Governing Artificial Intelligence by Standard and by Statute: A Comparative Review of ISO/IEC 42001 and the EU Artificial Intelligence Act
Artificial Intelligence is increasingly deployed across healthcare, finance, public administration, and education, creating value while introducing technical, ethical, and legal risks that require effective governance. ISO/IEC 42001:2023, the first certifiable AI management system standard, and the EU Artificial Intelligence Act, the first comprehensive binding AI regulation, have emerged as the two most influential governance instruments. This review compares their origins, scope, architecture, and governance approaches, examining their concerns, overlap, complementarity, strengths, and limitations. Findings show that the two instruments are complementary rather than competing: ISO/IEC 42001 offers a voluntary, process-based, organization-wide framework for responsible AI governance, while the EU AI Act establishes a product-centric, risk-based legal framework backed by enforcement, together forming a two-tier governance structure. The review recommends an integrated approach in which ISO/IEC 42001, supported by the NIST AI Risk Management Framework, helps operationalize compliance with the Act, and calls for dynamic risk assessment, sector-specific adaptation, and greater international harmonization.
Paper
The full text of this publication is not hosted on 44B due to licensing.
Read it at OpenAlex