The EU AI Act (Regulation 2024/1689) entered into force in August 2024 as the world's first comprehensive AI regulatory framework. UNUS London's Bridge Series maps every high-risk AI obligation directly to ISO/IEC 42001:2023 controls and database-driven evidence artefacts — giving UK regulated organisations a dual-compliance pathway from a single implementation.
The EU AI Act classifies AI systems by risk level. The classification determines the applicable obligations. Organisations shall determine which tier applies to each AI system they develop, deploy, or use — prior to placing the system on the market or into service.
AI systems posing an unacceptable risk to fundamental rights and safety are prohibited and shall not be deployed. No exceptions apply.
Subject to mandatory requirements under Articles 8–15, including conformity assessment, registration, and ongoing monitoring obligations.
Transparency obligations apply — users shall be informed they are interacting with an AI system. Specific disclosure requirements for chatbots and deepfakes.
No mandatory requirements apply. The Act encourages voluntary codes of conduct for minimal risk systems to support responsible AI use.
Each Bridge Series article takes one EU AI Act obligation for high-risk systems and maps it precisely to the corresponding ISO/IEC 42001:2023 AIMS control — then delivers the UNUS database artefact that evidences compliance with both simultaneously.
Mandatory risk management systems for high-risk AI shall be documented, implemented, and maintained throughout the lifecycle. Maps directly to ISO 42001 AI risk assessment and Annex A.8 impact assessment controls — one UNUS AI Risk Register satisfies both.
Training, validation, and testing data shall meet documented quality criteria, including bias examination and data lineage records. UNUS data acquisition logs and quality control procedures address both the EU Act's Article 10 and ISO 42001's Annex A.7.1 data governance control.
High-risk AI systems shall have technical documentation prepared before market placement and kept up to date. UNUS's controlled document register, aligned to ISO 42001 Clause 7.5, provides version-controlled technical documentation that satisfies Annex III of the EU AI Act.
High-risk AI systems shall automatically log events to enable post-market monitoring and investigation of incidents. UNUS Govern's immutable audit trail, designed for ISO 42001 performance evaluation requirements, delivers the automatic logging mandated by Article 12.
High-risk AI systems shall be sufficiently transparent to enable deployers to interpret outputs and use them appropriately. UNUS transparency records and explainability documentation, mapped to ISO 42001 Annex A.10, address Article 13 user information requirements directly.
High-risk AI systems shall allow effective oversight by natural persons, including the ability to override or halt the system. UNUS human oversight checkpoints, aligned to ISO 42001 Annex A.7.3, produce the documented oversight procedures required by Article 14.
High-risk AI systems shall achieve appropriate levels of accuracy and be resilient to errors and adversarial inputs. UNUS validation and testing records, combined with ISO 27001 security controls, provide the dual evidence trail required by Article 15 and ISO 42001 Annex A.9.4.
High-risk AI systems shall undergo conformity assessment before deployment and be registered in the EU database. UNUS's internal audit programme and management review cycle — aligned to ISO 42001 Clauses 9 and 10 — generate the conformity evidence required to complete registration.
Providers of high-risk AI shall establish post-market monitoring systems and report serious incidents to authorities. UNUS's nonconformity and incident register, designed for ISO 42001 Clause 10 corrective action requirements, delivers the post-market monitoring evidence mandated by Article 72.
The table below maps each high-risk AI obligation under the EU AI Act to its corresponding ISO/IEC 42001:2023 control reference and UNUS London evidence artefact. Organisations deploying one UNUS implementation shall address both frameworks simultaneously.
| EU AI Act Article | Obligation Summary | ISO 42001 Control | UNUS Artefact |
|---|---|---|---|
Art. 9 |
Risk management system — documented and operational throughout the AI lifecycle |
Cl. 6 + A.8.3 |
AI Risk Register |
Art. 10 |
Data governance — quality criteria, bias checks, and data lineage for training and test data |
A.7.1 + A.9.3 |
Data Acquisition Log |
Art. 11 |
Technical documentation — prepared before market placement, kept up to date |
Cl. 7.5 + A.9.5 |
Document Register |
Art. 12 |
Record-keeping — automatic logging of events throughout the operational lifetime |
Cl. 7.5 + Cl. 9.1 |
Immutable Audit Trail |
Art. 13 |
Transparency — sufficient information for deployers to interpret and use outputs appropriately |
A.10.1 + A.10.3 |
Transparency Records |
Art. 14 |
Human oversight — natural persons able to monitor, override, and halt the AI system |
A.7.3 + Cl. 8 |
Oversight Checkpoint Log |
Art. 15 |
Accuracy, robustness, and cybersecurity — resilient to errors, adversarial attacks, and data corruption |
A.9.4 + ISO 27001 |
Validation & Test Records |
Art. 43–51 |
Conformity assessment and EU database registration before deployment of high-risk systems |
Cl. 9 + Cl. 10 |
Audit Programme + SoA |
Art. 72 |
Post-market monitoring — systematic collection and review of data on operational performance |
Cl. 9.1 + Cl. 10 |
NCR & Incident Register |
UK organisations must navigate both domestic AI governance expectations and potential EU AI Act exposure. UNUS London's Bridge Series is structured to address both simultaneously — protecting against regulatory uncertainty on both sides of the Channel.
The EU AI Act applies progressively. Organisations shall track which obligations are now in force and plan for the obligations that apply from 2 August 2026. The timeline below identifies the key milestones relevant to UK organisations.
UNUS London delivers a fully evidenced EU AI Act compliance programme through the ISO/IEC 42001:2023 Bridge Series — one implementation, dual-framework coverage. High-risk AI operators shall not wait.