Existing customer? Sign in
If a vendor says their AI is safe, you now have a simple way to test it. The practical checklist for enterprises — big and small
If you are choosing AI for your business, you have probably heard a vendor say "our model is safe." But safe according to whom? Unlike a fridge or a car, there is not yet one single global safety certificate for AI. There is currently no universal certification that establishes that an AI system is “safe.”
As of 2026, safety is covered by three layers that work together. Understanding the layers makes it much easier to ask the right questions, but note that these are useful categories for an enterprise guide, but they are the author’s organising framework, not an official classification. There are also many other relevant regimes and standards: privacy/data-protection law, cybersecurity requirements, sector-specific regulation, product safety law, employment law, consumer protection, contractual requirements, national AI legislation, and other standards.
Layer 1:
The law — what you must follow if you operate in these regions.
The EU AI Act:
This is the most detailed AI law in the world. It came into force in 2024 and is being turned on in stages:
• February 2025: the AI Act’s first provisions began applying, including prohibitions on certain AI practices such as social scoring and certain uses of real-time remote biometric identification in publicly accessible spaces.
• August 2025: obligations for providers of general-purpose AI models (GPAI) started — they must keep technical documentation, publish a summary of copyrighted training data, and have a copyright policy.
• August 2026: this is the big one for enterprises. A specific government or regulatory organisation, called the "AI Office", is responsible for important aspects of frontier/GPAI safety oversight and has a large overall team, which includes a dedicated 36-person "AI Safety Unit", created to monitor and manage the risks of the most advanced artificial intelligence technologies. The AI Office as a whole employs many more people than just the sub-team mentioned. High-risk system rules apply, and the EU AI Office has full enforcement powers for frontier models. GPAI models with systemic risk are subject to additional obligations, including model evaluation and adversarial testing, systemic-risk assessment and mitigation, serious-incident reporting and cybersecurity requirements.
The Act presumes systemic risk for models trained using more than 10²⁵ FLOPs, (Floating Point Operations) placing it under strict regulatory watch, although the Commission can also designate models on capability or impact grounds. Companies outside the EU can still fall within the AI Act’s scope. Whether the Act applies, depends on factors such as where the AI system or GPAI model is placed on the market, where it is used, and in some circumstances where its output is used — not simply whether the company has EU customers.
Providers must maintain technical documentation, adopt a copyright-compliance policy, and publish a sufficiently detailed summary of the content used to train the model. August 2026 marks an important stage in the AI Act’s implementation: the Act’s broader framework becomes applicable and the Commission’s enforcement powers over GPAI providers begin. However, important high-risk AI obligations have transitional dates extending into 2027 and 2028.
(Source: EU AI Act implementation timeline — artificialintelligenceact.eu)
The Council of Europe Framework Convention on AI (CETS No. 225)
This is the first legally binding international treaty specifically addressing AI. It was adopted in May 2024 and opened for signature on 5 September 2024, but it has not yet entered into force. It has been signed by the EU, US, UK, Canada, Japan and others. Signature is distinct from ratification, and the Convention enters into force only once the treaty’s specified ratification requirements have been met. It does not give you technical benchmarks, but it sets the legal baseline: AI must respect human rights, democracy and the rule of law.
(Source: Council of Europe CETS No. 225)
Layer 2:
Certifiable management standards — what you can prove.
ISO/IEC 42001:2023
This is the first international standard for an AI Management System. It requires an organisation to define who is responsible for AI, how risks are assessed, how data quality and fairness are managed, and how transparency and human oversight work. Think of it like ISO 27001 for information security, but for AI.
In 2026 many providers — from AWS to smaller EdTech companies — are getting ISO 42001 certified. It is an internationally recognised standard for responsible AI, but important to note: as of 2026 it is not yet a harmonised European standard, so certification alone does not automatically mean you comply with the EU AI Act.
ISO 42001 certification does not certify that an AI model is safe. It certifies an organisation’s management system against the standard’s requirements, within the scope of the certification.
Enterprises use it to show they have the governance in place.
Related standards you will see mentioned:
ISO/IEC 23894 for AI risk management,
ISO/IEC 22989 for AI terminology, and ISO/IEC 42005 for AI impact assessments.
They complement rather than constitute a single “certification stack.”
(Source: iso.org/standard/42001)
Layer 3:
Voluntary risk frameworks — what mature companies use to manage day-to-day risk.
NIST AI Risk Management Framework (AI RMF 1.0):
Published by the US National Institute of Standards and Technology in January 2023, with a Generative AI Profile (NIST AI 600-1) added in July 2024. It is voluntary, but it has become the common language for enterprise AI risk. It is built around four functions:
Govern, Map, Measure, Manage.
The 600-1 profile adds specific risks for generative AI — hallucinations, data leakage, prompt injection, and misuse for disinformation or cyberattacks — and contains more than 400 suggested actions addressing 13 identified generative-AI risks.
If a vendor says "we follow NIST," you know they have a structured way to think about risk, but ask for evidence of how it has actually implemented the framework — for example, its risk assessments, testing processes, governance controls and monitoring.
(Source: nist.gov — AI RMF 1.0 and AI 600-1)
OECD AI Principles and UNESCO Recommendation:
The OECD Principles, first adopted in 2019 and updated in 2024, are non-binding but endorsed by about 50 countries. They are the source of the definition of an AI system that most laws now use.
UNESCO's 2021 Recommendation on the Ethics of AI was adopted by 193 countries and is the broadest global agreement on values.
(Source: oecd.ai/en/ai-principles)
A Practical Checklist for Enterprises — Big and Small
If a vendor says their AI is safe, you now have a simple way to test it:
5 Questions to ask:
1. Governance: Are you certified to ISO/IEC 42001, or working toward it? Who is accountable for AI risk in your company?
2. Risk framework: Do you map your systems to NIST AI RMF and the Generative AI Profile 600-1?
3. Legal readiness: Can you provide the technical documentation, training-data summary and incident reporting required by the EU AI Act for GPAI models, if we need it for EU customers?
4. Data and transparency: Where is our data stored, is it used to train your models, and can you explain how the model reached a decision in a high-stakes case?
5. Human oversight: What human review is required before the system takes action in a high-risk use case?
Conclusion
A vendor answering the above five questions clearly, gives you real peace of mind. If they cannot, you have learned something important too.
This checklist is also why looking at AI models from outside the USA and China can be useful — which we will cover in next week's blog.
(This article was drafted with the help of an AI assistant and reviewed and edited by the author. Sources were checked at time of publication.)
Your business is unique, but your software is off the shelf? Ditch the workarounds and let's build your ERP systems to fit your teams.