AI Standards: Navigating the EU Compliance Landscape

Published: Updated: 6 min read
AI Standards: Navigating the EU Compliance Landscape

The Emergence of AI Standards

Over the past decade, anyone working in IT system development will have noticed a clear pattern: major public procurement procedures, EU-funded projects and state investments have increasingly required organisations to implement new management system standards.

First came ISO 9001 for quality management, followed by ISO 14001 for environmental management, and later ISO 27001 for information security. These standards did not replace one another; instead, they built on and integrated with each other. Organisations that learned to think in integrated management systems were able to adapt far more easily.

With the emergence of artificial intelligence, the need for an AI-specific management system also became clear. This led to the publication of ISO 42001, a management system standard addressing the responsible, controlled and auditable use of AI within organisations.

The emergence of ISO 42001 was therefore not surprising. It was the next stage in an already familiar development process.

The real turning point, however, is that alongside voluntarily adopted standards, organisations now face a new regulatory compliance obligation: after the GDPR, the EU AI Act has arrived.

Why Are Standards Necessary?

The EU AI Act imposes legal obligations. However, the law usually defines what must be done, while standards help explain how those obligations can be implemented in a demonstrable and auditable way.

Standards do not replace legislation. Instead, they provide a practical framework for implementation and may, in certain cases, support a presumption of conformity.

Imagine a bank developing an AI-based credit scoring system. The EU AI Act requires high-risk AI systems to be developed and operated in a way that makes discriminatory and fundamental rights risks controllable, measurable and documentable.

The bank must be able to demonstrate that the system’s data processing, model and decision logic do not result in unjustifiably biased or discriminatory outcomes.

The question is not whether the organisation believes the system works properly, but how it can prove this to an auditor or authority.

A standardised management system can help the organisation operate a documented risk management process, identify bias and fundamental rights risks, validate and test the model’s behaviour, and monitor and log decisions.

This is no longer merely a statement. It becomes auditable and documentable evidence.

ISO 42001 Is Not the Whole Solution

The EU AI Act requires organisational-level governance, and ISO 42001 provides a strong foundation for this. However, compliance does not stop at organisational governance.

For high-risk AI systems, the conformity of each individual system must also be demonstrated. Article 17 of the EU AI Act requires providers of high-risk AI systems to operate a documented Quality Management System (QMS).

This includes the regulation of development, validation, monitoring, incident management, documentation and ongoing conformity.

ISO 42001 is an important AI governance framework, but it does not automatically ensure AI Act compliance and does not replace product-level conformity assessment for high-risk AI systems.

One important element of ISO 42001 is the AI System Impact Assessment. Organisations must regularly assess the potential impact of AI systems on affected persons, fundamental rights, business operations and, where relevant, society as a whole.

This approach aligns well with the risk-based logic of the EU AI Act, which focuses not only on how the technology functions, but also on its consequences.

ISO 42001 substantially supports these requirements, but it is not currently a harmonised AI Act standard. For this reason, European standardisation bodies are developing draft standards specifically focused on the requirements of the AI Act, such as prEN 18286.

ISO 42001 and prEN 18286: Two Different Levels of the Same System

For many organisations, the relationship between ISO 42001 and prEN 18286 is not immediately clear.

  • ISO 42001: organisational-level AI governance, AI policy, risk management, monitoring and management system controls.
  • prEN 18286: system- or product-level conformity, documentation, validation and demonstrable legal compliance.

ISO 42001 demonstrates that the organisation has an appropriate AI governance framework in place.

prEN 18286, by contrast, focuses on whether a specific AI system complies with the requirements of the EU AI Act.

ISO 42001 operates at organisational level. prEN 18286 addresses system-level conformity.

The relationship is similar to the one between ISO 9001 and CE marking. One confirms the existence of a quality management system, while the other confirms the conformity of a specific product.

This is why ISO 42001 is a useful governance framework, but it is not sufficient on its own to demonstrate AI Act compliance.

The Advantage of ISO 27001-Based Organisations

Organisations that already operate an ISO 27001 information security management system start from a significantly stronger position when preparing for AI Act compliance.

ISO 27001 already provides several basic processes and controls that can support AI governance:

  • monitoring and logging infrastructure;
  • incident response processes;
  • access control and authorisation management;
  • risk assessment methodology;
  • documentation and audit practices.

However, the difference is important.

ISO 27001 examines whether information remains confidential, intact and available. AI governance, by contrast, focuses on whether AI systems operate in a fair, reliable, transparent and controllable manner.

This requires organisations to assess, among other things:

  • the risk of biased or discriminatory operation;
  • the behaviour of models in unexpected situations;
  • the explainability of decisions;
  • the effectiveness of continuous supervision and monitoring.

For organisations with ISO 27001 already in place, the main task is usually not to build the foundations from scratch, but to introduce and integrate AI-specific controls and processes.

The AI-Specific Layer

The AI-specific layer is not limited to new processes and controls. ISO 42001 also places particular emphasis on adequate AI competencies within the organisation.

It is not enough to create policies. Employees involved in development, procurement, operations and business decision-making must understand how AI systems work, what risks they create and what limitations they have.

This requirement is closely aligned with the AI literacy expectations of the EU AI Act, which increasingly emphasise conscious and responsible AI use.

What Needs to Be Done Today?

If No AI Governance Framework Is Yet in Place

  1. Define AI policy, objectives and roles.
  2. Identify high-risk AI systems.
  3. Establish an AI-specific risk assessment process.
  4. Create monitoring and incident management processes.

If ISO 27001 Is Already in Place

  1. Carry out a gap assessment against the requirements of the EU AI Act.
  2. Extend the ISO 27001 monitoring infrastructure to AI systems.
  3. Introduce bias monitoring and model drift detection.
  4. Develop AI incident management and AI-specific documentation.

The Expected Outcome

  • every high-risk AI system is documented;
  • risk assessment has been carried out;
  • continuous monitoring is in place;
  • incident reporting is operational and demonstrable.

Closing Remarks

ISO 42001 and the EU AI Act should not be seen merely as administrative burdens. They represent the new operating norm for the responsible use of artificial intelligence.

Organisations that already have ISO 27001 foundations are in a strong position. Their key task is to build and integrate the AI-specific layer into their existing governance and control framework.

In the coming years, competitive advantage will increasingly belong to organisations that not only use artificial intelligence, but can also document, supervise and demonstrate its responsible operation from a compliance perspective.

In the future, the question will not be whether an organisation uses AI, but whether it can prove that it uses AI responsibly.

Postscript: one of the most important elements of AI Act compliance is risk assessment. It is both a legal obligation and a foundation of standard-based conformity. This topic deserves a separate article.

Try the AI Act risk classifier

Find out in 5 minutes which risk category your AI system falls into — free, 100% private, with a detailed PDF result.

Start the assessment
H
Pallos Gabriella
Harvey's · AI & compliance team
Experts in AI Act compliance, testing and security audits. Reach out any time with questions.
LinkedIn

Harvey's newsletter

Stay up to date with our AI Act content

One practical monthly summary on EU AI Act compliance — no spam, unsubscribe any time.

← Back to the blog