ISO 42001 procurement: the evidence
Nearly every page you will read on this asks whether ISO 42001 is becoming a UK procurement expectation. None of them counts. We did.
Across the whole of our UK notice corpus, the AI management system standard appears in one notice of 745,098 scanned notices. That is not because UK buyers are behind — it is because until the first UKAS accreditation in January 2026, no UK body could issue the certificate at all.
- 18 Dec 2023ISO/IEC 42001 published
- 6 Nov 2024DSIT consults on AI Management Essentials
- 17 Feb 2025PPN 017 on AI transparency
- 7 Jul 2025ISO/IEC 42006:2025 published — accredited certification becomes possible
- 15 Jan 2026First UKAS accreditation granted, to BSI
- 6 Feb 2026AI Management Essentials cancelled
- 18 May 2026The one UK notice naming the standard
- 27 Jul 2026EU AI Omnibus in force
- 2 Dec 2027EU high-risk obligations apply
ISO 42001 procurement, measured on the whole corpus
Before the number, what it counts. We read the published text of every notice — its title and its description. We do not read the tender pack, and the pack is where a requirement like this usually lives. So this is a floor: the count of notices that say it out loud, not the count of procurements that want it.
With that stated: our classifier read every notice we hold, and 745,098 of them carry a publication date and so enter the count, scanned on 1 August 2026. It found one. For comparison, and on exactly the same method, ISO 9001 appears in 412 notices and Cyber Essentials appears in 291 notices.
That gap is the subject of this page. It is not a gap in enthusiasm, and it is not evidence that UK buyers are slow. It is a gap in infrastructure, and it has a documented cause with a date attached to every link in it.
Two things follow, and they point in opposite directions. If you are being told that ISO 42001 is now a condition of winning UK public work, that is not what the notices say. If you are being told the standard is therefore pointless, that is not what this page says either — the standard is real, accredited UK certification now exists, and one notice is a beginning rather than a verdict.
The chain that explains the number
Three things have to exist before a buyer can put a certification in a tender: the standard, a rulebook for the bodies that audit against it, and an accredited body willing to issue it. For ISO 42001 the last of those arrived in the UK in January 2026.
ISO/IEC 42001:2023 is published
The certifiable management-system standard for artificial intelligence. ISO’s own stage record reads “60.60 2023-12-18 International Standard published”. [1]
DSIT consults on AI Management Essentials
A self-assessment tool distilled from ISO/IEC 42001, the EU AI Act and the NIST AI RMF, which the department intended to embed in government procurement. [6]
PPN 017 is published
The Procurement Act 2023 instrument on AI in procurement. It governs disclosure of a supplier’s AI use. It does not require an AI management certification. [8]
ISO/IEC 42006:2025 is published — the load-bearing node
The standard specifying requirements for the bodies that audit and certify to 42001, eighteen months after 42001 itself. Until it existed, accredited certification was structurally impossible: accreditation bodies had no harmonised basis on which to assess certifiers. [2]
UKAS grants the first UK accreditation
UKAS: “UKAS has granted BSI the first accreditation for certification of artificial intelligence (AI) management systems to ISO/IEC 42001:2023.” [3] The live proof is better than the press release — BSI’s UKAS Schedule of Accreditation, issue date 23 July 2026, carries the granted scope. [4]
The procurement plan is cancelled
DSIT’s government response: “DSIT will not be publishing AIME and therefore will not be making it a requirement of the government procurement process.” [7]
The one UK notice appears
FIRST RAIL HOLDINGS LIMITED publishes “First Cyber Security Tooling & Managed Services Tender” — £3,433,993, naming ISO 42001 among the frameworks its managed service must operate within. Four months after the first UK-accredited certificate could exist at all. [5]
The load-bearing sentence. The single UK notice naming ISO 42001 was published 18 May 2026 — four months after the first UK-accredited certificate could exist at all, and ten months after the standard governing the certifiers was published. A buyer cannot demand a certificate nobody in the country is accredited to issue. That is the mechanism, and every link in it has a primary source.
ISO 42001 certification UK: who can issue it, and since when
A certificate is only worth what the accreditation behind it is worth, and in the UK that accreditation is very new.
The United Kingdom Accreditation Service is the sole national accreditation body, and it is what makes a certificate from a UK certification body mean something to a buyer. On 15 January 2026 it announced that it had granted BSI “the first accreditation for certification of artificial intelligence (AI) management systems to ISO/IEC 42001:2023”. [3]
The stronger evidence is not the announcement but the schedule. BSI’s UKAS Schedule of Accreditation, issue date 23 July 2026, carries the granted scope in terms: “ARTIFICIAL INTELLIGENCE MANAGEMENT SYSTEMS / In accordance with ISO/IEC 17021-1:2015 and ISO/IEC 42006:2025 / ISO/IEC 42001:2023 Certification”. [4] A press release states an intention; a schedule is the live grant.
So how many UK bodies can actually issue you one? Five. We counted them rather than estimating, and the counting method is the point, because “very few” is what everybody says and nobody checks.
UKAS publishes a Schedule of Accreditation for every body it accredits, listing the exact scopes that body may certify against, with an issue number and an issue date. We enumerated the population rather than searching it — UKAS’s own keyword search caps its result set — by probing every management-systems schedule number from 0001 to 4000. Fifty-four exist. Five carry an artificial intelligence management systems scope, and all five cite ISO/IEC 42006:2025 as the basis on which they were assessed. [16]
This is the supply side of the whole argument, in one number. A buyer writing a condition of participation has to believe the market can satisfy it. Five accredited bodies is not a market a procurement officer can safely gate on — and it is a better answer to “why is nobody asking for this” than any claim about buyer conservatism.
Four things it is tempting to say here, and why each is wrong
These matter because they are what the most-linked pages on this topic say, and a reader arriving from one of them should be able to see the correction rather than a flat contradiction.
We have no source explaining why BSI published in November, and we are not guessing at one. The two dates are recorded, the reason for preferring the UKAS date is given, and that is as far as the evidence goes.
The AI management system standard, and what it certifies
The most consequential misunderstanding on this topic is not about dates. It is about scope: what the certificate is a certificate of.
ISO/IEC 42001:2023 certifies an artificial intelligence management system — the organisational apparatus by which a company decides what AI it will build, how it assesses risk, who is accountable, and how it reviews what it has deployed. [1] It is a management-system standard in the same family as ISO 9001 for quality and ISO/IEC 27001 for information security, and it works the same way: an auditor examines your processes and your records.
It does not certify a model. It does not evidence that any particular algorithm has been tested, that a system is accurate, or that a specific output is fair. An organisation can hold a valid ISO 42001 certificate and ship a bad model, in the same way an ISO 9001 holder can ship a bad product — the standard says the process exists and is followed, not that the output is good.
This matters commercially in both directions. If you are selling, claiming that the certificate demonstrates model quality is a claim the standard will not support and an informed evaluator will discount. If you are buying and you actually want assurance about a model, the certificate is the wrong instrument and you should be asking for testing evidence, not a certificate number.
The UK plan to put AI governance into procurement, and its cancellation
This is the strongest fact on the page, and it is the one most competing content gets backwards — because the intention is easy to find and the reversal is not.
DSIT built AI Management Essentials, a self-assessment tool distilled from ISO/IEC 42001, the EU AI Act and the NIST AI Risk Management Framework, and consulted on it between 6 November 2024 and 29 January 2025. The report Assuring a Responsible Future for AI, published 6 November 2024, states both the lineage and the intent verbatim:
“Drawing on key principles from existing AI-related standards and frameworks — including ISO/IEC 42001 (Artificial Intelligence - Management System), the EU AI Act, and the NIST AI Risk Management Framework — AI Management Essentials will provide a simple, free baseline of organisational good practice”, and “In the medium term we are looking to embed this in government procurement policy and frameworks to drive the adoption of assurance techniques and standards in the private sector.” [6]
That quote must never be published without what follows it. It is a November 2024 aspiration that a February 2026 decision explicitly reversed, and quoting the intent alone — which several competing pages do — is the single easiest way to be wrong on this topic.
The government response, published 6 February 2026:
“DSIT will not be publishing AIME and therefore will not be making it a requirement of the government procurement process.” [7]
The reasons given include that a size- and role-agnostic tool “struggled to meet the diverse needs of different users”, that “SMEs may lack the resources and in-house expertise needed to navigate them effectively”, and that “insights regarding the potential impact on competition” would inform future policy. [7]
An accuracy note, because the two documents are not interchangeable. The February 2026 government response does not mention ISO/IEC 42001. The 42001 lineage comes from the November 2024 Assuring a Responsible Future for AI report. We cite each claim to the document that actually says it.
What UK procurement policy says about AI, and what it does not
Two Procurement Policy Notes carry AI. Between them they cover disclosure and national security. Neither mentions a certification.
PPN 017 — transparency of AI use in procurement
Published 17 February 2025, PPN 017 is the Procurement Act 2023 instrument. Its subject is the disclosure of the supplier’s AI use — whether you used AI to write your bid, and what the buyer may ask about it. It is not about certifying an AI management system, and it does not require one. [8]
It is also more permissive than most bidders assume, and says so in terms: “It is important to note that suppliers’ use of AI is not prohibited during the commercial process but steps should be taken to understand the risks associated with the use of AI tools in this context, as would be the case if a bid writer has been used by the supplier.” [8]
Two precision points. PPN 017 does not use the language of superseding PPN 02/24; its actual sentence is “For procurements commenced and contracts awarded before this date, please refer to PPN 02/24”, and PPN 02/24 remains listed under the Public Contracts Regulations 2015 section of the PPN collection. And the PDF’s own dateline reads “Originally issued: November 2023 / Updated: February 2025”, which contradicts the GOV.UK publication date — we cite the GOV.UK page date. [8]
PPN 025 — national security, and AI as a critical sector
Published 19 June 2026, PPN 025 names artificial intelligence as one of four critical national-security sectors, alongside shipbuilding, steel and energy infrastructure, with DSIT as the AI Sector Lead. It “applies only to central government departments, their executive agencies and non-departmental public bodies”. [14]
This is the honest answer to “where is UK AI procurement policy actually going”: towards strategic market shaping and the national security exemption, not towards a certification gate. GOV.UK contradicts itself on the date — the publication page says 19 June 2026, the collection listing says 3 July 2026, and the document’s own dateline says “Issued: June 2026”. We use 19 June 2026.
The notice that does name it, read closely
One notice is a small number, and it is also a document you can read. Three details in it tell you more about the state of this market than any survey would.
Supporting Compliance and Regulatory Obligations: The managed SOC operates within recognised frameworks (e.g., ISO 27001, ISO 42001, ISO 22301, Cyber Essentials and UK NIS and GDPR) and supplies compliance reporting and rapid incident response evidence proactively.
Read live from our own corpus at the moment this page was served, including the evidence sentence — not transcribed. Every count here is a floor. We match the text of the notice, and a notice description is a summary — most tender packs demand things it never mentions. [5]
ISO 42001 vs ISO 27001: what UK buyers actually ask for
The useful version of “do I need ISO 42001” is comparative. Put it beside the certifications that appear in the same notices and the answer stops being a matter of opinion.
Pick one and the instrument reads its live numbers straight out of our corpus. The bar is drawn against the most-demanded certification in the set rather than against the corpus, because against 745,098 notices every one of these rounds to nothing.
Every figure read live through the same extractor that powers the Requirements Observatory, at the moment this page was served. Every count here is a floor. We match the text of the notice, and a notice description is a summary — most tender packs demand things it never mentions. “Open right now” counts notices whose deadline has not passed. [15]
On the same corpus and the same method, ISO 9001 appears in 412 notices against ISO 42001's 1 — roughly 412 times as often. That ratio, not the raw count, is the thing to carry away.
The practical reading for a supplier: ISO/IEC 27001 and Cyber Essentials are the certifications that actually gate UK public work in this space, and if you are choosing where to spend a certification budget with a tender in mind, that is where the evidence points. ISO 42001 is a differentiator you can lead with, not a gate you are failing. We break the wider set down on UK tender certifications, and per-requirement on the ISO 42001 requirement page.
AI buying is accelerating while the standard is absent
The negative finding above would be misleading on its own. The spend is arriving; it is the certificate that is not the gate.
Notices naming artificial intelligence have gone from 7.2 per 10,000 in 2019 to 12.9 per 10,000 in 2026 (a part year). That is the demand curve for the work. It is not the demand curve for the certificate.
Two caveats, both load-bearing. The series is a rate per 10,000 notices, never a raw count, because how much we ingest differs by year and raw counts across years would be invalid. And the 24 February 2025 Procurement Act go-live sits inside this series — notice conventions changed then, so the difference between the two colours is partly a change in how notices are written and not purely a change in what buyers are buying. 2026 is marked with an asterisk because it is a part year; the rate handles that correctly where a raw count would not. [15]
The EU AI Act dates, and why the old one is everywhere
Most pages arguing that ISO 42001 is about to become a procurement requirement lean on an EU deadline that moved. If you are reading a page that still says 2 August 2026, you are reading a page written before the Omnibus.
The AI Omnibus entered into force on 27 July 2026. The European Commission’s own wording: “On 27 July 2026, the AI Omnibus enters into force across the EU.” [10] The instrument is Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026. [11] Cite the regulation number and the OJ date rather than an adoption month: the number is checkable and the month is what gets misremembered.
High-risk obligations now apply from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for Annex I systems embedded in products. [10] Citing the OJ number rather than a tracker is both the correct source and a visible freshness signal, because nearly every competing page still carries the superseded date.
Two things this does not do, and they are the ones that get overstated. It does not make ISO 42001 mandatory anywhere — the Act works through conformity assessment against harmonised standards, and 42001 is a management-system standard rather than a harmonised standard under the Act. And it does not bind a UK buyer at all. It matters to a UK supplier because it may bind you, in the EU market, on those dates.
ISO 42001 tender requirements: where they would actually appear
If a buyer did want this, there are only a few places in a UK procurement where it could legitimately land — and knowing which one changes what you have to do about it.
Under the Procurement Act 2023 a certification can appear as a condition of participation, which is a gate: you either satisfy it or you are excluded, and the condition must be proportionate to the contract. [9] It can appear as an award criterion, which is scored rather than pass/fail — here the certificate earns you points and its absence costs you some. Or it can appear as a contractual term, an obligation to hold or obtain something during delivery rather than at bid time, which is the most negotiable of the three and the one most often missed.
The one notice we hold is the fourth case, and it is the commonest: a mention in a capability list. It is neither a gate nor a scored criterion — the buyer is describing the frameworks the service should operate within. That is worth recognising, because responding to a capability list as though it were a gate is how suppliers talk themselves out of bidding.
How we counted, and the match we threw away
A method section that shows you its own false positive is worth more than three paragraphs asserting rigour. Here is ours.
The population is every UK notice we hold from Find a Tender and Contracts Finder — 753,990 at the moment this page was served, the most recent published 19 August 2026. Of those, our requirements classifier has scanned 745,098, at classifier version 5, on 1 August 2026. It matches against the notice’s title and description, stores the sentence each match came from, and records a separate flag for obligation language.
A crude string search returns more, and the extra one is not a standard. Searching the whole corpus for the raw digits “42001” returns 2 matches, where the classifier keeps 1. The one it rejected is below.
…unit and the following parts: Piezosurgery PLUS Serial No: 420019086 1 standard handpiece Serial No: 408066023 1 Plus hand…
Pulled live from the corpus with the surrounding text, so you can see the rejection rather than take our word for it. If a future notice makes this list longer or shorter, this section changes with it. [15]
The same conservatism holds across the whole set rather than being tuned for this page. Raw string against extracted, on the two nearest comparators: ISO 9001 returns 508 raw and the extractor keeps 412; ISO 27001 returns 238 raw and the extractor keeps 224. The extractor understates by design, because a false positive in a published count is worse than a missed match.
Questions people actually ask about ISO 42001 and procurement
These are real search strings from this page’s own query data, reproduced as typed.
how long will it take before iso 42001 becomes a market expectation?
Nobody can give you a date, but the constraint is now supply rather than appetite, and that is a change. Accredited UK certification only became possible in July 2025 when ISO/IEC 42006:2025 gave accreditation bodies a basis to assess certifiers, and the first UKAS accreditation was granted in January 2026. A requirement cannot become normal faster than the certificates can be issued. Against that, the UK government’s one concrete plan to embed AI governance in procurement was cancelled in February 2026, so there is currently no policy driver pushing it. The honest answer is that as at 1 August 2026 it is present in one notice of 745,098, and the number to watch is not a forecast but that count — which this page re-reads every hour.
what industries are most likely to require iso 42001 from vendors?
On UK public-sector evidence the honest answer is that no industry requires it yet, and the single notice we hold is instructive about where it will start. It is not central government: it is a private rail operator buying a managed security service, and the standard appears alongside ISO/IEC 27001, ISO 22301 and Cyber Essentials in a list of frameworks the service should operate within. That is the pattern to expect — AI governance arriving as an extra line in an existing security schedule rather than as a standalone AI requirement. Regulated sectors that already run mature management-system certification, and buyers of AI-enabled managed services, are where it appears first.
how do procurement teams evaluate iso 42001 certifications
Ask for three things and the certificate becomes checkable rather than decorative: the certification body, the accreditation behind it, and the scope statement. The accreditation matters most — a certificate from a body with no accreditation for AI management systems has not been assessed against ISO/IEC 42006:2025 at all, and UKAS publishes each accredited body’s schedule showing exactly which scopes it holds. The scope statement matters second, because a management-system certificate covers named activities and sites and not necessarily the part of the business delivering your contract. And under the Procurement Act 2023, if a buyer intends to treat it as a condition of participation rather than an award criterion, that must be proportionate to the contract being let.
how do ai firms position iso 42001 in competitive proposals
The position that survives an informed evaluator is a narrow one: the certificate evidences that you run a governed AI development process, and it evidences nothing about any particular model. Firms that claim it demonstrates model quality, safety or fairness are making a claim the standard does not support, and an evaluator who knows the standard will mark it down. Used well it is a credibility shortcut in a section you have to write anyway — risk management, accountability, human oversight — letting you answer with an audited process rather than assertions. On UK public work it is currently a differentiator rather than a gate: what is actually being asked for is ISO/IEC 27001 and Cyber Essentials.
is iso 42001 mandatory for uk government contracts
No. Nothing in UK procurement policy names it: we ran a full-text check on both AI-relevant Procurement Policy Notes, PPN 017 and PPN 025, and neither contains the string “ISO” or “42001”. The nearest thing to a plan was AI Management Essentials, a DSIT self-assessment tool drawn partly from ISO/IEC 42001, which the department intended to embed in government procurement; on 6 February 2026 DSIT confirmed it “will not be publishing AIME and therefore will not be making it a requirement of the government procurement process”. A specific buyer can always choose to require a certification in a specific procurement, provided it is proportionate — but there is no general mandate, and on our corpus almost no instances.
iso 42001 vs iso 27001 which do i need for tenders
If you are choosing one with UK public tenders in mind, ISO/IEC 27001 — and it is not close. On our corpus ISO/IEC 27001 appears in 224 notices and Cyber Essentials in 291 notices, against one notice for ISO 42001. They also do different jobs: 27001 certifies an information security management system, 42001 an AI management system, and holding one says nothing about the other. Where AI governance is asked about at all, it is usually asked about inside a security schedule, which is another reason the security certification is the one that unlocks the conversation. The counts here are floors, and they are read live from our corpus.
does the eu ai act make iso 42001 mandatory
No. The Act works through conformity assessment against harmonised standards, and ISO/IEC 42001 is a management-system standard rather than a harmonised standard under the Act — holding it can help evidence parts of a risk-management obligation, but it is not a route to conformity in itself. The dates also moved, which is where most of the confusion on this comes from. The AI Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744, and high-risk obligations now apply from 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for systems embedded in products. Any page telling you that a 2 August 2026 deadline is forcing ISO 42001 into tenders is working from a superseded timetable.
how much does iso 42001 certification cost uk
We do not publish a figure, and we would treat any page that does with caution unless it names its source. Certification pricing depends on headcount, the number of sites, the scope of the management system and whether you already hold a certificate the auditor can build on, and it is quoted per organisation by the certification body. What we can tell you is the structural fact that bears on cost right now: very few UK bodies hold UKAS accreditation for this scope, so there is little competitive pressure on price and limited auditor availability. If you need a number, get quotes from accredited bodies and check each one’s UKAS schedule covers AI management systems before you compare them.
The terms, defined by whoever owns them
Ten terms you will meet in this argument, each with the source that defines it where one exists.
The figures on this page, and what each one measures
Four numbers, each labelled with exactly what it counts, and all four read live rather than quoted.
And the number we are not publishing. There is no defensible figure for the share of UK AI tenders that “now expect” ISO 42001. Several vendor pages publish one. We are not reproducing any of them, because we cannot tell you how they were counted, and the count we can do ourselves returns one notice.
Related reading
ISO 42001 in AI tenders
The companion page: what the standard asks of you, clause by clause, and how to evidence it in a bid.
The ISO 42001 requirement page
The Observatory’s own live record for this requirement — the count, the receipts, and every notice we have matched.
The Requirements Observatory
The same matcher across every certification, clearance and scheme UK buyers ask for, with the counts.
ISO 27001 in UK tenders
The certification that actually gates this work, and what buyers ask you to evidence.
Cyber Essentials in UK tenders
The other one — cheaper, faster, and required on more central government work than any ISO standard.
UK tender certifications
The whole set, and which of them are worth holding before you have a tender in front of you.
Machine learning RFP
Why ML work is not findable by classification, measured across 261 CPV codes.
The Procurement Act 2023
Conditions of participation, award criteria, and where a certification can legitimately sit.
Sources
- ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system, ISO. Stage record: “60.60 2023-12-18 International Standard published”.
- ISO/IEC 42006:2025, Requirements for bodies providing audit and certification of artificial intelligence management systems, ISO. Stage record: “60.60 2025-07-07 International Standard published”. This is the document that made accredited certification to 42001 structurally possible.
- UKAS grants first AIMS accreditation, United Kingdom Accreditation Service, 15 January 2026. “UKAS has granted BSI the first accreditation for certification of artificial intelligence (AI) management systems to ISO/IEC 42001:2023.”
- BSI Assurance UK Ltd, UKAS Schedule of Accreditation (PDF), issue date 23 July 2026. Carries the granted scope “ARTIFICIAL INTELLIGENCE MANAGEMENT SYSTEMS / In accordance with ISO/IEC 17021-1:2015 and ISO/IEC 42006:2025 / ISO/IEC 42001:2023 Certification”.
- FIRST RAIL HOLDINGS LIMITED, “First Cyber Security Tooling & Managed Services Tender”, Find a Tender. Procurement identifier ocds-h6vhtk-069b2e; published 18 May 2026; £3,433,993. Names ISO 42001 among recognised frameworks; a second sentence carries the typo “CSO/IEC 42001”.
- Assuring a Responsible Future for AI, Department for Science, Innovation and Technology, published 6 November 2024. Source for the AI Management Essentials lineage (ISO/IEC 42001, the EU AI Act, the NIST AI RMF) and for the intent to embed it in government procurement policy and frameworks.
- Guidance for using the AI Management Essentials tool: government response, DSIT, published 6 February 2026. “DSIT will not be publishing AIME and therefore will not be making it a requirement of the government procurement process.” This document does not mention ISO/IEC 42001 — the lineage claim is cited to [6], not to this.
- PPN 017: Improving transparency of AI use in procurement, Cabinet Office, published 17 February 2025. Full text (PDF). The PDF’s own dateline reads “Originally issued: November 2023 / Updated: February 2025”, which contradicts the GOV.UK publication date; we cite the GOV.UK date. Full-text checked: contains neither “ISO” nor “42001”.
- Procurement Act 2023, legislation.gov.uk. Source for conditions of participation, award criteria and the proportionality requirement.
- AI Omnibus enters into force, European Commission, 27 July 2026. “On 27 July 2026, the AI Omnibus enters into force across the EU.” Source for the 2 December 2027 and 2 August 2028 high-risk application dates.
- Regulation (EU) 2026/1744 of 8 July 2026 (the Digital Omnibus on AI), Official Journal L, 24 July 2026; in force 27 July 2026. The high-risk application dates are stated at article level: “(i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I”. The sequence, because a wrong one circulates: proposal 19 November 2025, political agreement 7 May 2026, Regulation dated 8 July 2026, OJ 24 July 2026, in force 27 July 2026. There is no official act on 29 June 2026.
- BSI becomes the first certification body accredited by UKAS and RvA to deliver certification for ISO/IEC 42001, BSI press release, 17 November 2025. Recorded here because it conflicts with [3] on the date of the UKAS grant. We prefer the UKAS date and state both rather than choosing silently. BSI’s RvA (Netherlands) accreditation dates from 9 December 2024, which is why this page never says “first in the world”.
- ISO/IEC 23894:2023, Information technology — Artificial intelligence — Guidance on risk management, ISO. Published 2023-02. Guidance, not a certifiable requirements standard.
- PPN 025: Protecting the UK’s national security through public procurement, Cabinet Office, published 19 June 2026. Names artificial intelligence as one of four critical national-security sectors with DSIT as Sector Lead; applies only to central government departments, their executive agencies and non-departmental public bodies. GOV.UK is internally inconsistent on the date (collection listing says 3 July 2026); we use the publication page date. Full-text checked: contains neither “ISO” nor “42001”.
- rfp.quest corpus, read live at the moment this page was served. 753,990 UK notices ingested from Find a Tender and Contracts Finder under the Open Government Licence v3.0, most recent published 19 August 2026. Requirement counts are produced by the extractor at
src/lib/requirements/extract.ts, classifier version 5, whose last full scan covered 745,098 notices on 1 August 2026; matches are against notice title and description only, each with a stored evidence sentence. The AI-demand series is a phrase match for “artificial intelligence” against the search index built over each notice’s title and description, expressed as a rate per 10,000 notices published in the same year, with the per-year totals taken from the same daily-refreshed aggregate the Observatory divides by. A phrase match on an index is not a substring match: it reads slightly lower than a raw text scan (93 against 97 in 2026), and it is used because a full text scan of the corpus cannot complete inside a single request. The trend is identical either way and the trend is the only thing claimed. Unlike this page’s sibling Descent pages, no figure here is a stamped literal — every one is re-read hourly, so a reader and a later auditor see the same number. - UKAS accredited-body schedules of accreditation, United Kingdom Accreditation Service. Counted 17 August 2026 by an exhaustive sweep rather than a keyword search, because CertCheck caps its result set: every management-systems schedule number from 0001 to 4000 was probed, 54 exist, and 5 carry an artificial intelligence management systems scope citing ISO/IEC 42006:2025 — BSI Assurance UK Ltd (0003, issue 192, 23 July 2026), schedule; LRQA Limited (0001, issue 220, 24 June 2026); NQA Certification Ltd (0015, issue 194, 5 May 2026); ISOQAR Limited (0026, issue 160, 4 June 2026); TUV UK Limited (0065, issue 059, 8 June 2026). Cross-checked against the UKAS AIMS development page’s pilot list of seven: Intertek Certification Ltd holds no 42001 scope and Schellman Compliance LLC is not a UKAS certification body. The sweep covers the management-systems schedule type only.