PRODVIS Magazin · Projekt-Erfolg 25.06.2026 7 min Lesezeit
Zurück zu den Erfolgsgeschichten

KI-Regulierung als Wettbewerbsvorteil

Warum ISO 42001 und EU AI Act ein agentisches ERP-Projekt nicht stoppen müssen.

Strategiematrix ISO 42001 und EU AI Act: strategischer Wert über operative Last – ISO 42001 (AIMS) und EU-AI-Act-Compliance liefern hohen Nutzen, Ad-hoc-KI-Piloten ohne System bleiben riskant Bild antippen zum Vergrößern
Strategischer Nutzen im Überblick: ISO 42001 und EU-AI-Act-Compliance schaffen hohen Wert bei beherrschbarer operativer Last – ad-hoc KI ohne System bleibt riskant.

Ein MedTech-Unternehmen hatte ein agentisches ERP-System begonnen. Die Umsetzung lief. Dann kam die Frage aus der Geschäftsführung: Stoppen wir das?

Der Grund war nicht die Technik. Der Grund war die Regulierung. ISO 42001 und der EU AI Act, beide gleichzeitig, beide für ein Medizintechnik-Unternehmen. Die Sorge im Führungsteam: ein Bürokratiemonster. Viel Aufwand, lange Laufzeit, am Ende ein Projekt, das mehr Papier produziert als Nutzen.

Unser Auftrag war klar. Die Geschäftsführung wollte keine Vertröstung. Sie wollte eine belastbare Antwort: Bremst uns diese Regulierung wirklich aus – oder nicht? Wir haben die Frage ernst genommen und gründlich geprüft. Was wir dabei gelernt haben, ist die eigentliche Geschichte dieses Beitrags.

Die falsche Frage und die richtige

Das Führungsteam fragte: Wie viel Bürokratie kommt auf uns zu? Das ist verständlich. Aber es ist die falsche erste Frage.

Die richtige Frage lautet: Welche KI betreiben wir überhaupt – und ist davon etwas Hochrisiko? Denn der EU AI Act knüpft Pflichten an Risikoklassen. Wer keine Hochrisiko-KI betreibt, hat einen ganz anderen Aufwand als wer es tut.

Der erste Schritt war deshalb keine Richtlinie und kein Schulungskonzept. Es war eine nüchterne Bestandsaufnahme: eine KI-Inventur. Welche Systeme sind im Einsatz? Wo? Und fällt etwas davon unter Hochrisiko?

Diese Inventur dauert in einem typischen mittelständischen Unternehmen wenige Wochen. Sie liefert zwei Ergebnisse. Erstens: Man weiß, worüber man redet. Zweitens, und das ist die häufigste Überraschung: Die eingesetzten Systeme fallen meist nicht unter Hochrisiko. Das nimmt Druck heraus.

Warum die Regulierung das Projekt nicht killt

Es gibt ein verbreitetes Missverständnis: ISO 42001 und EU AI Act seien zwei getrennte Projekte. Das stimmt nicht.

Normen sind freiwillig, Gesetze sind Pflicht. Beide lassen sich aber verbinden: Für jene Bereiche, die der EU AI Act regelt, entstehen derzeit sogenannte harmonisierte Normen, im Auftrag der EU erarbeitet und später im Amtsblatt der Union veröffentlicht. Wer eine solche Norm anwendet, profitiert von der Konformitätsvermutung: Die Behörden gehen dann davon aus, dass die gesetzlichen Anforderungen erfüllt sind, solange nichts Gegenteiliges nachgewiesen wird. Das kehrt die Beweislast um, ein erheblicher praktischer Vorteil. Für das KI-Managementsystem entsteht eine solche harmonisierte Norm gerade unter der Bezeichnung EN 18286.

ISO 42001 ist keine mandatierte Norm. Aber sie ist die direkte Vorstufe. Wer heute ein KI-Managementsystem in Anlehnung an ISO 42001 aufbaut, legt genau den Rahmen, den morgen EN 18286 und der AI Act verlangen. Man baut nicht zweimal. Man baut einmal – und richtig.

Genau das hat dem MedTech-Führungsteam die Sorge genommen. Die Regulierung war kein zweiter Berg. Sie war derselbe Berg, von zwei Seiten beschrieben.

Sechs Bausteine, die beide Systeme teilen

In der Fachpraxis von Anja Nestler decken sich ISO 42001 und EU AI Act in den wesentlichen Anforderungen. Sechs Bausteine tauchen in beiden auf:

  • Risikomanagement – KI-Risiken identifizieren, bewerten, kontrollieren (ISO 42001 Abschn. 6.1 · AI Act Art. 9).
  • Dokumentation – transparente Unterlagen zu Systemen, Daten und Protokollen (Abschn. 7.5 · Art. 11).
  • Daten-Governance – Datenqualität, Bias-Tests, Umgang mit sensiblen Daten (Anh. A.7 + B · Art. 10).
  • Menschliche Aufsicht – wirksame Kontrolle durch Menschen sicherstellen (Anh. A.9 · Art. 14).
  • Leistungsüberwachung – Genauigkeit, Robustheit, Validierung, Drift-Kontrolle (Abschn. 9 · Art. 15).
  • Kontinuierliche Verbesserung – Betrieb beobachten, Vorfälle melden, aktualisieren (Abschn. 10 · Art. 72/73).

Wer die sechs Bausteine nach ISO 42001 umsetzt, deckt die zentralen Anforderungen des EU AI Act strukturell ab.

Weniger Zeitdruck als befürchtet

Zur Lage nach damaligem Stand: Über den sogenannten „Digital Omnibus on AI“ haben sich Rat und Europäisches Parlament im Mai 2026 auf Fristenverschiebungen verständigt. Das Parlament hat sie am 16. Juni 2026 bestätigt; die formale Annahme stand zu diesem Zeitpunkt noch aus. Die Daten sollten vor jeder Entscheidung am aktuellen Stand geprüft werden.

  • Hochrisiko-KI, eigenständig (Annex III): vom 2. August 2026 auf den 2. Dezember 2027 verschoben.
  • Hochrisiko-KI in Produkten (Annex I): vom 2. August 2027 auf den 2. August 2028.
  • Nationale KI-Reallabore: vom 2. August 2026 auf den 2. August 2027.
  • Transparenzpflichten / Kennzeichnung: hier wurde die Frist verkürzt, von sechs auf drei Monate.

Für ein eingebettetes Medizinprodukt zählt vor allem die zweite Zeile. Das verschafft Zeit. Aber Zeit nützt nur, wer sie nutzt – nicht, wer wartet.

Woher der Frust wirklich kommt

Compliance-Projekte scheitern selten an den Normen. Sie scheitern an drei organisatorischen Ursachen:

  • Unklare Verantwortung. Trägt niemand im Führungsteam das Thema, wird es zur Daueraufgabe ohne Fortschritt.
  • Fehlende unternehmerische Verankerung. Compliance, die nur „weil Brüssel es will“ läuft, bleibt ein Fremdkörper.
  • Behandlung als Zusatzaufwand. Wer das Projekt neben dem Tagesgeschäft organisiert, schafft es nie. Es muss Teil der Führungsarbeit werden.

Alle drei sind behebbar. Sie verlangen keine Normenkenntnis, sondern Führungsentscheidungen.

Der praktische Weg

Im Projekt haben wir drei Hebel angesetzt:

  1. Verantwortung im Führungsteam klären. KI-Governance braucht einen Namen. Eine Person, die das Thema besitzt. Das kann die Geschäftsführung sein, die Leitung Digitalisierung oder ein Prokurist mit Mandat. Wichtig ist die klare Antwort auf: Wer trägt das bei uns?
  2. An echte Fragen andocken. Wer haftet, wenn unsere KI eine fehlerhafte Empfehlung gibt? Welche Kunden verlangen Nachweise zum KI-Einsatz? Haben wir Kontrolle über die KI-Tools, die Mitarbeiter täglich nutzen? Wenn die Antwort „wir wissen es nicht genau“ ist, ist Governance kein Bürokratieprojekt, sondern Risikovorsorge.
  3. Klein anfangen mit der KI-Inventur. Nicht mit dem vollen Apparat starten. Erst sehen, was da ist.

Darauf folgt ein Fahrplan über rund sechs Monate, in drei Phasen:

  • Phase 1 (Monat 1–2): Lückenanalyse, KI-Governance definieren, Anwendungsbereiche festlegen, KI-Systeme erfassen, Risiken bewerten, Richtlinien erstellen.
  • Phase 2 (Monat 3–4): Kontrollen umsetzen, Daten-Governance stärken, Dokumentation aufbauen, menschliche Aufsicht definieren.
  • Phase 3 (Monat 5–6): interne Audits, Management-Review, Lücken schließen, Zertifizierungsvorbereitung prüfen.

PRODVIS und Partner: gemeinsam statt allein

PRODVIS begleitet mittelständische Unternehmen seit Jahren bei der digitalen Transformation, von der ERP-Einführung bis zur Integration von KI in operative Prozesse. Die technischen Fragen sind lösbar. Die organisatorischen sind die eigentliche Herausforderung.

Für die Verzahnung von KI-Governance und Normkonformität arbeiten wir mit spezialisierten Partnern. Anja Nestler, Dipl.-Ing. und systemische Organisationsberaterin, arbeitet mit Führungsteams im Mittelstand. Als zertifizierte Normungsexpertin kennt sie die Welt der Normen von innen – ihr Fokus liegt jedoch auf der Frage, die über Erfolg oder Scheitern solcher Vorhaben entscheidet: Trägt das Führungsteam das Thema wirklich? Ihr Ansatz: nicht Bürokratie abbilden, sondern Steuerungsfähigkeit aufbauen. Sie unterstützt dabei, KI-Governance und Compliance-Anforderungen so in der Führungsarbeit zu verankern, dass aus regulatorischem Druck unternehmerische Klarheit wird.

Die Aufteilung im Projekt war einfach. PRODVIS bringt die ERP-, Prozess- und Agenten-Perspektive. Anja Nestler bringt die organisatorische Seite: die Verankerung im Führungsteam, an der KI-Projekte sonst oft scheitern. Zusammen hält das ein KI-Projekt in Bewegung und macht Governance handhabbar. Wie das ERP dabei zum Governance-Layer für agentische KI wird, beschreiben wir in einem eigenen Beitrag.

Fazit: Governance ist keine Bremse

Das MedTech-Projekt lief weiter. Es wurde nicht gestoppt. Es wurde besser strukturiert.

Wer KI verantwortungsvoll einsetzt, kann gegenüber Kunden, Banken und Behörden belegen, dass die Systeme kontrolliert, dokumentiert und haftungsrechtlich abgesichert laufen. In einem Markt, in dem KI-Missbrauch zunehmend öffentlich wird, ist das kein Marketing-Argument. Es ist ein Unterschied.

Governance ist keine Bremse, wenn man sie früh integriert. Sie kann ein Wettbewerbsvorteil sein. Entscheidend ist nicht die Norm. Entscheidend ist, dass jemand im Führungsteam sie trägt – und dass man klein anfängt, mit einer KI-Inventur.

A MedTech company had started an agentic ERP system. The work was under way. Then a question came from management: do we stop this?

The reason was not the technology. The reason was regulation. ISO 42001 and the EU AI Act, both at once, both for a medical technology company. The fear in the leadership team: a bureaucracy monster. A lot of effort, a long timeline, and in the end a project that produces more paper than value.

Our task was clear. Management did not want to be put off. They wanted a reliable answer: does this regulation really slow us down, or not? We took the question seriously and looked into it thoroughly. What we learned is the real story of this article.

The wrong question and the right one

The leadership team asked: how much bureaucracy is coming? That is understandable. But it is the wrong first question.

The right question is: which AI do we actually operate, and is any of it high-risk? The EU AI Act ties obligations to risk classes. A company without high-risk AI faces a very different effort than one with it.

So the first step was not a policy or a training plan. It was a sober stocktake: an AI inventory. Which systems are in use? Where? And does anything fall under high-risk?

In a typical mid-market company this inventory takes a few weeks. It delivers two results. First: you know what you are talking about. Second, and this is the most common surprise: the systems in use usually do not fall under high-risk. That takes the pressure out.

Why the regulation does not kill the project

There is a common misunderstanding: that ISO 42001 and the EU AI Act are two separate projects. They are not.

Standards are voluntary, laws are mandatory. But the two can be connected: for the areas the EU AI Act regulates, so-called harmonised standards are currently being developed, commissioned by the EU and later published in the Official Journal of the Union. Anyone who applies such a standard benefits from the presumption of conformity: authorities then assume the legal requirements are met, as long as nothing to the contrary is shown. That reverses the burden of proof – a considerable practical advantage. For the AI management system, such a harmonised standard is taking shape right now under the name EN 18286.

ISO 42001 is not a mandated standard. But it is the direct precursor. Anyone who builds an AI management system in line with ISO 42001 today lays exactly the framework that EN 18286 and the AI Act will demand tomorrow. You do not build twice. You build once – and properly.

That is exactly what eased the MedTech leadership team’s concern. The regulation was not a second mountain. It was the same mountain, described from two sides.

Six building blocks both systems share

In Anja Nestler’s practice, ISO 42001 and the EU AI Act overlap in their essential requirements. Six building blocks appear in both:

  • Risk management – identify, assess and control AI risks (ISO 42001 § 6.1 · AI Act Art. 9).
  • Documentation – transparent records of systems, data and logs (§ 7.5 · Art. 11).
  • Data governance – data quality, bias testing, handling of sensitive data (Annex A.7 + B · Art. 10).
  • Human oversight – ensure effective control by people (Annex A.9 · Art. 14).
  • Performance monitoring – accuracy, robustness, validation, drift control (§ 9 · Art. 15).
  • Continuous improvement – observe operation, report incidents, update (§ 10 · Art. 72/73).

Anyone who implements the six building blocks to ISO 42001 structurally covers the core requirements of the EU AI Act.

Less time pressure than feared

On the situation as it stood at the time: through the so-called “Digital Omnibus on AI”, the Council and the European Parliament agreed on deadline extensions in May 2026. Parliament confirmed them on 16 June 2026; formal adoption was still pending at that point. The dates should be checked against the current status before any decision.

  • High-risk AI, standalone (Annex III): moved from 2 August 2026 to 2 December 2027.
  • High-risk AI in products (Annex I): from 2 August 2027 to 2 August 2028.
  • National AI regulatory sandboxes: from 2 August 2026 to 2 August 2027.
  • Transparency / labelling obligations: here the deadline was shortened, from six to three months.

For an embedded medical device, the second line matters most. That buys time. But time only helps those who use it – not those who wait.

Where the frustration really comes from

Compliance projects rarely fail because of the standards. They fail for three organisational reasons:

  • Unclear ownership. If no one in the leadership team owns the topic, it becomes a permanent task without progress.
  • Weak business anchoring. Compliance run only “because Brussels wants it” stays a foreign body.
  • Treating it as extra work. Organise the project on the side of daily business and you never finish it. It has to become part of leadership work.

All three are fixable. They require not knowledge of standards, but leadership decisions.

The practical path

In the project we used three levers:

  1. Clarify ownership in the leadership team. AI governance needs a name. A person who owns the topic. It can be the management, the head of digitalisation or an authorised officer with a mandate. What matters is a clear answer to: who owns this here?
  2. Connect to real questions. Who is liable if our AI gives a faulty recommendation? Which customers now demand evidence of our AI use? Do we have control over the AI tools our staff use every day? If the answer is “we are not sure”, governance is not a bureaucracy project but risk prevention.
  3. Start small with the AI inventory. Do not start with the full apparatus. First see what is there.

That is followed by a roadmap over roughly six months, in three phases:

  • Phase 1 (months 1–2): gap analysis, define AI governance, set scope, record AI systems, assess risks, draft policies.
  • Phase 2 (months 3–4): implement controls, strengthen data governance, build documentation, define human oversight.
  • Phase 3 (months 5–6): internal audits, management review, close gaps, check certification readiness.

PRODVIS and partners: together, not alone

PRODVIS has accompanied mid-market companies through digital transformation for years, from ERP implementation to integrating AI into operational processes. The technical questions are solvable. The organisational ones are the real challenge.

For linking AI governance and standards conformity we work with specialist partners. Anja Nestler, Dipl.-Ing. and systemic organisational consultant, works with leadership teams in the mid-market. As a certified standards expert she knows the world of norms from the inside – but her focus is on the question that decides whether such initiatives succeed or fail: does the leadership team really own the topic? Her approach: not to depict bureaucracy, but to build steering capability. She helps anchor AI governance and compliance requirements in leadership work so that regulatory pressure turns into entrepreneurial clarity.

The split in the project was simple. PRODVIS brings the ERP, process and agent perspective. Anja Nestler brings the organisational side: the anchoring in the leadership team, where AI projects otherwise often fail. Together this keeps an AI project moving and makes governance manageable. How the ERP becomes a governance layer for agentic AI is described in a separate article.

Conclusion: governance is not a brake

The MedTech project continued. It was not stopped. It was structured better.

Anyone who uses AI responsibly can show customers, banks and authorities that the systems run in a controlled, documented and liability-proof way. In a market where AI misuse is increasingly public, that is not a marketing argument. It is a difference.

Governance is not a brake if you integrate it early. It can be a competitive advantage. What matters is not the standard. What matters is that someone in the leadership team owns it – and that you start small, with an AI inventory.

Nächster Schritt

Klären wir, wo Ihr Unternehmen steht — mit einer KI-Inventur als erstem Schritt.

Wir prüfen gemeinsam, welche KI Sie betreiben, was davon regulatorisch relevant ist und wie Governance Ihr ERP-Projekt stärkt statt bremst.