Since 2 August 2026, the EU AI Act has been largely applicable. Since then we have been asked the same question almost daily, usually in this form: “If we get certified to ISO 42001, are we then AI Act compliant?”
The short answer is: no. The longer answer is more interesting, because it explains why certification is nevertheless the most sensible first step. These are two different things that answer different questions. Treat them as equivalent and you buy a false sense of security. Play them off against each other and you throw away work you would otherwise have to do twice.
“The AI Act says what you are allowed to do. ISO 42001 says how you prove you have it under control. One does not replace the other — it makes it affordable.” – Christian Paredes, CEO Eucerta AG
A law and a standard: the difference decides everything
The EU AI Act is a regulation. It applies directly, without any national law having to transpose it, and no one can decide not to apply it. It classifies AI systems by risk: prohibited practices, high-risk systems, systems subject to transparency obligations, and the large remainder with minimal risk. Attached to this are obligations, regulatory supervision and fines.
ISO 42001:2023 is a standard. It is voluntary — and certifiable. It does not prescribe which AI is permitted. It describes how an organisation builds an AI management system: which systems are running, who is responsible for them, what impacts they have, which measures are in place, and how you know those measures are working.
That is the whole difference, and it has consequences. A law defines limits. A management standard builds the organisation that remains able to operate within those limits. No auditor in the world can certify that you are “AI Act compliant” — that determination is ultimately made by an authority or a court. What an auditor can certify is a functioning management system. And that is the evidence that procurement departments, customers and supervisory authorities actually want to see in practice.
What really applies to your company — as of September 2026
This is worth a close look, because the deadlines have shifted. The Digital Omnibus pushed back the obligations for high-risk AI, but left the rest untouched. According to the European Commission's timeline, the following currently applies:
- Since 2 February 2025: prohibited AI practices and the obligation to ensure AI literacy among your own staff.
- Since 2 August 2025: obligations for providers of general-purpose AI models.
- Since 2 August 2026: general applicability of the regulation, including transparency obligations.
- From 2 December 2027: high-risk AI under Annex III, i.e. standalone systems in areas such as recruitment or education.
- From 2 August 2028: high-risk AI embedded in regulated products.
Do not read the postponement as an all-clear. Two obligations affect practically every company that uses AI today. The first is AI literacy: your employees must understand what they are working with. The second is transparency: anyone speaking with a chatbot or presented with AI-generated content must be able to recognise it. Neither is a question of Annex III. Both apply now.
And the fines are not a bogeyman, but tiered. Article 99 of the regulation specifies up to €35 million or 7 percent of global annual turnover for prohibited practices, up to €15 million or 3 percent for breaches of obligations, and up to €7.5 million or 1 percent for providing incorrect information to authorities. For small and medium-sized enterprises and start-ups, the lower of the two figures expressly applies. That eases the burden, but it excuses nothing.
Where the two overlap — and where the gap remains
The overlap is large, and it lies exactly where the work arises. Both sets of rules assume that you know which AI systems are running in your organisation. Both require an assessment of risks and impacts. Both want named responsible persons, traceable documentation and human oversight of automated decisions.
Anyone who builds an AI management system to ISO 42001 does this groundwork just once. The inventory of AI systems, the impact assessment for each system, the role assignment as provider, deployer or user — that is the same substance from which the answers to every supplier questionnaire and every regulatory enquiry are drawn.
You need to see the gap just as clearly. ISO 42001 does not do the legal classification for you. Whether one of your systems falls under Annex III, whether you are a provider or merely a deployer, which transparency notices your products must carry: these are legal questions, and the standard does not answer them. It only provides the basis on which they become answerable at all. We say this openly — on our EU AI Act page just as here.
The sequence we recommend to companies
Start with the inventory, not with the legal question. As long as no one in the organisation can say which AI tools are in use in which department, any risk classification is speculation. In practice, this first step is almost always the most instructive: there are more systems than management expects.
Then build the management system and have it audited. That gives you structure, responsible persons and evidence. Only afterwards do you classify your systems into the risk categories of the regulation and derive the specific obligations. For most small and medium-sized enterprises using common office and sales AI, this second step is considerably smaller than feared.
The effort is plannable. With us, the first standard costs €179 per month, each additional one €149, with a 36-month term and a fixed price for companies with up to 30 employees. ISO 42001 is frequently bundled with ISO 27001, because information security and AI governance share around half of the system requirements. What your case costs, you can work out in the cost calculator, with no form and no sales call.
One more point, because it is often overlooked: with us, certificates are valid for three years from the audit date. A company's AI landscape changes considerably over three years. That is precisely why a management system that lives in a platform and is maintained between audits is worth more than a folder that goes to sleep after the audit.
Conclusion
ISO 42001 and the AI Act are not an either-or. Anyone who looks only at the law collects individual answers and has no system. Anyone who looks only at the standard has a good system and may overlook a legal obligation. The sustainable position is both: a certified management system as the foundation, legal classification as the review built on top of it.
The advantage of this sequence is that you can start immediately. The legal question cannot be answered without a system inventory — and the system inventory can be started today.
Your next step: Work out in the cost calculator what ISO 42001 means for your company, or check via express certification how quickly it can be done in your case.
Further reading:




