These two get talked about as if you had to choose between them. You do not. One is a law you may be obliged to follow. The other is a certificate you may choose to hold.
Confusing them wastes money in both directions: buying a certificate that discharges no legal duty, or treating a legal deadline as something a certificate makes go away.
The short version
| EU AI Act | ISO/IEC 42001 | |
|---|---|---|
| What it is | Regulation | Management system standard |
| Optional? | No, if it applies to you | Yes, always |
| Applies to | Specific AI systems, by risk class | How the organisation manages AI |
| Who says you comply | Ultimately a regulator | An accredited certification body |
| If you ignore it | Enforcement | Nothing, beyond commercial |
| Key date | 2 December 2027 for Annex III high-risk | None - certify when ready |
The Act asks: is this particular system safe and documented enough to be put on the market? The standard asks: does this organisation have a way of managing AI risk, and does it work?
Where they overlap and where they do not
The overlap is real, and it is why the question comes up at all. Both want risk assessment, documented roles, oversight of what AI systems do, and evidence that the oversight actually happens. If you build an AI management system to 42001, a decent share of what Annex III expects falls out of it. You will have an inventory, a risk method, clear accountability, and a record of decisions.
What 42001 will not do is classify your systems for you, produce the technical documentation the Act wants for a specific high-risk system, or satisfy a conformity assessment. Those are per-system obligations. A management system is organisational. The Act's heaviest duties attach to individual products.
It runs the other way too. The Act says nothing about whether your AI governance is any good as a practice, only whether particular systems clear particular bars. You can be compliant with the Act and still have no sensible way of deciding which AI projects to approve.
So do you need both?
It comes down to two questions, and they are worth answering in this order.
Does the Act apply to you, and how? Most organisations deploying AI internally are deployers rather than providers, and most internal agents are not Annex III high-risk. But "most" is not "all". Anything touching employment decisions, access to essential services, or evaluation of people deserves a careful classification rather than an optimistic one. If you land in Annex III, the obligations are not optional and a certificate does not stand in for them.
Is anyone asking you for assurance? This is the honest driver for 42001. If enterprise customers, procurement teams or partners are asking how you govern AI, a certificate answers in a form they can file. If nobody is asking, 42001 is a discipline you could adopt without paying to have it audited.
That gives four rough positions:
- Annex III systems and customers asking - you need Act compliance, and 42001 is a sensible frame to build it inside.
- Annex III systems, nobody asking - do the Act work. Certification is a later question.
- No Annex III systems, customers asking - 42001 is the useful one. Do not build a high-risk compliance programme you do not need.
- Neither - do the security work anyway, because an agent with unexamined reach into your systems is an operational risk regardless. Skip the paperwork until something changes.
The sequencing that saves money
If both apply, build the inventory once. Both start from the same question - what AI do we actually have, who owns it, what does it touch - and that inventory is the expensive part. Everything else is a different view over the same facts.
Start logging early too. The Act's high-risk obligations are evidentiary: monitoring, incident handling, records showing that oversight happened. A certification audit asks much the same. Neither is satisfied by a document written the month before the deadline, and both are satisfied cheaply by systems that were already producing records.
About the dates
The Digital Omnibus deferred Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I to 2 August 2028. Worth knowing precisely, because the delay is narrower than the headline suggests: Article 50 transparency duties applied from 2 August 2026 and were not deferred, and the Article 4 AI literacy duty has been in force since February 2025.
ISO/IEC 42001 has no deadline at all. That is a real difference in how you plan. The Act sets a date you work back from. The standard sets a bar you reach when you are ready. If a vendor tries to sell you urgency about 42001, be sceptical - there is none to sell.
One thing to be careful about
Nobody can certify you against ISO/IEC 42001 except an accredited certification body. Any consultancy, us included, can only prepare you for that audit. If someone offers to certify you directly, that is a reason to stop, not a shortcut.
We help ServiceNow-based organisations work out which of these actually applies to them, and prepare for whichever does - that is what an AI agent audit is for. If you would rather have that conversation than read another comparison table, get in touch.
This is a practical summary, not legal advice. Dates reflect the Digital Omnibus agreement as confirmed by the Council on 29 June 2026. Check your own obligations with counsel.
