CSOAI - framework comparison

ISO 42001 vs the EU AI Act

A certifiable management standard, or binding law? You likely need both - and one evidence base can serve them together.

You are interacting with an AI system.

The embedded 'Ask the Sovereign' panel (SovereignSpot) sends questions to the live Sovereign chat endpoint (os.meok.ai/api/chat), where a model writes the answer. The Art 50(1) notice for this surface is registered here and being wired; until the component ships, this registry entry is the disclosure.

Disclosed under EU AI Act Article 50(1). Every surface and its classification

Dimension
ISO/IEC 42001
EU AI Act
What it is
AI management-system standard (certifiable)
Binding regulation
Issued by
ISO/IEC (international)
European Union
Model
Plan-Do-Check-Act management system
Risk-tiered obligations by use case
Certification
Third-party certifiable (like ISO 27001)
No 'certificate' - conformity + market surveillance
Mandatory?
Voluntary, but a recognised assurance signal
Mandatory for in-scope systems
Penalties
None (lose certification)
Up to EUR 35m or 7% of global turnover
Relationship
Strong evidence base for compliance
Can presume conformity where harmonised
The CSOAI bridge: run one AI management system, certify to ISO 42001, and crosswalk the same evidence onto the EU AI Act - certification and compliance from a single source of truth.
Ask the Sovereign — ISO/IEC 42001 vs the EU AI Act — how they map and differ
Governed answer · AI governance & cybersecurity only · signed to Layer 0
Open the full AI OS →