001 certification does not, by itself, grant a legal presumption of conformity with the AI Act. That presumption only follows once a harmonised standard is formally cited in the Official Journal of the EU. The relevant standard, EN 18286:2026, was approved in July 2026, but citation has not yet happened. Until it does, providers of high-risk AI systems still need to complete the Act's own conformity assessment route. Our whitepaper explains this gap in full, and what to do about it in the meantime.

Where ITAM Discipline Gives You a Head Start

Both frameworks assume an organisation already knows which AI systems it runs, where they came from, and who is accountable for them. That is an asset-management problem before it is a legal one. Organisations with a mature IT Asset Management practice are structurally closer to compliance than they realise. For this reason, SAM Charter's ITAM Surgery engagement often starts exactly here, by building the AI asset inventory both frameworks depend on.

Download the Free Whitepaper

Get the full picture. Inside is the legal timeline following the EU's Digital Omnibus, plus a side-by-side comparison table. There is also a seven-step roadmap for satisfying both frameworks together. Download 'ISO42001 and the EU AI Act' now, free from SAM Charter.

 

Attached Files

1 file
pdf
ISO42001 vs EU AI Act Whitepaper.pdf
300.76 KB

Leave a comment

Your email address will not be published. Required fields are marked *