TL;DR
ISO 42001 is the first international management-system standard for AI. If you already run an ISO 27001 ISMS, you are extending a governance system you already operate.
A familiar shape.
ISO 27001 and ISO 42001 are management-system standards. Context, leadership, risk, controls, internal audits and improvement follow a familiar logic.
What is genuinely new.
The new layer is AI-specific risk: bias, explainability, drift, training data, autonomy and impact on people. Add the AI lifecycle from data and development through operation and retirement.
Why this matters for the AI Act.
The EU AI Act sets legal obligations for AI systems in scope. ISO 42001 can provide an operating frame to structure AI governance and keep evidence traceable.
Bottom line.
This is not an entirely new burden. It is the most natural extension of existing information-security governance into AI.