AI Act and ISO 42001

What does the AI Act mean for your organisation?

From an AI inventory and literacy to risk classification and control.

Map your AI applications, roles and risks and determine which obligations under the European AI Act are relevant.

Start with your role and use case

The rules differ for providers, deployers, importers and distributors. An organisation may have different roles for different applications.

For each AI system, describe its purpose, user, data involved, supplier, impact and the decisions it supports or makes.

  • prohibited applications
  • high-risk AI systems
  • transparency obligations
  • rules for general-purpose AI models
  • other AI involving general governance and due care considerations

Which application dates apply?

The general application date is 2 August 2026, subject to exceptions. The original prohibited practices and AI literacy provisions have applied since 2 February 2025; rules for general-purpose AI models since 2 August 2025, subject to transitional provisions. Following amending Regulation (EU) 2026/1744, the relevant high-risk rules in Chapter III, Sections 1–3, apply from 2 December 2027 for Article 6(2) / Annex III and from 2 August 2028 for Article 6(1) / Annex I. Article 6(5) is excluded from this postponement. New prohibitions introduced by the amendment apply from 2 December 2026. Also check the transitional provisions for existing systems in each case.

Providers and deployers must take measures to support AI literacy among relevant staff and others using AI systems on their behalf. The amended provision does not require a guarantee of any specific individual level of knowledge. Tailor guidance and training to people’s knowledge, the application and those affected.

Create a workable AI register

The internal AI register below is a practical way to maintain oversight. It is not a general statutory registration requirement for every AI application. Registration in the EU database, where required, is a separate obligation for specific systems and roles.

A spreadsheet can be a starting point, but agree who reports new applications and who assesses them. Include built-in AI features in existing software and informal use of generative AI.

Record at least the owner, purpose, supplier, data, users, risk category, decision-making and agreed controls.

What do you need to organise now?

Create one straightforward approval process proportionate to the risk. Not every application needs an extensive file, but every application must be identifiable and used responsibly.

The AI Act, GDPR and other rules alongside one another

The AI Act does not replace privacy, employment or consumer law. An AI application may also require a DPIA, an information security assessment, corporate governance decisions or a sector-specific assessment.

Use a single intake process that involves the relevant disciplines early, rather than separate checks afterwards.

Frequently asked questions

Does the AI Act apply only to developers?+

No. Organisations using AI systems may also have obligations.

Must every AI application be prohibited or certified?+

No. The obligations depend on the role and risk category.

What is AI literacy?+

Appropriate knowledge and skills to understand and use AI responsibly, tailored to the context and risks.

Sources and further reading

We prioritise primary sources for factual and time-sensitive information. Always check the current official publication when making important decisions.

Related articles

AI Act and ISO 42001ISO 42001 and the AI Act: what is the difference?Read article →GDPR and privacyWhen is a DPIA required?Read article →Suppliers and supply chain securityWhat does NIS2 mean for suppliers and the supply chain?Read article →

This is general guidance and does not replace a legal assessment or the official standard.