Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTES
Talk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

Comparisons

  • ISO 42001 vs EU AI Act
  • GDPR vs LGPD
  • TISAX vs ISO 27001
  • SOC 2 vs ISO 27001
  • ISO 27001 vs NIST CSF
  • ISO 42001 vs NIST AI RMF
  • BCP vs DRP
  • Pentest vs Vulnerability Assessment
  • CIS Controls vs ISO 27001
  • CSA STAR vs ISO 27001
  • SOC 2 Type 1 vs Type 2
  • NIS2 vs ISO 27001
  • ISO 27701 vs LGPD

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption

AI governance

ISO 42001 vs EU AI Act

They aren't rivals, and you don't have to choose between them. ISO/IEC 42001 is an international standard that organises how your company builds and uses artificial intelligence responsibly, and you can earn a certificate from it. The EU AI Act is European Union law: it applies to anyone offering AI in Europe, even with the company based in Brazil, and it carries fines. Doing ISO 42001 is the fastest way to get ahead of what the European law demands.

See AI Trust readinessJump to the comparison

In short

  • ISO 42001 is a standard: you follow it by choice, and you earn a certificate. The EU AI Act is law: you comply because you must, or you risk a fine.
  • The EU AI Act reaches your company outside Europe if you offer or use AI there. It applies by where the AI is used, not by where the company is based.
  • Holding ISO 42001 doesn't make you compliant on its own, but it builds almost all of the organisation, risk control and paperwork the law requires.
  • In practice, the best path joins both: you use ISO 42001 as the base and link each part of it to what the AI Act asks.

Side by side

What separates a standard from a law

What to compareISO/IEC 42001EU AI Act
What it isAn international standard for managing artificial intelligence. You follow it by choice.Regulation (EU) 2024/1689, a law that applies directly in Europe. Mandatory.
What it organisesHow the company handles AI from start to finish: rules, owners, risk and impact assessment, controls and continual improvement.Placing and using AI on the European market, with rules that change according to each system's risk.
How it worksA cycle of plan, do, check and adjust, with about 38 reference controls.Organised by risk level: prohibited uses, high risk, limited risk (you only have to inform) and low risk.
Who it applies toAny company that builds, provides or uses AI and wants to prove it does so carefully.Anyone whose AI reaches the European market or its users, wherever the company sits.
Is there a certificate?Yes. An accredited body issues the certificate, as with ISO 27001.No. It is compliance with the law. High-risk systems go through an assessment and get the CE marking.
Is there a deadline?No. You adopt it when you want, at your own pace.It arrives in phases: prohibited uses since Feb 2025, general-purpose models in Aug 2025, most high-risk rules in Aug 2026.
What the penalty isNo fine. What you risk is not getting the certificate, or losing it.Up to €35 million or 7% of worldwide turnover, whichever is higher, for prohibited uses.
How you prove itA valid ISO 42001 certificate, with follow-up audits.Technical documentation, a system assessment and registration in an EU database, for high-risk systems.

ISO 42001 was the first international standard for managing AI, from 2023. The EU AI Act is the world's first broad AI law.

The standard that earns a certificate

ISO/IEC 42001

It does for artificial intelligence what ISO 27001 does for information security: it creates an organised way to handle the topic. You set the rules for using AI, share out responsibilities, assess the risks and impacts, put controls in place and improve over time. In the end, a certificate shows customers, investors and regulators that your company takes the topic seriously.

  • You adopt it by choice and an accredited body issues the certificate
  • It covers AI from start to finish, across the company
  • About 38 reference controls, on a continual-improvement cycle
  • A base for showing diligence under the AI Act
The law

EU AI Act

It sorts each AI system by risk and asks more of those that carry more risk. Some uses are prohibited. High-risk ones need risk control, quality data, documentation, human oversight and an assessment before reaching the market. It applies to anyone offering AI in Europe, so a Brazilian company selling AI-enabled software there is already under the law.

  • Mandatory and directly applicable in Europe
  • Reaches providers outside the continent
  • Fines up to €35 million or 7% of worldwide turnover
  • High-risk rules take effect in August 2026

How they fit together

ISO 42001 puts into practice what the AI Act demands

The law says what you must ensure: risk control, care with data, documentation and a human eye on decisions. The standard says how to build all of that and keep it running. Doing ISO 42001 doesn't make you compliant automatically (only specific European standards give that guarantee), but it delivers almost the entire structure the law asks for, with proof that it exists. It is the safest shortcut for anyone who doesn't want to start from scratch.

  • ISO 42001's rules and owners satisfy the governance the AI Act asks for
  • The standard's risk and impact assessment feeds the law's risk control
  • The documentation and improvement routine support the required technical reports

Which is your case

Where to start

You sell or use AI in Europe

Start with the EU AI Act

It is mandatory. The first step is to check each system's risk: knowing whether any is prohibited, high-risk or only needs a user notice shapes everything else.

You want to prove you use AI responsibly

Go with ISO 42001

It is the proof that big customers and investors recognise, even outside Europe. And it leaves you ready for any AI rule still to come, wherever you operate.

You want to solve both at once

ISO 42001 linked to the AI Act

The most efficient path. You build the base with the standard and link each control to what the law asks, with a single paperwork and evidence effort.

Numbers that matter

€35M / 7%

EU AI Act fine ceiling (the higher of the two)

Aug 2026

when high-risk rules take effect

2023

year of ISO/IEC 42001, the first standard for managing AI

How DM11 helps

ISO 42001 readiness and EU AI Act alignment, with DM11

We build the AI governance with ISO 42001, sort your systems by the AI Act's risk levels and join the two into a single programme, with all the documentation and proof that support the certificate and answer the law.

  • One project covers both fronts, so you neither pay nor work twice
  • You find out early if any system is high-risk, before it turns into a fine
  • We handle the paperwork and evidence; your team keeps running the day to day
  • You reach the audit already knowing you'll pass, with no last-minute surprise
Explore AI Trust

Frequently asked

What people ask before deciding

Answers anchored in Regulation (EU) 2024/1689 and ISO/IEC 42001:2023.

Not automatically. The guarantee that you comply with the AI Act comes from specific European standards, and ISO 42001 isn't one of them. Even so, it delivers almost everything the law asks for: organisation, risk control, documentation and continual improvement, with proof that it works. That is why it is the fastest route to compliance, and the base almost every serious programme uses.

More questions? Talk to DM11

Start with your systems' risk and the distance to ISO 42001

A short conversation shows whether any system is high-risk and how far the path to governance runs. No commitment.

Talk to a specialistExplore AI Trust