Does our company need AI certification?

Should we have our use of AI certified? That’s a question many top corporate decision-makers are asking themselves right now—in part because key transparency requirements under Article 50 of the EU AI Act have been in effect since early August. A decision-making guide for business leaders!

Certification for AI? Not intended as a bureaucratic formality, but rather to clearly signal that a company has its AI processes «under control.» (Image: Depositphotos.com)

Until the summer of 2026, the idea sounded like science fiction: an artificial intelligence breaking free and hacking into another company on its own initiative. But then it happened at OpenAI of all places—one of the pioneers of AI development. During a security test, an AI agent left the designated test environment and attacked systems belonging to the AI company Hugging Face as well as other services. This incident shows that the capabilities of artificial intelligence are evolving faster than the rules and protective measures of many companies.

On top of that, there are new reports almost every day of AI glitches in everyday business life: flawed studies, fabricated sources, incorrect forecasts, or chatbots that can be tricked into making absurd statements. One famous example is the chatbot of an American car dealer that promised a customer a Chevrolet for one dollar. Other companies lost millions because they relied on flawed AI forecasts.

Smaller companies, in particular, face a dilemma

For business owners—especially those of smaller companies—this creates the following dilemma.

  • On the one hand, artificial intelligence offers enormous productivity gains. In processes where it is suitable, a company with five employees can now achieve a level of output that would previously have required ten or even 15 people. Quotes can be prepared more quickly, customer inquiries can be answered automatically, documents can be analyzed, and recurring tasks can be completed in a matter of seconds.
  • On the other hand, new risks are emerging. AI systems can hallucinate, invent information, and process confidential data that should never have been entered into the system in the first place. In addition, companies must comply with legal requirements—including the General Data Protection Regulation and the EU AI Act.

The key question today is no longer: Should we, as a company, use AI? It is: How can we use AI in a way that allows us to reap its benefits without losing control?

Stricter and more specific rules have been in effect since August

As of August 2, 2026, key transparency requirements under Article 50 of the EU AI Act have taken effect. Companies must now ensure that people can generally tell when they are communicating directly with an AI system, such as a chatbot—unless this is already obvious. Providers of generative AI systems must also label certain AI-generated content in a machine-readable format. Companies that publish AI-generated images, videos, or audio content that are deceptively realistic must generally label such “deepfakes.” A labeling requirement may also apply to AI-generated texts on topics of public interest. An important exception applies if the text has been fact-checked by a human and a person or editorial team assumes responsibility for its publication. A simple spell-check is not sufficient for this purpose.

This doesn't make things any easier for small businesses. Many business owners are asking themselves:

  • Are our employees allowed to use ChatGPT or other AI tools, and if so, for what purposes? What data may be entered into these systems?
  • Do we have to label AI-generated content?
  • Who verifies the results? And:
  • Who is responsible when something goes wrong?

Don't Prevent AI—Make It Manageable

The International Organization for Standardization has created an internationally recognized framework specifically for this challenge: ISO/IEC 42001. ISO 42001 is the world’s first management system standard for artificial intelligence. It describes how companies can use AI systematically, safely, and responsibly. The basic idea is simple: AI should not be hindered by bureaucracy. Rather, clear structures, responsibilities, and controls should help companies harness the technology’s potential in a controlled manner.

To this end, the standard requires, among other things:

  • an inventory of the AI applications used,
  • an assessment of the respective opportunities and risks,
  • clearly defined responsibilities,
  • Rules for Data and Confidential Information,
  • defined approval and review processes,
  • Skills and training for employees,
  • the monitoring of deployed AI systems,
  • handling errors and incidents,
  • Continuous improvement in AI management.

This brings AI out of the operational gray area. Instead of each employee deciding for themselves which tool may be used for which purpose, clear rules are established.

However, ISO 42001 does not replace legal advice and does not automatically guarantee compliance with the EU AI Act. Rather, the standard establishes a management system that enables companies to systematically identify legal, ethical, and economic requirements and implement them in practice.

Trust Is Becoming a New Competitive Advantage

The rapid expansion of artificial intelligence is giving rise to a new asset in the relationship between companies and their customers: trust in the safe use of AI. A company that hires an agency must be able to rely on the fact that AI-generated work products are reviewed through a clear process. After all, no client wants to receive, for example, a study or market research report whose sources are entirely fabricated. And the clients of a law firm must be able to trust that a legal brief does not cite court rulings that do not exist at all. This is exactly what has already happened on multiple occasions. Courts around the world have now documented numerous cases in which fabricated rulings and sources from AI systems were adopted without verification.

And every company whose employees use AI in their day-to-day work must ensure that those employees are adequately trained. They need to know that AI can present information convincingly yet still be wrong. They need to understand which data is confidential and why it should not be entered into public AI tools without careful consideration.

Imagine the opposite: An agency delivers fabricated results. A law firm unintentionally presents made-up facts in court. Employees upload confidential client information to freely accessible AI applications. Or a chatbot makes promises to clients that sound binding, but which the company cannot or does not want to fulfill. The real problem, then, is not the use of artificial intelligence. The problem is using it without clear rules.

ISO 42001 can be certified independently

Just as with a quality management system under ISO 9001 or an information security management system under ISO 27001, an AI management system can also be independently audited by companies such as DICIS AG (in Switzerland, for example, by SQS; Editor’s note). During such a certification process, an independent certification body assesses whether the company meets the requirements of ISO 42001 and actually applies its standards in practice. ISO itself does not conduct certifications; this task is carried out by independent certification bodies. Certification is voluntary and is not a legal requirement for the use of AI.

The key difference lies in external verification: The company does not merely claim that it uses artificial intelligence responsibly. Through certification, it has proof that its structures, processes, and controls in this regard have been independently audited. This can make the evaluation process as a (potential) supplier easier, particularly when dealing with larger clients. Instead of having to repeatedly answer extensive questionnaires about AI usage, the company has standardized proof that is recognized internationally.

Does my company need AI certification?

The clear answer is: Not every company needs ISO 42001 certification right away. If only a few employees occasionally use AI for internal ideas or to help with wording, a clear AI policy, well-defined responsibilities, and regular training may be sufficient for the time being.

Certification becomes more interesting when:

  • AI affects key business processes,
  • AI is integrated into products or services,
  • Work results are largely generated using AI,
  • sensitive or confidential data is processed,
  • Customers interact directly with AI systems,
  • AI-generated content is published,
  • many employees use various AI applications,
  • larger clients require documentation regarding AI management,
  • The company wants to position itself as a particularly secure and professional provider.

Software manufacturers, IT service providers, agencies, consulting firms, and other knowledge-intensive service providers are therefore among the companies for which certification may be of particular interest. For these companies, AI is often not just an internal tool, but an integral part of the service that customers purchase.

 Three questions determine the economic benefits

Managers who are facing the decision of whether or not to pursue certification should ask themselves three key questions:

  1. Can our customers trust that they will receive accurate results—regardless of how they were obtained? What matters is not whether a human or an AI created the initial draft. What matters is whether the result has been thoroughly reviewed.
  2. Can our customers trust that we use AI only within the limits permitted by law? These include, among other things, data protection, transparency requirements, copyright, and the requirements of the EU AI Act.
  3. Can our customers be confident that these standards apply throughout the entire company? Professional AI management must not depend on which employee is currently working on a task. The necessary skills, controls, and approvals must be available everywhere.

Anyone who can provide clear answers to these three questions builds trust. Anyone who also has the answers independently verified makes that trust visible.

A New Form of Quality Certification

Interest in ISO 42001 has risen significantly in 2026. According to our own analysis of global Google search trends, related search queries have nearly tripled within just a few months. The reason is obvious: The more artificial intelligence becomes a given in everyday business life, the more important the question of how reliably it is used becomes.

ISO 42001 certification can therefore become a new form of competitive advantage, as it signals to customers, clients, and business partners that this company does not use AI in an uncontrolled manner. It has assessed risks, defined responsibilities, trained employees, and had its processes independently audited.

Not every company needs a certificate right away. But every company that uses artificial intelligence needs clear rules. After all, the greatest danger isn’t that companies use AI. The greatest danger is that they use AI without knowing exactly where, how, and with what consequences.

To the author:

Dr. Jens-Uwe Meyer is the CEO of DICIS AG, Leipzig (https://www.dicisgroup.com/), which is itself certified to ISO 9001 (Quality Management) and ISO 27001 (Information Security Management). Among other features, it offers an AI assistant that enables companies to create the documentation required for ISO certification in no time.

This article originally appeared on m-q.ch - https://www.m-q.ch/de/braucht-unser-unternehmen-eine-ki-zertifizierung/

More articles on the topic