The EU AI Act's high-risk obligations become applicable on 1 August 2026 — and they reach UK companies whose AI output lands in the EU. ISO/IEC 42001 is the fastest structured route to readiness. Here is what the duties require, how the standard maps onto them, and — just as important — where it stops.
Most UK businesses I speak to have filed the EU AI Act under "not our problem — we left." That is a costly misreading. The Act is extraterritorial by design: it bites where the AI system is placed on the EU market, and where the output of an AI system is used inside the EU. Neither test asks where your company is registered.
So a Portsmouth software firm with Dutch customers is potentially in scope. So is a UK consultancy whose AI-assisted reports are relied on by a client in Dublin. And with the bulk of the high-risk obligations becoming applicable on 1 August 2026, the window to build the governance evidence — not just claim it — is now measured in weeks.
This piece sets out three things: what the high-risk duties actually require, an indicative mapping showing how far ISO/IEC 42001 (the AI management system standard) carries you, and an honest account of the gaps the standard will not close on its own.
If an AI system you build, sell, or operate produces output that is used in the EU, assume you are in scope until a documented assessment tells you otherwise — and keep that assessment as evidence.
The Act is tiered, not blanket. Most business software is not high-risk. The high-risk category is defined by use case, not by how clever the model is — and it covers AI used in areas such as employment and worker management (CV screening, promotion or task-allocation decisions), access to essential services including creditworthiness assessment, education and vocational training decisions, biometrics, critical infrastructure, and safety components of regulated products.
That last one catches people out. If your AI is a safety component of a product that already falls under EU product-safety legislation, it can be high-risk regardless of how mundane it looks.
The first deliverable, therefore, is not a policy — it is an AI inventory. Every AI system you develop, embed, buy, or operate; what it does; whose data it touches; whether its output reaches the EU; and a reasoned classification against the Act's tiers. Auditors and regulators alike will ask for this before anything else, and "we don't think we're high-risk" is not an answer unless you can show the working.
For systems that are high-risk, the Act sets out a cluster of provider duties. In practical terms you need to be able to evidence all of the following:
Read that list again and it should feel familiar. It is, almost line for line, the shape of a management system: govern the risk, control the data, document the thing, log what it does, tell people how to use it, keep a human in the loop, test it, and run a QMS over the top.
ISO/IEC 42001:2023 is the international AI management system standard. It uses the same Harmonised Structure as ISO 9001, ISO 14001, ISO 45001 and ISO 27001 — context, leadership, planning, support, operation, performance evaluation, improvement — with an Annex A control set specific to AI: AI policy, internal organisation, resources for AI systems, AI system impact assessment, lifecycle management, data for AI systems, information for interested parties, responsible use, and third-party relationships.
The overlap with the Act's high-risk duties is substantial. This is an indicative mapping — it is a planning aid, not a conformity claim — but it shows why so many UK firms are using 42001 as the delivery vehicle:
| EU AI Act high-risk duty | Where ISO/IEC 42001 builds it | Fit |
|---|---|---|
| Risk management system across the lifecycle | Clause 6.1 (actions to address risks & opportunities); Annex A AI system impact assessment | Strong |
| Data & data governance, bias examination | Annex A — data for AI systems (provenance, quality, preparation) | Strong |
| Technical documentation | Clause 7.5 (documented information) + lifecycle documentation controls | Partial — structure yes, EU-specified format no |
| Record-keeping & automatic logging | Clause 9.1 (monitoring, measurement, analysis); lifecycle operation controls | Partial — the standard expects records; the Act specifies logging |
| Transparency & information for deployers | Annex A — information for interested parties | Strong |
| Human oversight | Annex A — responsible use of AI systems; competence (Clause 7.2) | Strong |
| Accuracy, robustness, cybersecurity | Lifecycle verification & validation; interfaces with ISO 27001 Annex A for the security half | Partial — pair with ISO 27001 |
| Quality management system | The whole of ISO 42001 Clauses 4-10 | Strong |
| Conformity assessment, CE marking, EU declaration, EU database registration | — | Not covered |
| Post-market monitoring & serious-incident reporting to authorities | Clause 10 improvement gives the mechanism, not the regulatory reporting duty | Partial at best |
You will see vendors imply that an AI governance module makes you EU AI Act compliant. It does not, and an assessor will not thank you for repeating it. Three things are worth stating plainly:
ISO 42001 is not a harmonised standard under the Act. Certification does not confer a presumption of conformity in the way a harmonised standard would. It is powerful evidence that you run a disciplined AI management system; it is not a passport.
The product-level duties are genuinely separate. Conformity assessment, the EU declaration of conformity, CE marking and registration in the EU database are regulatory steps with their own process. No management-system standard delivers them.
Roles matter. The Act distributes duties between providers, deployers, importers and distributors. A UK firm that merely uses a third-party high-risk system carries deployer duties — meaningful, but different from a provider's. Getting your role wrong is the fastest way to build the wrong evidence pack.
List every AI system you develop, embed, buy or operate. Capture purpose, data used, who relies on the output, and whether that output reaches the EU. This single artefact drives everything downstream.
For each system: which tier, and are you provider or deployer? Write down the reasoning. A defensible "not high-risk" conclusion is worth as much as a compliance project — but only if it is documented.
For anything high-risk or borderline, assess the risks to health, safety and fundamental rights, and record the mitigations. This is the 42001 Annex A control that most directly answers the Act's risk-management duty.
Provenance, representativeness, bias examination, preparation steps. This is where most organisations are thinnest, and it is the hardest to reconstruct retrospectively.
Traceable logs over the system's lifetime, and a named competent person who can interpret, monitor, intervene and override — with the training record to prove competence.
Record the Act itself, your role, the applicable articles and the 1 August 2026 milestone, with a review date. If you hold ISO 27001, control A.5.31 already expects this discipline — extend it to AI.
Almost every UK organisation I take through 42001 already holds, or is working towards, ISO 27001. That is fortunate, because the Act's accuracy-robustness-cybersecurity requirement is half an information-security problem, and the transparency and documentation duties lean on records discipline you have already built.
Because both standards share the Harmonised Structure, you are not running two management systems. You are extending one: the same context, leadership, competence, documented-information, internal-audit and management-review machinery, with an AI-specific Annex A layered on top. In practice that turns a daunting programme into an extension of something already certified — which is the difference between a nine-month project and a focused quarter.
This is precisely the problem PICMS was built for. The platform ships the ISO 42001 Annex A control set alongside ISO 27001's 93 Annex A controls, so the AI management system sits next to the information security management system rather than in a separate silo. The legal register carries the EU AI Act as a tracked obligation with its own review date, and AI evidence mapping links the documents you already hold to the controls they satisfy — so when an assessor asks "show me your AI impact assessment and the data-governance evidence behind it", the answer is a filter, not a fortnight.
To be plain about what software does and does not do: PICMS does not make you compliant, and this article is general guidance rather than legal advice. What it does is hold the obligation on your register, keep the control set and its evidence current, and make the gap between where you are and where 1 August 2026 requires you to be visible while there is still time to close it.
PICMS ships the ISO 42001 Annex A control set alongside ISO 27001, tracks the EU AI Act on your legal register, and maps your existing evidence to the controls it satisfies.