Help understanding and complying with the new EU rules for artificial intelligence.

Rechtsstand: 2. September 2026

Regulation (EU) 2024/1689 · Legal status September 2026

The EU AI Act is here. The only question left is how well prepared you are.

Since August 2, 2026, the AI Regulation has been largely in effect. The Digital Omnibus has softened some deadlines — but not the obligation to know which AI you use and who is responsible for it.

  • Current deadlines under the Digital Omnibus of July 2026
  • Concrete examples from eight industries
  • Honest assessment: what ISO 42001 covers — and what it doesn't
ISO-42001-Signet
Aug 2, 2026
AI Regulation generally applicable

Transparency obligations under Art. 50 take effect

Dec 2, 2027
High-risk AI under Annex III

postponed by the Digital Omnibus

Aug 2, 2028
AI in regulated products (Annex I)

postponed by the Digital Omnibus

up to €35 million
Fine framework

or 7% of global annual turnover for prohibited practices

Deadlines

What applies when — as of September 2026

The Digital Omnibus on AI was published in the Official Journal on July 24, 2026, and entered into force on July 27, 2026. It significantly postpones the obligations for high-risk AI — everything else remains in place.

  1. February 2, 2025

    Prohibited AI practices (Art. 5) and AI literacy obligation (Art. 4)

    applies — unaffected by the Omnibus
  2. August 2, 2025

    Obligations for general-purpose AI models (GPAI, Art. 53)

    applies — enforcement since August 2026
  3. August 2, 2026

    General applicability of the Regulation, transparency obligations (Art. 50)

    has applied for one month
  4. December 2, 2027

    High-risk AI under Annex III (standalone systems)

    postponed, originally August 2, 2026
  5. August 2, 2028

    High-risk AI under Annex I (AI in regulated products)

    postponed

What the postponement does not mean: it is not an all-clear. Prohibited practices, AI literacy, transparency obligations and the GPAI rules already apply. And anyone who has to demonstrate high-risk compliance in 2027 does not have 15 months for it — rather, they must operate a functioning risk management system by then, one that requires data from ongoing operations.

Applicability

Two questions determine your obligations

1 – What role do you have? The regulation distinguishes above all between *providers* — those who develop an AI system or place it on the market under their own name — and *deployers*, who use an AI system under their own responsibility. Most companies are deployers. Deployer obligations are leaner, but they exist: use as intended, human oversight, information of affected persons, logging.

2 – Which risk class does the system fall into? Prohibited, high-risk, subject to transparency obligations, or minimal risk. You carry out the classification yourself — no one does it for you. And this is exactly where most fail: there is no register, so there is no classification either.

  • Prohibited

    Social scoring, emotion recognition in the workplace, untargeted scraping of facial images, and other practices under Art. 5. In effect since February 2025.

  • High risk

    including personnel selection, creditworthiness, access to education, critical infrastructure, law enforcement, plus AI in regulated products.

  • Subject to transparency obligations

    Chatbots, generated content, deepfakes: people must know that they are dealing with AI. In effect since August 2026.

  • Minimal risk

    the majority. No special obligations, but the AI competence obligation under Art. 4 still applies.

Eight industries, eight concrete cases

Abstract risk classes help no one. Here is how the regulation lands on the table in practice.

HR and Recruiting

Selection, promotion, performance evaluation — under Annex III generally high risk

A company uses automated CV screening. From December 2027, this will require risk management, evidence of data quality, logging, and documented human oversight. Those who start today will have the evidence by then. Those who start in 2027 will not.

Finance and Insurance

Credit scoring of natural persons and risk assessment in life and health insurance — high risk

A credit institution with AI-supported scoring must be able to explain which characteristics are factored in, how bias was checked, and who can override a rejection.

Health and Medical Technology

AI as a medical device falls under Annex I — deadline August 2028, but with full product conformity

A provider of image analysis software must integrate the AI requirements into its existing conformity assessment, not alongside it.

Industry and mechanical engineering

AI as a safety component in machinery — Annex I

A machine manufacturer with AI-supported fault detection on the press needs the AI documentation as part of the machinery conformity.

Public administration

Access to services, access to education, migration and law enforcement context — high risk, partly additional fundamental rights impact assessment

An authority that pre-sorts applications must keep the decision comprehensible and contestable — and inform those affected.

Education and further training

Admission, assessment, examination monitoring — high risk

A provider with automated exam assessment needs proof of fairness, error rates and a path to human review.

Software and SaaS

Role can shift from operator to provider — the most costly misjudgement in practice

A SaaS provider integrates a third-party model and markets the feature under its own name. This makes it a provider — with significantly more far-reaching obligations than its team assumes.

Retail and marketing

Chatbots, generated content, personalization — transparency obligations under Art. 50, since August 2026

A retailer with an AI chatbot and AI-generated product images must label both. This is not a future scenario, it applies now.

Where ISO 42001 structurally covers the obligations of the regulation

Not a substitute for a conformity assessment — but the structure in which the required evidence is generated in the first place.

What ISO 42001 provides for this

  • Risk management system (Art. 9)AI risk assessment and treatment across the entire lifecycle
  • Data and data governance (Art. 10)Requirements for the origin, quality and use of data
  • Technical documentation (Art. 11)Documented information and system inventory
  • Record-keeping obligations and logging (Art. 12)Monitoring, measurement, recording of AI systems
  • Transparency towards operators (Art. 13)Transparency and communication requirements
  • Human oversight (Art. 14)Roles, responsibilities, intervention options
  • Accuracy, robustness, cybersecurity (Art. 15)partially — cybersecurity mainly via ISO/IEC 27001
  • Provider's quality management system (Art. 17)that is exactly an AIMS according to 42001
  • AI literacy (Art. 4)Competence, training and awareness requirements
  • Conformity assessment and CE (Art. 43)not covered — separate procedure
  • Registration in the EU database (Art. 49)not covered — separate obligation
Coverage

Coverage

  • Risk management system (Art. 9)high
  • Data and data governance (Art. 10)high
  • Technical documentation (Art. 11)medium — the product-specific depth comes from Annex IV, not from the standard
  • Record-keeping obligations and logging (Art. 12)medium
  • Transparency towards operators (Art. 13)medium
  • Human oversight (Art. 14)high
  • Accuracy, robustness, cybersecurity (Art. 15)medium (combination with 27001 recommended)
  • Provider's quality management system (Art. 17)high
  • AI literacy (Art. 4)high
  • Conformity assessment and CE (Art. 43)none
  • Registration in the EU database (Art. 49)none

Plain text

What an ISO 42001 certificate delivers — and what it doesn't

A lot is currently being claimed in the market. So here is our position, as clearly as possible:

An ISO 42001 certificate establishes no presumption of conformity under the AI Act. This arises exclusively from harmonised standards listed in the Official Journal of the EU; the corresponding European standardisation work is still ongoing. Anyone who promises you otherwise is selling you a risk.

What ISO 42001 delivers: it forces your organisation to do what the regulation requires anyway — know which AI is in use, assign responsibility, assess risks, govern data, ensure oversight, handle incidents. And it has this externally audited. When an authority, a major client or an insurer asks, the difference between "we're working on it" and an audited management system is substantial.

Frequently Asked Questions about the EU AI Act

Very likely yes, as soon as you place AI systems on the market in the EU or their outputs are used in the EU. The regulation has effect beyond the EU border, similar to the GDPR.

From "we should sometime" to "we can prove it"

Fill out the self-check or directly calculate what ISO 42001 — alone or with 27001 — costs for you.