The AI Act and ISO 42001 in Process Automation: How to Implement AI and UiPath in Line with Compliance Principles

Not every RPA process is subject to the AI Act—but when automation is enriched with AI models that evaluate, classify, or recommend decisions, the risk category changes, and specific legal obligations arise. The organization must ensure, among other things, a system owner, data control, and a real Human-in-the-Loop mechanism, while ISO 42001 helps organize all this operationally. Penalties for violating the AI Act can reach €35 million or 7% of global turnover, which is why governance must be designed from the outset, rather than tacked on right before an audit.

 

Not so long ago, process automation mainly meant predictable RPA robots: fetch data, execute a rule, save the result.

Today, we increasingly integrate language models, document classification, AI agents, response generation, and decision-making or decision-recommending capabilities into our processes. Automation is no longer just executing instructions. It is beginning to interpret information and genuinely impact the course of a process.

This is exactly where the AI Act and ISO/IEC 42001 come into play.

The AI Act dictates what obligations we must fulfill

The AI Act introduces a risk-based approach. The scope of obligations depends less on the chosen tool and more on:

  • what the AI system is used for,
  • what data it processes,
  • who it impacts,
  • what decisions it makes or supports,
  • what the consequences of its malfunction might be.

Not every workflow built in UiPath is an AI system. Classic automation based on clearly defined business rules remains a predictable RPA solution.

The situation changes when a process utilizes an AI model for purposes such as:

  • evaluating candidates or employees,
  • analyzing creditworthiness,
  • profiling clients,
  • detecting fraud,
  • classifying cases and setting their priorities,
  • interpreting documents,
  • generating responses,
  • recommending decisions that affect humans.

In such cases, it is not enough to say: “The model is provided by an external vendor.” The organization using the solution can still act as the deployer of the AI system and be held responsible for how it is applied.

ISO 42001 outlines how to manage AI within an organization

ISO/IEC 42001 does not replace the AI Act. It is an AI management system standard that helps organizations structure accountability, policies, risks, data governance, monitoring, and the lifecycle of systems utilizing artificial intelligence.

Simply put:

The AI Act sets the legal requirements, while ISO 42001 helps build the organizational mechanism to fulfill them.

An ISO 42001 certification does not automatically guarantee full compliance with the AI Act. It can, however, provide the structure, documentation, and evidence demonstrating that AI is managed consciously, rather than deployed using a “let’s plug in the model and see what happens” approach.

Compliance Starts Before Writing the Workflow

Before launching AI-driven automation, an organization should answer several fundamental questions.

  1. Does the process actually use AI? 

Not every OCR, business rule, or automation is an AI system. It is crucial to clearly separate deterministic RPA from predictions, content generation, and the autonomous operation of models.

  1. What is the purpose of the system?

 A model preparing a draft summary carries a different risk than a model rejecting a client’s application, evaluating an employee, or suggesting a transaction block.

  1. Who owns the solution? 

Every system should have at least:

  • a business owner,
  • a technical owner,
  • designated accountability for risk and compliance.

AI without an owner quickly becomes the digital equivalent of a binder labeled “miscellaneous.”

  1. What data goes into the model? 

You must define:

  • data sources and quality,
  • the legal basis for processing,
  • the scope of personal and confidential data,
  • the retention period,
  • the location of processing,
  • the rules for sending data to external models.
  1. Where is the human? 

The Human-in-the-Loop should not be a decorative “Approve” button. The human must be provided with sufficient information, time, and authority to genuinely evaluate and challenge the AI’s recommendation. They must also know what they are responsible for and in which scenarios they should halt the process.

6. Can we retrace the decision? 

The organization should be able to determine:

  • which process was triggered,
  • which workflow version was used,
  • which model and its version were applied,
  • what input data was provided,
  • what output the model generated,
  • what the confidence level was,
  • who approved the decision,
  • what actions were taken next.

Without adequate logs, an audit might end with the conclusion: “The robot did something, but we don’t know exactly why.”

How Can UiPath Support This?

Within the UiPath environment, you can utilize, among other features:

  • Orchestrator and centralized logging,
  • role and access management,
  • automation versioning,
  • Action Center and Human-in-the-Loop processes,
  • governance policies,
  • AI Trust Layer,
  • monitoring of processes and agents,
  • separation of DEV, TEST, and PROD environments,
  • log exports to audit, SIEM, or GRC systems.

Merely having these features does not equal compliance, however. They must be properly configured and tied into organizational procedures.

Governance should be designed alongside the process, not tacked on a week before an audit.

The Minimum Standard for AI-Driven Automation

Every process utilizing AI should have at least:

  • a description of its purpose and permitted use,
  • a business and technical owner,
  • a risk classification,
  • a register of used models and vendors,
  • a description of input and output data,
  • an impact assessment on people and the organization,
  • defined confidence thresholds,
  • a Human-in-the-Loop pathway,
  • access control compliant with the principle of least privilege,
  • versioning of models, prompts, and workflows,
  • logs enabling action recreation,
  • quality, security, and resilience tests,
  • an error and incident handling procedure,
  • periodic reviews of the solution’s effectiveness,
  • a plan for system shutdown or reverting to a manual process,
  • an appropriate level of knowledge and training for those using the AI.

The AI Act specifically requires providers and deployers of AI systems to take measures ensuring an adequate level of AI literacy among the staff operating such solutions.

What are the penalties for non-compliance?

Violating the AI Act can lead to inspections, orders to restrict or withdraw the system, and significant financial penalties. Depending on the type of infringement, maximum fines under the regulation can reach up to €35 million or 7% of the company’s total worldwide annual turnover.

However, non-compliance means more than just administrative fines. It also entails the risk of halted processes, lost contracts, claims from affected individuals, audit issues, and a loss of trust from clients and employees.

A lack of ISO 42001 certification is not a legal violation in itself. The problem arises when an organization cannot demonstrate that it has an effective AI risk management system in place, or when compliance with the standard was required by a client, tender, or contract.

Key Takeaway

Compliance is not about banning an organization from using AI. It is about ensuring the organization can answer three questions:

  1. What does our AI system do?
  2. How do we control its operation?
  3. Who is responsible when the output is wrong?

UiPath can provide many of the mechanisms needed to deploy AI securely. However, it will not replace accountability, governance, and a properly designed process.

The biggest risk today is not the lack of AI in an organization. The biggest risk is AI that is already running, but is not listed in any register, has no owner, and leaves an insufficient audit trail.

Scale Innovations Responsibly with XELTO DIGITAL

As an organization grows, so does its complexity and operational risk. The application of artificial intelligence amplifies these challenges, which is why merely implementing technology is no longer enough today.

At XELTO, we streamline company operations during their growth—we stabilize processes and systems (from integration to automation) and take full accountability for the final result. The challenge of managing artificial intelligence has an operational dimension, and we deliver solutions that guarantee the secure scaling of operations. Our team of experts, working out of our Kraków office and beyond, will ensure that your RPA processes and AI Agents operate not only efficiently but also in accordance with the highest compliance standards.

Automation is your future. Contact us, and let’s build a secure environment for your processes.

We Care. We Deliver.

 

Author: Mikołaj Zieliński | Automation Solution Architect