AI Act Standards: The Bottleneck Remains a Legal Issue
As of April 20, 2026, the main obstacle to the use of standards under the AI Act is not the existence of technical drafts, but rather their legal effect. No standard developed for the AI Act has yet had its reference published in the Official Journal of the European Union. Consequently, the presumption of compliance provided for in Article 40 cannot apply. For suppliers of high-risk systems, the political timeline therefore cannot replace either technical evidence or compliance management. See also: the AI Act implementation timeline.
Updated September 10, 2026. Regulation (EU) 2026/1744 amending the AI Act was published in the Official Journal on July 24, 2026, and entered into force on July 27. The new deadlines for high-risk systems are now set for December 2, 2027 (Annex III) and August 2, 2028 (Annex I). Full coverage in our feature article.
The Essentials in 30 Seconds
- The Commission’s standardization decision is Decision C(2023)3215 of May 22, 2023, addressed to CEN and CENELEC.
- It called for deliverables in 10 areas, including risk management, quality, cybersecurity, and conformity assessment.
- The initially requested delivery date was April 30, 2025: this date has now passed.
- The prEN 18286 draft, relating to the quality management system under Article 17, entered the public inquiry phase on October 30, 2025.
- Without a reference to the Official Journal, Article 40 does not provide any presumption of conformity, even when a technical text is available.
What Happened
First, we must correct a terminological point that frequently clouds the debate. Request M/606 does not concern the AI Act: the Commission presents it as its request for standardization under the Cybersecurity Resilience Regulation. For artificial intelligence, the reference document is Implementing Decision C(2023)3215, dated May 22, 2023, addressed to the European Committee for Standardization and the European Committee for Electrotechnical Standardization.
The request covered ten areas of work: risk management; governance and data set quality; record-keeping; transparency; human oversight; accuracy; robustness; cybersecurity; quality management; and conformity assessment. These are precisely the building blocks a supplier needs to transform the requirements of Articles 9 through 15 and Article 17 into verifiable procedures, records, and controls. The delivery date set at that time—April 30, 2025—highlights the extent of the delay: it could not be met under the initial schedule.
CEN and CENELEC have entrusted a central part of this effort to the joint technical committee JTC 21. The committee states that it is dedicated to AI standardization and that its deliverables respond to a request for standardization from the Commission. The Commission’s webpage confirms that CEN and CENELEC are working together on this committee, with groups responsible for standards intended for high-risk systems.
What is the status of the projects
The most concrete indication comes from prEN 18286, titled “Artificial Intelligence – Quality Management System for EU AI Act Regulatory Purposes.” The Commission notes that on October 30, 2025, it became the first draft harmonized standard in AI to enter the public inquiry phase. This stage allows national standards organizations to comment on the draft before its final publication. The text is designed to help providers of high-risk systems address the quality management system requirements of Article 17.
This progress should not be confused with the availability of a legally binding standard. A public inquiry produces a draft; it does not complete the formal vote, the publication of a European standard, or the review that subsequently allows the Commission to publish a reference in the Official Journal. It is therefore reasonable to use a draft as material for internal preparation, for example, to organize responsibilities, document controls, and post-market surveillance. It would, however, be imprudent to present it as an automatic path to compliance.
The other areas of focus identified by the Commission—risks, data, logging, transparency, human oversight, accuracy, robustness, and cybersecurity—remain essential. But their technical maturity, on its own, does not address the regulatory question. The operational issue is not simply “which standard should be followed?” but “exactly which requirement does this standard cover, and has its reference been published?”
The Presumption Barrier
Article 40 of Regulation (EU) 2024/1689 is explicit: High-risk systems that comply with harmonized standards, or parts of such standards, whose references have been published in the Official Journal, are presumed to comply with the covered requirements. The publication of the reference is therefore not a mere editorial formality; it is the condition that triggers the presumption.
As of April 20, 2026, no references to AI Act harmonized standards have been published in the Official Journal. The consequence is simple: an organization cannot invoke the presumption of conformity under Article 40. It must be able to demonstrate, using its own evidence, that the system meets the applicable requirements. Existing standards or drafts can provide a framework for this demonstration; they do not replace it.
This discrepancy explains why the standardization timeline is a bottleneck in its own right. A policy change to the deadlines may provide more time. It does not, in and of itself, make the legal shortcut provided for in Article 40 available. Conversely, a standard published without reference in the Official Journal does not yet provide this shortcut either.
What to Do Now
- Correct the source registry — distinguish between the AI Act C(2023)3215 of M/606, which falls under cyber resilience.
- Map the requirements — link each applicable requirement in Articles 9 through 15 and 17 to evidence, a responsible party, and a review cycle.
- Proceed cautiously with projects — use prEN 18286 as a preparation framework, without characterizing it as a standard conferring a presumption of conformity.
- Monitor the Official Journal — verify the publication of references, requirement by requirement, before making any claim of presumption of conformity.
- Pave the way without presumption — consolidate the technical file and the quality management system independently of future standardization.
Sources
- European Commission, areas of harmonized standards and the role of JTC 21: digital-strategy.ec.europa.eu
- EUR-Lex, Article 40 of Regulation (EU) 2024/1689 and conditions for publication in the Official Journal: eur-lex.europa.eu
- European Commission, standardization request addressed to CEN and CENELEC under the AI Act and areas covered: digital-strategy.ec.europa.eu
- European Commission, request M/606 identified as falling under the Cyber Resilience Regulation: digital-strategy.ec.europa.eu
← AI Act: Parliament Sets Deadlines for High-Risk Applications (March 18, 2026)Digital Omnibus: Legal Deadline Precedes Compromise (2026-04-29) →