The AI Act standards landscape
Article 40 makes harmonised standards the practical route to demonstrating conformity. None exists yet. This page maps every deliverable being developed, which article it targets, how far along it is, and where the international standards you may already hold fit around the edges.
The one fact to take away
Zero AI Act harmonised standards have been cited in the Official Journal. Until a reference is published there, applying a standard builds readiness and evidence: it does not create the Article 40 presumption of conformity. Any vendor claiming “harmonised standard compliance” today is describing something that does not yet exist.
How the mechanism works
Article 40 gives a rebuttable presumption: a high-risk AI system conforming to harmonised standards whose references have been published in the Official Journal is presumed to conform with the Chapter III Section 2 requirements those standards cover. The practical effect is evidential: the burden shifts to a market surveillance authority to show the standard was inadequate.
Three gates sit between a draft and that presumption: the standard has to be finalised by CEN-CENELEC; the Commission has to accept it against the standardisation request; and the reference has to be cited in the Official Journal. Passing the first two is not enough.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
The JTC 21 deliverables
Developed under the Commission’s standardisation request M/593 and its amendment M/613. Stages move; the date on this page is when we last checked.
| Reference | Subject | AI Act target | WG | Stage |
|---|---|---|---|---|
| EN 18286 | Quality management system for EU AI Act regulatory purposes | Art. 17 | WG2 | Approval (Formal Vote) |
| prEN 18228 | Risk management for AI systems | Art. 9 | WG2 | Enquiry |
| prEN 18229-1 | AI trustworthiness framework, part 1 | Ch. III Sec. 2 (horizontal) | WG4 | Enquiry |
| prEN 18282 | Cybersecurity of AI systems | Art. 15 | WG5 | Enquiry |
| prEN 18229-2 / -3 | AI trustworthiness framework, parts 2 and 3 | Ch. III Sec. 2 (horizontal) | WG4 | Drafting |
| prEN 18283 | Concepts, measures and requirements for managing bias | Art. 10(2)(f)–(g) | WG3 | Working draft |
| prEN 18284 | Quality and governance of datasets | Art. 10 | WG3 | Drafting |
| prEN 18285 | Conformity assessment | Arts. 43–48 | WG2 | Drafting |
| prEN 18281 | Evaluation methods for accurate computer vision systems | Art. 15 | WG3 | Drafting |
| prEN ISO/IEC 24970 | AI system logging | Art. 12 | WG3 | Drafting |
| prEN ISO/IEC 23282 | Evaluation methods for natural language processing | Art. 15 | WG3 | Drafting |
The acceleration measure worth knowing about
In October 2025 the CEN and CENELEC Technical Boards adopted an exceptional package to accelerate the JTC 21 work items. Under it, where an Enquiry outcome is positive the Formal Vote stage can be skipped, with Enquiry comments addressed in the next version of the standard rather than before publication.
Expert analysis. That means a first edition may reach publication carrying known unresolved comments. If you are building a conformity argument on a first edition, read the Enquiry commentary as well as the standard.
CEN-CENELEC has indicated a Q4 2026 availability target for prioritised deliverables. It is an availability target, not a per-item publication guarantee, and availability is not the same as citation in the Official Journal.
Where the standards you already hold fit
| Standard | Status under the AI Act | What it is actually good for |
|---|---|---|
| ISO/IEC 42001:2023 AI management system | Not harmonised | Organisational AI governance, certification, and answering procurement questions today. EN 18286 includes a mapping annex to its Annex A controls. Full mapping → |
| ISO/IEC 23894:2023 AI risk management guidance | Guidance only | Structuring an Article 9 risk process. It is guidance, not a requirements standard, so it cannot be certified against or confer presumption. In detail → |
| ISO/IEC 27001:2022 Information security | Not harmonised | Most of the Article 15 cybersecurity machinery, minus the AI-specific attack classes. Compared → |
| ISO 9001 Quality management | Not harmonised | EN 18286 includes a mapping annex for organisations already running a QMS. |
| NIST AI RMF US voluntary framework | Non-EU, voluntary | A governance vocabulary and a useful bridge for US-headquartered organisations. No EU legal effect. Crosswalk → |
| ISO/IEC 42005 AI system impact assessment | Verify status | Reported as an international standard on AI system impact assessment, relevant to Article 27 FRIA practice. Confirm the current edition and status before relying on it. |
What to do while none of them is harmonised
- Build from the Article text. The requirements are in the Regulation. A standard is a route to demonstrating conformity, not the source of the obligation.
- Track EN 18286 closely if you are a high-risk provider: it is the most advanced and it targets Article 17, which is the article that organises everything else. Status →
- Do not wait. Inventory, classification and data lineage are independent of standards and are the long lead items.
- Record which standards you applied, in full or in part, and where you did not apply one, the solution adopted instead. Annex IV heading 7 asks for exactly this.
Status labels on this page
Verified fact: The JTC 21 deliverable references, their AI Act targets and working groups, the M/593 and M/613 standardisation request, the October 2025 acceleration decision, and that no deliverable had been cited in the Official Journal at the last review.
Expert analysis: The three-gate framing, and the observation that a first edition may carry unresolved Enquiry comments.
Unsettled: Per-item publication dates and Official Journal citation dates. Development stages move; verify against the CEN-CENELEC work programme.
Build the layer that does not depend on standards
The organisational management system, the AI inventory and the data lineage all have to exist whichever standard eventually carries the presumption. That is the work with no reason to wait.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
Are there any harmonised standards for the EU AI Act yet?
No. As at the last review of this page, no European standard developed under the CEN-CENELEC JTC 21 work programme had been published and cited in the Official Journal of the European Union. Presumption of conformity under Article 40 attaches only to harmonised standards whose references have been published there, so none of the deliverables currently grants it. EN 18286 on quality management systems is the most advanced, having passed Enquiry and reached the Approval or Formal Vote stage.
Which standards will support EU AI Act compliance?
CEN-CENELEC JTC 21 is developing a set of European standards under the Commission's standardisation request M/593 and its amendment M/613. The main deliverables are EN 18286 on quality management systems for Article 17, prEN 18228 on risk management for Article 9, prEN 18229 parts 1 to 3 as a horizontal AI trustworthiness framework, prEN 18282 on cybersecurity for Article 15, prEN 18283 on managing bias and prEN 18284 on dataset quality and governance for Article 10, prEN 18285 on conformity assessment, prEN 18281 on computer vision evaluation, prEN ISO/IEC 24970 on AI system logging for Article 12, and prEN ISO/IEC 23282 on natural language processing evaluation.
Is ISO/IEC 42001 a harmonised standard under the AI Act?
No. JTC 21 assessed ISO/IEC 42001 against the Article 17 quality management system requirement, found its goals and definitions were not aligned, and developed the bespoke European standard EN 18286 instead. ISO/IEC 42001 remains valuable for organisational AI governance and for procurement, and EN 18286 includes an annex mapping to ISO/IEC 42001 Annex A controls so certified organisations can reuse controls, but it does not confer Article 40 presumption of conformity.
When will EU AI Act harmonised standards be published?
CEN-CENELEC has indicated an availability target of Q4 2026 for the prioritised deliverables, which is a target rather than a guaranteed per-item publication date. In October 2025 the CEN and CENELEC Technical Boards adopted an exceptional acceleration package for the JTC 21 work items, under which a positive Enquiry outcome can allow the Formal Vote stage to be skipped, with comments addressed in the next version. Publication in the standard's own right is separate from citation in the Official Journal, which is what triggers Article 40 presumption.