Français

ISO 42001 and the AI Act: what certification proves, and what it does not

No, an ISO/IEC 42001 certificate does not make you compliant with the EU AI Act. Two verifiable reasons, and what the standard genuinely brings to a compliance file.

No. And the sufficient reason is verifiable by anyone: the Article 40 presumption of conformity is reserved for standards whose reference is published in the Official Journal of the European Union. No standard appears there under the AI Act, neither ISO/IEC 42001, nor any other.

This page deals with the ISO 42001 case. The general presumption mechanism, its three conditions and the state of the European standardisation programme are set out on the harmonised standards page: that is where the distinction sits between a standard in preparation, a published European standard, and a reference cited in the Official Journal. EN ISO/IEC 42001:2026 falls into the second category.

What is ISO/IEC 42001?

A management standard, not a product standard. It describes how an organisation organises itself around AI, not how an AI system must be designed, documented or tested. It is an international standard for an artificial intelligence management system: an organisational framework (policy, roles, risk analysis, controls, management review, continual improvement) in the tradition of ISO 9001 for quality or ISO/IEC 27001 for information security.

Its European version, EN ISO/IEC 42001:2026, was published on 18 March 2026, a date reported by a published analysis, not by an official source. It is an adoption: the international text becomes a European standard and is taken into national catalogues.

Does ISO 42001 make you compliant with the EU AI Act?

No, for two reasons, and one of them is enough. Its reference is not published in the Official Journal, so it opens no presumption under Article 40. And it was not written for the AI Act: it does not come from the standardisation request addressed to CEN-CENELEC.

Its reference is not published in the Official Journal

This is the sufficient reason. As at 24 August 2026, the date of our last check, no harmonised standard reference had been published in the Official Journal of the European Union under Regulation (EU) 2024/1689. Four official sources agree: the Commission’s harmonised standards portal, EUR-Lex, the AI Act Service Desk and the Commission’s standardisation page.

It is a dated fact, and it will expire. We recheck it at each update of this page.

It was not written for the AI Act

This is the substantive reason, and it explains why the first is unlikely to change soon.

The Regulation’s standardisation programme rests on a request addressed to CEN and CENELEC, Implementing Decision C(2025) 3871 final of 23 June 2025, titled “on a standardisation request […] as regards high-risk AI systems in support of Regulation (EU) 2024/1689”. Standards developed in response to that request are designed to serve the Chapter III requirements.

ISO/IEC 42001 is not among them. It is an ISO/IEC text taken up as a European standard, developed in an international framework and to its own purpose, predating the request, and outside its scope.

Does ISO 42001 overlap with Article 17?

Nobody can say, and that is precisely the problem: no mapping between the two could be identified. The commonest commercial argument is plausible on paper and contradicted by the only published analysis on the subject — but neither side rests on anything the Commission has published.

The most common commercial argument is that a management system conforming to ISO/IEC 42001 “covers the essentials” of the quality management system required by Article 17. It is plausible on paper, and it is contradicted by the only published analysis on the subject, which describes EN ISO/IEC 42001:2026 as a voluntary management standard that “was not developed in response to the Commission’s standardisation request, is not calibrated on Article 17 and does not cover its requirements”.

That analysis is not an official source, and we quote it as published. It nonetheless deserves to be set against the opposite claim, which rests on nothing: no mapping between ISO/IEC 42001 and Article 17 has been identified.

The careful position is therefore this. Certification brings organisational discipline (written policies, defined roles, periodic reviews, documentary traceability) and that discipline will be useful on the day Article 17 becomes applicable. It brings no coverage of a requirement that can be relied on.

Which standard does target Article 17?

A European standard built on Article 17 does exist, and it does not suffice either. This is the point the sales pitches leave out. A European standard attached to Article 17 has existed since July 2026, EN 18286:2026, exactly what the market is looking for when it buys ISO 42001. And it opens no presumption either, for want of a reference cited in the Official Journal. Its case is set out on the harmonised standards page.

The accurate formula holds for both: a published European standard, not yet harmonised.

So what is an ISO 42001 certificate for?

For organising yourself, and for showing a customer that you have. Two real things, and it would be dishonest to deny them.

Installing a discipline the Regulation will require. Written policies and procedures, risk management, data governance, traceable responsibilities, periodic review: an organisation running an AI management system is already used to documenting and being audited. On the day Article 17 becomes applicable (2 December 2027 for Annex III systems) that habit will be worth far more than a project started six months before.

Answering tenders. The certificate is recognised and third-party audited. That is a legitimate commercial argument, provided it is not presented as regulatory compliance.

What it does not do: reverse the burden of proof. Before a market surveillance authority, an ISO/IEC 42001 certificate excuses no Chapter III requirement, does not replace the Annex IV technical documentation, and is no substitute for the conformity assessment procedure.

How do you describe it without getting it wrong?

Name the certificate, never the compliance. ISO/IEC 42001 says something true about your management system and nothing about your conformity with the Regulation. Every accurate formulation keeps the two apart; every inaccurate one lets the first stand in for the second. Four wordings, and what they should be.

❌ Not to write✅ Accurate
“ISO 42001 certified, therefore AI Act compliant”“ISO 42001 certified; our AI Act compliance will rest on technical documentation and conformity assessment”
“ISO 42001 is the AI Act harmonised standard”“A published European standard, not yet harmonised”
“ISO 42001 covers the Article 17 requirements”“It installs management discipline; coverage of the requirements is established by nobody”
“Certification replaces conformity assessment”“It prepares for it; it is no substitute”

And if a vendor sells you AI Act compliance built on ISO 42001, one question places the seriousness of the offer: is the standard’s reference published in the Official Journal of the European Union?

What this page rests on

Articles 17, 40 and 42 of Regulation (EU) 2024/1689 in the consolidated version of 27 July 2026, the authentic text remaining the one published in the Official Journal. Implementing Decision C(2025) 3871 final of 23 June 2025 for the standardisation request. The state of harmonised standardisation is established on four official sources checked on 24 August 2026. The characterisation of EN ISO/IEC 42001:2026 against Article 17 comes from a published analysis, quoted as published and flagged as unofficial: it is the only one available, and it has no counterpart in the opposite direction.

Sources. Regulation (EU) 2024/1689, consolidated text of 27 July 2026 and Regulation (EU) 2026/1744, both consulted on 27 August 2026.

Frequently asked questions

Does an ISO/IEC 42001 certificate make me compliant with the AI Act?

No. The Regulation attaches effect to a certificate only in specific cases, and ISO/IEC 42001 falls into none of them: it does not open the Article 40 presumption, for want of a reference published in the Official Journal; it is not one of the specific presumptions in Article 42; and it does not replace the conformity assessment procedure. It is a governance asset, not proof of compliance.

Is ISO 42001 a harmonised standard?

No. EN ISO/IEC 42001:2026 is a European standard published in March 2026 according to the only published analysis available (no official source states the date) and it is the European adoption of an international standard. Becoming a harmonised standard takes one further step: publication of its reference in the Official Journal of the European Union by an implementing act. That has not happened, and no standard benefits from it to date under the AI Act.

Does it at least cover the Article 17 requirements?

The only published analysis on the point concludes the opposite: developed outside the standardisation request addressed to CEN and CENELEC, it is not calibrated on Article 17 and does not cover its requirements. Treat any claim of overlap with caution: what certification brings is organisational discipline, not coverage of regulatory requirements.

Is there a standard actually calibrated on the AI Act?

Yes, and this is the point nobody makes: EN 18286:2026, published by CEN-CENELEC in July 2026, is titled Artificial intelligence – Quality management system for EU AI Act regulatory purposes and attaches explicitly to Article 17. But its reference is no more published in the Official Journal: it too opens no presumption.

Read next

This content is a technical and regulatory information resource. It does not constitute legal advice.