Tuesday, September 29, 2026

EN 18286 vs ISO 42001: The EU AI Act's Real Standard in 2026


Two standards. One regulation. And a certificate that may not mean what your board thinks it means.

If you build, sell or deploy AI in Europe, 2026 has handed compliance teams a new dilemma: certify to ISO 42001 now, or organise everything around EN 18286, the first standard written specifically for the EU AI Act? The honest answer is that they do different jobs, and only one of them is aimed squarely at the law. Here is what is confirmed, what is still pending, and how to plan around both.

What Is EN 18286?

EN 18286:2026, titled Artificial intelligence – Quality management system for EU AI Act regulatory purposes, was prepared by CEN/CLC/JTC 21 under the European Commission's standardisation request M/613 and approved by CEN-CENELEC on 12 July 2026. CEN-CENELEC describes it as the first harmonised European standard supporting the AI Act, and it is not tied to any single sector.

Its job is narrow and important: it turns Article 17, the quality management system (QMS) duty for providers of high-risk AI systems, into auditable requirements. Its Annex ZA, the section that links a standard to the law, covers Article 17(1) and the first sentence of Article 11(1).

What Is ISO 42001?

ISO/IEC 42001:2023, published in December 2023, is the world's first certifiable AI management system (AIMS) standard. It follows the same harmonised structure as ISO 27001, so it slots neatly beside an existing security programme, and any organisation that develops, provides or uses AI can adopt it. Certification is voluntary and third-party audited. However, it is not a harmonised standard under the AI Act, so a certificate alone gives no legal presumption of conformity.

EN 18286 vs ISO 42001: Key Differences

FactorEN 18286:2026ISO/IEC 42001:2023
Issued byCEN-CENELEC (European)ISO/IEC (international)
Built forEU AI Act Article 17 QMS dutyGeneral AI governance
Best suited toProviders of AI systems, especially high-riskAny organisation developing, providing or using AI
Presumption of conformityPossible once cited in the Official JournalNone; not harmonised
NatureEuropean Standard for regulatory purposesVoluntary, certifiable management system

The Catch: No Presumption of Conformity Yet

Under Article 40 of the AI Act, a provider that follows a harmonised standard gets a presumption of conformity with the requirements it covers, but only once the Commission cites that standard in the Official Journal of the European Union. In the latest public checks we found (August 2026), EN 18286 was published but not yet cited, and CEN-CENELEC has said the reference is expected later in 2026. Verify the current status before briefing your board.

Two practical consequences follow. Until citation, EN 18286 is not a legal safe harbour, yet it is the clearest preview of what regulators and notified bodies will expect. And even after citation it covers only part of the Act, so other obligations still need their own evidence.

Digital Omnibus: More Time, Not Less Work

The Digital Omnibus on AI has been in force since 27 July 2026. It moved the stand-alone high-risk (Annex III) deadline from 2 August 2026 to 2 December 2027, and high-risk AI embedded in regulated products (Annex I) to 2 August 2028. The telling reason: harmonised standards and national authorities were not ready.

Do not mistake this for a pause. Prohibited practices and AI literacy duties already apply, general-purpose AI obligations are unchanged, and Article 50 transparency rules have applied since 2 August 2026, with a grace period to 2 December 2026 for machine-readable marking on generative systems already on the market. Fines for prohibited practices can reach €35 million or 7% of global turnover. For European buyers and regulators, documented readiness now is fast becoming a trust signal, not just a legal checkbox.

Do You Need Both? Usually, Yes

Think of it this way: ISO 42001 is your organisation-wide AI governance engine; EN 18286 is the regulator-facing QMS blueprint. EN 18286 even includes annexes relating it to ISO 9001 and ISO/IEC 42001, a sign that Europe expects the standards to coexist rather than compete. Building once and mapping twice saves both budget and audit fatigue.

For most providers, the smartest sequence is to build an AIMS on ISO 42001 now, since enterprise buyers recognise it and it reuses your ISO 27001 scaffolding, then gap-assess it against EN 18286. VISTA InfoSec's guide to EU AI Act vs ISO 42001 explains why a certificate never replaces conformity assessment, CE marking or registration duties.

Your 5-Step Plan for 2026

  1. Inventory every AI system, including AI hidden inside SaaS tools. This EU AI Act compliance checklist shows how.
  2. Confirm your role and risk class: provider, deployer, importer or distributor, and whether anything is high-risk.
  3. Stand up an AIMS with expert ISO 42001 certification support.
  4. Gap-assess against EN 18286 (clauses 4–10) and document evidence for Articles 11 and 17.
  5. Track the Official Journal and re-baseline your roadmap to December 2027, using these 10 EU AI Act readiness controls as a working list.

FAQs

Is EN 18286 mandatory?

Standards are voluntary, but harmonised ones offer a presumption of conformity once cited. Article 17 duties for high-risk providers are mandatory either way.

Does ISO 42001 prove EU AI Act compliance?

No. It certifies your management system, not compliance with the Act.

When do high-risk obligations apply?

2 December 2027 for Annex III systems and 2 August 2028 for Annex I products.

Final Thoughts

EN 18286 is the standard built for the EU AI Act; ISO 42001 is the governance foundation that gets you there faster. Start with ISO 42001, map to EN 18286, keep evidence audit-ready, and treat the Omnibus extension as runway, not relief. Ready to turn standards into evidence? Talk to the team at VISTA InfoSec, whose European engagements run through Zulon Audits OÜ, and request an EU AI Act readiness review.

No comments:

Post a Comment

EN 18286 vs ISO 42001: The EU AI Act's Real Standard in 2026

Two standards. One regulation. And a certificate that may not mean what your board thinks it means. If you build, sell or deploy AI in Europ...