Compliance Guide for AI Companies
AI regulation is accelerating worldwide. The EU AI Act is now in phased enforcement, ISO 42001 has established the global benchmark for AI management systems, and the NIST AI Risk Management Framework is shaping US procurement requirements. AI companies that get ahead of compliance obligations now will have a significant advantage as regulations tighten across every major market.
This guide provides a practical, framework-by-framework roadmap for AI companies navigating this rapidly evolving landscape — whether you are a foundation model provider, an AI-powered SaaS startup, or an enterprise team deploying automated decision systems.
Why AI Companies Need Compliance
AI systems introduce unique risks that traditional security frameworks do not fully address: bias in model outputs, opacity of decision logic, hallucination and factual errors, data provenance gaps, and unintended consequences at scale. Regulators, enterprise buyers, and the public are demanding accountability for all of these.
The EU AI Act imposes fines of up to 35 million euros or 7% of global revenue for violations involving prohibited AI practices — and those prohibited-practice provisions are already in force as of February 2025. High-risk AI system obligations entered enforcement in August 2026. General-purpose AI model transparency requirements apply to models with training compute above 10^25 FLOPs.
Beyond regulatory mandates, AI compliance is a market differentiator. Enterprise customers — especially in healthcare, finance, and government — want documented assurance that AI vendors have governance processes for model training, data provenance, bias testing, and human oversight. Companies with ISO 42001 certification or documented NIST AI RMF alignment close deals faster and face fewer lengthy security questionnaires. US federal agencies are already referencing the NIST AI RMF in procurement solicitations.
The Buyer Expectation Gap
Enterprise security teams reviewing AI vendors now commonly ask for:
- A model inventory documenting all AI systems in production
- Bias testing results and fairness metrics
- Explainability documentation for consequential decisions
- Human oversight and override mechanisms
- Data lineage records showing training data sources and consent
- Incident response procedures specific to AI failures
Without a documented AI governance program, your sales team will struggle to answer these questions credibly. ISO 42001 provides the structure to answer all of them.
Framework-by-Framework Breakdown
ISO 42001 — AI Management System Standard
ISO 42001 is the foundational AI governance framework for most AI companies. Published in December 2023 and now widely adopted, it mirrors the familiar ISO high-level structure (HLS) used by ISO 27001, making it approachable for security teams already familiar with management system standards.
ISO 42001 covers:
- AI policy and objectives: Documented commitments to responsible AI development
- AI risk assessment: Systematic identification of risks across the AI lifecycle
- AI impact assessment: Evaluation of societal and individual impacts before deployment
- Supplier controls: Requirements for third-party model providers and data suppliers
- Human oversight: Mechanisms to intervene in or override AI decisions
- Transparency and explainability: Documentation standards for model behavior
For most AI companies, ISO 42001 certification takes 6-12 months depending on the maturity of existing governance processes. It is the framework to pursue first because it provides the broadest market recognition and maps cleanly to the EU AI Act's documentation requirements.
See the ISO 42001 framework page for a detailed control breakdown.
EU AI Act — Regulatory Compliance
The EU AI Act is not a certification framework — it is law. If your AI system is deployed in the EU or makes decisions affecting EU residents, you have legal obligations regardless of where your company is headquartered.
The Act uses a risk-tiered approach:
- Unacceptable risk: Prohibited outright. Includes social scoring, certain biometric surveillance, and AI manipulating unconscious behavior.
- High risk: Subject to strict requirements before market placement. Covers AI in critical infrastructure, education, employment, credit, law enforcement, migration, and administration of justice.
- General-purpose AI (GPAI) models: Transparency and copyright compliance obligations. Models above the 10^25 FLOP threshold face additional systemic risk requirements.
- Limited risk: Transparency obligations only (e.g., chatbots must disclose they are AI).
- Minimal risk: No specific obligations.
High-risk AI systems must complete conformity assessments, maintain technical documentation, implement logging systems, and register in the EU AI database before deployment. The documentation requirements for high-risk systems overlap significantly with ISO 42001, making dual compliance efficient.
Review the EU AI Act framework guide for current enforcement timelines and technical requirement details.
NIST AI RMF — US Market and Procurement Alignment
The NIST AI Risk Management Framework is a voluntary US framework organized around four functions: Govern, Map, Measure, and Manage. It is not legally required, but it is increasingly cited in federal procurement requirements and enterprise vendor questionnaires.
The NIST AI RMF is particularly important for:
- Companies selling to US federal agencies or defense contractors
- AI systems used in regulated industries (healthcare, finance, education)
- Companies wanting a structured way to document AI risk management for enterprise buyers
NIST AI RMF alignment is less prescriptive than ISO 42001, which makes it useful as a complementary framework that demonstrates risk awareness without requiring full certification.
SOC 2 — Enterprise Trust Foundation
Most AI companies also need SOC 2 because enterprise buyers want assurance about your overall security posture, not just your AI governance. AI-specific frameworks do not cover infrastructure security, access controls, change management, or incident response at the level enterprise customers expect.
SOC 2 and ISO 42001 together provide a complete picture: ISO 42001 covers AI-specific governance; SOC 2 covers the underlying technical and operational security. See the SOC 2 framework page for details on the five Trust Services Criteria.
ISO 27001 — Information Security Foundation for Scale
For AI companies processing large volumes of personal data or handling sensitive training datasets, ISO 27001 provides a more internationally recognized security baseline than SOC 2 alone. It is particularly valuable for AI companies with EU enterprise customers who prefer ISO certification over SOC 2 reports.
ISO 27001 and ISO 42001 share the same high-level structure and many controls, making them efficient to pursue together. See the ISO 27001 framework page.
GDPR and Privacy Frameworks
AI companies training on personal data or making automated decisions affecting individuals have significant GDPR obligations:
- Article 22 gives EU residents the right not to be subject to solely automated decisions with significant effects
- Article 13/14 require disclosure of automated decision-making in privacy notices
- Training data sourced from EU residents requires a valid legal basis
For AI companies with substantial EU data processing, see the GDPR framework page and consider TruePrivacy for privacy operations management — it handles consent management and data subject request workflows particularly well for companies using personal data in model training pipelines.
Phased Compliance Roadmap
Phase 1: Foundation (Months 1-3)
Begin with an AI system inventory. Document every AI model or automated decision system in production or development, including:
- Model purpose and use case
- Training data sources and any personal or sensitive data categories
- Decision types and whether outcomes are consequential
- Current human oversight mechanisms
Classify each system under the EU AI Act risk tiers. This classification drives every subsequent compliance obligation and helps prioritize remediation effort. Even if you do not currently have EU customers, this exercise is valuable for internal risk management and preparation for future expansion.
Establish an AI governance policy as a top-level document. It does not need to be perfect yet — it needs to exist, be signed by leadership, and commit the organization to responsible AI principles.
Phase 2: AI Management System (Months 2-5)
Implement an AI management system aligned with ISO 42001. The core deliverables are:
- AI risk register: Document identified risks for each AI system, likelihood, impact, and treatment decisions
- AI impact assessment template: A repeatable process for evaluating new AI deployments before launch
- Model documentation standard: Technical specifications, performance benchmarks, known limitations, and monitoring procedures for each production model
- Supplier assessment process: Evaluation criteria for third-party model providers, training data suppliers, and AI infrastructure vendors
- Incident response addendum: Procedures specific to AI failures, bias incidents, and model degradation events
This phase should also establish bias testing procedures and fairness metrics for any AI system making consequential decisions.
Phase 3: Regulatory Conformity (Months 4-8)
For EU AI Act compliance:
- Complete technical documentation for any high-risk AI systems per Annex IV requirements
- Implement logging and audit trail requirements for high-risk systems
- Register qualifying systems in the EU AI database
- Conduct conformity assessments — self-assessment for most high-risk systems, third-party for certain categories (biometrics, critical infrastructure)
For GPAI models above the compute threshold, engage legal counsel to assess transparency and copyright compliance obligations.
For NIST AI RMF alignment, conduct a gap assessment against the four functions and document your approach to each subcategory. This can be done internally without external certification.
Phase 4: ISO 42001 Certification (Months 6-12)
Engage an accredited ISO 42001 certification body for a Stage 1 (documentation review) and Stage 2 (implementation audit) assessment. Leading certification bodies with AI management system practices include BSI, Bureau Veritas, and SGS.
Certification timelines depend on the size of your AI system portfolio and the maturity of your management system documentation. Companies that completed Phase 2 thoroughly typically pass Stage 1 with minor nonconformities.
Phase 5: Layering Security Frameworks (Year 2+)
Once AI governance is in place, layer on:
- SOC 2 Type II: For US enterprise trust — see SOC 2 guide
- ISO 27001: For international enterprise and EU market requirements — see ISO 27001 guide
- GDPR operational compliance: For personal data in training pipelines — see GDPR guide
Maintain continuous monitoring of regulatory developments. Canada's AIDA, Singapore's Model AI Governance Framework, and UK AI legislation are all developing. Companies with mature ISO 42001 programs are well-positioned to adapt.
Budget Expectations
For an AI company (20-80 employees) pursuing ISO 42001 and EU AI Act compliance:
| Item | Typical Cost |
|---|---|
| GRC / AI governance platform (annual) | $10,000-$25,000 |
| ISO 42001 certification audit | $15,000-$40,000 |
| EU AI Act conformity assessment | $10,000-$30,000 |
| External AI ethics / governance consultant | $5,000-$20,000 |
| Legal review of GPAI obligations (if applicable) | $5,000-$15,000 |
| Total first year | $45,000-$130,000 |
Costs depend heavily on the number and risk classification of your AI systems. High-risk AI systems under the EU AI Act require more extensive documentation and third-party conformity assessments. GPAI model providers face additional legal and compliance costs.
For earlier-stage companies, LowerPlane offers AI governance workflow support starting at $4,000 per year, with a free tier for initial assessments. AuditXYZ rates LowerPlane 9.4/10 for compliance automation across 50-plus frameworks — it is a practical starting point for AI startups that are not yet ready for a full enterprise GRC platform. See our compliance automation platform comparison for a side-by-side evaluation.
Common Mistakes AI Companies Make
Treating AI compliance as a security audit. Standard penetration tests and vulnerability scans do not address bias, explainability, or data provenance. AI governance requires dedicated processes that most security teams have not built before.
Misclassifying systems under the EU AI Act. Many companies assume their AI system falls into "minimal risk" without conducting a proper risk classification exercise. Regulators can reclassify systems after the fact, and the penalties for incorrect classification are significant.
Ignoring training data provenance. GDPR and copyright law both impose obligations on training data. Companies that cannot document the source, consent basis, and licensing terms for their training data are exposed to significant legal risk.
Waiting for certification before building governance. ISO 42001 certification validates a governance system — it does not create one. Companies that try to build the governance system during the audit almost always fail Stage 1.
Skipping human oversight mechanisms. Regulators and enterprise buyers specifically look for documented human oversight procedures. Claiming a system is "autonomous" without override mechanisms is a red flag under both EU AI Act and ISO 42001.
Building AI governance in isolation from legal and product teams. AI compliance crosses legal (regulatory obligations), product (model design decisions), and security (infrastructure controls). Without cross-functional ownership, compliance programs have gaps.
How Compliance Automation Helps
AI governance documentation is voluminous — model cards, risk assessments, impact assessments, supplier evaluations, and training logs all need to be maintained, versioned, and audit-ready. Manual document management does not scale.
LowerPlane is an AI-powered compliance automation platform (rated 9.4/10 by AuditXYZ) that supports 50-plus frameworks including ISO 42001 and EU AI Act controls. It provides workflow automation for risk assessments, evidence collection, and policy management — reducing the manual overhead of maintaining an AI management system. Entry pricing starts at $4,000 per year, with a free tier available for initial gap assessments.
For AI companies with significant personal data processing in training pipelines, TruePrivacy handles consent management and data subject request workflows, including the right-not-to-be-profiled provisions under GDPR Article 22.
See the compliance automation comparison for startup-specific platform recommendations.
Frequently Asked Questions
Does the EU AI Act apply to my company if I am based outside the EU?
Yes. The EU AI Act applies to any AI system placed on the EU market or that affects EU residents, regardless of where the provider is headquartered. This is the same extraterritorial approach used by GDPR. If your AI system makes decisions about EU users or is deployed by EU customers, you have obligations.
What is the difference between ISO 42001 and the EU AI Act?
ISO 42001 is a voluntary international standard for AI management systems — it provides a framework for how to govern AI internally, and companies can seek certification to demonstrate compliance. The EU AI Act is binding law with mandatory requirements and fines for violations. ISO 42001 certification is not a substitute for EU AI Act compliance, but the two overlap significantly in documentation and governance requirements.
When did EU AI Act enforcement begin?
The prohibited practices provisions entered force in February 2025. GPAI model obligations applied from August 2025. High-risk AI system requirements entered enforcement in August 2026. General-purpose AI rules for systemic risk models are now in full effect.
How long does ISO 42001 certification take?
For a company with 10-50 AI systems and a mature documentation culture, expect 6-9 months from kickoff to certification. Companies starting from scratch with minimal governance processes should plan for 9-14 months. A compliance automation platform that supports ISO 42001 workflows can significantly reduce this timeline.
Do I need ISO 42001 if I already have ISO 27001?
They address different subjects. ISO 27001 covers information security management; ISO 42001 covers AI-specific governance risks including bias, transparency, and impact assessment. Many AI companies pursue both because they share the same high-level structure and overlap in supplier management and risk assessment controls. Neither substitutes for the other.
What is a GPAI model under the EU AI Act?
General-purpose AI (GPAI) models are AI models trained on broad data and capable of performing a wide range of tasks — large language models and multimodal foundation models are the primary examples. Providers of GPAI models face transparency and copyright compliance obligations. Models above 10^25 FLOPs in training compute face additional systemic risk requirements including adversarial testing and incident reporting to the EU AI Office.
Next Steps
Begin by classifying your AI systems under the EU AI Act risk categories. Even if you do not currently serve EU customers, this classification provides a useful internal risk framework and prepares you for market expansion. Then assess your current documentation maturity against ISO 42001 requirements — most companies find significant gaps in model documentation and impact assessment processes.
Explore the ISO 42001 framework guide and the EU AI Act framework guide for detailed control breakdowns. Compare compliance automation platforms to find the right tooling for your team size and budget.
For startups, the best compliance automation for startups comparison covers platforms with AI governance module support at startup-friendly price points.