← Back to all articles
Insights

ISO/IEC 42001 and the EU AI Act: What Your AIMS Certificate Actually Buys You Now That EN 18286 Is Published

Generated image

There is a sentence going around sales decks right now: "Get ISO 42001 certified and you're EU AI Act ready." It is not true, and the gap between it and the truth just got much easier to see.

On 31 July 2026, CEN-CENELEC announced the publication of EN 18286:2026 'Artificial intelligence - Quality management system for EU AI Act regulatory purposes' - the first European standard published in support of the AI Act. It exists precisely because ISO/IEC 42001 could not do the job.

If you hold an ISO 42001 certificate, or you are being sold one as a route to AI Act conformity, this post is the honest version of what it does and does not buy you.

What ISO 42001 certification actually attests

ISO/IEC 42001 is the international standard for an artificial intelligence management system (AIMS). It follows the familiar Annex SL management-system structure - context, leadership, planning, support, operation, performance evaluation, improvement - with an Annex A control set covering AI policy, internal roles and responsibilities, AI impact assessment, data management, system lifecycle documentation, and third-party and supplier relationships.

A certificate says something quite specific: an accredited body examined your organisation's management system within a defined scope and found it conformant. That is a real and valuable thing. It is also a statement about your company, not about any particular AI system you ship.

Hold that distinction. Everything else follows from it.

Presumption of conformity, in one paragraph

Under Articles 40 and 41 of the AI Act, a provider that applies a harmonised standard cited in the Official Journal of the European Union is presumed to conform with the requirement that standard covers. That presumption is the whole prize: it shifts the burden, it makes conformity assessment tractable, and it is what auditors and notified bodies will look for. Two things have to be true for it to apply - the standard must be harmonised under the Commission's standardisation request, and it must be cited in the OJEU. We covered the mechanics of this in our guide to harmonised standards and presumption of conformity under Articles 40 and 41, so we will not repeat them here.

ISO/IEC 42001 satisfies neither condition. It is not a harmonised European standard and it is not cited in the OJEU. No amount of certification changes that.

Why JTC 21 wrote a new standard instead of adopting ISO 42001

The obvious question is why the European standardisers did not simply adopt ISO/IEC 42001 as the AI Act's quality management standard. It already existed. It was already being certified against. Adoption would have saved years.

They looked at it and declined. CEN/CLC/JTC 21 - the technical committee working under the Commission's M/613 standardisation request - judged ISO/IEC 42001's objectives, scope and definitions insufficiently aligned with what Article 17 actually demands, and the European AI Office had signalled misalignment concerns as early as 2024. Comparative analysis of the two documents makes the shape of the problem clear, and it comes down to one structural mismatch.

ISO 42001 governs an organisation. The AI Act regulates a product.

The AI Act is New Legislative Framework law. It works the way CE-marked product legislation works: each high-risk AI system is assessed against defined requirements at the point it is placed on the market, and the provider issues a declaration of conformity for that system. The unit of regulation is the system, not the company.

An organisation-level certificate cannot discharge a system-level obligation. You can have an exemplary AIMS and still place a non-conformant high-risk system on the EU market. The certificate would be entirely accurate and entirely beside the point.

EN 18286:2026 - published, but not yet the finish line

EN 18286:2026 is the standard written for the actual requirement. It specifies the requirements and guidance for defining, implementing and maintaining a quality management system for organisations that provide AI systems, it is not specific to any sector, and it is aimed squarely at Article 17. CEN-CENELEC approved it on 12 July 2026, following a public enquiry that ran from 30 October 2025 to 22 January 2026.

Here is the nuance that most coverage skips, and it matters more than the publication itself:

Publication by CEN-CENELEC and citation in the Official Journal are two different events. EN 18286:2026 has been published. It has not yet been cited in the OJEU. Citation is a discretionary act of the Commission, taken after it assesses whether the standard adequately covers the legal requirements, and it runs on its own timetable.

Until citation happens, EN 18286 gives you a well-designed blueprint and a strong evidentiary story. It does not yet give you presumption of conformity either. Anyone telling you otherwise is ahead of the facts.

The practical read: EN 18286 is now the document to build your Article 17 quality management system against, on the working assumption that citation follows. But build it as engineering, not as a legal shield you already hold.

The honest overlap: what your ISO 42001 evidence is worth

None of this makes ISO 42001 a waste. It makes it scaffolding rather than a shortcut. Here is where the evidence you have already generated is genuinely reusable.

ISO/IEC 42001 element Reusable evidence for What still has to be built
AI policy, leadership commitment, defined roles Article 17 QMS, governance layer The Article 17 elements specific to regulatory compliance, conformity assessment and post-market obligations
AI impact assessment (Annex A) Article 9 risk management inputs; Article 27 FRIA inputs Article 9's continuous, lifecycle-wide iteration and residual-risk judgements per system
Data management controls Article 10 data governance Article 10's specific requirements on relevance, representativeness, error rates and bias examination across training, validation and testing sets
System lifecycle documentation Article 11 and Annex IV technical file inputs The prescriptive nine-section Annex IV structure, which 42001 will not produce
Supplier and third-party controls Article 25 role clarity; Article 26 deployer duties Formal role determination and the contractual chain the Act assumes
Internal audit, management review, nonconformity handling Article 17 QMS, assurance layer Little structurally: this is the strongest transfer of the set

And here is what ISO 42001 does not touch at all:

  • Article 43 conformity assessment, including the notified-body route where it applies
  • CE marking and the EU declaration of conformity
  • Article 11 and Annex IV technical documentation in its prescribed form
  • Articles 49 and 71 registration in the EU database before placing on the market
  • Article 72 post-market monitoring plan
  • Article 73 serious incident reporting on statutory clocks
  • Article 5 prohibitions, which are absolute bans rather than risks to be managed down

That second list is where the Article 99 penalties live.

Where the deadline actually sits

Do not calibrate against the old dates. Regulation (EU) 2026/1744 - the Digital Omnibus on AI - was published in the OJEU on 24 July 2026 and entered into force on 27 July 2026. It moved standalone Annex III high-risk obligations from 2 August 2026 to 2 December 2027, and high-risk AI embedded in products already covered by EU product-safety law to 2 August 2028.

What did not move: Article 50 transparency obligations apply from 2 August 2026. Article 5 prohibitions and Article 4 AI literacy were already applicable. Two further prohibitions - non-consensual intimate imagery and AI-generated child sexual abuse material - take effect on 2 December 2026.

A meaningful share of third-party writing still repeats "August 2026" as the high-risk deadline. It is wrong, and it will make your plan wrong.

What to do, depending on where you are

You already hold ISO 42001. Do not treat it as a milestone reached. Run a gap analysis against EN 18286:2026 and against the Article 17 text directly, and separately against the product-level obligations in the bullet list above - because your certificate says nothing about them. Then map your existing evidence to AI Act artefacts so you are reusing rather than regenerating. Expect the quality-management overlap to be substantial and the technical-file and conformity-assessment work to be almost entirely new.

You are mid-implementation. Stop and re-scope before you certify. If your driver was AI Act readiness rather than customer assurance, EN 18286 is now the better target for the QMS work, and you have until December 2027. If you have commercial reasons to hold the 42001 certificate - and many organisations do, particularly for enterprise procurement - carry on, but budget separately for the product-level programme.

You have not started. Do not begin with a certification project. Begin with role determination and classification: are you a provider or a deployer, and is the system high-risk? Everything downstream depends on those two answers, and both are free to establish. Then decide whether an AI management system certificate is the right vehicle for your organisation at all.

Eight questions for anyone selling you "AI Act compliance via ISO 42001"

  1. Is ISO/IEC 42001 a harmonised standard under the AI Act? (Correct answer: no.)
  2. Is it cited in the Official Journal of the European Union? (No.)
  3. Which article of the AI Act does our certificate discharge on its own? (None.)
  4. What is your view on EN 18286:2026, and when do you expect OJEU citation?
  5. Which of our 42001 artefacts will you map to the Annex IV technical file, and who produces the rest?
  6. Who signs our EU declaration of conformity, and on what evidence?
  7. How does this engagement address Article 49 registration and Article 73 incident reporting?
  8. If our role is deployer rather than provider, what changes in your scope?

If the answers to the first three are anything other than plain nos, you are in a sales conversation rather than a compliance plan.

The short version

ISO 42001 is a good management system standard and an increasingly common commercial requirement. It builds habits, artefacts and audit muscle that transfer directly to the AI Act's governance layer. What it cannot do - structurally, not temporarily - is turn an organisational certificate into a product-level conformity claim.

EN 18286:2026 is the standard that will eventually do that job for Article 17, and it is published but not yet cited. Build against it. Reuse your ISO 42001 evidence aggressively. And keep the two claims separate when you write them down, because a regulator will.