The AI Act regulates by role and by risk, not by technology. The first question is therefore not which model a system uses but which role the organisation holds — provider, deployer, importer, distributor, authorised representative, or product manufacturer — because the duties attach to the role. The same tool can place an organisation in one role when it is bought and a different one when it is rebranded or materially modified.
The timeline has moved. Prohibited practices under Article 5 have applied since 2 February 2025 and obligations for general-purpose AI models since 2 August 2025. The general applicability date of 2 August 2026 has now passed. Obligations for stand-alone high-risk systems under Annex III were deferred to 2 December 2027 by Regulation (EU) 2026/1744, which entered into force on 27 July 2026; high-risk AI embedded in products under Annex I moves to 2 August 2028. The deferral changed the deadline, not the substance of what has to be built.
ISO/IEC 42001:2023 supplies the management-system structure — 38 Annex A controls across nine areas, certifiable by an accredited body. It is a useful vehicle for AI governance and a credible signal in procurement, but certification is not a conformity assessment under the AI Act. The two answer different questions and require separate evidence, and a certificate will not shorten a high-risk conformity assessment by a single step.
Where AI processes personal data, the obligations overlap rather than stack. Article 22 of the GDPR governs automated decisions with legal or similarly significant effects, Article 35 may require an impact assessment, and Article 27 of the AI Act adds a fundamental rights impact assessment for certain deployers. One inventory and one set of decision records can serve all three; three parallel exercises usually produce three inconsistent answers about the same system, which is the version an auditor tends to find.