Browse all tools and resources →

Read me Page help ↗
Observatory

ISO/IEC 42001 vs EU AI Act

The same obligation themes, side by side, from the catalogue that powers the rest of this site — 20 catalogued requirements across 16 themes. Expand any requirement to read it. Free, no login.

Comparing 2 of 38 regulations we track. This URL is the comparison — send it to anyone.

Guidance

ISO/IEC 42001 — AI Management System (AIMS)

Authority
ISO/IEC · International (certifiable)
Catalogued requirements
5, none mandatory
Themes it legislates on
5 of the 16 below
Maximum exposure
Certification standard — no penalties
Next dated obligation
Nothing dated ahead in our calendar
Official source last read
2026-10-05 — host refuses automated checks
In force

EU Artificial Intelligence Act (Reg. 2024/1689)

Authority
European Union · EU / EEA
Catalogued requirements
15, all mandatory
Themes it legislates on
15 of the 16 below
Maximum exposure
Up to €35M or 7% of global annual turnover (GPAI-specific: up to €15M or 3%)
Next dated obligation
2026-12-02 — EU AI Act — NCII/CSAM ban + end of marking grace period (in 55 days)
Official source last read
2026-10-07 — unchanged since our last read

Where they overlap

Every theme below appears in exactly one group, so these account for all 16 of them. Sharing a theme means both regimes legislate in that area — it does not mean complying with one discharges the other.

Both legislate here · 4 themes

ISO/IEC 42001 · EU AI Act

Risk management systemTechnical documentationMonitoring after deploymentIncident reporting

1 of the 2 legislates here · 11 themes

EU AI Actnot: ISO/IEC 42001

Outright bansRights impact assessmentData & training dataAccuracy, robustness & securityConformity assessmentRegistration & public listingTransparency & explanationTelling people AI was usedLabelling AI-generated contentHuman oversight & overrideLogging & records

1 of the 2 legislates here · 1 theme

ISO/IEC 42001not: EU AI Act

AI policy, roles & governance

Requirement by requirement

A dash means we have not catalogued a requirement for that regulation under that theme — a summary of our catalogue, not a finding that the law is silent. Always check the official text, linked from each regulation's page.

ThemeISO/IEC 42001EU AI Act
What is forbidden outright
Outright bans Are some uses forbidden regardless of safeguards? —
Art. 5 Prohibited AI practices must

Practices such as social scoring, manipulative/subliminal techniques, exploitation of vulnerabilities, untargeted facial scraping, and (most) real-time remote biometric identification are banned and cannot be placed on the EU market.

Read it in context →
What you must assess first
Risk management system Must you run a documented, continuous risk process?
Cl. 6 AI risk & impact assessment should

Plan the AIMS: perform AI risk assessment and AI system impact assessment, set objectives.

Read it in context →
Art. 9 Risk-management system must

Establish, document and maintain a continuous risk-management system across the AI lifecycle.

Read it in context →
Rights impact assessment Must you assess the impact on people before deploying? —
Art. 27 Fundamental Rights Impact Assessment must

Certain deployers must perform a Fundamental Rights Impact Assessment before putting the system into use.

Read it in context →
What you owe the data
Data & training data Are there duties on the data the system learns from? —
Art. 10 Data & data governance must

Training, validation and testing data must meet quality criteria and be examined for bias; document provenance and representativeness.

Read it in context →
What you must build and prove
Accuracy, robustness & security Must you hit and evidence performance targets? —
Art. 15 Accuracy, robustness & cybersecurity must

Achieve appropriate accuracy, robustness and cybersecurity, and declare metrics.

Read it in context →
Technical documentation Must a technical file exist before deployment?
Cl. 8 / Annex A Operational controls should

Implement Annex A controls (data, documentation, lifecycle, third parties) and a Statement of Applicability.

Read it in context →
Art. 11 / Annex IV Technical documentation must

Draw up and keep up-to-date technical documentation demonstrating conformity (the Annex IV technical file).

Read it in context →
Conformity assessment Must someone certify it before it goes to market? —
Art. 43 Conformity assessment must

Undergo the relevant conformity-assessment procedure and draw up an EU declaration of conformity before market entry.

Read it in context →
Registration & public listing Must the system be registered or published somewhere? —
Art. 49 EU database registration must

Register the high-risk system in the EU database before placing it on the market.

Read it in context →
What you must tell people
Transparency & explanation Must you explain how it works, and to whom? —
Art. 13 Transparency & instructions for use must

Provide deployers with clear instructions: capabilities, limitations, and required human oversight.

Read it in context →
Telling people AI was used Must people be told an AI was involved? —
Art. 50 Transparency for certain systems must

Inform people they are interacting with an AI system (chatbots) and label AI-generated/manipulated content.

Read it in context →
Labelling AI-generated content Must generated output be marked or watermarked? —
Art. 50(2) Marking of synthetic content must

Mark AI-generated audio, image, video or text in a machine-readable, detectable way.

Read it in context →
What you must do while it runs
Human oversight & override Must a person be able to intervene, review or stop it? —
Art. 14 Human oversight must

Design the system so humans can effectively oversee it, intervene, and stop it.

Read it in context →
Logging & records Must the system keep records of what it did? —
Art. 12 Record-keeping (logging) must

Automatically record events (logs) over the system lifetime to ensure traceability.

Read it in context →
Monitoring after deployment Must you keep watching it once it is live?
Cl. 9 Performance evaluation should

Monitor, measure, audit and review AIMS performance.

Read it in context →
Art. 72 Post-market monitoring must

Operate a post-market monitoring system to collect and review performance data after deployment.

Read it in context →
Incident reporting Must failures be reported, and to whom?
Cl. 10 Improvement & incidents should

Address nonconformities and continually improve the AIMS.

Read it in context →
Art. 73 Serious-incident reporting must

Report serious incidents and malfunctioning to the competent market-surveillance authority.

Read it in context →
What the organisation must carry
AI policy, roles & governance Must the organisation itself be governed, not just the system?
Cl. 5 Leadership & AI policy should

Top management establishes an AI policy, roles and responsibilities for the AI management system.

Read it in context →
—

Which one bites first

Every dated obligation attached to these regulations, merged into one timeline.

EU AI Act 2025-07-10 · in force

EU AI Act — GPAI Code of Practice published

The final GPAI Code of Practice (Transparency, Copyright, Safety & Security chapters) gives providers a voluntary route to demonstrate compliance ahead of harmonised standards.

EU AI Act 2026-08-02 · in force

EU AI Act — Art. 50 transparency obligations in force

Now live. Chatbots must disclose they are AI; deepfakes and emotion-recognition/biometric-categorisation uses must be disclosed. The Commission adopted final Art. 50 guidelines on 20 July 2026, and the AI Office's enforcement powers over GPAI providers (fines up to €15M or 3% of turnover) became applicable the same day. Providers' machine-readable marking of synthetic content under Art. 50(2) has a grace period to 2 Dec 2026.

EU AI Act 2027-12-02 · in 420 days

EU AI Act — serious-incident reporting (Art. 73)

Providers of high-risk systems must report serious incidents to authorities within 15 days (10 days on a death; 2 days for widespread infringement or critical-infrastructure disruption).

EU AI Act 2027-12-02 · in 420 days

EU AI Act — Annex III high-risk obligations apply

Full high-risk regime (risk management, data governance, logging, human oversight, accuracy, conformity assessment, registration). Moved from Aug 2026 to 2 Dec 2027 by the Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal 24 July 2026 and in force since 27 July 2026, so this date is settled law.

EU AI Act 2028-08-02 · in 664 days

EU AI Act — Annex I embedded high-risk obligations apply

High-risk AI embedded in regulated products (machinery, medical devices, vehicles) must comply. Moved from Aug 2027 to 2 Aug 2028 by the Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026.