EU AI Act High-Risk Rules Are Live. ISO 42001 Isn't Enough
The EU AI Act's high-risk AI system requirements became enforceable on August 2, 2026. Many AI vendors prepared by getting ISO 42001 certified, but the certification leaves five specific gaps the Act requires: product-level conformity assessment, prescriptive technical documentation, built-in human oversight interfaces, fundamental rights impact assessments, and post-market monitoring with 15-day incident reporting. This post maps each gap and what to do about it.
The Date Nobody Should Have Missed
On August 2, 2026, the EU AI Act's high-risk AI system requirements became legally enforceable. That was eight days ago. If your company sells an AI system into the European Union that qualifies as high-risk under Annex III , think recruitment screening, credit scoring, biometric categorisation, or medical device AI , you are now subject to mandatory obligations covering risk management, data governance, technical documentation, transparency, human oversight, and accuracy. And the penalties for getting it wrong are not small.
Under Article 99 of the EU AI Act, non-compliance with the high-risk obligations can draw fines of up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. For a Series B SaaS company with €30M in revenue, that is €900,000. For an enterprise vendor crossing €100M, it is €3M. These are not hypothetical numbers. The enforcement architecture is now active.
Many AI vendors prepared for this moment by pursuing ISO/IEC 42001 certification. That was smart. But here is what the ISO 42001 marketing materials will not tell you: certification alone leaves gaps the EU AI Act specifically requires you to close. This post maps those gaps.
The Timeline (Because It Matters)
The EU AI Act, formally Regulation (EU) 2024/1689, was published in the Official Journal on July 12, 2024 and entered into force on August 1, 2024. It uses a staggered implementation schedule under Article 113:
- February 2, 2025: Prohibited AI practices banned (social scoring, real-time biometric surveillance in public spaces, emotion recognition in workplaces).
- August 2, 2025: General-purpose AI model rules took effect, including transparency and documentation requirements for foundation model providers.
- August 2, 2026: This one. All obligations for high-risk AI systems under Annex III became enforceable. Risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity , all live.
- August 2, 2027: The final wave. Certain high-risk categories get an extra year, specifically AI systems that are safety components of products regulated under existing EU harmonisation legislation (machinery, medical devices, toys, etc.).
If your AI system does not fall into that 2027 extension category, you have been in scope since last week. The grace period is over.
Where ISO 42001 Helps (Credit Where It's Due)
ISO/IEC 42001:2023 is the first international management system standard for AI. It provides a structured framework for establishing, implementing, maintaining, and continually improving an AI management system (AIMS). Clause 4 requires understanding the organisation and its context , including external regulatory obligations. Clause 6 covers AI risk assessment and treatment. Clause 8 addresses operational planning and control. Annex A provides a set of control objectives covering everything from AI policy to data quality to supplier management.
If you have a functioning ISO 42001 management system, you have the scaffolding. You have documented processes for risk assessment. You have defined roles and responsibilities. You have internal audit cycles. These are real assets when facing the EU AI Act. But scaffolding is not the finished building.
Gap 1: Conformity Assessment Is Not an Internal Audit
ISO 42001 requires internal audits (Clause 9.2) and management reviews (Clause 9.3). These are process audits , they check that your AIMS is working as designed. The EU AI Act requires conformity assessment under Article 43 for high-risk AI systems. This is a product-level assessment that verifies the AI system itself meets each of the mandatory requirements in Articles 8 through 15.
The difference matters. Your ISO 42001 internal auditor can confirm you have a risk management process. The EU AI Act conformity assessor needs to confirm the risk management output , that specific risks were identified, that mitigation measures were tested, that residual risk is acceptable. An internal audit finding of "risk management process is documented and followed" does not satisfy Article 9's requirement for "testing of the identified risk management measures."
For most Annex III high-risk AI systems, conformity assessment can initially be performed internally (Annex VI). But the documentation , including a written EU declaration of conformity , must stand up to external scrutiny by notified bodies and market surveillance authorities. ISO 42001 internal audit records will not substitute for conformity assessment evidence.
Gap 2: Technical Documentation Goes Further Than ISO 42001 Asks
ISO 42001 Annex A.7.4 requires documented information about AI system design but is deliberately flexible about what that documentation looks like. Article 11 of the EU AI Act and Annex IV lay out a specific, prescriptive list:
- A general description of the AI system including its intended purpose
- A detailed description of the system design and development methodology
- Design specifications including algorithms, data, training methodologies
- Metrics used to measure accuracy, robustness, and other performance indicators
- Logging capabilities (Article 12 requires automatic event logging)
- Human oversight measures (Article 14 requires built-in interfaces)
- Description of changes made to the system (post-market monitoring, Article 72)
The gap is not that ISO 42001 forbids any of this. It is that ISO 42001 does not require any of it at a specific level of detail. An organisation with ISO 42001 certification may have perfectly adequate documentation for a management system audit but still fall short of Annex IV's technical documentation requirements. The Annex IV document is closer to what you would submit for a medical device CE marking than what you would show a management system auditor.
Gap 3: Human Oversight Is Prescriptive Under the Act
ISO 42001 Annex A.9.3 says the organisation should determine the level of human involvement in AI system decision-making. It uses the language of "should" , it is a control objective, not a hard design requirement.
Article 14 of the EU AI Act is not optional. High-risk AI systems must be designed and developed so that natural persons can oversee their functioning. This includes specific measures: the ability to fully understand the system's capacities and limitations, remain aware of automation bias, correctly interpret outputs, decide not to use the system in a particular situation, and override or reverse its output. The human oversight interface must be built into the system , it cannot be bolted on through a policy document.
If your ISO 42001 AIMS documents that "humans review high-risk decisions" but your AI system does not provide a built-in override mechanism, you have a compliance gap that an ISO 42001 certificate does not close.
Gap 4: Fundamental Rights Impact Assessment (FRIA)
ISO 42001 Clause 6.1.2 covers AI risk assessment and treatment. It is broad , it asks you to identify risks related to the AI system and plan actions to address them. But it does not specifically require a fundamental rights impact assessment, which Article 27 of the EU AI Act mandates for certain deployers of high-risk AI systems.
A FRIA is not a generic risk assessment. It must assess the specific impact of the AI system on the rights enshrined in the EU Charter of Fundamental Rights: non-discrimination, data protection, freedom of expression, right to an effective remedy. It must describe the deployer's processes for human oversight, the categories of natural persons affected, and the measures taken to mitigate identified risks. It must be conducted before the system is put into use and updated throughout its lifecycle.
An ISO 42001 risk register , even a thorough one , almost certainly does not meet the specificity of a FRIA unless it was designed to. Most ISO 42001 audits do not probe for Charter-level rights analysis. EU market surveillance authorities will.
Gap 5: Ongoing Post-Market Monitoring and Incident Reporting
ISO 42001 Clause 10 requires continual improvement , monitoring, measurement, analysis, and evaluation. This is a sound management principle. But Article 72 of the EU AI Act creates a specific, legal obligation for providers of high-risk AI systems to establish and document a post-market monitoring system that collects and analyses data on the system's performance throughout its lifetime. And Article 73 requires providers to report any serious incident to the market surveillance authorities within 15 days of becoming aware of it.
"Continual improvement" under ISO 42001 does not equal "post-market monitoring system with defined KPIs and a 15-day incident reporting obligation." The first is a management commitment. The second is a regulated process with legal consequences for missing deadlines.
What to Do Now
If you have ISO 42001 certification and you sell a high-risk AI system into the EU, here is your compliance roadmap:
- Confirm your classification. Not every AI system is high-risk. Check Annex III. If you are in education, employment, essential services, law enforcement, migration, or democratic processes, assume high-risk until proven otherwise. The list is broader than most founders think.
- Gap-assess your ISO 42001 evidence against Annex IV. Take your existing technical documentation and map it, point by point, against the Annex IV requirements. Where ISO 42001 asks for "documented information," Annex IV asks for "design specifications including algorithms and training methodologies." Fill every gap.
- Build the human oversight interface. If your system does not have a built-in override or stop mechanism accessible to human operators, you need one. A policy saying "an operator will review outputs" is not enough , the interface must exist in the product.
- Conduct a FRIA if you are a deployer. Article 27 applies to deployers, including bodies governed by public law and private operators in specific high-risk categories. If that is you, start the FRIA now. If you are a provider, help your deployers by sharing the information they need to complete theirs.
- Set up post-market monitoring with a 15-day incident reporting clock. Define what a "serious incident" looks like for your system. Assign responsibility. Test the reporting workflow before you need it , because when you need it, you will have 15 calendar days, not 15 business days.
For a deeper look at the specific obligations that went live, see our breakdown of the five EU AI Act compliance obligations that every AI vendor needs to address. And if you are mapping multiple frameworks, our analysis of ISO 42001, NIST AI RMF, and EU AI Act convergence shows where the frameworks align and where they do not.
At BizThriveAI, we audit AI vendors against both ISO 42001 and EU AI Act readiness frameworks. We have seen firsthand that organisations with strong management systems still stumble on the prescriptive product-level requirements. The gap between a certified process and a compliant product is real, and it is where enforcement action lands.
If you are an AI vendor selling into the EU, now is the time to close these gaps. The enforcement architecture is active. The fines are substantial. And the compliance burden only increases from here , the 2027 wave will bring even more Annex III categories into scope.
Get a compliance gap assessment or see what an AI audit report looks like before market surveillance authorities ask you for one.
Written by David Swan, reviewed and fact-checked against primary regulatory sources. AI-assisted but human-directed.
Frequently asked questions
What changed on August 2, 2026 for AI vendors?
The EU AI Act's high-risk AI system obligations under Articles 8-15 became legally enforceable. This includes mandatory requirements for risk management, data governance, technical documentation, transparency, human oversight, accuracy, robustness, and cybersecurity for any AI system classified as high-risk under Annex III.
Does ISO 42001 certification cover the EU AI Act's high-risk requirements?
Partially but not completely. ISO 42001 provides a management system framework that helps with process-level compliance, but it does not cover product-level conformity assessment, prescriptive technical documentation (Annex IV), built-in human oversight interfaces (Article 14), fundamental rights impact assessments (Article 27), or post-market monitoring with incident reporting (Articles 72-73).
What are the fines for non-compliance with the EU AI Act's high-risk rules?
Under Article 99, non-compliance with high-risk AI obligations can result in fines of up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. For providing incorrect information, fines reach up to €7,500,000 or 1%.
Which AI systems are classified as high-risk under the EU AI Act?
Annex III lists high-risk categories including AI systems used in biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services (credit scoring, insurance), law enforcement, migration and border control, and administration of justice and democratic processes. AI systems that are safety components of regulated products are also high-risk.
What is the difference between ISO 42001's risk management and the EU AI Act's conformity assessment?
ISO 42001 requires a risk management process , a system for identifying and addressing AI risks. The EU AI Act's conformity assessment (Article 43) requires verification of specific risk management outputs: that individual risks were identified, tested, and mitigated with documented evidence. A process-level audit finding does not satisfy product-level conformity assessment.
When do the remaining EU AI Act deadlines take effect?
The final wave of obligations takes effect on August 2, 2027, covering AI systems that are safety components of products regulated under existing EU harmonisation legislation (e.g., machinery, medical devices, toys). Prohibited practices were banned from February 2, 2025, and general-purpose AI rules took effect August 2, 2025.


