Skip to content

Europe

Independent · Brussels & Berlin

Technology · AI regulation

Big Tech adopts ISO AI safety standard while governments lag behind

AWS, Google, Microsoft, OpenAI, Anthropic and IBM now hold ISO/IEC 42001 certification, giving corporate buyers a globally recognised trust mark as EU, US and UK regulators move at different speeds.

By , Technology Editor

Published

7 min read

Six of the world's most prominent artificial intelligence providers have quietly secured a credential that did not exist eighteen months ago. Amazon Web Services, Google Cloud, Microsoft, OpenAI, Anthropic and IBM now hold ISO/IEC 42001 certification for portions of their AI operations, the first global management-system standard for the technology. The certificate does not promise that ChatGPT will stop hallucinating, that Claude cannot be misused, or that Gemini is free from bias. What it does provide is evidence that an independent auditor has examined the company's AI governance and found it meets an internationally agreed baseline.

For corporate buyers nervous about embedding generative models into products used by millions, that evidence is suddenly valuable. Procurement teams can point to a recognised mark rather than conducting their own ad-hoc due diligence. In the absence of binding government rules that are both comprehensive and current, ISO 42001 has become the de facto trust mark for enterprise AI.

Regulators are writing laws the market has already outpaced

The European Union adopted the world's first comprehensive AI legislation in 2024, yet the most onerous obligations for high-risk systems will not apply until 2027 and 2028. The United States relies on a patchwork of existing statutes, state-level initiatives and the voluntary NIST AI Risk Management Framework, which carries no formal certification. Britain has chosen oversight by existing sector regulators rather than a dedicated AI Act. Japan passed a promotion-oriented law, while Singapore continues to favour voluntary governance and testing sandboxes.

The result is a regulatory vacuum that private standard-setting has filled. The International Organization for Standardization and the International Electrotechnical Commission published ISO/IEC 42001 in December 2023 after work by their joint technical committee on information technology. A companion standard, ISO/IEC 42006, followed in 2025, setting requirements for the bodies that audit and certify management systems. Neither ISO nor IEC inspects companies; they write the rules. Accredited certification bodies do the audits.

Britain moves first on accreditation

In January 2026 the UK Accreditation Service accredited the British Standards Institution as the first certification body authorised to issue ISO/IEC 42001 certificates under the UK scheme. That decision opened the door for the flurry of big-tech certifications announced over the summer. AWS, Google and Microsoft have each obtained certification for parts of their AI operations, typically covering specific cloud services or model-hosting platforms rather than their entire AI portfolios.

The scope matters. A certificate covering Azure's AI infrastructure does not automatically extend to every model a customer deploys on it. But it does confirm that Microsoft has assigned responsibility, assessed risks, documented decisions, monitored performance and established incident-response processes for the certified scope. That is more concrete than most vendor self-assessments.

Europe builds its own compliance ladder

While ISO works globally, the European Committee for Standardization and the European Electrotechnical Committee for Standardization published the first harmonised European standard for the AI Act in July 2026. Once the European Commission formally recognises it, companies that follow the CEN-CENELEC standard will gain a legal presumption of conformity with the relevant requirements of the regulation. The European standard targets the specific obligations the AI Act imposes on providers of high-risk systems, such as quality-management systems, technical documentation and post-market monitoring. ISO 42001 is broader, addressing general AI governance across any application.

The two standards overlap but are not interchangeable. A company certified to ISO 42001 cannot claim presumption of conformity with the AI Act. A company following the harmonised European standard cannot claim a globally recognised commercial credential. Large firms will almost certainly adopt both. AWS, Google and Microsoft have the compliance budgets to run parallel programmes. For smaller vendors the duplication is a significant burden.

Small vendors face a compliance squeeze

A mid-sized European AI startup selling into regulated sectors such as healthcare, finance or public administration now needs to demonstrate AI Act compliance to win contracts. That means engaging consultants, preparing technical files, and paying for audits against the harmonised standard. If the same startup sells internationally, customers will also ask for ISO 42001. The cost of two audit cycles, two sets of documentation, and two certification bodies can exceed the annual revenue of a small firm.

This dynamic risks entrenching the market position of the largest providers. They can absorb compliance as a cost of doing business; smaller competitors may exit regulated markets or sell through the platforms of the certified giants, further concentrating the AI supply chain. The European Commission has acknowledged the disproportionate impact on small and medium enterprises in its impact assessments, but the legislative timetable offers no relief before the high-risk obligations take effect.

Why companies are not waiting for legislators

Alexandru Voica, head of corporate affairs and policy at Synthesia, the London-based AI video company valued at $4 billion after a $200 million funding round, explained the commercial logic. "AI has moved incredibly fast over the past four years, and rigid, prescriptive regimes like the EU AI Act struggle to keep pace with that rate of technological change," he said. "Standards gave us structure around AI-specific risk management, data security, and privacy." Synthesia adopted ISO 42001 rather than wait for the European harmonised standard to be finalised and recognised.

Voica's assessment reflects a wider sentiment among AI vendors. The technology cycle, new model architectures, new capabilities, new risk vectors, now runs at six to twelve months. Legislative cycles run at years. Standards bodies, while slower than industry, move at a pace measured in months rather than years, and their consensus process includes engineers who understand the technical detail.

The US relies on a framework without teeth

The National Institute of Standards and Technology published its AI Risk Management Framework in early 2023. It is widely respected, referenced in procurement guidance, and used as a reference by some insurers. But it remains voluntary and carries no certification scheme comparable to ISO 42001. The Biden administration's executive order on AI directed federal agencies to use the framework, but that applies only to government procurement. There is no federal mandate for private-sector adoption, and Congress has not passed comprehensive AI legislation.

State-level activity is accelerating. Colorado's AI Act, which takes effect in 2026, imposes duties on developers and deployers of high-risk systems. California has advanced multiple bills addressing transparency, watermarking and frontier-model safety. The result is a fragmenting compliance landscape that makes a single global standard more attractive to multinational vendors.

What the certificate actually proves

ISO/IEC 42001 certifies the management system, not the model. It confirms that the organisation has defined AI policies, assigned roles, conducted risk assessments, implemented controls, and established monitoring and improvement loops. It does not test model outputs for accuracy, fairness or robustness. An auditor checks that the company has a process for evaluating those attributes, not that the evaluation produced a particular result.

This distinction is critical. A certified company can still deploy a biased model if its risk-assessment process concluded the bias was acceptable for the intended use case. The certificate attests to the rigour of the decision-making, not the correctness of the decision. For regulators, that is a feature: the law sets the outcome requirements; the standard helps companies demonstrate they have a credible process for meeting them.

Sources

  1. CEPA

    cepa.org · 2026-08-26

People mentioned

  • Alexandru Voica

    Head of corporate affairs and policy, Synthesia

Organisations

International Organization for Standardization · International Electrotechnical Commission · European Committee for Standardization · European Electrotechnical Committee for Standardization · UK Accreditation Service · British Standards Institution

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.