---
title: "AI Act in 2026: The Legal Obligation Is Already Underway"
description: Explore the intersection of the AI Act and ISO/IEC 42001, highlighting legal obligations and management frameworks for effective AI governance.
image: https://blog.isecauditors.com/hubfs/ria-en-2026-la-obligacion-legal-ya-esta-en-marcha.png
---

English

- [Spanish](https://blog.isecauditors.com/ria-en-2026-la-obligacion-legal-ya-esta-en-marcha)
- [English](https://blog.isecauditors.com/en/ai-act-in-2026-the-legal-obligation-is-already-underway)

[![290x123px\_isecauditors](https://blog.isecauditors.com/hs-fs/hubfs/ISEC%20Media/Blog%20Media/290x123px_isecauditors.png?width=290&height=91&name=290x123px_isecauditors.png) ![290x123px\_isecauditors](https://blog.isecauditors.com/hs-fs/hubfs/ISEC%20Media/Blog%20Media/290x123px_isecauditors.png?width=290&height=91&name=290x123px_isecauditors.png)](https://blog.isecauditors.com/?hsLang=en)

- [← www.isecauditors.com](https://www.isecauditors.com/)
- [academy.isecauditors.com](https://academy.isecauditors.com/)

- [← www.isecauditors.com](https://www.isecauditors.com/)
- [academy.isecauditors.com](https://academy.isecauditors.com/)

[ISO 42001](https://blog.isecauditors.com/en/tag/iso-42001) [AI](https://blog.isecauditors.com/en/tag/ai) [AIR](https://blog.isecauditors.com/en/tag/air) [Implementation of an SGIA](https://blog.isecauditors.com/en/tag/implementation-of-an-sgia)

# AI Act in 2026: The Legal Obligation Is Already Underway

[Alberto Villar Arévalo](https://blog.isecauditors.com/en/author/alberto-villar)  Sep 29, 2026, 11:06:07 AM

As of September 2026, the AI Act can no longer be treated as a future regulation. Regulation (EU) 2024/1689 entered into force in 2024 and is binding in its entirety and directly applicable in the Member States. Some obligations have applied since February 2025, including those relating to certain prohibited practices and AI literacy; others since August 2025; and on 2 August 2026, the general application of the Regulation and the effective supervision of new obligations began. \[1–2\]

AI Act: Implementation Timeline Relevant as of September 2026

| **02/02/2025** | **02/08/2025** | **02/08/2026** | **2027-2028** |
| --- | --- | --- | --- |
| First obligations: prohibitions, definitions, and AI literacy | Governance, general-purpose AI models, and other provisions | **General application of the Regulation and new transparency obligations** | Phased application of high-risk obligations: 02/12/2027 (Annex III) and 02/08/2028 (Annex I), according to the current consolidated text |
| **Key legal and operational point. The AI Act is a legally binding regulation and directly applicable. ISO/IEC 42001 is not a law, and its implementation or certification is voluntary, unless there is a contractual or sector-specific obligation requiring it. However, if an organization intends to claim conformity with ISO/IEC 42001 or obtain certification, it must implement the requirements of the standard, including the internal audit of the AIMS (Artificial Intelligence Management System) and management review. \[1, 3–4\]** |  |  |  |

# AI Act and ISO 42001: Mandatory vs. Voluntary

The AI Act establishes which practices are prohibited, which obligations apply to each operator, and which requirements must be met by certain AI systems and models. Non-compliance may result in supervisory actions, corrective measures, and financial penalties that, for the most serious infringements, may reach €35 million or 7% of the worldwide annual turnover, where the higher percentage applies. \[1\]

ISO/IEC 42001 approaches the issue from a different perspective: it defines how to establish a management system to govern AI systematically through context, leadership, policy, roles, risk and impact assessments, controls, documented information, operations, measurement, internal audit, management review, and continual improvement. Certification is voluntary and is carried out by an independent certification body; ISO does not certify organizations. \[3–4\]

# Who Is Affected by the AI Act and What Role Does ISO 42001 Play?

The first question for any organization is not, "Do we need ISO 42001 certification?" but rather, "What role do we play in relation to each AI system, and what legal obligations apply to us?"

The AI Act distinguishes between operators and assigns different obligations depending on the role, the type of system, and the level of risk. ISO/IEC 42001 can provide the common governance framework for managing those roles within a single organization, including both internally developed AI and third-party solutions. \[1\]

| **Aspect** | **AI Act / RIA** | **ISO/IEC 42001** |
| --- | --- | --- |
| **Nature** | European Union Regulation: a legal obligation when applicable. | Voluntary international management system standard. |
| **Purpose** | To regulate the development, placing on the market, and use of AI according to risks, operators, and use cases. | To govern AI through a structured, repeatable, and continually improvable AIMS (Artificial Intelligence Management System). |
| **Who Must Comply** | Providers, deployers, importers, distributors, authorized representatives, and certain providers of general-purpose AI models, depending on the case. | Any organization that wishes to systematically manage the AI it develops, provides, or uses. |
| **Assessment / Certification** | May require conformity assessment and, depending on the case, the involvement of third parties or notified bodies. | AIMS certification is voluntary and carried out by an independent certification body. |
| **Internal Audit** | There is no general obligation for an “AI Act internal audit” applicable to all operators; however, it is a recommended tool for validating compliance and supporting evidence. | Internal auditing is a requirement of the AIMS (Clause 9.2) and is necessary to demonstrate that the management system has been implemented before certification. |
| **The Key Is Integration, Not Duplication. A single inventory of AI systems, a common methodology for risk and impact assessment, clear roles and responsibilities, supplier controls, data management, documentation, human oversight, monitoring, and incident management can generate evidence that is useful for both the AI Act and ISO/IEC 42001. The objective is for a single organizational capability to support two different needs: legal compliance and certifiable AI governance.** |  |  |

# From Legal Obligation to an Auditable Management System

The convergence is particularly evident in organizations operating high-risk AI systems or sensitive AI use cases. Among other requirements, the AI Act mandates risk management, data governance and quality, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity, monitoring obligations, and corrective measures. For providers of high-risk systems, Article 17 additionally requires a documented quality management system. \[1\]

ISO/IEC 42001 makes it possible to transform many of these obligations into sustainable management processes: identifying context and interested parties, defining scope and policy, assigning responsibilities, assessing AI risks and impacts, establishing objectives and controls, governing data and third parties, ensuring competence and AI literacy, controlling documented information, measuring results, and correcting deviations. It is precisely this management layer that prevents compliance from depending on isolated documents or specific individuals. \[3\]

However, equivalence should never be assumed automatically. The AI Act contains specific legal obligations, such as system classification, conformity assessment, registration, CE marking, and certain transparency requirements, which must be explicitly verified. Likewise, ISO/IEC 42001 includes management system requirements that may go beyond what the AI Act requires for a particular organization. A gap analysis should identify both directions.

# What Being Truly Aligned Means

A mature organization should be able to answer, with evidence, at least the following questions: What AI systems does it use or develop? What is their intended purpose? Who acts as provider, deployer, or another operator? How are the systems classified under the AI Act? Which data, models, suppliers, and components are involved? What risks and impacts have been assessed?  
Who approves their use? How is human oversight ensured? What is monitored during operation? How are changes, incidents, and complaints managed? How is continued effectiveness of controls demonstrated?

| **Role / Situation** | **AI Act Implications** | **What the AIMS Should Govern** |
| --- | --- | --- |
| **Provider** | Primary responsibility for system requirements, documentation, conformity assessment, and post-market monitoring where applicable. | Lifecycle management, design, risks, data, testing, documentation, change management, security, suppliers, and monitoring. |
| **Deployer** | Use in accordance with instructions, human oversight, and specific obligations associated with the context of use. | Use case approval, competencies, intended use, operational controls, monitoring, and escalation processes. |
| **Importer / Distributor** | Verification activities and obligations before placing or making certain AI systems available on the market. | Due diligence, supplier evidence, procurement conditions, traceability, and third-party management. |
| **General-Purpose AI / Third-Party AI** | Specific obligations may fall on the model provider; however, the business user remains responsible for its own use of the system. | Model inventory, contracts, received documentation, risk assessments, usage restrictions, and dependency monitoring. |

## Phase 1: Gap Assessment and Prioritized Action Plan

The first step should be a joint AI Act + ISO/IEC 42001 gap analysis. The objective is not to distribute a generic questionnaire, but to gather information through interviews with the areas that actually understand and operate AI: executive management, technology, development, data, security, privacy, compliance, human resources, procurement, legal, and business owners, among others. The scope should begin with the inventory of AI systems, including third-party services and any uses that may exist outside corporate channels.

| **Analysis Area** | **Example Checks** | **Expected Outcome** |
| --- | --- | --- |
| **Governance, Scope, and Roles** | AI inventory, AI Act classification, intended purpose, operators, policy, committee, responsibilities, and AI literacy. | Scope and responsibility mapping; identification of governance gaps and legal obligations. |
| **Risks, Data, and Lifecycle** | Risk/impact assessment methodology, data quality and provenance, bias, testing, security, change management, and suppliers. | Existing controls, technical and documentation gaps, and prioritized remediation projects. |
| **Transparency, Oversight, and Improvement** | Information provided to users, rights, human oversight, monitoring, incident management, auditing, metrics, and continual improvement. | Evidence matrix, compliance level assessment, and an Action Plan with verifiable closure criteria. |

During the gap assessment, AI Act applicability is evaluated for each system and operator role, clauses 4 to 10 and Annex A controls of ISO/IEC 42001 are reviewed, and every requirement is compared against actual evidence. The result should be an objective assessment of compliance and maturity levels, accompanied by a prioritized Action Plan identifying what must be corrected, who should do it, with what priority, and what evidence will allow the action to be considered complete.

## Phase 2: Implementation of Measures

The Action Plan transforms the diagnosis into concrete projects. Depending on the identified gaps, the organization may require improvements in: Governance, policies, and procedures, AI inventory and classification, Risk and impact assessment methodology, Use case approval process, Data governance and quality, MLOps/SDLC practices, Supplier management, Transparency and human oversight controls, Security and privacy, Change and incident management, Metrics and monitoring, Training and awareness, Technical documentation and conformity evidence.

| **Implementation Approach** | **How Internet Security Auditors Can Help** |
| --- | --- |
| Client-Led Implementation | Internet Security Auditors acts as an expert advisor, reviews deliverables, answers questions, and validates that the implemented actions effectively address the identified gaps. |
| Implementation with Internet Security Auditors Support | Internet Security Auditors can develop or support the projects defined in the Action Plan to the extent required by the organization, from documentation and governance to risk management, supplier oversight, controls, and evidence preparation. |

## Phase 3: Internal Audit and Certification Readiness

The third phase independently verifies that what has been implemented is operating effectively. Under ISO/IEC 42001, internal auditing is part of the AI Management System (AIMS) requirements and is necessary to move confidently toward certification. It should verify conformity and implementation, document findings, and support corrective actions and management review. External certification is subsequently carried out by an independent certification body. \[3–4\]

| **ISecAuditors Phase** | **Objective** | **Key Deliverables** |
| --- | --- | --- |
| **1. Gap Assessment and Action Plan** | Assess compliance with the AI Act and ISO/IEC 42001 through interviews, document reviews, and validation against actual evidence. | Requirements and evidence matrix; compliance assessment; prioritized gaps; Action Plan including owners, priorities, and closure criteria. |
| **2. Implementation** | Close identified gaps through the projects defined in the Action Plan, with the level of ISEC support required by the client. | Governance and documentation; risk and impact management; data management; supplier oversight; lifecycle controls; training; metrics; and operational evidence. |
| **3. Internal Audit** | Independently verify the conformity and effectiveness of the AIMS and assess alignment with applicable AI Act obligations. | Findings and corrective actions; validation of implemented actions; readiness for ISO/IEC 42001 certification; and increased assurance of AI Act compliance. |

Within the AI Act, there is no general obligation for an equivalent internal audit applicable to all operators. Nevertheless, it is highly recommended as an assurance mechanism before an inspection, conformity assessment, or client request. Where the Regulation requires a specific conformity assessment or a notified body, internal auditing does not replace those requirements.

Internet Security Auditors can support all three phases: Gap Assessment and Action Plan; implementation assistance to the extent required by the client; and assessment or internal audit services. Where Internet Security Auditors has participated in the implementation phase, the audit should be organized with appropriate safeguards for independence and objectivity, for example by using professionals different from those who carried out the reviewed work.

More information about Internet Security Auditors' services: [AI Compliance Assessment and Support Services](https://www.isecauditors.com/en/evaluation-and-compliance-support-in-the-use-of-ai) | [ISO 42001 AI Management System Implementation.](https://www.isecauditors.com/en/implementation-of-aims-iso-42001)

[![ai-act-and-iso-42001-legal-obligation-and-certification](https://blog.isecauditors.com/hs-fs/hubfs/ISEC%20Media/Blog%20Media/ai-act-and-iso-42001-legal-obligation-and-certification.jpg?width=696&height=202&name=ai-act-and-iso-42001-legal-obligation-and-certification.jpg)](https://www.isecauditors.com/en/implementation-of-aims-iso-42001)

# Conclusions

The AI Act and ISO/IEC 42001 do not compete with one another. The former establishes legal obligations and regulatory consequences, while the latter provides a voluntary and certifiable framework for governing AI consistently. Integrating both avoids maintaining two separate compliance ecosystems and allows evidence to be reused where genuine equivalence exists.

The practical journey is progressive: understand the current situation through a gap analysis based on interviews and evidence; convert identified gaps into a prioritized Action Plan; implement the necessary measures; and conclude with an internal audit. For organizations seeking certification, this path prepares the AI Management System. For organizations prioritizing AI Act compliance, it provides the ability to demonstrate that AI systems have been identified, assessed, governed, and controlled.

References  
🔗 [Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence. Consolidated version in force as of 27 July 2026.](https://eur-lex.europa.eu/eli/reg/2024/1689/spa)  
🔗 [European Commission – Navigating the AI Act: implementation timeline, governance, compliance, and enforcement.](https://digital-strategy.ec.europa.eu/es/faqs/navigating-ai-act)  
🔗 [ISO – ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system.](https://www.iso.org/standard/42001)  
🔗 [ISO – ISO/IEC 42001 Explained: management system scope and the voluntary nature of certification.](https://www.iso.org/home/insights-news/resources/iso-42001-explained-what-it-is.html)  
[🔗 Internet Security Auditors – AI Compliance Assessment and Support Services.](https://www.isecauditors.com/en/evaluation-and-compliance-support-in-the-use-of-ai)  
[🔗 Internet Security Auditors – ISO 42001 AI Management System Implementation.](https://www.isecauditors.com/en/implementation-of-aims-iso-42001)  
[🔗 Internet Security Auditors – ISO 42001 vs. AI Act: How to Integrate an AI Management System into European Regulatory Frameworks.](https://blog.isecauditors.com/en/iso42001-vs-ria-how-to-integrate-the-ai-management-system-into-european-regulatory-frameworks?hsLang=en)

Sources consulted on 11 September 2026. Tables and summaries prepared based on the cited sources.

- [Tweet](https://twitter.com/share)

---

![author-image](https://blog.isecauditors.com/hubfs/Logo_isecauditors_contraccion_HP.png)

[Alberto Villar Arévalo](https://blog.isecauditors.com/en/author/alberto-villar)

PCI SSA, PCI QSA, CISSP, CSSLP, ISO 27001 L.A., CSFPC, SFPC   
 Security Consultant   
 Consulting Department

---

[Legal Notice](https://www.isecauditors.com/aviso-legal)

[Policy Privacy](https://www.isecauditors.com/politica-privacidad)

[Cookie Policy](https://www.isecauditors.com/politica-cookies)

<https://www.facebook.com/ISecAuditors> <https://twitter.com/ISecAuditors> <https://www.instagram.com/ISecAuditors/> <https://www.linkedin.com/company/internet-security-auditors/> <https://www.youtube.com/ISecAuditors>

---

Copyright © 2026 - All rights reserved

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Alberto Villar Arévalo",
    "url" : "https://blog.isecauditors.com/en/author/alberto-villar"
  },
  "dateModified" : "2026-09-29T09:06:07.594Z",
  "datePublished" : "2026-09-29T09:06:07.000Z",
  "headline" : "AI Act in 2026: The Legal Obligation Is Already Underway",
  "image" : [ "https://blog.isecauditors.com/hubfs/ria-en-2026-la-obligacion-legal-ya-esta-en-marcha.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.isecauditors.com/en/ai-act-in-2026-the-legal-obligation-is-already-underway",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.isecauditors.com/hubfs/isec_logo.png"
    },
    "name" : "Internet Security Auditors, S.L."
  }
}
```