ISO 42001
The standard for managing AI.
ISO 42001 is voluntary and the AI Act is not; which operator you are decides how much of the Regulation's evidence the standard produces, and the free determination says whether your system is high-risk at all.
Answer above to read the determination for your case; the full tool takes your answers with it.
Continue: is your system high-risk?38
controls in Annex A
28
clauses that carry requirements
Write the AI policy
Clause 5.2 from eleven answers: what the company uses AI for, its position, the uses it rules out, who is accountable, the objectives, the requirements that apply, and how the policy sits beside the others.
Write an AI system impact assessment
Clause 6.1.4 for one system: what it is for and how it could be misused, the people it touches, the consequences to individuals, to groups and to society with a likelihood and a severity each, the benefits, the measures, the result and the review date, as the record an auditor reads.
Write the AI system inventory
The register an auditor opens first: every AI system with its purpose, the company's role, its status and owner, the data, tooling, hosting and people it depends on, the date of its impact assessment and the AI Act reading, with a summary table.
All 38 Annex A controls
One plain-English line per control, grouped the way Annex A groups them.
What we cover, clause by clause
Every clause from 4 to 10, where its records live in the product, and where the limits of any software sit.
Every free template on one page
The AI Act's high-risk dates moved on 27 July 2026
Regulation (EU) 2026/1744, the Digital Omnibus on AI, applies the high-risk requirements from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, in place of the 2026 and 2027 dates of the original text. ISO 42001 gives the structure of the quality management system Article 17 asks a provider for, and the article below maps the 13 aspects of Article 17(1) to Annex A: 13 have a control behind them, 6 of those with something still to be written for the Regulation itself, and none of it is a presumption of conformity.
Is your system high-risk? The determination, free, in writingThe AI Act: the dates as amended, the tool, the articles
Read next
The AI Act for a software company: which role you are, what applies to everyone, what applies only to a high-risk provider, the SME provisions, and the dates as amended
A software company meets the AI Act in one of six roles, and most of the Regulation only applies to two of them. What counts as an AI system at all, why shipping a vendor's model under your own name makes you the provider, the three duties every company has since 2025 and 2026 (AI literacy, the prohibitions, transparency), the two routes to high-risk and what each role then owes from 2 December 2027, the general-purpose model line, the SME and small mid-cap provisions the Digital Omnibus widened, and one table of who owes what from when. Read from the two Regulations on CELLAR on 12 September 2026.
The AI Act after the Digital Omnibus: the dates that changed on 27 July 2026, and which ISO 42001 controls produce the evidence for Article 17's thirteen aspects and Articles 9 to 15
Regulation (EU) 2026/1744, signed 8 July 2026, published 24 July, in force 27 July, moved the AI Act's high-risk dates to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems, rewrote AI literacy as a duty to take measures, and made the post-market monitoring plan part of the technical documentation. Most of what ranks still gives the old dates. The dates as amended, what else changed for a provider, and our mapping of Article 17's thirteen quality-management aspects, Articles 9 to 15, 72 and 73, and the operator duties of Articles 4 and 26 to the Annex A controls of ISO/IEC 42001, with what the Regulation asks for that the standard does not produce.
AI literacy under Article 4 of the AI Act, as rewritten on 27 July 2026: what 'take measures' means, who it covers, what it does not require, and the record to keep
Article 4 has applied to every provider and deployer of an AI system since 2 February 2025. The Digital Omnibus rewrote it: measures to support the development of AI literacy, taking account of people's knowledge and the context, and, in terms the Regulation now uses, no duty to guarantee any specific level of literacy of any individual. The Commission is to publish practical examples and the AI Board common objectives. What the article asks, why it has no fine of its own in Article 99, how ISO 42001's competence and awareness clauses produce the record, and a one-page programme.
What a deployer of a high-risk AI system owes under Article 26 of the AI Act: the twelve paragraphs in order, the Article 27 impact assessment, when you become the provider, and the records an ISO 42001 system keeps
Most companies will meet the AI Act as deployers: they buy or licence a system someone else built and use it under their own authority. For a high-risk system the duties are in Article 26, twelve paragraphs, unchanged by the Digital Omnibus, applying from 2 December 2027 for Annex III systems. Each paragraph read in order, the Article 27 fundamental rights impact assessment and who carries it, the three ways a deployer becomes the provider under Article 25, the Article 86 right to explanation, the Article 99 ceiling, and the ISO 42001 control that produces each record.
Article 50 of the AI Act for a company that ships or uses generative AI: the four transparency duties in force since 2 August 2026, the 2 December 2026 transition, the code of practice and the EU icon
Article 50 is the AI Act obligation that reaches a company whether or not its system is high-risk: tell people they are talking to an AI, mark generated content so machines can detect it, disclose deep fakes and AI-written text on matters of public interest, inform people exposed to emotion recognition. It has applied since 2 August 2026, the Digital Omnibus left it unchanged and gave providers of generative systems already on the market until 2 December 2026 for the marking duty. The four paragraphs read in order, who is provider and who is deployer for each, the Commission's code of practice of 10 June 2026 with its two-layer marking and its AI icon, the fine, and the record an ISO 42001 system keeps.
The ISO 42001 AI policy for a software company: what Clause 5.2 asks for, the ten sections, the AI Act duties it names, the mistakes an auditor flags, and a page that writes it
Clause 5.2 of ISO/IEC 42001 asks top management for an AI policy that fits what the company uses AI for, gives the frame for the AI objectives, commits to the requirements that apply and to improving the system, is documented, communicated and available, and says how it sits beside the other policies. Three Annex A controls, A.2.2, A.2.3 and A.2.4, ask for the policy, its alignment with the other policies and its review. A short AI policy for a software company runs to ten sections: purpose, scope, position, the uses ruled out, accountability, objectives, the requirements that apply, the other policies, communication and review. The requirements section is where the AI Act enters: the literacy duty of Article 4, the transparency duties of Article 50 where the company generates content, and a recorded high-risk determination per system that the policy itself never asserts. A free page writes the policy from eleven answers in six languages.
The ISO 42001 AI system impact assessment: what Clause 6.1.4 asks for, the three levels of consequence, where it meets the AI Act, the mistakes an auditor flags, and a page that writes it
Clause 6.1.4 of ISO/IEC 42001 has the company assess what each AI system could do to the individuals and groups it touches and to society, keep the result as documented information, and act on it through the system's life cycle; Clause 8.4 runs the process and four Annex A controls ask for the process, the retention, the harm to individuals and groups, and the harm beyond the users. It is the record the standard has and ISO 27001 does not. An assessment an auditor accepts names the purpose and the foreseeable misuse, the people, the consequences at the three levels with a likelihood and a severity each, the benefits, the measures, a result and a review date; under the AI Act it is the input to the Article 27 fundamental rights impact assessment and the place the company's own reading of the system is recorded. A free page writes it for one system.
ISO 42001 certification: what it is, and whether it is early
ISO/IEC 42001 is the AI management system standard. Here is what it asks for, how it relates to an existing ISO 27001, and an honest read of current demand.
Related:ArticlesFree tools