[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"article:en:the-ai-act-after-the-digital-omnibus-the-dates-that-changed-and-which-iso-42001-controls-produce-the-evidence-for-article-17-and-articles-9-to-15":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"body":9},"en","the-ai-act-after-the-digital-omnibus-the-dates-that-changed-and-which-iso-42001-controls-produce-the-evidence-for-article-17-and-articles-9-to-15","The AI Act after the Digital Omnibus: the dates that changed on 27 July 2026, and which ISO 42001 controls produce the evidence for Article 17's thirteen aspects and Articles 9 to 15","Regulation (EU) 2026\u002F1744, signed 8 July 2026, published 24 July, in force 27 July, moved the AI Act's high-risk dates to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, rewrote AI literacy as a duty to take measures, and made the post-market monitoring plan part of the technical documentation. Most of what ranks still gives the old dates. The dates as amended, what else changed for a provider, and our mapping of Article 17's thirteen quality-management aspects, Articles 9 to 15, 72 and 73, and the operator duties of Articles 4 and 26 to the Annex A controls of ISO\u002FIEC 42001, with what the Regulation asks for that the standard does not produce.","2026-09-12","\nTwo things a company building or using AI in the Union needs to know on 12 September 2026, and most pages get the first one wrong. The first is that the AI Act's dates are no longer the ones in the text of 2024: Regulation (EU) 2026\u002F1744, the Digital Omnibus on AI, signed on 8 July 2026, published in the Official Journal on 24 July and in force since 27 July, replaced the high-risk timetable. The second is that ISO\u002FIEC 42001, the AI management system standard, produces a large part of what Article 17 asks a provider of a high-risk system to have, and a well-defined part of what it does not. This article is both, read from the two Regulations on CELLAR on 12 September 2026 and from the standard's Annex A; the mapping is ours, checkable against the texts, and the standard's wording is not reproduced.\n\n## The dates, as amended\n\nArticle 113 as amended by Regulation (EU) 2026\u002F1744, with the transitional rule the amendment added to Article 111.\n\n| Applies from | What |\n| --- | --- |\n| 2 February 2025 | Chapters I and II: subject matter, definitions, AI literacy (Article 4), prohibited practices (Article 5) |\n| 2 August 2025 | Chapter V, general-purpose AI models, and the governance and penalties chapters |\n| 27 July 2026 | Articles 102 to 110, the amendments to other Union acts |\n| 2 August 2026 | The Regulation in general, the transparency obligations of Article 50 included |\n| 2 December 2026 | Article 50(2), machine-readable marking of synthetic content, for systems already on the market on 2 August 2026 (Article 111(4) as amended) |\n| 2 December 2027 | Chapter III, Sections 1 to 3: the high-risk requirements and the provider and deployer obligations, for systems classified high-risk under Article 6(2) and Annex III |\n| 2 August 2028 | The same, for systems classified high-risk under Article 6(1) and Annex I, the product safety legislation |\n\nThe original text had 2 August 2026 for Annex III and 2 August 2027 for Annex I. The amendment also set 2 September 2027 as the date by which the Commission adopts guidance and a template for the post-market monitoring plan (Article 72(3) as amended), and inserted Article 4a, which lets a provider process special categories of personal data for bias detection and correction under conditions.\n\n## What else the Omnibus changed for a provider\n\nFour changes reach a company's compliance programme directly. Article 4 was rewritten: providers and deployers take measures to support the AI literacy of their staff and of others operating AI on their behalf, and the article now says in terms that this does not require guaranteeing any specific level of literacy of any individual; the Commission and member states are to support the effort, with practical examples. Article 17(2) now says the quality management system is proportionate to the provider's size, naming SMEs, start-ups and SMCs. Article 10 lost its paragraph 5 and refers to the new Article 4a for special-category data, and applies only to the testing data sets for systems not trained with data. Article 72(3) makes the post-market monitoring plan part of the Annex IV technical documentation, on the Commission's template once adopted. Article 6 gained paragraphs 1a to 1c, which take AI used solely for non-safety aspects such as performance optimisation, service efficiency, automation, convenience or quality control out of the definition of a safety component.\n\n## Article 17: the thirteen aspects, mapped\n\nArticle 17(1) requires a provider of a high-risk AI system to have a quality management system \"documented in a systematic and orderly manner in the form of written policies, procedures and instructions\" with at least thirteen aspects. ISO 42001 is a management system standard, so this is where the two meet most directly. The mapping names the Annex A controls and clauses of ISO\u002FIEC 42001:2023 whose records are the process behind each aspect; the basis says whether the standard's record is the evidence, or the standard runs the process and the AI system supplies the evidence.\n\n| Article 17(1) | ISO 42001 | Basis |\n| --- | --- | --- |\n| 17(1)(a): A strategy for regulatory compliance, conformity assessment and the management of modifications | 4.2, A.2.2, A.2.3, A.6.2.5 | Process; the system supplies the evidence |\n| 17(1)(b): Design, design control and design verification | A.6.1.3, A.6.2.2, A.6.2.3, A.6.2.4 | Process; the system supplies the evidence |\n| 17(1)(c): Development, quality control and quality assurance | A.6.1.3, A.6.2.3, A.6.2.4 | Process; the system supplies the evidence |\n| 17(1)(d): Examination, test and validation before, during and after development, and how often | A.6.2.4, A.6.2.6 | Process; the system supplies the evidence |\n| 17(1)(e): The technical specifications and standards applied, and the means used where harmonised standards are not | A.6.2.2 | Process; the system supplies the evidence |\n| 17(1)(f): Data management, from acquisition to retention | A.7.2, A.7.3, A.7.4, A.7.5, A.7.6 | Record is the evidence |\n| 17(1)(g): The risk management system of Article 9 | 6.1.2, 6.1.3, A.5.2, A.5.3, A.5.4, A.5.5 | Process; the system supplies the evidence |\n| 17(1)(h): A post-market monitoring system, per Article 72 | A.6.2.6, A.8.3 | Process; the system supplies the evidence |\n| 17(1)(i): Serious incident reporting procedures, per Article 73 | A.8.4, A.3.3 | Process; the system supplies the evidence |\n| 17(1)(j): Communication with authorities, notified bodies, operators, customers and interested parties | A.8.2, A.8.5, A.10.4 | Process; the system supplies the evidence |\n| 17(1)(k): Record-keeping of all relevant documentation and information | 7.5, A.6.2.7, A.6.2.8 | Record is the evidence |\n| 17(1)(l): Resource management, including security of supply | A.4.2, A.4.3, A.4.4, A.4.5, A.4.6, A.10.3 | Process; the system supplies the evidence |\n| 17(1)(m): An accountability framework for management and staff | 5.3, A.3.2, A.10.2 | Record is the evidence |\n\nWhat the standard does not produce for Article 17, aspect by aspect: for (a), the conformity assessment procedure of Article 43 and Annexes VI and VII and the rule for substantial modifications; for (d), the frequency of tests and the validation after development; for (e), the statement of which harmonised standards or common specifications the system is built to and the means used where they do not cover a requirement; for (g), Article 9's process over the lifetime with testing against defined metrics and a residual-risk judgement per hazard; for (h), the post-market monitoring plan on the Commission's template; for (i), the report to the market surveillance authority within Article 73's deadlines, 15 days in general, 2 days for a widespread infringement or an incident under Article 3(49)(b), 10 days for a death. The other seven aspects are what a conforming AI management system already holds.\n\n## Articles 9 to 15, 72 and 73: the requirements on the system\n\nSection 2 of Chapter III is the list of requirements a high-risk system must meet, and the pattern changes: the control fixes what the system must do, the system is the evidence.\n\n| Article | ISO 42001 | Basis |\n| --- | --- | --- |\n| 9: Risk management system | 6.1.2, 6.1.3, A.5.2, A.5.3, A.5.4, A.5.5, A.6.2.4 | Process; the system supplies the evidence |\n| 10: Data and data governance | A.7.2, A.7.3, A.7.4, A.7.5, A.7.6 | Process; the system supplies the evidence |\n| 11: Technical documentation, per Annex IV | A.6.2.3, A.6.2.7 | Process; the system supplies the evidence |\n| 12: Record-keeping: automatic logs over the lifetime | A.6.2.8 | Process; the system supplies the evidence |\n| 13: Transparency and instructions for use | A.8.2, A.6.2.7, A.10.4 | Process; the system supplies the evidence |\n| 14: Human oversight | none | Not in Annex A |\n| 15: Accuracy, robustness and cybersecurity | A.6.2.4, A.6.2.6 | Process; the system supplies the evidence |\n| 72: Post-market monitoring | A.6.2.6, A.8.3 | Process; the system supplies the evidence |\n| 73: Reporting of serious incidents | A.8.4, A.3.3 | Process; the system supplies the evidence |\n\nThe gaps are specific. Article 10 specifies the properties of the training, validation and testing sets, relevant, sufficiently representative, as far as possible free of errors and complete, with the design choices, origins, preparation, assumptions, bias examination and gaps documented; Annex A governs data, the Regulation specifies it. Article 11 fixes the contents of the technical documentation in Annex IV, with a simplified form for SMEs, start-ups and SMCs. Article 12 requires the system itself to log the events it names. Article 13 fixes the contents of the instructions for use, the declared accuracy metrics among them. Article 14 is the one requirement no Annex A control produces: oversight measures built into the system or specified for the deployer, so that the people assigned can understand its limits, watch for automation bias, interpret the output, decide not to use it and stop it. Article 15 asks for declared accuracy, resilience to errors and feedback loops, and resilience to data poisoning, model poisoning, adversarial examples and model flaws, which is where ISO 27001's controls carry the cybersecurity half and neither standard tests robustness for you.\n\n## Articles 4 and 26: the duties of a company that uses AI\n\nMost companies are deployers, not providers. Article 4 applies to both since 2 February 2025, [as rewritten by the Omnibus](\u002Farticles\u002Fai-literacy-under-article-4-of-the-ai-act-as-rewritten-on-27-july-2026-what-take-measures-means-who-it-covers-what-it-does-not-require-and-the-record-to-keep); Article 26 applies to deployers of high-risk systems from the same dates as the provider obligations.\n\n| Article | ISO 42001 | Basis |\n| --- | --- | --- |\n| 4: AI literacy | 7.2, 7.3, A.4.6 | Record is the evidence |\n| 26: Deployers of high-risk systems | A.9.2, A.9.3, A.9.4, A.6.2.8, A.8.5 | Process; the system supplies the evidence |\n\nFor a deployer, what ISO 42001 does not settle is in Article 26 itself: human oversight assigned to competent natural persons, input data relevant to the intended purpose, the system's logs kept for at least six months, workers' representatives and affected workers informed before a high-risk system is used at the workplace, and the fundamental rights impact assessment of Article 27 where the deployer is a public body or a private one providing public services, or a bank or insurer using the Annex III credit and insurance systems.\n\n## What this adds up to\n\nFor a provider of a high-risk system, ISO 42001 is the Article 17 quality management system in its structure and in ten of its thirteen aspects; what has to be written for the Regulation is the conformity assessment route, the technical documentation to Annex IV with the post-market monitoring plan inside it, the Article 9 risk process with its metrics, the incident procedure with the authority and the deadlines, and the human oversight of Article 14. For a company that uses AI, the standard's clauses on competence and awareness and its A.9 controls on use are the Article 4 and Article 26 record. The dates give a provider of an Annex III system until 2 December 2027, and none of the dates give anyone a reason to publish a page with 2 August 2026 on it after 27 July.\n\n[The 38 Annex A controls of ISO 42001 in plain English](\u002Fiso-42001\u002Fcontrols), [what StandardOS covers of the standard clause by clause](\u002Fiso-42001) and [the certification question, with the tender count](\u002Farticles\u002Fiso-42001-certification) are the companion pieces.\n\n## Sources\n\n- Regulation (EU) 2024\u002F1689 (the AI Act), Articles 4, 6, 9 to 15, 17, 26, 27, 50, 72, 73, 111 and 113, Annexes III and IV, read on CELLAR on 12 September 2026.\n- Regulation (EU) 2026\u002F1744 of 8 July 2026 (the Digital Omnibus on AI), Article 1, points (5), (6), (8), (9), (10), (11), (30), (39) and (40); Official Journal of 24 July 2026, ELI http:\u002F\u002Fdata.europa.eu\u002Feli\u002Freg\u002F2026\u002F1744\u002Foj; in force 27 July 2026.\n- ISO\u002FIEC 42001:2023, Annex A and clauses 4.2, 5.3, 6.1.2, 6.1.3, 7.2, 7.3 and 7.5, cited by number; the text is ISO's and is not reproduced; the mapping is ours.\n\nThis is not legal advice. Whether a given system is high-risk is decided under Article 6 and the Annexes; the mapping is a reading of two texts, not a presumption of conformity.\n",1789383983933]