Start with Maditon
← Back to Resource Center
EU AI Act · Standards 6 min read

EU AI Act vs ISO 42001 — what's the difference

ISO/IEC 42001 is the international AI management system standard. How it differs from the EU AI Act, where the two reinforce each other, and which to start with.


ISO/IEC 42001 — published December 2023 — is the world’s first management-system standard for artificial intelligence. The EU AI Act became law eight months later. The two are often confused, sometimes treated as alternatives, and almost always pitched together by consultants. This guide is the practical comparison.

The fundamental difference

The EU AI Act is law. It applies to anyone placing AI systems on the EU market or using them in the EU. You don’t choose to be in scope; you classify your way through it.

ISO 42001 is a voluntary management-system standard. It’s the AI equivalent of ISO 27001 (for information security) or ISO 9001 (for quality). You choose to implement it, and you can choose to be certified by a third party.

The two are complementary, not substitutable. A company can be:

  • Compliant with the AI Act without being ISO 42001 certified
  • Certified to ISO 42001 without satisfying every AI Act obligation
  • Both — which is the target posture for any serious AI provider

What each one actually covers

EU AI Act — what it regulates

The Act regulates AI systems and GPAI models placed on the EU market. It imposes:

  • Outright bans on certain practices (Art. 5)
  • Classification of systems into risk tiers
  • Provider obligations for high-risk systems (Art. 9–17)
  • Deployer obligations (Art. 26)
  • Transparency obligations (Art. 50)
  • GPAI obligations (Art. 53)
  • Conformity assessment, CE marking, EU database registration
  • Fines tied to violations

It is product-and-system focused, with specific obligations per system.

ISO 42001 — what it covers

ISO 42001 establishes an AI Management System (AIMS) — an organisational framework for governing AI activities. It covers:

  • Context of the organisation and its AI activities
  • Leadership and AI policy
  • Planning (objectives, risks, opportunities)
  • Support (resources, competence, awareness, communication, documented information)
  • Operation (operational planning, AI impact assessments, AI risk treatment)
  • Performance evaluation (monitoring, internal audit, management review)
  • Continuous improvement

It is organisation-and-process focused. It tells you how to run AI governance; the EU AI Act tells you what you must achieve for each system.

Where they reinforce each other

The overlap is substantial. A company with a mature ISO 42001 AIMS already has most of the organisational infrastructure to comply with the EU AI Act:

| Concept | EU AI Act | ISO 42001 | |---|---|---| | AI inventory | Implicit in Art. 9 risk management | Clause 4 (context) + Annex B controls | | AI policy | Implicit through governance documentation | Clause 5 (leadership) | | Risk assessment | Art. 9 | Clause 6.1, Annex B control 6 | | Impact assessment on people | Art. 27 (FRIA) for certain deployers | Annex B (AI impact assessment) | | Lifecycle controls | Articles 9–17 | Annex B (system lifecycle) | | Roles and responsibilities | Art. 4 (AI literacy) + Art. 26 (deployer) | Clause 5.3 + competence | | Documentation | Art. 11 + Annex IV | Clause 7.5 | | Internal audit | Implicit in risk-management system | Clause 9.2 | | Continuous improvement | Post-market monitoring (Art. 72) | Clause 10 |

If you run ISO 42001 properly, you generate roughly 60–70% of what the EU AI Act asks for as a byproduct.

Where they diverge

Three meaningful differences:

1. ISO 42001 is voluntary, the AI Act isn’t

Failing ISO 42001 means failing an audit. Failing the AI Act means fines.

2. ISO 42001 has no risk classification

ISO 42001 does not classify AI systems into tiers. It treats every AI system the same — and lets the organisation determine the risk through internal assessment. The AI Act mandates a specific classification (prohibited / high / limited / minimal) per system. The ISO standard accommodates the classification but doesn’t impose it.

3. ISO 42001 has no equivalent of the Article 5 prohibitions

ISO 42001 does not ban specific practices. Implementing ISO 42001 will not catch you if your AI system implements emotion recognition in the workplace (banned by EU AI Act Art. 5). The Act is harder-edged.

Which one to start with — the practical sequence

For a European SME:

  1. Classify your AI systems against the EU AI Act first. The Act is law. Knowing your classification (high / limited / minimal) drives every downstream decision.
  2. Implement the AI Act obligations for each system. Most teams can do this with disciplined process and a compliance platform — without formal ISO certification.
  3. Adopt ISO 42001 controls organically. Even without certification, lifting controls from ISO 42001 Annex B is one of the fastest ways to mature your AI governance.
  4. Consider ISO 42001 certification when commercially valuable. Certification is mainly valuable when enterprise customers ask for it in vendor assessments or when you operate across jurisdictions where ISO recognition matters.

The order matters: the AI Act has hard deadlines, now expected to be 2 Dec 2027 and 2 Aug 2028 (postponed from 2 August 2026 and 2 August 2027 under the Digital Omnibus, agreed May 2026 and pending formal adoption). ISO 42001 certification can be added later. Reversing the order — pursuing certification first and discovering an AI Act non-conformity in your scope statement — wastes effort.

Will ISO 42001 ever be a “harmonised standard” under the AI Act?

This is the question consultants get asked most. As of mid-2026, the answer is not directly. The European Commission has commissioned CEN-CENELEC JTC 21 to develop harmonised standards specifically for the AI Act. ISO 42001 informs that work, but the harmonised standards (when finalised) will be distinct, EU-specific, and will provide a presumption of conformity for the relevant AI Act obligations.

Most expert observers expect the eventual EU harmonised standards to draw heavily from ISO 42001’s structure. Companies that adopt ISO 42001 now should expect a relatively small step to the harmonised standards once they publish.

Where Maditon fits

The product is built around the EU AI Act because that’s the load-bearing regulation. The risk classifications, the dossier exports, the registration tracking, the human-acceptance workflow — they map directly to the AI Act’s structure. The same artefacts then map cleanly onto ISO 42001’s documentation requirements (Annex B controls), so customers who later pursue certification have most of the evidence already in the platform.