The AI Act, a binding regulatory framework governing the use of AI
The world’s first legal framework for artificial intelligence
Published in the Official Journal of the European Union (OJEU) on 12 July 2024, the European AI Regulation (AIR) entered into force on 1 August 2024. It constitutes a binding regulatory framework.
Regulation (EU) 2024/1689 establishes harmonised rules intended to regulate the use of artificial intelligence. It focuses on the protection of fundamental rights, transparency, governance, and accountability.
A risk-based approach
In line with previous European regulations dealing with cybersecurity and digital issues, the AI Act promotes a risk-based approach.
The regulation classifies AI systems according to four risk levels:
- Unacceptable risk — Prohibition: Concerns systems such as behavioural manipulation, social scoring, or certain forms of real-time biometric recognition.
- High risk — Strict obligations: Applies to critical sectors: recruitment, health, education, justice, critical infrastructure, credit assessment, and border control.
- Limited risk — Transparency obligations: Groups together consumer tools such as chatbots or image and video generation systems (deepfakes).
- Minimal risk — No specific obligations: Encompasses the majority of current applications: anti-spam filters, video games, or standard content recommendation algorithms.
The European AI regulation primarily concerns AI developers and deployers, providers of high-risk AI systems, and providers of general-purpose AI (GPAI) models.
Software publishers integrating AI components into their products are particularly concerned. The AI Act imposes on them, in particular, the requirement to demonstrate that they have properly taken into account the risks inherent in AI integration and implemented all necessary measures to ensure the responsible use of artificial intelligence.
AI Act: application from 2027 for high-risk AI systems
The full applicability of the European AI regulation was scheduled for 2 August 2026. As part of the "Digital Package on Simplification" (or "Digital Omnibus Package"), the schedule and methods for implementing the AI Act have been reviewed. The objective: to simplify the implementation of the text and ensure that the rules remain clear, simple, and compatible with innovation.
The application of obligations regarding high-risk AI systems is scheduled as follows:
- From 2 December 2027 for AI systems used in high-risk contexts such as biometrics, critical infrastructure, education, etc.
- From 2 August 2028 for systems integrated as safety components and covered by European Union sectoral legislation regarding safety and market surveillance.
In the event of non-compliance with the obligations, the AI Act provides for fines of up to €35 million or 7% of total worldwide annual turnover.
ISO 42001 certification, an effective methodological framework to prepare for AI Act compliance
ISO 42001, a standard dedicated to AI governance
While the AI Act constitutes a binding regulatory framework, the ISO 42001 standard is a voluntary standard, the first standard dedicated to AI management. It allows organisations to implement governance around artificial intelligence via an AI Management System (AIMS).
Any organisation developing, integrating, or operating AI systems and wishing to establish, implement, maintain, and continually improve an AI management system can voluntarily commit to an ISO 42001 certification process.
Producers, providers, and users of AI systems can use it to attest that they have properly taken into account the risks and challenges posed by AI, and that they are addressing them through concrete measures. The objective: to ensure the development and use of AI systems in a responsible and secure manner.
Many overlaps between ISO 42001 and the AI Act
Although ISO 42001 and the AI Act are not of the same nature (the former constitutes a voluntary framework, the latter a binding regulatory framework), their requirements have many correspondences, particularly regarding:
- Governance and risk management,
- Data governance and quality,
- Technical documentation and transparency,
- Traceability and log keeping,
- Human control and supervision,
- Accuracy, robustness, and cybersecurity,
- Evaluation of societal impacts.
As a management system standard, ISO 42001 allows for the tracking and documentation of practices. By providing a documented framework and a methodology for implementing AI governance, ISO 42001 certification helps organisations to effectively prepare for their AI Act compliance.
Note
The AI Act provides for several additional requirements that the ISO 42001 standard does not cover (strict classification by risk levels and prohibitions, CE marking and EU declaration of conformity, mandatory registration in an EU public database, etc.).
ISO 42001 certification does not, therefore, lead to full compliance with the AI Act on its own. However, it constitutes a relevant methodological framework to effectively prepare for compliance with the European AI regulation.

