EU details standards plan for high-risk AI compliance
The European Commission is prioritising harmonised standards to give companies a clearer route to compliance under the AI Act. The rules cover high-risk AI systems affecting safety, health and fundamental rights, including uses in critical infrastructure and law enforcement, and require obligations to be met before products reach the market and monitored throughout their lifecycle.
European harmonised standards are intended to turn legal requirements into technical specifications, reduce compliance costs, support market benchmarking and strengthen trust in AI systems. CEN and CENELEC are developing standards through JTC 21 across areas including risk management, dataset governance and quality, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management and conformity assessment.
Once CEN and CENELEC publish harmonised standards, the Commission reviews them against the AI Act before referencing approved standards in the Official Journal of the EU. Their use remains voluntary, but companies applying them are presumed compliant. On 30 October 2025, prEN 18286: Artificial Intelligence – Quality Management System for EU AI Act Regulatory Purposes became the first harmonised AI standard to enter public enquiry, targeting Article 17 requirements for providers of high-risk systems.
The Digital Omnibus proposed on 19 November 2025 linking high-risk AI rules to the availability of support tools, including standards. The latest application dates would be 2 December 2027 for Annex III AI Act systems and 2 August 2028 for systems covered under Annex I, while international alignment through bodies such as ISO/IEC SC 42 remains central to avoiding fragmented compliance regimes.