EU AI Act Standards Published Without Legal Conformity, ISO 42001 Gap Widens
The European Commission advanced AI Act standardization on September 22, but EN 18286 has not been cited in the Official Journal, meaning ISO 42001 certification alone does not create EU legal conformity.
EU publishes AI Act standards without presumption of conformity
The European Commission released updated AI Act standardization work on September 22, covering ten areas including risk management, dataset governance, record-keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management, and conformity assessment. But the key standard—EN 18286:2026, designed specifically for EU AI Act regulatory purposes—cleared its CEN-CENELEC formal vote on July 12 and still has not been cited in the EU's Official Journal. Without that citation, the standard does not yet provide the Act's formal "presumption of conformity."
For enterprise buyers, this creates a concrete procurement problem: vendors claiming that ISO/IEC 42001 certification satisfies EU AI Act compliance are overstating their legal position. ISO 42001 establishes an AI management system, but it is not itself cited by the EU AI Act as a harmonized route to conformity. Procurement and legal teams deploying high-risk AI in Europe should budget separately for AI management-system certification, technical documentation, conformity assessment, logging, post-market monitoring, and controls mapped to the eventual harmonized standards. The regulatory stakes are material—the EU AI Act's most serious violations can carry fines of up to €35 million or 7% of worldwide annual turnover.
Comp AI raises $34 million, shifts governance to software budgets
AI compliance and security startup Comp AI announced a $34 million Series A on September 17, bringing its total funding to more than $36 million. The financing is significant because it treats AI governance as a software category rather than exclusively policy or consulting work. The company's positioning centers on automating compliance and security work for AI systems.
The round gives Comp AI resources to expand product development, integrations, sales, and automated evidence collection—areas that directly affect whether enterprises can operationalize AI controls at scale. Buyers evaluating AI governance tools should compare Comp AI with established GRC and security platforms adding AI inventories, model-risk controls, policy enforcement, and evidence management. The funding may increase competitive pressure on vendors such as OneTrust, IBM, Microsoft, ServiceNow, Credo AI, Holistic AI, Monitaur, and Fairly AI, though the announcement does not provide customer counts, pricing, or independent performance benchmarks.
The financing is a concrete signal that investors expect AI compliance to become a software budget rather than an exclusively manual legal or audit process. Enterprises should nevertheless distinguish funding momentum from product maturity: the announcement does not establish Comp AI's deployment count, control coverage, audit outcomes, or measurable reduction in compliance labor.
Audit leaders report governance-control gap despite policy adoption
A survey of 108 audit leaders, reported September 18, found that organizations have AI policies in place but that rapid AI adoption, evolving regulation, and geopolitical uncertainty are overwhelming governance, controls, and risk-management practices. The survey is important for buyers because it points to a common implementation problem: having an AI policy is not the same as maintaining an inventory of models and use cases, assigning risk tiers, documenting controls, monitoring performance, and preserving evidence for audits.
AI governance budgets are likely to move toward continuous control monitoring, model inventories, approval workflows, logging, and evidence retention—not merely policy-generation tools. Internal audit, security, privacy, procurement, and legal teams may need a shared system of record for AI applications and vendors. Buyers should ask vendors for measurable evidence such as the number of systems inventoried, percentage of high-risk use cases with completed assessments, time to produce audit evidence, and integration coverage across cloud and model providers.
The governance market is fragmenting among enterprise GRC suites adding AI modules, security platforms adding AI discovery and model controls, specialist AI-governance vendors focused on risk classification, testing, fairness, explainability, or regulatory mapping, and compliance-automation startups such as Comp AI. The survey supports demand for these categories but does not establish which vendor is winning or provide comparative product-performance data.
What to watch: FTC personalized-pricing proceeding and vendor claims
The U.S. Federal Trade Commission's proceeding concerning AI-driven individualized pricing using personal data reached a comment deadline of September 25, 2026, after being extended from September 18. For enterprises, this matters beyond retail pricing. The issue touches the use of AI systems to infer willingness to pay or personalize offers from consumer data, creating potential obligations around privacy, discrimination, transparency, and documentation.
Retailers, financial-services companies, travel platforms, and ad-tech buyers should review whether AI pricing or offer-optimization systems use sensitive or behavior-derived data. Procurement teams may need contractual rights to inspect training data, feature inputs, decision logic, testing records, and change histories. Vendors competing in pricing optimization may need stronger governance evidence, including bias testing and explanations of how individualized prices or offers are generated. The deadline and subject matter are established, but the FTC has not finalized policy, penalty amounts, or new compliance mandates.
The September developments clarify that ISO 42001 certification and EU AI Act conformity are not equivalent, that AI governance is attracting venture capital as a software category, and that having an AI policy does not equal having operational controls. Buyers should scrutinize vendor claims about compliance and demand measurable evidence of control coverage, audit performance, and regulatory alignment.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
