AI + Standards

ISO 42001 or the EU AI Act - what is the difference?

Huceptron InsightsBy the Huceptron senior partners·6 min read

These two get discussed as alternatives, which they are not. One is a regulation that applies to you whether you like it or not. The other is a management system standard you may voluntarily certify against. Choosing between them is not the decision; understanding what each buys is.

What each one is

The EU AI Act is law. Directly applicable across the Union, enforced in Ireland by sectoral market surveillance authorities, with penalties up to EUR 35 million or 7% of worldwide turnover at the top tier. You do not opt in and you cannot certify your way out of it.

ISO/IEC 42001:2023 is the first certifiable management system standard for artificial intelligence, published in December 2023. It specifies requirements for establishing and continually improving an AI management system - the organisational machinery around AI, not the technology itself. If you have been through ISO 27001, the shape will be immediately familiar: context, leadership, planning, support, operation, evaluation, improvement.

How they relate

The honest relationship is that 42001 is a good way to build the machinery the Act assumes you have, without being a substitute for the Act's specific requirements.

The Act requires, for high-risk systems, a risk management system, data governance, technical documentation, logging, human oversight, accuracy and robustness, and a quality management system. A 42001-conformant AI management system produces most of the organisational half of that list as a by-product.

What it does not produce is the system-specific conformity work. 42001 will not tell you whether your recruitment tool meets Annex III requirements.

What certification actually buys

Three things, and it is worth being precise because the marketing around this is loose.

Commercial proof. An independently audited certificate you can put in front of a procurement team without a conversation. In tenders, increasingly, this is the whole point.

Internal discipline. Surveillance audits force the reviews to actually happen. Organisations are considerably better at doing things somebody will check.

Evidence of diligence. Regulators weigh what an operator did to mitigate. A certified management system is not a defence, but it is not nothing.

What it does not buy: a presumption of conformity with the AI Act. That role belongs to harmonised European standards, which are a different instrument. Anyone telling you 42001 certification makes you AI Act compliant is overselling.

Where NIST fits

The NIST AI Risk Management Framework 1.0, released in January 2023, with its Generative AI Profile added in July 2024, is voluntary, free, and not certifiable. It is a genuinely useful way to think about AI risk - govern, map, measure, manage - and it is widely used to structure assessments.

It carries no legal weight in the EU and no certificate. Its value is as a method, and as a common vocabulary when talking to American partners.

Which to do first

For nearly every Irish company: the Act first, and only then 42001 if there is a commercial reason.

The reasoning is simple. The Act is compulsory and has dates attached. 42001 is optional, costs real money in audit fees and internal effort, and delivers most of its value to organisations that sell to buyers who ask for it.

The exception is the firm whose customers already demand certification - typically selling into regulated sectors or the public sector. There, the certificate is a commercial asset and the sequencing argument reverses.

What the certificate is worth in the UK, the US and Australia

Nothing in UK, United States or Australian law requires ISO/IEC 42001. What has changed is that the certificate became checkable. ISO/IEC 42006:2025, published in July 2025, sets the requirements for the bodies that certify against 42001, and accreditation followed: BSI became the first certification body accredited by UKAS for ISO/IEC 42001, announced in November 2025 and confirmed by UKAS in January 2026, and secured ANAB accreditation in the United States in March 2026. Standards Australia adopted the standard as AS ISO/IEC 42001:2023 in February 2024, and JAS-ANZ is accrediting certification bodies.

The practical consequence for a buyer is one question: is your certificate accredited, and by whom. An unaccredited certificate is a document. An accredited one is a document somebody else is answerable for.

What it buys in each place. In the UK it answers procurement, and it lines up with a national assurance market the government is deliberately building rather than regulating - DSIT published a roadmap for trusted third-party AI assurance in September 2025 and a stakeholder consortium has been running since June 2026. In the United States it is a governance record, which matters when the FTC asks how an AI claim was substantiated, or when a plaintiff asks what testing was done before an employment tool went live. In Australia it aligns closely with the six practices in the Guidance for AI Adoption that replaced the Voluntary AI Safety Standard in October 2025, and with what APRA told regulated entities in April 2026 when it called for a step change in AI governance.

What it does not buy, anywhere, is a defence. Colorado’s original AI Act offered an affirmative defence built on the NIST framework. Enforcement of that Act was suspended by court order in April 2026 and the replacement statute, effective 1 January 2027, dropped the defence. No regime in the EU, the UK, the United States or Australia treats certification as compliance. It shortens the conversation; it does not end it.

A practical middle path

Do the Act work in a 42001-shaped way. Build the inventory, the risk assessments, the oversight arrangements and the logs using the management-system structure, so that certification later is a matter of auditing what already exists rather than starting again.

That costs almost nothing extra at the time and saves a great deal if the commercial case for certification arrives later - which, in our experience of Irish tender documents, it increasingly does.

One week. Then you know.
The AI audit week - what applies to you, where the gaps are, and what to do first
See what the week covers →