AI Certification Is Becoming a Passport to Market Access
сертификация ИИEU AI ActISO/IEC 42001
Not every model needs a certificate
I would not describe the current situation as universal AI licensing: as of 25 September 2026, no such regime exists. However, the idea that a serious product cannot reach the market without demonstrable compliance is no longer a forecast; it already reflects procurement practice and regulation.
The European Union's EU AI Act sets a specific threshold for high-risk systems covered by the law. Before entering the market, they require technical documentation, risk management, human oversight, performance and bias information, and conformity assessment. This is already a mandatory procedure, but it is not a universal certificate for every model.
For generative systems, Article 50 introduces transparency obligations from 2 August 2026. For certain pre-existing systems, the transition period for labelling obligations ends on 2 December 2026. On the date of this publication, the first deadline has passed while the second has not: the regulatory calendar is not theoretical.
ISO/IEC 42001 addresses a different challenge: it is a certifiable standard for an AI management system and is increasingly seen as evidence of supplier maturity. NIST's AI RMF 1.0 and AI 600-1 provide risk-management frameworks, but do not create a certificate by themselves. In the United States, according to the referenced overview of the 2026 federal order, advance information sharing remains voluntary, while mandatory federal licensing of new models is explicitly excluded.
Why the market asks for certificates anyway
For enterprise buyers, the difference between a legal obligation and a voluntary standard quickly becomes blurred: if a supplier cannot demonstrate that its system is under control, excluding it from procurement is simply easier. That is why ISO/IEC 42001 is becoming not a legal licence, but a practical entry filter.
My engineering conclusion is straightforward: reviewers will not assess a decorative document on the wall, but the coherence of the evidence. The model's purpose, data provenance, known limitations, bias-testing results, risk assessment, human controls and deployment records must form one auditable picture.
The teams that win are those that build evidence collection into development rather than assembling a folder just before an audit. Closed models and suppliers that can show only metrics, without context for use and controls, lose out.
A certificate does not prove that a model is good. But the absence of verifiable traces increasingly proves that it should not be trusted in a serious operational environment.