One standard, many rulebooks: where AI regulation stands around the world, what every regime asks for in common and what ISO 42001 certification evidences, wherever you operate.
Ask where artificial intelligence (AI) regulation stands and you will get a different answer on every continent. The European Union (EU) has a comprehensive Act with dates attached. South Korea has one in force. The United States (US) has no federal statute but a fast-moving patchwork of state laws. The United Kingdom (UK) has principles and regulators rather than an AI act. Much of Asia governs through guidance, administrative rules or promotion-first legislation.
A reasonable conclusion would be that global AI governance has to be built market by market, each programme to its own rulebook. In practice the regimes have more in common than the headlines suggest. Regulators differ on mechanism far more than they differ on substance, and once the legal machinery is set aside, the same demands repeat from one regime to the next:
- a defined, repeatable way of identifying and treating AI risk
- transparency about where AI is used, and documentation to back it
- named accountability and meaningful human oversight
- governance of the data AI is built on
- a route for reporting and handling incidents
- clarity about responsibilities where AI is bought in or supplied
ISO 42001, the first certifiable international standard for an AI management system, formalises this list. The rulebooks differ; the governance they assume does not. Building that governance once, to a certifiable standard, then adapting it at the edges is a more workable plan than running a compliance programme per jurisdiction. This article therefore surveys the landscape by mechanism rather than by map.
Hard law with dates
Two comprehensive AI regimes are now binding.
The EU AI Act is the most developed. Its prohibitions and AI literacy duty already apply and its transparency obligations have applied since 2 August 2026. Following the Digital Omnibus, the main high-risk obligations apply from 2 December 2027, with high-risk AI embedded in regulated products following on 2 August 2028. Penalties for prohibited practices reach seven per cent of total worldwide annual turnover. What an ISO 42001 certificate does and does not get you under the Act deserves its own treatment, and has one: the companion piece to this article works through it obligation by obligation. In short: certification is not conformity, but it is the governance foundation a conformity case gets built on.
The second is South Korea's. The AI Basic Act and its Enforcement Decree took effect on 22 January 2026. It imposes duties on high-impact and generative AI, including risk assessment, impact assessment, transparency and the labelling of AI-generated content. It applies extraterritorially to systems that affect the Korean market and requires larger foreign operators to appoint a domestic representative. The Ministry of Science and ICT (MSIT) has set a grace period of at least one year, during which fact-finding investigations and administrative fines are generally deferred except in cases of serious harm. The obligations themselves apply now.
Rules that will not stand still
The United States has no comprehensive federal AI statute. Federal executive action sets the policy layer, including Executive Order 14365 of December 2025, which presses towards federal preemption of state AI laws; its effect is for the courts to determine. Binding private-sector duties sit mostly in state law, and the state layer will not hold still. In 2024 Colorado became the first state to pass a comprehensive AI law. After two delays, it was repealed and replaced in May 2026 before it ever took effect; the narrower replacement is due to apply from 1 January 2027. The Texas Responsible Artificial Intelligence Governance Act (TRAIGA) took effect in January 2026, in a far narrower form than its original draft. California has a stack of its own, from frontier-developer transparency to automated decision-making rules phasing in through 2027. The volume is the clearest signal of more change to come: by March 2026, state lawmakers had introduced 1,561 AI-related bills across forty-five states.
None of this is a reason to wait for clarity. It is a reason to stop building compliance to one statute's wording, which can be out of date within a legislative session. The durable investment is a governance system that produces the evidence every version of these laws asks for (an inventory, risk and impact assessment, disclosure discipline, human oversight) and adapts at the edges as statutes come and go.
The US reference point is the National Institute of Standards and Technology (NIST) AI Risk Management Framework (AI RMF), the voluntary methodology many American risk teams already use. It is not certifiable, and it aligns closely with ISO 42001; NIST publishes a crosswalk between the two. In practice the framework organises the risk work; the standard turns it into something an independent party has verified.
Principles, guidance and administrative rules
The United Kingdom has taken a principles-based route: cross-sector principles applied through existing regulators rather than a single AI statute. Japan's 2025 AI legislation is promotion-oriented, with obligations that are largely non-punitive. Singapore offers a model governance framework and voluntary testing tools. China regulates through administrative measures, including labelling requirements for generative AI. In every market, sectoral regulators in areas such as financial services, health and employment are applying existing powers to AI now, without waiting for AI-specific law.
Soft law is still a demand for evidence. A regulator applying principles asks the same first question a statute does: show us how you govern this.
The buyer as regulator
For most organisations, the first regulator to ask for evidence is not a government. It is a customer. AI governance clauses and due diligence questionnaires are spreading through enterprise procurement faster than any statute. They cover much of the same ground from one market to the next and they observe no grace periods. Boards and insurers are asking the same questions from the other direction. Procurement is the one regime with global reach today, and the place where an accredited certificate works hardest, because it answers much of the questionnaire with a single piece of independently verified evidence.
The common core, and what certification evidences
The table below sets out the requirement themes that recur across the regimes above, and what an ISO 42001 management system contributes to each. All ISO 42001 references are to the standard itself.
|
Requirement theme |
Where it appears |
What ISO 42001 contributes |
|
Risk management |
EU AI Act Article 9; Korea's high-impact AI duties; NIST AI RMF; procurement questionnaires |
A defined, repeatable risk methodology with treatment, review and continual improvement (Clause 6) |
|
Impact assessment |
EU AI Act fundamental rights impact assessments; Korea's impact assessment duties; US state automated-decision laws |
Documented assessment of effects on individuals, groups and society (Annex A.5) |
|
Transparency and documentation |
EU AI Act Articles 11, 13 and 50; Korea's generative AI labelling; US state disclosure laws |
Documented information discipline and defined communication to interested parties (Clause 7, Annex A.8) |
|
Accountability and oversight |
EU AI Act Article 14; US state human-review rights; UK regulator principles |
Top-management accountability, assigned roles and escalation routes (Clause 5, Annex A.3) |
|
Data governance |
EU AI Act Article 10; sectoral rules in finance, health and employment |
Controls on the provenance, quality and preparation of data for AI (Annex A.7) |
|
Third-party AI |
EU AI Act value-chain obligations; procurement flow-down clauses |
Defined supplier and customer responsibilities across the AI life cycle (Annex A.10) |
The right-hand column is organisational machinery, not legal conformity. That distinction is the subject of the companion article, and it holds everywhere, not only in Europe.
What certification does, and does not, get you in any market
No certificate makes an organisation compliant with any of the regimes above, and it should never be presented as one. What an accredited ISO 42001 certificate provides is independently verified evidence that the governance foundation exists and works: risks assessed on a defined method, accountability allocated, competence maintained, suppliers managed, the whole system audited and improved. In regulatory engagement, procurement, customer due diligence and board assurance alike, that removes the question that otherwise dominates the conversation: whether there is anything underneath the policy statements at all.
The timing logic is the same everywhere; only the date changes. Certification typically takes six to twelve months, and the management system has to exist before the audit does. In Europe the date is December 2027. In Korea the grace period on investigations and fines ends no earlier than January 2027. In the United States the date is whichever statute reaches you first or, more likely, the next customer questionnaire. Work back from whichever date applies to you and the start lands close to now. The calendar makes that argument on its own.
Evidence that travels
One management system, one audit trail, one certificate. Because the underlying demands are so similar, evidence built this way is equally usable in Brussels, in Seoul, in a US state attorney general's inquiry and in a supplier questionnaire. LRQA is a UKAS accredited certification body for ISO 42001, which means our own competence and impartiality have been independently assessed.
The LRQA ISO 42001 Readiness Pack sets out what certification involves, what it asks of your organisation and where to begin.
To discuss AI governance certification, speak to the LRQA ISO 42001 team.
