ISO 42001 and the EU AI Act: What UK Companies Actually Need to Do
Two things happened in quick succession: the EU adopted the world's first comprehensive AI law, and ISO published the world's first certifiable AI management standard. They are frequently confused, sometimes deliberately by vendors. This article untangles them for UK companies, and explains when each one actually applies to you.
Two different instruments
The EU AI Act is law. It applies to providers and deployers of AI systems placed on the EU market or affecting people in the EU, wherever the company sits, which is why a UK firm selling AI-enabled software into Europe cannot ignore it. Its obligations scale with risk: prohibited practices at the top, strict duties for high-risk systems, transparency duties for others, and comparatively little for minimal-risk uses.
ISO/IEC 42001 is a standard. Nobody is obliged to adopt it. It defines an Artificial Intelligence Management System (AIMS): the governance, risk assessment, impact assessment and lifecycle controls an organisation wraps around its development and use of AI. Like ISO 27001, it is certifiable by independent audit.
Does the AI Act apply to you?
For a UK company the honest questions are: do you place an AI system on the EU market, do your outputs get used in the EU, and does what you build or deploy fall into the Act's high-risk categories, such as AI used in recruitment, credit scoring, critical infrastructure or medical devices? If the answers are no, the Act may touch you only lightly. If any answer is yes, you have real obligations, with substantial penalties for getting the serious ones wrong, and your EU customers will increasingly ask you to evidence compliance in procurement long before a regulator ever calls.
Where ISO 42001 fits
The AI Act tells you what outcomes are required. It does not tell you how to run an organisation that reliably achieves them. That is precisely what a management system standard does, and it is why ISO 42001 has become the practical backbone for AI Act readiness: risk and impact assessments become systematic rather than heroic, roles and accountability are defined, data and model lifecycles are documented, and evidence accumulates as a by-product of normal operation rather than a scramble before an audit or a customer questionnaire.
Certification also solves a commercial problem the Act does not: proof. A certificate from an accredited body is a one-line answer to the AI governance section of every security questionnaire you will see this year.
What UK companies should actually do
- Inventory your AI. You cannot govern what you have not listed, and most organisations are using more AI than they think, much of it embedded in SaaS tools.
- Classify against the Act. Establish whether anything you provide or deploy touches the EU and where it sits in the risk hierarchy. This is usually a short, clarifying exercise.
- Stand up proportionate governance. An AI policy, a risk and impact assessment process, and clear accountability. ISO 42001 gives you the structure so you are not inventing one.
- Build on what you have. If you already run ISO 27001, the overlap is substantial: the same management system disciplines, extended to AI. The two certify well together.
A note on timing
The AI Act's obligations phase in over several years, and standards and guidance underneath it are still maturing. That is an argument for starting with governance now, not for waiting: organisations that certified ISO 27001 early will recognise the pattern, because the companies that treat AI governance as a design decision rather than a retrofit will spend far less and win the enterprise deals in the meantime.
Cybercontrols is itself certified to ISO/IEC 42001, one of the first UK consultancies to be so, and we implement the standard for clients alongside ISO 27001 and ISO 27701. If you want to know what the AI Act and ISO 42001 mean for your specific products, a free scoping call with a senior consultant will map it out.
