Compliance2026-08-069 min read

Your ISO 42001 Certificate Is Not An AI Act Shield, And EN 18286 Is The Reason

ISO 42001 was ratified as a European standard in March 2026 and national bodies must adopt it by September, which reads like harmonisation and is not. The AI Act grants presumption of conformity only to standards cited in the Official Journal, none exist yet, and the quality management standard the Commission actually commissioned is a separate document called EN 18286. Here is what that gap means for your certificate, your RFP answers and your next two quarters.

There is a sentence being written into vendor questionnaires, sales decks and board papers across Europe right now, and it is wrong in a way that is going to cost somebody money. The sentence is that ISO 42001 certification demonstrates compliance with the EU AI Act. You can see how the belief formed. ISO/IEC 42001 was approved as a European standard by CEN on 13 March 2026, published as EN ISO/IEC 42001:2026, and the 34 national standards bodies have until September 2026 to give it national status. That sequence looks exactly like harmonisation. It is not harmonisation, and the difference is not a technicality, it is the difference between holding a legal presumption and holding an evidentiary burden.

The mechanism is Article 40 of the AI Act. A provider gets presumption of conformity with an essential requirement only where it conforms to a harmonised standard whose reference has been published in the Official Journal of the European Union. Publication in the Official Journal is a Commission act that follows a standardisation request, a European standard drafted against that request, and an assessment that the standard actually covers the legal requirement. As of August 2026, no AI Act harmonised standard has been cited in the Official Journal. Not one. A European standard adopted through CEN is a technical document with national status, which is useful and reputable, and it is a different thing from a legal shield. Until a citation appears, every provider of a high risk system carries the full burden of proving conformity clause by clause with its own technical file, whatever certificates hang on the wall.

The specific case of quality management makes the point sharper than any general argument. Article 17 of the Act requires providers of high risk AI systems to operate a quality management system, and the obvious move would have been to point at ISO/IEC 42001 and be done. The Commission did not do that. It assessed 42001 against the Article 17 requirement, found that the goals and definitions of the standard were not aligned with what the Act asks for, and CEN-CENELEC JTC 21 wrote a bespoke European standard instead. That standard is EN 18286, Artificial Intelligence, Quality management system for EU AI Act regulatory purposes. Its public enquiry ran from 30 October 2025 to January 2026 and it is now at the formal vote stage, which makes it the furthest advanced deliverable in the whole family. If you have been treating your 42001 management system as the answer to Article 17, the European standards body that examined the question has already told you it is not.

It is worth seeing the rest of the family, because it tells you where the real work lands. prEN 18228 covers risk management for Article 9, prEN 18229-1 covers logging for Article 12, and prEN 18282 covers cybersecurity for Article 15, and all three are in public enquiry. Further back in drafting sit prEN 18283 on bias management, whose working draft consultation closed on 30 April 2026, prEN 18229-2 and prEN 18229-3 on accuracy, robustness, transparency and human oversight, prEN 18284 on dataset quality and governance, and prEN 18285 on the conformity assessment framework itself. The CEN-CENELEC acceleration package targets Q4 2026 for the prioritised deliverables, while the amended Commission standardisation request runs to 28 February 2027. Read that list next to your own architecture and the pattern is clear: the Act is being operationalised as seven or eight separate control disciplines, and a single management system certificate was never going to cover all of them.

None of this makes ISO 42001 a waste of money, and we have argued the opposite twice this year, so it would be strange to reverse now. The correct mental model is two layers. The lower layer is the operating system: an AI inventory with named owners, an impact assessment habit, lifecycle controls, supplier due diligence, incident handling for AI specific failure modes. That is what 42001 gives you, it is genuinely hard to retrofit, and it is what buyers are actually testing when they ask about your AI governance. The upper layer is legal conformity against a specific regulation, which requires mapping evidence to specific articles and, eventually, to the harmonised standards that will be cited. A company running the lower layer will produce the upper layer in weeks when EN 18286 lands. A company with neither will need a year, and by then the citation will already be in a procurement clause it has signed.

The immediate practical exposure is contractual rather than regulatory, and it is close. Enterprise buyers have started putting AI Act compliance warranties into master agreements, and sales teams under quota have started accepting them on the strength of a 42001 certificate. That is a bad trade in both directions. If you are the vendor, you have warranted conformity with a regime whose technical benchmarks are not published yet, against a standard the Commission has already said does not align with the requirement in question. If you are the buyer, you have taken a warranty that means less than it reads. The honest answer to the RFP question is short and it wins more deals than the overclaim: we hold ISO 42001, we maintain an AI system inventory and impact assessments, we are tracking EN 18286 and the JTC 21 deliverables, and we will map our quality management system to the harmonised standards when they are cited in the Official Journal. Put that in the trust centre and stop improvising it call by call.

The work for the next two quarters is a gap map, and it is cheaper now than later. Take your Annex A controls from 42001 and lay them against the Article 17 quality management elements: the regulatory compliance strategy, design control, data management, testing and validation, post market monitoring, serious incident reporting, record keeping, and the accountability framework. Most of your existing evidence will land somewhere, and the holes will cluster in the same three places for nearly everyone, which are post market monitoring, technical documentation kept current rather than written once, and traceability from a model version to the dataset and the test results behind it. Fix those three while there is no deadline attached and EN 18286 becomes a delta rather than a programme. Vanta, Drata, Secureframe, Sprinto and Thoropass all now ship ISO 42001 frameworks that cross map to the ISO 27001 and SOC 2 controls you already evidence, so a large part of this is inheritance rather than new control design, and doing it inside the platform you already pay for keeps the evidence in one place when an auditor asks.

The trigger event to watch is narrow and easy to monitor: the first citation of an AI Act harmonised standard in the Official Journal. That is the moment presumption of conformity becomes available, the moment the compliance platforms will race to ship the mapped framework, and the moment your buyers language shifts from asking about ISO 42001 to asking which harmonised standards you conform to. On current timelines that is plausibly late 2026 or the first half of 2027, and EN 18286 is the most likely first name on the list. Between now and then, the useful posture is to be precise in public and busy in private. Say what your certificate actually proves, do not let a sales cycle turn it into a legal claim, and spend the interval closing the three gaps above. The companies that get hurt here will not be the ones without certification, they will be the ones who believed the certificate finished the job.

ISO 42001EU AI ActEN 18286harmonised standardsAI governanceISO 27001SOC 2

Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.

// Signal, not noise

Get the next post by email

One short email when something worth knowing ships. No spam, unsubscribe anytime.

More from the blog