If your company is based in the United States and sells software, services or products into the European Union, here is the short answer. The EU AI Act is law and you may well be inside its reach. ISO/IEC 42001 is a voluntary standard you can certify to. And as of September 2026, holding a 42001 certificate does not give you any presumption of conformity with the AI Act. The two work at different layers. The Act says what a high-risk AI system must do and prove before it can be sold in the EU. ISO 42001 says how to run the organization that builds, buys or operates that system. Used together they cover most of what a regulator or customer will ask; used alone, neither finishes the job.
The question we hear most often from US clients is "do we need both?" The answer depends on what you sell and to whom, so here is what each one requires, where they overlap, what changed in 2026, and what to do this quarter.
What ISO 42001 is, and what it is not
ISO/IEC 42001:2023 was published in December 2023. It is a management system standard in the same family as ISO 9001 and ISO 27001, and it follows the same Annex SL structure, so clauses 4 to 10 will look familiar to anyone who has run one of those systems. Annex A adds the AI-specific controls, grouped into nine control areas. The standard is certifiable by accredited certification bodies.
A few clauses do most of the work. Clause 4 defines which AI systems are in scope and what interested parties expect of them. Clause 6.1 sets up the AI risk assessment, the risk treatment plan and, in 6.1.4, the AI system impact assessment: a documented look at how a system could affect individuals, groups and society, and not only the organization itself. Clause 8 turns those plans into operation, and 8.4 requires the impact assessments to actually be performed and kept. Clause 9 covers monitoring, internal audit and management review. Supplier and third-party AI sits in the Annex A control area on third-party and customer relationships.
What ISO 42001 does not do is set technical requirements for the AI systems themselves. It does not say what accuracy a model must reach, how training data must be curated, or what logging a system must produce. It governs the organizational layer: roles, policies, risk processes, documentation and review. That distinction is the whole reason 42001 cannot, by itself, satisfy the EU AI Act. For a fuller tour, see our clause-by-clause breakdown.
What the EU AI Act actually requires
The EU AI Act (Regulation (EU) 2024/1689) is binding law with fines scaled to global revenue. Using a prohibited AI practice can draw a fine of up to EUR 35 million or 7 percent of worldwide annual turnover, whichever is higher. Breaching the high-risk obligations runs to EUR 15 million or 3 percent.
The Act sorts AI systems into four tiers.
Prohibited practices. Social scoring by public authorities, most real-time remote biometric identification in public spaces, and AI that manipulates behavior through subliminal techniques. Banned since 2 February 2025.
High-risk systems. Two routes in. Annex I covers AI that is a safety component of, or is itself, a product already subject to EU product law, such as medical devices and machinery. Annex III lists standalone use cases: employment, access to credit and insurance, education, critical infrastructure, law enforcement, migration and the administration of justice.
Limited-risk systems. Chatbots, emotion recognition and AI-generated content carry transparency duties under Article 50. People must be told they are dealing with AI, and synthetic content must be marked.
Minimal-risk systems. Everything else, which is most AI in use today.
For high-risk systems, Articles 9 through 17 set the substance: a lifecycle risk management system (Article 9), data governance (Article 10), technical documentation (Article 11), automatic logging (Article 12), transparency and instructions for deployers (Article 13), human oversight designed into the system (Article 14), accuracy, robustness and cybersecurity (Article 15), and a quality management system covering the provider's whole development and deployment chain (Article 17). Providers also need a conformity assessment, CE marking and EU database registration before the system goes to market.
General-purpose AI models, including the large language models most companies build on, have their own obligations under Chapter V, in force since 2 August 2025 for model providers.
The extraterritorial scope US companies underestimate
The AI Act applies to you if you place an AI system on the EU market, put it into service in the EU, or the output of your system is used in the EU. Where the company is incorporated does not matter. That is the same logic that pulled US companies into GDPR in 2018.
US companies likely to have obligations include:
- SaaS providers whose AI features are used by EU customers, or by EU-based employees of US customers
- HR technology vendors whose screening, ranking or performance tools touch candidates or workers in the EU
- Fintech and insurtech firms whose AI-assisted credit, underwriting or fraud decisions affect EU residents
- Medical device, diagnostic and life sciences companies with any EU market presence, where Annex I applies through the existing device regulations
The Act also distinguishes providers, who place a system on the market under their own name, from deployers, who use one professionally. Providers carry most of the high-risk obligations, but deployers of high-risk AI have real duties too: use the system as instructed, assign human oversight, keep the logs, and in some cases run a fundamental rights impact assessment. Most US companies are both, depending on the system, and a company that fine-tunes a vendor model and sells it under its own brand has become a provider whether it intended to or not.
ISO 42001 vs. EU AI Act side by side
| Dimension | ISO/IEC 42001:2023 | EU AI Act (Regulation (EU) 2024/1689) |
|---|---|---|
| Nature | Voluntary standard, certifiable | Binding law, enforceable |
| Who it applies to | Any organization that develops, provides or uses AI, by choice | Providers, deployers, importers and distributors of AI on the EU market or whose output is used in the EU |
| Geographic reach | Global, self-selected | Extraterritorial |
| Risk approach | Management system with AI risk and impact assessments | Tiered classification: prohibited, high, limited, minimal |
| Core obligation | Build, operate and improve an AI management system | Meet tier-specific technical and organizational requirements |
| Enforcement | Certification body audits; loss of certificate | Market surveillance authorities and the EU AI Office; fines up to EUR 35M or 7% of turnover |
| Timeline | At your own pace; four to twelve months is typical | Phased: prohibitions Feb 2025, GPAI Aug 2025, high-risk Dec 2027 and Aug 2028 under the 2026 revisions |
| Verification | Accredited third-party certification | Conformity assessment; notified bodies for some high-risk systems |
| Technical requirements | None on the AI system itself | System-level: data governance, logging, human oversight, accuracy and robustness |
| Status under the Act | EN ISO/IEC 42001:2026 adopted March 2026; not cited in the Official Journal, so no presumption of conformity | Harmonized standards still being written; prEN 18286 for quality management is due late 2026 |
For a comparison that includes the NIST framework, see ISO 42001 vs NIST AI RMF vs EU AI Act.
Does ISO 42001 certification give a presumption of conformity with the AI Act?
Not today. This is the point that changed in 2026, and it is the one most older articles get wrong.
The AI Act works the way EU product law usually works. The European Commission asks the European standards bodies, CEN and CENELEC, to write harmonized standards for the Act's requirements. Once a harmonized standard is cited in the Official Journal of the European Union, a provider who follows it is presumed to comply with the requirements it covers, which turns an open-ended legal duty into an auditable checklist.
On 18 March 2026, CEN-CENELEC adopted EN ISO/IEC 42001:2026, bringing the ISO standard into the European system. But adoption as a European standard and citation as a harmonized standard are two different things. As of this writing, no harmonized standard for the AI Act has been cited in the Official Journal, EN ISO/IEC 42001:2026 included. So a 42001 certificate, on its own, does not create a presumption of conformity with any article of the Act.
The standard being written to do that job for Article 17 is prEN 18286, the quality management system standard for AI Act purposes, currently a draft with a target of late 2026. It is expected to draw on 42001's structure while adding the system-level requirements the Act demands, so an organization already running a 42001 system should be well placed when it arrives. Other harmonized standards are on a similar track, and the high-risk dates were pushed back partly so providers would have standards to work against.
The practical reading for a US company: build the management system now, because you will need one under Article 17 regardless. Do not tell your EU customers, or your own board, that the certificate closes the AI Act question.
How ISO 42001 builds your EU AI Act foundation
Even without the presumption, the overlap is substantial and the work carries over.
- The clause 6.1 risk assessment and treatment feed directly into the lifecycle risk management system Article 9 requires.
- The AI system impact assessment under clauses 6.1.4 and 8.4 produces most of what a deployer needs for a fundamental rights impact assessment under Article 27, and much of what a provider needs for the instructions for use under Article 13.
- The Annex A controls on data for AI systems and on third-party relationships give you a home for the Article 10 data governance duties and the supply-chain obligations that run through the Act.
- The whole standard is a quality management system for AI, which is the shape Article 17 asks for.
Where the Act goes beyond 42001 is at the system level: the data governance, logging, engineered human oversight and accuracy requirements of Articles 10 to 15, and the conformity assessment that gates entry to the EU market. These are engineering and product decisions a management system standard will not make for you. What the management system does is make sure someone owns those decisions, that they are documented as they are made, and that they get revisited.
In our experience the organizations that struggle here are rarely the ones that did nothing; they are the ones that did sensible things and cannot show it. Companies that already run ISO 9001 or ISO 27001 tend to get there fastest; see what 42001 adds to a 9001 system if that describes you.
The timeline US companies are actually working with
Parts of the Act are already in force. The high-risk dates moved in 2026, and many articles still show the original schedule.
- 2 February 2025: prohibited practices banned. In force.
- 2 August 2025: obligations for general-purpose AI model providers. In force.
- 2 August 2026: the original general application date for the remaining provisions, including the Article 50 transparency duties. Under the 2026 revisions the high-risk obligations were carved out and moved to the dates below; check the current status of the transparency duties for your own systems.
- December 2027: high-risk obligations for Annex III use cases, under the 2026 revisions.
- August 2028: high-risk obligations for Annex I systems (AI embedded in regulated products such as medical devices), under the 2026 revisions.
Treat those last two as the current plan; the revisions were tied partly to the availability of harmonized standards, and the dates could move again.
On the ISO side, the typical path from gap assessment to certificate is four to twelve months. Two things extend that in 2026. Certification bodies are reporting auditor backlogs, and some Stage 2 audits have waited six months or more. And the certified population is still small: fewer than 100 organizations held a certificate in January 2026 and roughly 350 did by spring. Our realistic timeline article walks through the phases.
Put those two schedules together and a US company that wants a certificate before the December 2027 date, with time left for the Act's system-level work, should be starting the gap assessment in the next two quarters.
What a US company selling into the EU should do now
A short list, in the order we would run it.
-
Inventory every AI system you provide, deploy or embed. Include AI features inside SaaS tools and vendor models under your own product. For each one, record whether it reaches the EU and whether it falls into Annex I, Annex III, the Article 50 tier, or none of them. A 42001 auditor asks for the same list.
-
Decide, per system, whether you are a provider or a deployer. A provider of a high-risk system owns the conformity assessment, the technical file, the Article 17 quality management system and the EU database registration. A deployer owns oversight, logging, following the instructions for use and, for some uses, a fundamental rights impact assessment.
-
Run a gap assessment against ISO 42001. Whether or not you plan to certify, a structured assessment gives you a roadmap and tells you which of the Act's organizational requirements you already meet. Our fixed-fee gap assessment is $9,750.
-
Start the technical documentation now for anything that could be high-risk. Articles 11 and 12 cannot be satisfied retroactively. Logging that was never switched on cannot be recovered, and a technical file assembled two years after the design decisions is thin exactly where a notified body will probe.
-
Watch prEN 18286, and do not forget US law. Once the harmonized standards are cited in the Official Journal, following them will be the fastest route to conformity, so keep your 42001 documentation modular enough to absorb them. At home, Texas's TRAIGA took effect on 1 January 2026, and Colorado replaced its 2024 AI Act with a narrower law, SB 26-189, effective 1 January 2027.
If you are an FDA-regulated manufacturer using AI inside the quality system, there is a sixth item. In April 2026 FDA issued a warning letter citing "inappropriate use of artificial intelligence" under 21 CFR 211.22(c), where AI-written specifications, procedures and master records had been released without qualified review. Our AI-in-the-quality-system review at $5,000 is built for that question, and the GMP manufacturers page explains how 42001 fits alongside a quality system you already run.
The competitive dimension
In our experience, the organizations that treat AI governance as part of how they sell end up ahead on the things that decide enterprise deals: security questionnaires, procurement reviews, and the growing set of customers who now ask, in writing, how a vendor governs its AI. With only a few hundred certificates issued worldwide, ISO 42001 is still rare enough to stand out in that conversation. As the harmonized standards arrive and the high-risk dates approach, documented AI governance will shift from a differentiator to a baseline expectation, in Europe first and then in US enterprise procurement.
If you want a clear picture of where you stand before committing to a full implementation, start with the ISO 42001 consulting overview or get in touch and we will tell you plainly whether you need a gap assessment, an AI records review, or neither yet.
Frequently Asked Questions
Does ISO 42001 certification satisfy the EU AI Act?
No. EN ISO/IEC 42001:2026 was adopted as a European standard in March 2026, but it has not been cited in the Official Journal as a harmonized standard, so a certificate gives no presumption of conformity with the Act. The standard being written for that job is prEN 18286, expected in late 2026.
Does the EU AI Act apply to US companies?
Yes, if you place an AI system on the EU market, put it into service there, or the output of your system is used in the EU. Where the company is incorporated does not matter, which is the same logic GDPR used in 2018.
When do the EU AI Act high-risk obligations take effect?
Under the 2026 revisions, high-risk obligations for Annex III use cases apply from December 2027 and for Annex I regulated products from August 2028. The prohibitions (February 2025) and the general-purpose AI model obligations (August 2025) are already in force.
Should a US company pursue ISO 42001 before the AI Act deadlines?
If you sell into the EU with anything that could be high-risk, building the management system now is sensible, because Article 17 requires a quality management system and 42001 is the only certifiable AI management system standard today. The certificate itself does not replace conformity assessment.
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.