AWS, Google Cloud, Microsoft, OpenAI, Anthropic, and IBM now boast an addition to their AI safety and security credentials: ISO/IEC 42001 certifications.
The certificate confirms that the companies have established a process to identify and manage AI risks. Although it does not guarantee that OpenAI’s ChatGPT will always produce accurate answers, that Anthropic’s Claude cannot be misused, or that Alphabet’s Gemini is free from bias, it gives nervous corporate customers something valuable: evidence that an outside auditor has examined a company’s AI management and meets the standard.
That’s enough to turn ISO 42001 into AI’s first global trust mark.
Although skepticism remains about private sector certifications, governments are struggling to come up with viable alternatives. The European Union adopted binding AI legislation, only to postpone implementing some of its most demanding obligations for high-risk systems until 2027 and 2028. The US relies on existing laws, state rules, and voluntary guidance. Britain has opted for oversight by existing regulators rather than a general AI law. Japan has adopted a promotion-focused law, while Singapore continues to favor voluntary governance and testing.
“AI has moved incredibly fast over the past four years, and rigid, prescriptive regimes like the EU AI Act struggle to keep pace with that rate of technological change,” said Alexandru Voica of Synthesia, a London-based AI video company valued at $4 billion after a $200 million funding round. “Standards gave us structure around AI-specific risk management, data security, and privacy.”
In the absence of clear, government-adopted rules, Synthesia and other companies are turning to the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). These Geneva-based non-governmental organizations bring together global experts to agree on standards for everything from hair dryers to household utensils. The IEC focuses on electrical and electronic technologies, while the ISO works across most other sectors. On information technology, including AI, they work together.
Their joint AI committee published ISO/IEC 42001 in December 2023. It requires companies to assign responsibility, assess risks, document decisions, monitor performance, and respond when problems emerge. A second standard, ISO/IEC 42006, came out in 2025 and sets out requirements for the bodies that audit and certify those management systems.
The ISO does not inspect companies or award certificates. Private certification bodies conduct these audits. In January 2026, the UK Accreditation Service accredited the British Standards Institution as the first certification body under its scheme authorized to issue ISO/IEC 42001 certifications. Large technology companies including AWS, Google, and Microsoft have obtained ISO/IEC 42001 certification for parts of their AI operations.
The US promotes the NIST AI Risk Management Framework, but it remains voluntary and is awarded without an official certification comparable to ISO 42001. Europe has a different approach. In July 2026, the European Committee for Standardization and the European Electrotechnical Committee for Standardization (CEN-CENELEC) published the first European standard designed to help companies comply with the EU AI Act. It focuses on how providers of high-risk AI systems organize and document their quality controls. Once the European Commission formally recognizes it, companies following the CEN-CENELEC standard will gain a presumption that they comply with the law.
ISO 42001 and the new European standard overlap, but they are not interchangeable. ISO 42001 concerns general management of AI, while the European standard targets specific legal obligations imposed on providers of high-risk AI applications.
Companies will probably choose to adopt both the ISO and European standards. ISO certification provides a globally recognized commercial credential. Harmonized European standards can give companies a presumption of conformity with the relevant requirements of the bloc’s AI Act. Large companies can absorb the duplication. Small vendors may struggle with the cost and complexity of hiring consultants and auditors.
Regulators will continue to write laws, and standards bodies will continue to publish technical standards. Their work will help determine which AI systems reach the market, and what companies must do to sell them. While regulators write the law, the market is already deciding what counts as safe.
Dr. Anda Bologa is a senior researcher in the Tech Policy Program at the Center for European Policy Analysis (CEPA).
Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
Tech 2030
A Roadmap for Europe-US Tech Cooperation