News
EU AI Act Enforcement Begins: ISO/IEC 42001 Supports New AI Compliance Needs
The EU began enforcing general-purpose AI obligations in August 2026. ISO/IEC 42001 helps organisations build AI governance systems that support EU AI Act compliance but does not replace legal requirements.
Prem Kumar Dvivedi · ١٢ سبتمبر ٢٠٢٦
The European Union has moved into a new phase of AI regulation. The obligations for providers of general-purpose AI (GPAI) models started applying on 2 August 2025. From 2 August 2026, the European Commission began enforcing these requirements. AI models that were already on the EU market before 2 August 2025 have until 2 August 2027 to meet the requirements.
The EU has also introduced new transparency requirements from 2 August 2026. These rules require certain AI systems to inform people when they are interacting with AI. They also require certain AI-generated or manipulated content to carry appropriate markings. A limited grace period applies until 2 December 2026 for the machine-readable marking requirement for certain AI systems already on the market before August 2026.
Source: Cloud Security Alliance — EU AI Act, prEN 18286 and ISO 42001
What Does the EU AI Act Require?
The AI Act requires GPAI providers to maintain technical documentation about their models. Providers must also publish a summary of the content used to train their models and maintain policies that address copyright requirements. Providers of models with systemic risks have additional duties. These include risk assessment, incident reporting and cybersecurity measures.
These requirements show that AI governance is no longer limited to creating a policy and keeping it on file. Organisations need processes that remain active throughout the AI model's lifecycle.
How does ISO/IEC 42001 Support AI Compliance?
ISO/IEC 42001 can provide a structured framework for managing AI-related risks and governance. It can help organisations establish processes for areas such as risk management, data governance, technical documentation, record-keeping, transparency, human oversight and quality management.
The Cloud Security Alliance has highlighted how ISO/IEC 42001 can support organisations as they work toward AI governance and EU AI Act compliance. However, ISO/IEC 42001 does not automatically mean that an organisation complies with the EU AI Act.
The European AI Act creates legal obligations based on an organisation's role. A company must first understand whether it acts as a provider, deployer, importer or another relevant actor under the Act. It can then determine which requirements apply to its AI systems.
Why Organisations Need a Structured AI Governance System?
The growing number of AI regulations makes it harder for organisations to manage compliance through isolated policies and documents. A structured management system can help organisations identify AI risks, assign responsibilities, maintain records and review controls regularly.
For organisations considering ISO/IEC 42001 certification, the standard can provide a practical foundation for building an AI management system. Organisations can then map that system against the specific legal requirements that apply to their AI activities.
This approach can make compliance work more organised and help businesses prepare for changing AI regulations without treating a certification as a substitute for legal compliance.
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO/IEC 42001, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
١٣ سبتمبر ٢٠٢٦
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
١٣ سبتمبر ٢٠٢٦
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
١٣ سبتمبر ٢٠٢٦
