The EU AI Act Decoded: Key Requirements and How They Map to ISO/IEC 42001
EU AI Act · ISO 42001 · AI Governance · AI Compliance · AIMS · Regulation 2024/1689 · Responsible AI · GRC
Regulation (EU) 2024/1689 — the EU AI Act — is the first comprehensive, horizontal law regulating artificial intelligence. It applies to any organisation that places AI systems on the EU market or whose AI outputs are used in the EU, regardless of where the company is headquartered. If GDPR taught us anything, it is that extraterritorial EU regulation shapes global practice. The AI Act will do the same.
A risk-based pyramid
The Act does not regulate "AI" as a monolith. It sorts systems into four tiers, and your obligations depend entirely on where you land.
At the top sit the prohibited practices (Article 5), banned since 2 February 2025: subliminal manipulation, exploitation of vulnerabilities, social scoring, predictive criminal risk assessment of individuals, untargeted scraping of facial images, emotion inference in workplaces and schools, biometric categorisation by sensitive attributes, and real-time remote biometric identification in public spaces. A ninth prohibition — AI capable of generating non-consensual intimate imagery or CSAM — was added by the 2026 AI Omnibus and applies from 2 December 2026. Violations carry the maximum penalty: €35 million or 7% of global annual turnover.
The second tier is high-risk AI (Article 6 and Annex III): AI used in biometrics, critical infrastructure, education, employment and worker management, access to essential services and credit, law enforcement, migration, and justice. Providers of these systems must implement a risk management system (Art. 9), data governance with bias controls (Art. 10), technical documentation (Art. 11), automatic logging (Art. 12), transparency to deployers (Art. 13), human oversight (Art. 14), accuracy and cybersecurity (Art. 15), and a full quality management system (Art. 17) — then pass conformity assessment, affix CE marking, and register in the EU AI database. Note the revised timeline: after the May 2026 AI Omnibus, Annex III high-risk obligations apply from 2 December 2027, and embedded product-safety AI from August 2028.
The third tier covers transparency obligations (Article 50) — chatbots must disclose they are machines, synthetic media must be labelled. Everything else is minimal risk. Separately, general-purpose AI model providers have been subject to documentation, copyright, and training-data-summary obligations since August 2025, with additional safety duties for systemic-risk models.
Where ISO/IEC 42001 fits
ISO/IEC 420systems and justify controls. Article 10 data governance aligns with Annex A.7 (data quality, provenance, bias testing); Article 14 human oversight maps to the standard's oversight controls; Article 17's quality management system is essentially what Clauses 4–10 of an AIMS deliver; and Article 26 deployer duties align with A.9's responsible-use processes.
The differences matter too. The AI Act is binding law with prescriptive, tiered obligations and severe penalties; ISO 42001 is voluntary, flexible, and role-based (provider vs. user). The Act regulates systems by use case; the standard governs the organisation's management of AI as a whole — including minimal-risk systems the Act largely ignores. And ISO 42001 brings something the Act cannot: independent third-party certification on the familiar ISO 27001-style audit cycle, which is fast becoming a procurement expectation.
Practical takeaway
Treat the two as complementary. Build the AIMS first: an AI system register, risk and impact assessments, data governance, human oversight records, and supplier controls. Then overlay the AI Act's tier-specific legal requirements — prohibition screening now, transparency labelling from 2026, and full high-risk conformity work planned against the December 2027 deadline. Organisations already running ISO 27001 will find the integration natural, since both standards share the same high-level structure. The regulation tells you what you must achieve; ISO 42001 tells you how to run it, prove it, and keep it audit-ready.