Latin American organisations already operate artificial intelligence at a speed their own governance cannot match. The ISO/IEC 42001:2023 standard, published in December 2023, established the first international framework for AI management systems (ISO, 2023). This report structures the state of the field with a declared evidence cut-off — May 2026, updated with the final adoption of the Digital Omnibus by the Council of the EU on 29 June 2026 — and explains the three frameworks that every board will encounter.


Data from the field

Three simultaneous processes broke the traditional model of technology governance.

01

Constant updates

Models in production consume ongoing updates · new foundation models, fine-tuning, updated datasets. The exact cadence varies by provider and by quarter — it is verified in each provider's public release notes, without third-party statistics. A system certified in January may be operationally unrecognisable in April.

02

Automatic deployment

Providers deploy changes without customer intervention. What runs in production today is the system that was audited plus the drift accumulated since the last review — and that drift bears no one's signature within the organisation.

03

The invisible chain

The technology supply chain introduces vectors of change that the organisation inherits without seeing them. The provider's provider's provider changes something, and the audited organisation takes on that change unknowingly.

The record of harm runs alongside the three signals: the public artificial intelligence incident database added 346 entries in 2025 and has accumulated more than 1.360 since its creation (AI Incident Database, 2026).

Annual certification still made sense when reality waited for the auditor. Today, reality does not wait. It moves.

The three frameworks. The table that structures the field

Three frameworks coexist in practice, and each answers a different question. The most common misreading in the field is to treat them as substitutes. ISO/IEC 42001 structures the management system; the EU AI Act regulates systems within its scope of application; the NIST AI RMF provides a technical risk vocabulary. An organisation may need to combine them depending on its roles, use cases, contracts and jurisdictions; none becomes mandatory merely because the others exist.

FrameworkNatureScopeStatusWho it binds
ISO/IEC 42001:2023International management system standard · certifiable by accredited bodiesThe management system that oversees the models (AIMS) · context, leadership, risks, controls, improvementPublished in December 2023 · verifiable certification body accreditations in operationVoluntary · binding on those who adopt it or undertake to comply with it by contract
EU AI Act · Regulation (EU) 2024/1689European regulation whose scope includes certain situations outside the EUSystems and actors covered by the regulation, classified by role and risk levelPhased · timeline subject to the applicable text and the entry into force of the Digital Omnibus (see timeline)Providers, deployers and other actors only when they fall within its scope of application
NIST AI RMFVoluntary risk management frameworkTechnical risk vocabulary and practices throughout the system lifecycleVersion 1.0 published in 2023 (NIST, 2023) · North American technical referenceNo one by law · binding through contract or internal adoption

The European regulatory clock · post-Omnibus timeline

On 29 June 2026, the Council of the EU gave the final green light to the Digital Omnibus on AI. The adopted text sets new dates for the transparency of generated content and for high-risk systems. The official press release itself stated that the act would subsequently be published in the Official Journal and enter into force on the third day following that publication. A compliance decision must therefore verify the published text and its effective date, rather than rely solely on the announcement.

ObligationDateStatus as of July 2026
Absolute prohibitionsFebruary 2025In force and applicable
General-purpose models (GPAI)August 2025In force and applicable
Transparency of generated content2 December 2026Date of the adopted text · verify publication and entry into force
High risk · Annex III2 December 2027Date of the adopted text · verify publication and entry into force
High risk · Annex I2 August 2028Date of the adopted text · verify publication and entry into force

An auditor's reading of the timeline fits into one sentence: the world's most ambitious AI law had to slow down before being applied, while the public record of incidents continues to grow. The gap between the pace of the system and the pace of governance also reaches regulators.

The accreditation chain has already reached AI

ISO/IEC 42001 shares the harmonised structure of ISO 9001, ISO/IEC 27001 and ISO 14001, allowing it to be integrated with existing management systems. The chain that makes certification verifiable is also in operation: ANAB publishes the corresponding accreditation programme, and in March 2026 BSI reported accreditations from ANAB, UKAS and RvA to certify under ISO/IEC 42001. Estimates of the worldwide number of certificates issued circulate without a consolidated primary source; this report refrains from citing them. What can be verified today are the scopes of accreditation and the regional adoption data that piece 17 organises with declared sources.

Two mistakes recur in organisations starting the process. First · confusing certification with the model's technical compliance. ISO 42001 certifies the management system that oversees the model; the model's performance is demonstrated through other means. Second · transferring the information security audit team directly to AI without specific training. The conceptual overlap is real; technical equivalence is not there yet.

What changes for the auditor

Audit practice needs three components that the traditional model lacked · auditable telemetry, independent reviews at variable intervals and change-based, rather than calendar-based, verification. The full temporal pathology — why the annual visit no longer captures operations and what evidence each component generates — has its own piece: report 04 in this series, which applies Criterion 09.

What remains is the profession's longstanding question. How what is declared is demonstrated. What evidence supports each technical claim. Who signs off on each critical decision.

A certificate issued without underlying auditable telemetry is a certificate that has expired on the day it is signed.