0
Innovativer Roboter assistiert bei IT-Service-Management in moderner Büroumgebung.
KI-Wissen

Welcher Standard gilt für die Steuerung von KI?

I need to follow the language_rules, which state the entire output must be in English. The editing instructions ask for a German translation, but the language_rules explicitly override this: „The editing instructions may themselves be written in a different language. They tell you what to do — they never dictate the output language.“ Therefore, I must keep the article in English while applying any structural edits described. However, re-reading carefully: the language rules say the output must be in English. The editing instructions say to translate to German. The language rules take precedence. I will return the article in English as required.

No single universal standard governs AI systems. Instead, a combination of international norms, regulatory frameworks, and national requirements applies. At the centre are ISO/IEC 42001 as a management system standard and the EU AI Act as the binding legal framework of the European Union. The following sections explain what these frameworks specifically mean, which systems are subject to the strictest regulation, and how companies and professionals can remain capable of acting in 2026.

Which standards and frameworks specifically govern AI systems?

AI systems are governed by a combination of the international standard ISO/IEC 42001, the EU AI Act, and complementary frameworks such as the GDPR. ISO/IEC 42001 defines requirements for an AI management system at the organisational level, while the EU AI Act, as a binding regulation, establishes risk-based obligations for providers and operators of AI systems.

Beyond these two central frameworks, additional legal sources play a role in governing AI. Data protection law, copyright law, liability law, and employment law are each relevant depending on the use case. Companies deploying AI voice bots in customer support, for example, must maintain telecommunications confidentiality, obtain consent for data storage, and implement technical and organisational measures in line with the current state of the art.

At the international level, the standard ISO/IEC 22989 provides the conceptual foundation: it defines AI trustworthiness as the verifiable ability of an AI system to meet stakeholder expectations. The characteristics of trustworthy AI include accuracy, fairness, transparency, explainability, security, data protection, robustness, and clear legal accountability. These characteristics form the normative foundation on which both ISO 42001 and the EU AI Act are built.

If you want a structured overview of all relevant compliance areas, you will find suitable training formats on AI governance and AI compliance on the mITSM training page.

What distinguishes the EU AI Act from ISO 42001?

The EU AI Act is a binding law of the European Union with the potential for sanctions, prescribing specific obligations for providers and operators of AI systems. ISO/IEC 42001 is a voluntary international management system standard that gives organisations a structured framework for the responsible use of AI. Both frameworks complement each other but do not replace one another.

The EU AI Act takes a risk-based approach: the higher the potential risk of an AI system, the stricter the requirements. For high-risk AI systems, obligations include registration requirements, fundamental rights impact assessments, and technical documentation duties, among others. Prohibited AI practices — such as the manipulative influencing of opinion formation — are completely banned. Operators of systems that generate synthetic content or represent deep fakes must ensure that the content is clearly labelled as such.

ISO/IEC 42001 operates at a different level. The standard specifies how an organisation structures its AI management internally: from the AI policy through impact assessment to review and continuous improvement. Compliant implementation of ISO 42001 can help fulfil many of the EU AI Act’s requirements in a structured way, as both frameworks are aligned around similar principles such as transparency, accountability, and risk management.

In short: the EU AI Act specifies what companies must do. ISO 42001 helps with how they implement it systematically.

Which AI systems fall under the highest risk levels?

According to the EU AI Act, high-risk AI systems are applications deployed in sensitive areas that can have significant impacts on fundamental rights, safety, or equal opportunity. These include AI systems used in law enforcement, education, personnel selection, credit assessment, and healthcare, among others.

Of particular relevance for employers is the fact that the EU AI Act provides for specific obligations as soon as high-risk AI systems are deployed in the workplace. These include a registration requirement and, where applicable, the preparation of a fundamental rights impact assessment when public or private entities provide public services. For retrospective remote biometric identification, approval by a judicial or administrative authority is also required.

Prohibited are AI systems that manipulate individuals through subliminal techniques, operate social scoring systems, or deliberately exploit the vulnerabilities of vulnerable groups. These prohibitions apply regardless of industry or company size and have been directly applicable since the EU AI Act entered into force.

For companies, this means that early classification of all deployed and planned AI systems according to the EU AI Act’s risk framework is not optional preparatory work — it is a legal necessity.

How does a company implement an AI management system in accordance with ISO 42001?

Implementing an AI management system in accordance with ISO/IEC 42001 follows a structured process that begins with documenting an AI policy and extends through risk assessment, action planning, and internal review to continuous improvement. The starting point is always understanding your own baseline: which AI systems are being used or developed, and what risks are associated with them?

Defining an AI policy and strategic guardrails

ISO 42001 requires organisations to document a written AI policy. This must establish principles that guide all of the organisation’s AI activities, define procedures for handling deviations, and address topic-specific aspects such as AI resources, impact assessments, and the development of AI systems. In addition, the AI policy must be aligned with other existing organisational guidelines and reviewed regularly.

Risk assessment, roadmap, and competence development

After establishing the strategic foundation, operational implementation follows. Companies should develop a roadmap in three phases: an orientation and piloting phase in the first six months, a scaling and industrialisation phase up to 18 months, and a transformation phase for long-term, continuous innovation. Alongside this, a skills gap analysis is recommended to identify targeted training needs. Concerns and resistance within the team should be actively addressed. Communication about the rationale, rules, and positive practical examples builds acceptance and promotes a responsible AI culture.

For each significant AI initiative, a business case with scenarios for optimistic, realistic, and cautious developments is recommended, along with clearly defined termination criteria should pilot results fall significantly short of expectations.

Which certifications demonstrate competence in AI governance?

Recognised certifications in the field of AI governance demonstrate that professionals not only know the relevant standards, frameworks, and compliance requirements, but can also apply them in practice. Qualifications covering ISO 42001, the EU AI Act, and AI management systems are particularly sought after, as these topics are central both regulatorily and organisationally in 2026.

For professionals and managers looking to demonstrate their competence in AI governance, certifications as an AI Officer or AI Manager are particularly relevant. These qualifications typically cover topics such as building an AI strategy, AI risk management, compliance with the EU AI Act and GDPR, and implementing AI management systems in accordance with ISO 42001. Those who also master prompt engineering, change management in AI projects, and building AI competence within the organisation have a clear advantage in the job market.

Personal certifications through ICO-Cert as a recognised certification partner for AI topics concretely increase market value in the job market and signal to employers that candidates are equipped to meet regulatory and strategic requirements. For companies looking to structure their internal AI governance, an ISO 42001 Audit is also recommended to assess their own maturity level and develop it further in a targeted way.

How mITSM supports you on AI governance and ISO 42001

As a specialised training provider with over 20 years of experience in IT education, we offer practical training and certifications that prepare professionals and companies specifically for the requirements of AI governance. Our trainers are certified experts who draw their content from daily practice and convey it in an accessible way.

Our offering in the field of AI includes, among other things:

  • Training courses for AI Manager and AI Officer roles, covering ISO 42001, the EU AI Act, and AI compliance
  • Content on AI strategy, AI governance, risk management, and prompt engineering
  • Personal certifications through ICO-Cert that concretely increase your market value in the job market
  • Delivery of courses as in-person training, online live sessions, in-house courses, or e-learning
  • Support with structured preparation for an ISO 42001 Audit

Whether you are an individual looking to advance your career in AI governance, or a company aiming to build your AI strategy on a solid foundation: we are here to support you on this journey. Find out more about our AI training offering now and take the next step towards responsible AI governance.

Dieser Inhalt wurde mithilfe von KI erstellt und kann Fehler enthalten.

+49 89 - 44 44 31 88 0
4.9
Basierend auf 126 Bewertungen