CSOAI - framework comparison

ISO 42001 vs the EU AI Act

A certifiable management standard, or binding law? You likely need both - and one evidence base can serve them together.

You are interacting with an AI system.

The embedded 'Ask your Council assistant' panel (SovereignSpot) sends questions to the configured /api/chat model endpoint, where a single model writes the answer; no Council review, vote, or signature is implied. The Art 50(1) notice for this surface is registered here and being wired; until the component ships, this registry entry is the disclosure.

Disclosed under EU AI Act Article 50(1). Every surface and its classification

Dimension
ISO/IEC 42001
EU AI Act
What it is
AI management-system standard (certifiable)
Binding regulation
Issued by
ISO/IEC (international)
European Union
Model
Plan-Do-Check-Act management system
Risk-tiered obligations by use case
Certification
Third-party certifiable (like ISO 27001)
No 'certificate' - conformity + market surveillance
Mandatory?
Voluntary, but a recognised assurance signal
Mandatory for in-scope systems
Penalties
None (lose certification)
Up to EUR 35m or 7% of global turnover
Relationship
Strong evidence base for compliance
Can presume conformity where harmonised
The CSOAI bridge: run one AI management system, certify to ISO 42001, and crosswalk the same evidence onto the EU AI Act - certification and compliance from a single source of truth.
Council OS — ISO/IEC 42001 vs the EU AI Act — how they map and differ

Answers from published measurement, or it refuses. Your question is typed into the lobby — nothing sends until you press Ask.

Open Council OS

Deterministic pane commands · grounded /api/chat lane · consent checkpoint on consequential steps