News feed

    AI Standardisation Watch

    Edition 16 · September 2026

    Edition 16 (September 2026): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 16, September 2026. Based on information available as at 8 September 2026. One standard published, three rejected at enquiry.

    Open this edition →

    Pipeline at this issue

    EN 18286quality management

    Published 22 Jul 2026, not yet cited

    prEN 18228risk management

    Rejected at enquiry, comment resolution November 2026

    prEN 18229 (5 parts)trustworthiness framework

    Part 1 rejected at enquiry · Part 3 at enquiry · Parts 2, 4, 5 with the Commission

    prEN 18282cybersecurity

    Rejected at enquiry, revised scope at ballot

    prEN 18283bias

    Commission comments under review

    prEN 18284datasets

    Commission comments under review

    prEN 18285conformity assessment

    Agreed as a mature draft 4 Sep 2026

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 16, September 2026.

    AI Act timeline

    You are here · 2026-09-08

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · in force

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026 · in force

      General application, including Article 50 transparency duties

    5. 2 Dec 2026 · next

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    3 months to article 50(2) marking obligations apply to ai systems already on the market

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    From draft to legal effect
    1. A working group writes a first draft against the Commission's request.

    2. National members comment. Thousands of comments are normal at this stage.

    3. Before enquiry, the Commission assesses whether the draft is eligible to become a harmonised standard (HAS assessment).

    4. National standards bodies comment and vote. The draft can fail on the number of countries in favour or on the weighted population in favour.

    5. After a positive enquiry, the draft may be published without a formal vote (CEN-CENELEC Technical Board, October 2025). After a negative enquiry, comments are resolved and a formal vote is held, as happened with EN 18286.

    6. 06Published as ENnot yet binding

      The standard exists and can be bought and applied — but it carries no legal effect yet.

    7. The Commission publishes the reference of the standard in the Official Journal.

    8. Only now does following the standard show compliance with the AI Act requirement it covers.

    A finished standard and a standard that gives presumption of conformity are two different things. So far, most of the delay has come before publication: drafts reached enquiry months later than planned, and every enquiry vote on a core draft has been negative. EN 18286 is the first to be published; its citation in the Official Journal is still pending.

    steps 01–06 are technical work · steps 07–08 are what makes it law-relevant

    How a European standard travels from draft to legal effect.

    Who writes what inside JTC 21

    Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.

    WG1

    Strategic advisory

    Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.

    Main deliverables

    prCEN/CLC/TR 18347

    WG2

    Operational aspects

    Quality management, risk management and conformity assessment.

    Main deliverables

    EN 18286 · prEN 18228 · prEN 18285

    WG3

    Engineering aspects

    Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.

    Main deliverables

    prEN 18284 · prEN 18283 · ISO/IEC 24970

    WG4

    Foundational and societal aspects

    Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.

    Main deliverables

    prEN 18229-1 to 18229-5

    WG5

    Cybersecurity

    Security of AI systems; formed later than the other four groups.

    Main deliverables

    prEN 18282

    five working groups · one shared deadline

    Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.

    Where the disagreement sits

    Trustworthiness, first draft (comments reported February 2025) prEN 18229

    over 2,000 comments

    Restructured afterwards

    Risk management, committee draft prEN 18228

    1,300 comments

    Moved on to enquiry

    Quality management, committee draft prEN 18286

    1,100 comments

    Moved on to enquiry

    Quality management, public enquiry, January 2026 EN 18286

    1,288 comments

    Failed on both country count and weighted population

    Logging (prEN 18229-1), public enquiry, August 2026 prEN 18229-1

    443 comments

    Rejected on weighted population

    number of comments received on each draft · red marks a vote that did not pass

    How much friction each draft met during comment rounds and voting.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. As before, it notes that ongoing projects are confidential and that details should be requested from national standards bodies. The issue reports that important milestones have been reached on the standards requested by the Commission to support the AI Act.

    CEN-CENELEC JTC 21

    Next plenary. The 15th JTC 21 plenary will take place in hybrid format in Winterthur, Switzerland, on 6 and 9 October 2026, with working group sessions on 7 and 8 October. Edition 17 will report the outcomes.

    WG1 (strategic advisory). Survey of national standards bodies. The survey on inclusiveness in national standards bodies ran from 15 June to 31 August and received 15 contributions from 13 countries. The results will be presented at the plenary and reported in Edition 17.

    Overview report (prCEN/CLC/TR 18347). A second working draft of Overview and architecture of standards in support of the EU AI Act is open for comment until 1 October. The report explains the harmonised standards being prepared under the standardisation request C(2025) 3871, how they relate to each other, and their relevance to the AI Act.

    Certification bodies (prEN ISO/IEC 42006). ISO/IEC 42006:2025, on requirements for bodies auditing and certifying AI management systems, is at enquiry for direct adoption as a European standard until 29 October.

    Working group reports

    WG2 (operational aspects). Quality management system. EN 18286, Quality management system for EU AI Act regulatory purposes, was published on 22 July 2026, the first available standard supporting the AI Act.

    Risk management. The public enquiry on prEN 18228 closed on 30 July, and the draft was rejected by a majority of national standards bodies. The newsletter reads this as a signal that the large number of comments must be addressed. The editors will prepare proposed resolutions, and final comment resolution meetings are set for the first week of November. Separately, in July the working group completed a new work item proposal for an AI risk catalogue, which JTC 21 is expected to endorse at the October plenary.

    Conformity assessment. For prEN 18285, several comment resolution meetings were held in August and early September. A proposed new scope is at ballot until 21 September. Under it, the standard would set procedures and processes for assessing AI systems against all the requirements of the AI Act, including the Article 43 conformity assessment carried out through internal control (Annex VI) or with a notified body (Annex VII). The primary audience would be providers of high-risk AI systems, while providers of other AI systems could use it to align voluntarily with the Act. After the meeting on 4 September, the draft was agreed as mature and will be sent to the Commission for review.

    WG3 (engineering aspects). Bias and datasets. prEN 18283 (Concepts, measures and requirements for managing bias in AI systems) and prEN 18284 (Quality and governance of datasets in AI systems) were both approved by WG3 and sent to the Commission in July for its pre-enquiry check. The Commission's comments arrived in August and are under review. The aim for both is to reach public enquiry before the October plenary.

    NLP evaluation. ISO/IEC DIS 23282, on evaluation methods for accurate NLP systems, developed in parallel with ISO lead, is at ballot until 25 November. Logging. ISO/IEC 24970 on AI system logging is at ballot until 23 October.

    WG4 (foundational and societal aspects). The split of prEN 18229, the AI trustworthiness framework, into five parts has been formally agreed. Part 1 (logging): the public enquiry closed on 20 August. The draft had enough national standards bodies in favour, but was rejected because it did not meet the weighted population threshold, which the newsletter reads as national bodies insisting that their comments be properly considered. The editors have proposed resolutions for all 443 comments. Reconsideration requests are due by 25 September, with comment resolution meetings from 30 September to 2 October. Part 3 (human oversight): at public enquiry until 22 October. Parts 2, 4 and 5 (transparency, accuracy and robustness): submitted to the Commission for assessment before public enquiry.

    WG4 has also started a new technical report, Safeguarding Fundamental Rights in Trustworthy AI. It will examine how the trustworthiness, risk management, bias mitigation and data governance frameworks developed in JTC 21 protect fundamental rights across the AI lifecycle, and identify the technical, organisational and procedural measures that help prevent, mitigate and remedy risks to those rights.

    WG5 (cybersecurity). The public enquiry on prEN 18282, Cybersecurity specifications for AI systems, closed on 30 July, and the draft was rejected by a majority of national standards bodies. (The newsletter heading refers to "prEN 18228", which appears to be a typo.) The editors are preparing proposed resolutions. A new scope, closer to the AI Act, is at ballot until 16 September. It states that the standard addresses organisational and technical measures to ensure the cybersecurity of AI systems across their lifecycle, proportionate to the circumstances and risks; deals with cybersecurity specific to AI systems, not conventional cybersecurity; is meant to help organisations meet applicable product regulatory requirements; and is aimed primarily at organisations placing high-risk AI systems on the market or putting them into service, without being sector-specific.

    ISO/IEC JTC 1/SC 42

    Plenary and leadership. The 18th SC 42 plenary will be held in hybrid format in Montreal on 26 and 30 October 2026, with working group meetings during the week. Wael Diab's third and final term as chair ends on 31 December 2027. The secretariat has nominated Peter Mattson as chair-elect for 2027 and chair for 2028–2030, subject to approval at the JTC 1 plenary in November.

    Projects that have moved forward since Edition 15. Bias: IEEE 7003-2024, Standard for Algorithmic Bias Considerations, has been proposed for direct adoption by SC 42 through a DIS ballot, which the newsletter links to the European bias standard, prEN 18283. Performance measurement: ISO/IEC DIS 4213, on performance measurement for classification, regression, clustering and recommendation tasks, is at ballot until 26 October. Agentic AI: Amendment 2 to ISO/IEC 22989 adds concepts and terminology for agentic AI; all committee draft comments have been resolved and the CD ballot is open until 23 October.

    Enquiries and ballots under way. ISO/IEC 23282 (NLP evaluation), at DIS ballot until 25 November; ISO/IEC TR 24030 (AI use cases), at CD ballot until 23 October; ISO/IEC 24970 (logging), at ballot until 23 October; ISO/IEC 25589 (framework for human-machine teaming), at CD ballot until 23 September; ISO/IEC 25590 (output data quality of generative AI), at CD consultation until 15 October; ISO/IEC 42007 (framework for conformity assessment schemes), at DIS ballot until 3 November; ISO/IEC TS 42119-3 (verification and validation analysis), at DIS ballot until 24 September.

    Approved or advancing. ISO/IEC DIS 25029 (AI-enhanced nudging) and ISO/IEC DIS 42102 (characterising AI methods and capabilities) were both approved with comments when their ballots closed on 7 September. ISO/IEC TS 25568 (risks in generative AI) has moved to the draft technical specification stage. ISO/IEC TR 42109 (human-machine teaming use cases) is expected to move to draft technical report ballot in September.

    In comment resolution or drafting. The committee draft of ISO/IEC TS 25571 (template for documenting ethical issues) received 276 comments, now being resolved in meetings throughout September. ISO/IEC 25870, now titled Data elements for reporting AI system incidents, is due to reach CD ballot in September. A draft of ISO/IEC 25880 (organisational implementation of human-machine teaming) is out for comment.

    Fora

    CEN-CENELEC will hold webinars for its experts on 22 September and 1 October 2026 on the first batch of changes to the European standard (EN) development process. The changes include shorter voting phases and streamlined procedures, aimed at making development faster and more predictable. The webinars will cover the implementation timeline and what the changes mean for technical committees.

    Nice to know, useful to read

    Over the summer, ANEC published factsheets summarising the main points of, and its positions on, the standards on AI quality management, AI risk management, cybersecurity for AI, and computer vision evaluation. ITU-T Study Group 17 reported to SC 42 on its meeting in Geneva on 1–10 June 2026. Its portfolio now includes more than 100 completed or ongoing work items on AI security and trustworthiness, most of them on AI security.

    My reading

    The pattern is now unmistakable. Of the core harmonised standards that went to public enquiry in 2025–2026, only one has made it through: EN 18286, which itself failed its first enquiry vote before being approved and published on 22 July. In the summer of 2026, risk management (prEN 18228) was rejected by a majority of national bodies, cybersecurity (prEN 18282) was rejected by a majority of national bodies, and logging (prEN 18229-1) won enough national bodies but was rejected on the weighted population threshold.

    In all three cases, national bodies are insisting that their comments be dealt with properly. The Technical Board's fast track to publication without a formal vote, which applies only after a positive enquiry, has not been available for any of them.

    For the timeline, this matters. Comment resolution on risk management is not due until November, and a formal vote will follow. The Q4 2026 target for the prioritised deliverables now looks very hard to meet for risk management, cybersecurity and logging, and the amended standardisation request expires on 28 February 2027. The Digital Omnibus has moved the high-risk application dates to December 2027 and August 2028, which leaves room. But for the moment, the only published candidate standard is EN 18286, and even that does not yet give a presumption of conformity, because it has not been cited in the Official Journal.

    Three developments point in a constructive direction. Clearer scopes: the revised scopes for cybersecurity and conformity assessment now tie those standards explicitly to high-risk AI systems and, for conformity assessment, to Article 43 and Annexes VI and VII, which should make it easier to see which legal obligation each clause is meant to discharge. A cross-cutting check on fundamental rights: the new WG4 technical report will test how the whole JTC 21 framework protects fundamental rights, covering prevention, mitigation and remedy, a direct response to the long-running question of whether standards can carry those obligations. And the risk catalogue returns: split out of the risk management standard in September 2025 to save time, it is now back as a project of its own.

    For the live status of each standard, see the Standards Explorer.

    Why drafts fail: see the vote overview.

    Coming up (as of 15 September 2026)

    DateMilestone
    16 September 2026Ballot on the revised scope of prEN 18282 (cybersecurity) closes.
    21 September 2026Ballot on the revised scope of prEN 18285 (conformity assessment) closes.
    22 September and 1 October 2026CEN-CENELEC webinars on changes to the EN development process.
    25 September 2026Deadline for reconsideration requests on prEN 18229-1 (logging).
    30 September – 2 October 2026Comment resolution meetings on prEN 18229-1.
    1 October 2026Comments close on the second working draft of prCEN/CLC/TR 18347.
    Before the October plenaryTarget for public enquiry on prEN 18283 (bias) and prEN 18284 (datasets).
    6 October 2026According to press reports, the Commission is expected to present its proposal to revise Regulation (EU) No 1025/2012.
    6–9 October 202615th JTC 21 plenary in Winterthur, with the expected endorsement of the AI risk catalogue work item and results of the national standards body survey.
    22 October 2026Public enquiry on prEN 18229-3 (human oversight) closes.
    23 October 2026Ballots close on ISO/IEC 24970 (logging), Amendment 2 to ISO/IEC 22989 (agentic AI) and ISO/IEC TR 24030.
    26–30 October 202618th SC 42 plenary in Montreal.
    29 October 2026Enquiry on prEN ISO/IEC 42006 closes.
    First week of November 2026Final comment resolution meetings on prEN 18228 (risk management).
    25 November 2026DIS ballot on ISO/IEC 23282 closes.
    2 December 2026Article 50(2) marking obligations apply to AI systems already on the market.
    Q4 2026CEN-CENELEC target for availability of the prioritised deliverables.
    28 February 2027Amended standardisation request (M/613) expires.
    2 December 2027High-risk obligations apply to Annex III systems.
    2 August 2028High-risk obligations apply to Annex I systems.

    Still outstanding: the citation of EN 18286 in the Official Journal, which is what triggers presumption of conformity. As far as I can find, it had not been published as of 15 September 2026.

    Edition 15 · June 2026

    Edition 15 (June 2026): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 15, June 2026. The programme's centre of gravity shifts from drafting to decision.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    approved unanimously

    prEN 18228risk management

    enquiry to 30 Jul

    prEN 18229trustworthiness

    Part 1 to 20 Aug

    prEN 18282cybersecurity

    enquiry to 30 Jul

    prEN 18283bias management

    to Commission 1 Jul

    prEN 18284datasets

    working draft

    prEN 18285conformity assessment

    after Luxembourg

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 15, June 2026.

    AI Act timeline

    You are here · 2026-06-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · in force

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026 · next

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    less than a month to general application, including article 50 transparency duties

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Who writes what inside JTC 21

    Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.

    WG1

    Strategic advisory

    Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.

    Main deliverables

    prCEN/CLC/TR 18347

    WG2

    Operational aspects

    Quality management, risk management and conformity assessment.

    Main deliverables

    EN 18286 · prEN 18228 · prEN 18285

    WG3

    Engineering aspects

    Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.

    Main deliverables

    prEN 18284 · prEN 18283 · ISO/IEC 24970

    WG4

    Foundational and societal aspects

    Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.

    Main deliverables

    prEN 18229-1 to 18229-5

    WG5

    Cybersecurity

    Security of AI systems; formed later than the other four groups.

    Main deliverables

    prEN 18282

    five working groups · one shared deadline

    Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.

    Three tracks, one legal difference

    Europe

    CEN-CENELEC JTC 21

    Harmonised standards written on request from the European Commission.

    • prEN 18228 risk
    • prEN 18286 quality
    • prEN 18229 trustworthiness

    Yes — once cited in the Official Journal

    International

    ISO/IEC JTC 1/SC 42

    Global AI standards, sometimes adopted in Europe, sometimes deliberately not.

    • ISO/IEC 42001
    • ISO/IEC TS 12791
    • ISO/IEC 24029

    No — may be referenced, but does not carry presumption

    Professional body

    IEEE

    Engineering practice standards developed outside the EU framework.

    • Ethically aligned design series
    • Transparency and privacy standards

    No — useful practice, no legal effect under the AI Act

    The turning point

    The Commission found ISO/IEC 42001 not aligned with the quality management system required by Article 17. EN 18286 became the dedicated European route instead — which is why the two tracks are not interchangeable.

    only the European track can give presumption of conformity

    Three standardisation tracks, and why only one of them carries presumption of conformity.

    Which standard answers which article
    Art. 9

    Risk management system

    prEN 18228

    ISO/IEC 23894

    Art. 10

    Data and data governance

    prEN 18284

    prEN 18283 · ISO/IEC TS 12791

    Art. 12

    Record-keeping and logging

    prEN 18229-1

    Art. 13

    Transparency to deployers

    prEN 18229-2

    ISO/IEC 12792

    Art. 14

    Human oversight

    prEN 18229-3

    Art. 15

    Accuracy and robustness

    prEN 18229-4 · 18229-5

    ISO/IEC 24029-2 · 4213

    Art. 15

    Cybersecurity

    prEN 18282

    ISO/IEC 27090

    Art. 17

    Quality management system

    prEN 18286

    Art. 43

    Conformity assessment

    prEN 18285

    left: the legal requirement · middle: the standard seeking presumption · right: standards referenced but without legal effect

    Which draft standard answers which requirement of the AI Act.

    The deadlines that moved
    ObligationOriginallyNow

    Standards delivery to the Commission

    30 April 2025

    Missed — request now expires 28 February 2027

    High-risk duties, Annex III use cases

    2 August 2026

    2 December 2027

    High-risk duties, Annex I products

    2 August 2027

    2 August 2028

    Prohibited practices and AI literacy

    2 February 2025

    2 February 2025 — unchanged

    General-purpose AI model obligations

    2 August 2025

    2 August 2025 — unchanged

    The duties were pushed back; the standards they depend on were not delivered on time either. The gap between the two is the story this newsletter keeps returning to.

    Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026

    The deadlines that moved, and where they landed.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. As before, it notes that ongoing projects are confidential and that details should be requested from national standards bodies.

    News from the European Union

    Digital Omnibus. After the provisional trilogue agreement of 7 May 2026, the European Parliament approved the Digital Omnibus amending the AI Act in plenary on 16 June. The text confirms the postponement of the high-risk obligations: stand-alone high-risk systems in sensitive areas, including biometrics, critical infrastructure, education, employment, migration, asylum and border control, will be covered from 2 December 2027; AI systems that are safety components of products, such as lifts or toys, will be covered from 2 August 2028. The stated purpose of this sequencing is to have technical standards and other support tools in place before the rules apply. At the time of writing, Council endorsement and publication in the Official Journal were still pending.

    A new standardisation request on data quality. The Commission began consulting on a standardisation request for two European data quality standards, one on data quality metrics and one on collaborative data quality management, to be adopted by 1 November 2027. CEN-CENELEC, and JTC 21 in particular as the committee responsible for AI and data, will be closely involved.

    High-risk classification guidelines. A targeted consultation, open until 23 July, asked for feedback on the clarity and usefulness of the Commission's draft guidelines on classifying high-risk AI systems. The guidelines are meant to help providers, deployers and market surveillance authorities decide whether a system is high-risk, with practical examples across different areas and use cases.

    Council of Europe Framework Convention. The EU formally approved the Council of Europe Framework Convention on AI and Human Rights, Democracy and the Rule of Law on 21 April 2026. The Convention sets general principles and obligations to protect human rights, democracy and the rule of law across the AI lifecycle. Within the EU, it will be implemented exclusively through the AI Act and, where relevant, other Union law.

    CEN-CENELEC JTC 21

    Certification bodies. The proposal to adopt ISO/IEC 42006:2025 (requirements for bodies auditing and certifying AI management systems) as a European standard was approved, and the next step is public enquiry.

    WG1 (strategic advisory). Overview report. The technical report Overview and architecture of standards in support of the EU AI Act (prCEN/CLC/TR 18347) was mature. Its next step, approval by simple majority, depended on the outcome of a JTC 21 ballot on splitting the trustworthiness framework into five parts.

    Inclusiveness survey. Task Group Inclusiveness launched a survey of JTC 21 members on good practices for involving civil society in standardisation, especially in AI. Results will be presented at the next plenary, on 6–9 October 2026.

    Working group reports

    WG2 (operational aspects). Risk management (prEN 18228). The draft was at public enquiry through the national standards bodies until 30 July. It turns the requirements of Article 9 into an operational framework, and the newsletter described it as the first cross-sectoral AI risk management standard built on product-safety concepts such as intended purpose and reasonably foreseeable misuse. It also described it as the first global standard to address fundamental rights risks explicitly, anchored in the EU Charter. More than 150 experts from 34 countries contributed, and since April 2024 over 2,500 comments had been resolved by consensus in some 380 hours of meetings. The Commission's preliminary assessment found it a valid candidate for harmonisation under Article 9.

    Quality management system (EN 18286). The draft was approved unanimously and was expected to become the first published standard under the standardisation request. It specifies requirements and guidance for a quality management system for organisations providing AI systems, designed to support regulatory compliance. Conformity assessment (prEN 18285): work was moving quickly, helped by contributions made after the Luxembourg workshop in late April.

    WG3 (engineering aspects). Bias (prEN 18283). After the comment period, the editors prepared a disposition of comments. Technical compromises were reached at a hybrid comment resolution meeting on 1–2 June, with further meetings planned until 18 June. The draft was due to go to the Commission for review on 1 July.

    Data (prEN 18284). The updated working draft of Quality and governance of data in AI systems was still in preparation, with discussion focused on the data lifecycle and the data quality model. Two subgroups, one for editing and one for comments, had been set up, and collected comments were being resolved.

    Computer vision. The standard on evaluation methods for accurate computer vision systems (prEN 18281) was rejected in its current form at public enquiry, which closed on 11 June. It is not mandated under the request, but it matters because it is cross-referenced by the accuracy standard, which is. The taxonomy of computer vision tasks (prEN 18288) was at public enquiry until 16 July.

    Natural language processing. Committee draft feedback on ISO/IEC 23282 (evaluation of NLP systems) and ISO/IEC TR 23281 (overview of NLP tasks), both in parallel development under ISO lead, was under review. Logging (ISO/IEC 24970): technical comments from the DIS ballot were resolved, and the document was sent for its final draft (FDIS) ballot. AI methods and capabilities (ISO/IEC 42102): the framework for characterising AI system methods and capabilities, developed jointly under ISO lead, reached the enquiry stage.

    WG4 (foundational and societal aspects). Trustworthiness framework. prEN 18229 then consisted of three work items: Part 1 (logging), Part 2 (accuracy and robustness) and Part 3 (transparency and human oversight). A JTC 21 ballot was under way on splitting it into five parts: logging, transparency, human oversight, accuracy and robustness. Logging had been reviewed by the Commission and was at public enquiry until 20 August. Transparency was still under discussion in the working group, focusing on assessment methods, transparency mechanisms, terminology, and interplay with the risk management, quality management and cybersecurity standards. Human oversight was also still under discussion, focusing on the feasibility of oversight, reaction times, observation periods, and interplay with the same standards. Accuracy and robustness remained in drafting, with the Commission having commented on the very first version.

    Other WG4 work. AI ethicists (EN 18274): the formal vote on competence requirements for AI ethics professionals closed with 100% approval. Continuing projects covered specifications for upskilling on AI ethics and for tools to handle ethical issues, a technical report on risk management in critical digital infrastructure, and EN 18287, Frugal AI: guidelines and metrics for the environmental impact of AI.

    WG5 (cybersecurity). prEN 18282, Cybersecurity specifications for AI systems, was at public enquiry until 30 July, and the Commission's preliminary assessment found it a valid candidate for harmonisation. It covers organisational and technical measures to secure high-risk AI systems throughout their lifecycle, proportionate to the circumstances and risks. For AI-specific vulnerabilities, this includes measures to prevent, detect, respond to, resolve and control attacks such as data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws. It also provides objective criteria for deciding whether a given measure adequately meets a specific vulnerability-related goal.

    ISO/IEC JTC 1/SC 42

    The SC 42 plenary met in Singapore on 20–24 April 2026. The committee's portfolio now covers about 150 standards, technical specifications and technical reports, published or in development.

    New preliminary work items. Frontier AI risk management and impact assessment will explore the characteristics of frontier AI models and systems and whether to standardise additional provisions on their risks and impacts, including for public safety and security. Context for AI systems will explore data requirements and approaches for describing, managing, using and sharing context in AI systems, including AI agents, identify gaps, assess the feasibility and priority of new standards, and recommend new work. Safety of AI models, systems and applications will explore safety objectives and constraints, including for public safety and security, how safety interacts with other trustworthiness characteristics (including the limits of traditional safety), and how safety should be handled across the lifecycle and the value chain.

    WG2 (data). ISO/IEC TR 5259-6 (visualisation framework for data quality) was being published, and the committee draft of ISO/IEC TR 42103 (synthetic data in AI systems) was out for comment.

    WG3 (trustworthiness). ISO/IEC TR 42106 (differentiated benchmarking of AI quality characteristics) was being published, and ISO/IEC 42105 (human oversight) was ready for its final draft stage. The second edition of ISO/IEC 25059 (quality model for AI systems) had its DIS comments reviewed and was open for a preview until 15 June before final approval. The DIS ballot on ISO/IEC 24029-3 (robustness of neural networks) closed with approval, and the DIS of ISO/IEC 25029 (AI-enhanced nudging) was at final enquiry. The committee draft of ISO/IEC TS 22443 (societal concerns and ethical considerations) was approved, and a committee draft of ISO/IEC TS 25571 (template for documenting ethical issues) was out for consultation.

    WG4 (use cases). A working draft of ISO/IEC 25589 (framework for human-machine teaming) was available, with committee draft stage expected in July. The 234 committee draft comments on ISO/IEC TR 42109 (human-machine teaming use cases) were being discussed. A new project, ISO/IEC 25880, on organisational implementation of human-machine teaming, was approved. A revised ISO/IEC TR 24030 on AI use cases, with 53 candidate use cases submitted so far, was expected to reach committee draft stage by July.

    Other groups. Testing: ISO/IEC TS 42119-2 (overview of testing AI systems) was published, and ISO/IEC TS 42119-3 (verification and validation analysis) was registered for final approval. Health informatics: the committee draft of ISO/IEC TR 18988 (AI in health informatics) was approved. Functional safety: comments on the committee drafts of the three-part ISO/IEC TS 22440 were under review. Conformity assessment schemes: the committee draft of ISO/IEC 42007 was in comment resolution. AI methods and capabilities: ISO/IEC DIS 42102 was at enquiry in parallel in CEN-CENELEC.

    Fora

    On 14 April 2026, the Commission, with ITU and the UN Office of the High Commissioner for Human Rights, held a seminar on human rights and ICT standardisation. It discussed how technical standards can help ensure AI is developed and deployed consistently with human rights, including privacy, data protection, non-discrimination, access to impartial information and the right to work. The report and slides are available through StandICT.eu.

    The issue also pointed to IEEE's AI activities (more than 100 AI-related standards, more than 10 AI journals including IEEE Transactions on Artificial Intelligence, and more than 100 AI conferences). Upcoming conferences in summer 2026 included the World Congress on Computational Intelligence (Maastricht, 21–26 June), the Cloud Summit (Washington, 25–26 June), the International Conference on Human-Machine Systems (Singapore, 1–3 July), a conference on sustainable AI for social impact (Hyderabad, 13–14 August), a conference on computational intelligence in bioinformatics (Athens, 31 August–2 September), and the International Conference on Responsible AI (Melbourne, 3–5 September).

    Nice to know, useful to read

    The Seoul Statement. At the International AI Standards Summit in December 2025, organised by IEC, ISO and ITU, hosted by Korea's standards agency (KATS) and held in partnership with the UN Office on Digital and Emerging Technologies, OHCHR and the OECD, the three organisations issued the Seoul Statement. It commits them to incorporating socio-technical dimensions into standards development, deepening understanding of how international standards interact with human rights, strengthening an inclusive multistakeholder community for AI standards, and enhancing public-private cooperation on AI capacity building.

    ANEC on computer vision. A factsheet on prEN 18281 supports common methods for evaluating the accuracy, reliability, robustness and fairness of computer vision systems in areas such as biometrics, age estimation, retail, driver assistance and medical imaging. It insists that testing must represent diverse demographic groups and real-world conditions to prevent bias, discrimination and safety risks.

    Magnifica Humanitas. Pope Leo XIV's encyclical on safeguarding the human person in the age of AI acknowledges the benefits of AI, warns of its threats and stresses the need for regulation.

    EESC opinion. On 29 April, the European Economic and Social Committee adopted an opinion on the EU standardisation strategy in the context of the revision of Regulation (EU) No 1025/2012. It calls for stronger participation by SMEs, trade unions and civil society, greater transparency in the European standardisation system, and better coordination of EU positions in international standards bodies. UNESCO reported to SC 42 on its work, including its recommendations on the ethics of AI and on the ethics of neurotechnology.

    My reading

    This is the most consequential issue in the series. Three of the core harmonised standards were now at or past public enquiry: risk management and cybersecurity, both with a preliminary Commission finding that they are valid candidates for harmonisation, and quality management, approved unanimously after failing its enquiry vote in January. The logging part of the trustworthiness framework was also at enquiry. For the first time, the programme's centre of gravity had shifted from drafting to decision.

    The claims made for prEN 18228 deserve attention. A risk management standard that is cross-sectoral, built on the product-safety concepts of intended purpose and reasonably foreseeable misuse, and that addresses fundamental rights risks anchored in the Charter is exactly what critics said standards could not deliver. Whether it succeeds will be judged on the text now at enquiry, not on the description. But the ambition is on record.

    Two setbacks are worth keeping in view. The computer vision evaluation standard was rejected at enquiry, and although it is not itself mandated, the accuracy standard relies on it. And the trustworthiness framework was still being reorganised, from three work items towards five parts, with transparency, human oversight, accuracy and robustness all still in discussion or drafting. Those are the requirements closest to how people actually experience AI systems, and they are the ones furthest from completion.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    June 2026Where it stands now
    Omnibus approved by Parliament; Council endorsement pendingThe Council adopted the text on 29 June 2026. It was published as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, with the dates reported in the newsletter.
    EN 18286 approved unanimously, expected to be first publishedApproved on 12 July 2026 and published as EN 18286:2026 in July, the first harmonised-standard candidate under the request to be published. Citation in the Official Journal is outstanding.
    prEN 18228 and prEN 18282 at public enquiry until 30 JulyBoth enquiries have closed. Comment resolution and formal vote are the next steps.
    Ballot on splitting prEN 18229 into five partsA JTC 21 project editor reported at the end of July that the series now has five parts. The public enquiry on Part 1 (logging) ran until 20 August 2026. Part 3 (human oversight) reached enquiry in July, with comments open until 22 September 2026.
    prEN 18283 to the Commission on 1 JulyI have not confirmed its current status.
    prEN 18281 rejected at enquiryI have not confirmed how the working group will proceed. The accuracy part of the trustworthiness series refers to it.
    Next JTC 21 plenary, 6–9 October 2026According to press reports on a draft, the Commission is expected to present its proposal for a revision of Regulation (EU) No 1025/2012 in the same week, on 6 October 2026.
    Programme deadlinesCEN-CENELEC aims for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027.
    Transparency obligationsArticle 50 obligations were not postponed by the Omnibus. Article 50(2) applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026.

    Stages for the prEN drafts are drawn from the newsletter, public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Edition 14 · April 2026

    Edition 14 (April 2026): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 14, April 2026. The 14th plenary, and the moment the programme moves from drafting into public enquiry.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    ready for formal vote

    prEN 18228risk management

    ready for enquiry

    prEN 18229trustworthiness

    Part 1 being split

    prEN 18282cybersecurity

    enquiry expected June

    prEN 18283bias management

    consultation to 30 Apr

    prEN 18284datasets

    reworked draft

    prEN 18285conformity assessment

    Luxembourg workshop

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 14, April 2026.

    AI Act timeline

    You are here · 2026-04-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · in force

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026 · next

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    3 months to general application, including article 50 transparency duties

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    From draft to legal effect
    1. A working group writes a first draft against the Commission's request.

    2. National members comment. Thousands of comments are normal at this stage.

    3. Before enquiry, the Commission assesses whether the draft is eligible to become a harmonised standard (HAS assessment).

    4. National standards bodies comment and vote. The draft can fail on the number of countries in favour or on the weighted population in favour.

    5. After a positive enquiry, the draft may be published without a formal vote (CEN-CENELEC Technical Board, October 2025). After a negative enquiry, comments are resolved and a formal vote is held, as happened with EN 18286.

    6. 06Published as ENnot yet binding

      The standard exists and can be bought and applied — but it carries no legal effect yet.

    7. The Commission publishes the reference of the standard in the Official Journal.

    8. Only now does following the standard show compliance with the AI Act requirement it covers.

    A finished standard and a standard that gives presumption of conformity are two different things. So far, most of the delay has come before publication: drafts reached enquiry months later than planned, and every enquiry vote on a core draft has been negative. EN 18286 is the first to be published; its citation in the Official Journal is still pending.

    steps 01–06 are technical work · steps 07–08 are what makes it law-relevant

    How a European standard travels from draft to legal effect.

    Who writes what inside JTC 21

    Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.

    WG1

    Strategic advisory

    Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.

    Main deliverables

    prCEN/CLC/TR 18347

    WG2

    Operational aspects

    Quality management, risk management and conformity assessment.

    Main deliverables

    EN 18286 · prEN 18228 · prEN 18285

    WG3

    Engineering aspects

    Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.

    Main deliverables

    prEN 18284 · prEN 18283 · ISO/IEC 24970

    WG4

    Foundational and societal aspects

    Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.

    Main deliverables

    prEN 18229-1 to 18229-5

    WG5

    Cybersecurity

    Security of AI systems; formed later than the other four groups.

    Main deliverables

    prEN 18282

    five working groups · one shared deadline

    Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.

    The deadlines that moved
    ObligationOriginallyNow

    Standards delivery to the Commission

    30 April 2025

    Missed — request now expires 28 February 2027

    High-risk duties, Annex III use cases

    2 August 2026

    2 December 2027

    High-risk duties, Annex I products

    2 August 2027

    2 August 2028

    Prohibited practices and AI literacy

    2 February 2025

    2 February 2025 — unchanged

    General-purpose AI model obligations

    2 August 2025

    2 August 2025 — unchanged

    The duties were pushed back; the standards they depend on were not delivered on time either. The gap between the two is the story this newsletter keeps returning to.

    Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026

    The deadlines that moved, and where they landed.

    Who is actually in the room

    Inclusiveness survey

    146/195

    75% of eligible JTC 21 members and observers answered the spring 2025 survey.

    120+

    Turin plenary

    participants from 21 countries

    150+

    Bath plenary

    participants from 20+ countries

    800+

    ISO/IEC SC 42

    registered experts, 70 national bodies

    350+

    Civil society webinars

    participants at the largest sessions

    Newsletter reach, edition by edition

    70+
    Edition 3
    500+ views
    Edition 5
    250+
    Edition 7
    several hundred
    Edition 8

    figures as reported in the newsletter

    Who takes part, and how far the work reaches.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. As before, it notes that ongoing projects are confidential and that details should be requested from national standards bodies. Most of this issue is devoted to the 14th JTC 21 plenary.

    News from the European Union

    The Digital Omnibus. In 2025 the Commission proposed ten "Omnibus" packages, each amending several EU acts at once to reduce administrative burden. The digital package covers data, cybersecurity and AI. The newsletter expected the AI Omnibus to affect the AI Act's implementation timeline and, with it, the development of the harmonised standards. At the time of writing, trilogue negotiations were expected to continue until 28 April. Any amendments were expected to be adopted before 1 August 2026, when the Annex III high-risk obligations were then due to apply, and a possible postponement of certain provisions was under discussion.

    CEN-CENELEC JTC 21: the 14th plenary

    The plenary was held online from 11 to 13 March 2026, with about 170 participants from 21 European countries, observers from Japan, and representatives of civil society and professional organisations. The Commission took an active part, and the EU Agency for Fundamental Rights attended a JTC 21 plenary for the first time.

    The Commission's messages. Faster procedures are welcome, but not at the expense of quality. Drafts sent to public enquiry must be sufficiently mature. The shortage of technical contributions remains a key challenge.

    The Commission's role. The Commission described its role as overseeing timely implementation of the standardisation request; supporting acceleration, including by assessing draft deliverables; providing ongoing expertise on the AI Act; contributing to the AI Board's subgroup on standards and coordinating with Member States; funding JTC 21, including through grants; and issuing guidance where appropriate.

    Published European AI documents. The list of CEN-CENELEC publications had grown. Alongside the documents listed in earlier issues, it now includes EN ISO/IEC 12792:2025 (transparency taxonomy) and EN ISO/IEC 5259-1 to 5259-4 (data quality for analytics and machine learning). In addition, ISO/IEC 42001 had been approved for direct adoption as a European standard.

    Enquiries and joint drafts. The public enquiry on prEN ISO/IEC 25059 (quality models for AI systems) had just closed. Committee drafts of the three-part CEN/CLC ISO/IEC/TS 22440 on functional safety and AI systems (requirements, guidance and application examples), consulted in parallel in SC 42 and JTC 21, were approved with comments.

    Working group reports

    WG1 (strategic advisory). Timeline. Timelines were being closely monitored. All standards scheduled for submission to public enquiry by 15 February 2026 were delivered on time. Full coverage of the standardisation requirements was, however, not expected before 2027.

    Technical Coherence Forum. The forum works to prevent inconsistencies, gaps and overlaps between working group deliverables. It had agreed a common JTC 21 definition of "interested parties": a person, group or organisation that can affect, be affected by, or perceive itself to be affected by a decision or activity.

    Task Group Inclusiveness. Besides producing this newsletter, the task group published a summary of its survey results. It was about to send a questionnaire to national standards bodies on civil society participation at national level, covering the role of civil society organisations, supporting national policies, barriers, good practices and evaluation.

    WG2 (operational aspects). The group's focus was on delivering the operational standards under the request, making sure each editorial team has enough people to finish. Risk management: prEN 18228 was ready for public enquiry. Quality management system: for prEN 18286 the enquiry was closed and all comments reviewed; after the harmonised standards review, the draft was ready for formal vote by the national standards bodies.

    Conformity assessment. The AI conformity assessment framework was still in preparation, with a workshop in Luxembourg on 28–30 April expected to move it forward. Certification bodies: a ballot on direct adoption of ISO/IEC 42006:2025 (requirements for bodies certifying AI management systems) ran until 14 May.

    Dissemination. A plan was being prepared to support the use of WG2's standards, possibly extending to all JTC 21 standards, by building a community of practitioners and a feedback mechanism on implementation challenges. The newsletter described the progress on risk management and quality management as a significant contribution by JTC 21 to implementing the AI Act.

    WG3 (engineering aspects). Bias: the working draft of prEN 18283 was under consultation until 30 April. Datasets: a new working draft of prEN 18284, now titled Quality and governance of data in AI systems, was being prepared after substantial rework. Computer vision: the standard on evaluation methods for accurate computer vision systems (prEN 18281) was at public enquiry until 11 June, and the taxonomy of computer vision tasks (prEN 18288) was on its way to enquiry. Natural language processing: ISO/IEC 23281 (overview of NLP tasks) was in comment resolution after its committee draft ballot. Logging: the DIS ballot on ISO/IEC 24970 was approved with comments, to be resolved before the final draft ballot.

    WG4 (foundational and societal aspects). Trustworthiness framework, Part 1: work continued on prEN 18229-1 (Logging, transparency and human oversight), and the group decided to split it in two — logging, the most advanced component, and transparency and human oversight. Part 2: prEN 18229-2 (Accuracy and robustness) was still in development. AI ethicists: the formal vote on EN 18274 (competence requirements for AI ethics professionals) was in progress. Environmental impact: EN 18287 (guidelines and metrics for the environmental impact of AI) was planned to go to public enquiry at the next plenary in October. Other continuing projects covered upskilling on AI ethics, tools for ethical issues, risk management in critical digital infrastructure, and impact assessment in the context of EU fundamental rights.

    WG5 (cybersecurity). The cybersecurity standard was substantially revised after the Commission's comments. An updated version was sent to the Commission in March, with public enquiry expected in June.

    Next plenary. Because several standards were about to enter public enquiry, which in practice freezes technical discussion, no plenary was planned in the near term. The next plenary was set for October 2026.

    ISO/IEC JTC 1/SC 42

    The SC 42 plenary was scheduled for Singapore, 20–24 April 2026, with updates to follow.

    Approved with comments. The draft technical report ISO/IEC 5259-6 (data quality visualisation); the DIS ballots on ISO/IEC 25059 (quality models for AI systems) and ISO/IEC 42105 (human oversight), with the editor's proposed resolutions for the latter available; and the committee drafts of ISO/IEC 42007 (framework for conformity assessment schemes) and ISO/IEC 42109 (human-machine teaming use cases).

    Open ballots. ISO/IEC 24029-3 (statistical methods for robustness) was at DIS ballot until 27 April, ISO/IEC 25029 (AI-enhanced nudging) was at DIS enquiry, and ISO/IEC 42102 (characterising AI system methods and capabilities) was to proceed to DIS ballot.

    New work. ISO/IEC 25864 (resilience assessment of AI systems) and ISO/IEC 26320 (corpus development and maintenance for NLP systems) were added to the work programme, and a committee draft consultation on ISO/IEC 42111 (guidance on lightweight AI systems) ran until 1 May.

    Fora

    ANEC published a factsheet on the results of its AI Task Force, funded by the European AI & Society Fund in 2025, describing how its nine members contributed at national level and in JTC 21.

    Nice to know, useful to read

    Civil society letter on the AI Omnibus. A group of 34 organisations and individuals, representing civil society, consumers, doctors, hospitals and healthcare services, conformity assessment bodies and academia, wrote to the Commission, the Cyprus Council Presidency and MEPs. They warned that proposals in the AI Omnibus would weaken the scope and effectiveness of the AI Act. The letter was published by BEUC.

    International bodies. UNESCO joined ISO/IEC JTC 1/SC 42. At ITU, Study Group 17 is developing a strategy for AI security in telecommunications through a correspondence group established at its April 2025 meeting, aiming to make SG17 the lead group on AI security within ITU-T. ISO launched Standards Insider, a monthly newsletter for its technical community.

    Research projects on AI harms. The PHAWM project (Participatory Harm Auditing Workbenches and Methodologies), with seven academic institutions and more than twenty partners, is developing a participatory approach to AI auditing that involves domain experts, regulators, affected people and end users, not only technical experts. It works through four use cases (health, media content, cultural heritage and collaborative content generation), building auditing "workbenches", methodologies and training, and aims to contribute to a certification framework for AI systems. The Horizon Europe project FINDHR, with AlgorithmWatch among the partners, has published free toolkits, training and guidelines on preventing algorithmic discrimination in hiring, tailored separately for software developers, HR professionals and policymakers.

    My reading

    This issue marks a change of phase. The programme was moving from drafting into public enquiry, and the plenary accepted that enquiry "freezes" technical debate, so the next plenary was pushed to October. The Commission's emphasis that drafts must be mature before enquiry, and that speed must not cost quality, reads as a lesson from the failed QMS enquiry reported in the previous issue. The admission that full coverage of the request is not expected before 2027 is the clearest statement yet, from inside the committee, that the harmonised standards would not be ready for the original August 2026 date.

    The definition of "interested parties". The agreed wording follows the familiar ISO management system definition but explicitly adds "group". For standards meant to address fundamental rights harms, which often fall on groups, not only on individuals, that addition is not cosmetic.

    The first split of prEN 18229-1. Logging was separated from transparency and human oversight because it was further ahead. This was a step towards the five-part structure the series has today.

    Finally, the civil society letter on the Omnibus is a reminder that the timeline of the standards and the scope of the Act were now being negotiated at the same time, in different forums, with different people in the room.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    April 2026Where it stands now
    AI Omnibus in trilogue until 28 AprilPolitical agreement was reached in early May 2026. The European Parliament approved the text on 16 June and the Council adopted it on 29 June. It was published as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. High-risk obligations now apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    prEN 18286 ready for formal voteApproved on 12 July 2026 and published as EN 18286:2026 in July. Citation in the Official Journal is outstanding.
    prEN 18228 ready for public enquiryAt public enquiry as of June 2026.
    Cybersecurity standard: enquiry expected in JuneprEN 18282 was at public enquiry as of June 2026.
    prEN 18229-1 to be split into logging and transparency/human oversightThe series now has five parts: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1, now titled Logging, went through public enquiry, with national comment windows reported to have closed in July–August 2026. Part 3 reached enquiry in July 2026, with comments open until 22 September 2026.
    prEN 18283 working draft under consultation until 30 AprilThe consultation closed as planned. The standard was still in drafting as of June 2026.
    Conformity assessment workshop in LuxembourgprEN 18285 was still in drafting as of June 2026.
    Full coverage of the request not expected before 2027CEN-CENELEC aims for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027.
    ISO/IEC 42001 approved for direct adoptionAdopted as a European standard but not intended for harmonisation under the AI Act. EN 18286 is the dedicated route to Article 17.
    Framework for conformity assessment schemes listed as ISO/IEC 42007This confirms the number used in Edition 12. The "42107" in Edition 13 appears to have been a typo.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Edition 13 · February 2026

    Edition 13 (February 2026): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 13, February 2026. Includes a figure mapping AI Act requirements to the standards expected to support them.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    enquiry failed

    prEN 18228risk management

    to Commission

    prEN 18229trustworthiness

    to Commission

    prEN 18282cybersecurity

    drafting

    prEN 18283bias management

    Delft workshop

    prEN 18284datasets

    Delft workshop

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 13, February 2026.

    AI Act timeline

    You are here · 2026-02-28

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · in force

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026 · next

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    5 months to general application, including article 50 transparency duties

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Who carries which duty

    01 · Provider

    Develops or places the system on the market

    • Risk and quality management
    • Technical documentation
    • Conformity assessment, CE marking, registration

    02 · Importer

    Brings a third-country system into the Union

    • Verifies assessment and documentation
    • Checks marking and representative
    • Keeps records, cooperates with authorities

    03 · Distributor

    Makes the system available down the chain

    • Checks marking and accompanying documents
    • Acts on non-conformity it becomes aware of
    • Storage and transport conditions

    04 · Deployer

    Uses the system under its own authority

    • Follows instructions, ensures human oversight
    • Input data relevance, log keeping
    • FRIA where required (Article 27)

    The chain can flip · Article 25

    A deployer, importer or distributor becomes the provider — with every provider duty attached — when it puts its own name or trade mark on a high-risk system, changes its intended purpose, or substantially modifies it.

    Authorised Representative

    Appointed by a third-country provider

    • Holds documentation for ten years
    • Point of contact for authorities

    Operator

    Umbrella term covering every role in the chain

    • Used where a duty applies regardless of role

    duties travel left to right along the chain

    How duties travel along the supply chain, and where a role changes hands.

    Who writes what inside JTC 21

    Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.

    WG1

    Strategic advisory

    Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.

    Main deliverables

    prCEN/CLC/TR 18347

    WG2

    Operational aspects

    Quality management, risk management and conformity assessment.

    Main deliverables

    EN 18286 · prEN 18228 · prEN 18285

    WG3

    Engineering aspects

    Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.

    Main deliverables

    prEN 18284 · prEN 18283 · ISO/IEC 24970

    WG4

    Foundational and societal aspects

    Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.

    Main deliverables

    prEN 18229-1 to 18229-5

    WG5

    Cybersecurity

    Security of AI systems; formed later than the other four groups.

    Main deliverables

    prEN 18282

    five working groups · one shared deadline

    Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.

    Which standard answers which article
    Art. 9

    Risk management system

    prEN 18228

    ISO/IEC 23894

    Art. 10

    Data and data governance

    prEN 18284

    prEN 18283 · ISO/IEC TS 12791

    Art. 12

    Record-keeping and logging

    prEN 18229-1

    Art. 13

    Transparency to deployers

    prEN 18229-2

    ISO/IEC 12792

    Art. 14

    Human oversight

    prEN 18229-3

    Art. 15

    Accuracy and robustness

    prEN 18229-4 · 18229-5

    ISO/IEC 24029-2 · 4213

    Art. 15

    Cybersecurity

    prEN 18282

    ISO/IEC 27090

    Art. 17

    Quality management system

    prEN 18286

    Art. 43

    Conformity assessment

    prEN 18285

    left: the legal requirement · middle: the standard seeking presumption · right: standards referenced but without legal effect

    Which draft standard answers which requirement of the AI Act.

    Where the disagreement sits

    Trustworthiness, first draft (comments reported February 2025) prEN 18229

    over 2,000 comments

    Restructured afterwards

    Risk management, committee draft prEN 18228

    1,300 comments

    Moved on to enquiry

    Quality management, committee draft prEN 18286

    1,100 comments

    Moved on to enquiry

    Quality management, public enquiry, January 2026 EN 18286

    1,288 comments

    Failed on both country count and weighted population

    Logging (prEN 18229-1), public enquiry, August 2026 prEN 18229-1

    443 comments

    Rejected on weighted population

    number of comments received on each draft · red marks a vote that did not pass

    How much friction each draft met during comment rounds and voting.

    The deadlines that moved
    ObligationOriginallyNow

    Standards delivery to the Commission

    30 April 2025

    Missed — request now expires 28 February 2027

    High-risk duties, Annex III use cases

    2 August 2026

    2 December 2027

    High-risk duties, Annex I products

    2 August 2027

    2 August 2028

    Prohibited practices and AI literacy

    2 February 2025

    2 February 2025 — unchanged

    General-purpose AI model obligations

    2 August 2025

    2 August 2025 — unchanged

    The duties were pushed back; the standards they depend on were not delivered on time either. The gap between the two is the story this newsletter keeps returning to.

    Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026

    The deadlines that moved, and where they landed.

    Who is actually in the room

    Inclusiveness survey

    146/195

    75% of eligible JTC 21 members and observers answered the spring 2025 survey.

    120+

    Turin plenary

    participants from 21 countries

    150+

    Bath plenary

    participants from 20+ countries

    800+

    ISO/IEC SC 42

    registered experts, 70 national bodies

    350+

    Civil society webinars

    participants at the largest sessions

    Newsletter reach, edition by edition

    70+
    Edition 3
    500+ views
    Edition 5
    250+
    Edition 7
    several hundred
    Edition 8

    figures as reported in the newsletter

    Who takes part, and how far the work reaches.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. As before, it notes that ongoing projects are confidential and that details should be requested from national standards bodies.

    News from the European Union

    High-Level Forum. The Forum's Sherpa subgroup, its main operational body, held its 12th meeting online on 10 February 2026. It discussed the Forum's work programme for 2026–2028, wrapped up the activities of its first mandate, and prepared the 4th Forum meeting, scheduled for 19 March in Brussels.

    Final report of Workstream 12 on AI. The workstream aimed to raise awareness of the AI standards being developed under the Commission's request, encourage broader participation, and improve understanding of their scope. Its final report gives an overview of the outreach carried out on the AI Act, the standardisation request, and the role of JTC 21 working with ISO/IEC JTC 1/SC 42.

    CEN-CENELEC JTC 21

    Inclusiveness survey. The survey carried out in spring 2025 received 146 responses from the 195 eligible JTC 21 members and observers. The newsletter cautions that representativeness cannot be fully guaranteed, but says the results show strengths, gaps and opportunities for more equitable participation. A summary is on the JTC 21 website.

    Next plenary. The next plenary was to be held online on 11–13 March 2026.

    Overall progress. Work on the standards supporting the AI Act had accelerated considerably since December 2025.

    WG1 (strategic advisory). The Commission reviewed the final version of the technical report Overview and architecture of standards in support of the AI Act before its public enquiry. The report presents the standards being prepared under the standardisation request C(2025) 3871 and explains how they relate to each other and to the requirements of the Act.

    Working group reports

    WG2 (operational aspects). Risk management. prEN 18228 was finalised in December 2025 and submitted to the Commission ahead of public enquiry, with a revised scope awaiting approval. It sets requirements and practical guidance for identifying, addressing and mitigating risk across the AI lifecycle, for a broad range of AI-based products and services, with explicit attention to vulnerable people. It covers risks to health and safety and to fundamental rights, with potential impacts on individuals, organisations, markets and society. It also sets out methods for determining whether a set of risk management measures can keep identified risks monitored and managed at an acceptable level.

    Quality management system. The public enquiry on prEN 18286 closed at the end of January 2026, and the draft did not obtain the required approval, failing both the count of national members in favour and the weighted population criterion. It received 1,288 comments. The project editor had prepared proposed resolutions for all of them, and requests for reconsideration were to be handled at a five-day hybrid meeting in London from 2 to 6 March.

    ISO/IEC 42001. The enquiry on direct adoption of ISO/IEC 42001 ran until 12 February. The newsletter repeated that it is not intended to be harmonised under the AI Act. EN 18286 is the candidate harmonised standard for the Act's requirements in this area, including those relating to health, safety and fundamental rights.

    WG3 (engineering aspects). Bias. prEN 18283 defines concepts, measures and requirements for assessing and treating bias not intended by the provider or deployer under their specification of the AI system. It covers data-related bias, including bias in datasets used to develop, train or assess AI systems, and system or model bias arising from algorithmic factors such as design choices.

    Datasets. prEN 18284 sets guidance and requirements for creating and managing datasets, including design choices, collection and preparation, and defines metrics for representativeness, relevance, completeness and correctness across training, validation and test data, for any AI technology.

    Timeline for both. The two drafts were reviewed in depth at a three-day hybrid workshop in Delft in early January. Further adjustments were being made, with the aim of submitting them to the Commission ahead of public enquiry by 15 June 2026.

    Natural language processing. ISO/IEC TR 23281 (overview of NLP tasks, including the effects of language diversity across all languages, dialects and variants, official or not) and prEN ISO/IEC 23282 (evaluation methods for NLP systems, including requirements on implementing metrics and on the technical resources used in evaluation) were both approved with comments.

    Logging. prEN ISO/IEC 24970 was at European enquiry until 10 February, as a parallel project under SC 42 lead. It describes common capabilities, requirements and an information model for logging events in AI systems, for use together with a risk management system. Subject to a positive Commission assessment, it was expected to support Article 12 at least in part.

    WG4 (foundational and societal aspects). prEN 18229-1 (Logging, transparency and human oversight). The revised draft with the editor's responses was circulated in December. Reconsideration requests were received until 4 January and reviewed on 7 and 9 January, after which the final working group version was sent to the Commission ahead of enquiry.

    prEN 18229-2 (Accuracy and robustness). The revised draft was also circulated in December. Reconsideration requests closed on 27 January and were reviewed on 28 and 30 January, and the final version was due to go to the Commission at about the time the newsletter was published.

    prEN 18274 (Competence requirements for professional AI ethicists). The draft was approved at enquiry with comments. It sets out the knowledge, skills and attitudes required of AI ethicists, including a strong understanding of European values and fundamental rights. The editor's proposed disposition of comments was published on 13 January, with further contributions invited until 5 February, reconsideration requests until 10 February, and discussion on 12 February.

    WG5 (cybersecurity). COBALT, an EU Horizon project on cybersecurity certification of ICT using decentralised digital twins, was granted liaison status.

    ISO/IEC JTC 1/SC 42 (selected work)

    Ballots and advanced drafts. Data quality visualisation. The draft technical report ISO/IEC 5259-6, a visualisation framework for assessing the results of data quality measures, was at ballot until 19 February.

    Robustness. ISO/IEC 24029-3, on statistical methods for assessing neural network robustness, was at ballot until 27 April.

    Human oversight. ISO/IEC 42105 was at ballot until 19 February.

    Nudging. Comment resolution on ISO/IEC 25029 was due to finish in early March, before a draft international standard ballot. The standard is meant to support both organisations using AI-enhanced nudges and those protecting consumers, workers and the public.

    Conformity assessment schemes. The committee draft of the high-level framework for developing conformity assessment schemes for AI systems (listed here as ISO/IEC 42107) was approved with comments.

    Human-machine teaming use cases. The draft technical report ISO/IEC 42109 was collecting use cases from many sectors, structured by relation type, objective, data characteristics, stakeholder considerations and trustworthiness considerations, in coordination with ISO/IEC 25589 and ISO/IEC 25880.

    New projects. Human-machine teaming. A ballot on ISO/IEC 25880, requirements and guidance for organisational implementation of human-machine teaming, ran until 20 April.

    Large language models. ISO/IEC 26200, a framework for evaluation, ethical use and interoperability of LLMs, was approved. It will cover testing methods, performance criteria, bias mitigation, risk management, security, sector-specific applications and regulatory alignment.

    Bias in healthcare. ISO/IEC TS 26312, on how healthcare organisations should identify and address bias in AI during procurement, implementation and monitoring, was at new-project ballot. It covers algorithmic, data representation, labelling and deployment-related bias in clinician- and patient-facing applications. The newsletter noted that the healthcare sector is very active in AI standardisation.

    Functional correctness. ISO/IEC 26582, on conformity assessment of the functional correctness of AI systems based on the ISO/IEC 25059 quality models, was at ballot until 29 April.

    Fora

    On 3 February, ANEC and the EU Fundamental Rights Agency held a webinar on FRA's report Assessing High-risk Artificial Intelligence: Fundamental Rights Risks. Based on interviews with providers, deployers and experts in education, employment, migration, law enforcement and public benefits, the report argues that a fundamental rights approach to AI is feasible and supports the trust needed for innovation and competitiveness.

    Nice to know, useful to read

    The issue pointed to NIST's Generative Artificial Intelligence Profile (NIST AI 600-1, July 2024) under the AI Risk Management Framework, and to a December 2025 report by the EU-funded law enforcement network CYCLOPES with standardisation recommendations based on practitioners' needs in fighting cybercrime.

    It also highlighted a December 2025 guide by the Danish Institute for Human Rights and the European Center for Not-for-Profit Law on fundamental rights impact assessments under the AI Act. The guide treats the FRIA as a decision point before deployment, involving scoping, structured deliberation on the severity and likelihood of harms with affected people and rights experts, mitigation and monitoring, public transparency and thorough documentation. It stresses that FRIAs work best when embedded in an organisation-wide AI governance strategy with clear roles and resources.

    My reading

    The headline is easy to miss: the quality management standard, the first harmonised AI Act standard to reach public enquiry, failed its enquiry vote on both the number of national members and the weighted population criterion, with 1,288 comments. That matters for two reasons. It shows that national standards bodies were not willing to wave the first harmonised standard through, whatever the time pressure. And because the Technical Board's fast track to publication applies only after a positive enquiry, EN 18286 had to go the longer way, through reconsideration and a formal vote.

    The figure on the last page deserves close reading. It confirms that EN 18286 is mapped not only to Article 17(1) but also to Articles 11(1) and 72, which is broader than a pure quality management standard. It shows prEN 18283 on bias and prEN 18285 on conformity assessment as referenced documents that do not seek presumption of conformity, with bias under Article 10 carried instead by the datasets standard. And it shows ISO/IEC 24970 on logging in the same non-presumptive role, even though the text says it may support Article 12 subject to the Commission's assessment. Readers relying on any of these standards for compliance should check which role each one is intended to play.

    Finally, the new scope of prEN 18228 names fundamental rights risks explicitly and includes methods for judging whether residual risk is acceptable. That is a substantive answer, in the text of the standard itself, to the criticism that standards cannot carry fundamental rights obligations.

    Which standards are meant to carry presumption of conformity

    AI Act requirementStandard seeking presumption of conformityReferenced standards not seeking presumption
    Quality management (Art. 17)prEN 18286, mapped to Art. 17(1), Art. 11(1) and Art. 72, and linked to prEN 18228
    Risk management (Art. 9)prEN 18228
    Data quality (Art. 10)prEN 18284prEN 18283 (bias management, Art. 10(2)(f)–(g)); ISO/IEC TS 12791:2024
    Record keeping (Art. 12)prEN 18229-1 (Arts. 12–14)prEN ISO/IEC 24970 (AI system logging)
    Transparency (Art. 13)prEN 18229-1 (Arts. 12–14)ISO/IEC 12792 (transparency taxonomy)
    Human oversight (Art. 14)prEN 18229-1 (Arts. 12–14)
    Robustness (Art. 15)prEN 18229-2ISO/IEC 24029-2:2023 and ISO/IEC 24029-3 (neural network robustness)
    Accuracy (Art. 15)prEN 18229-2ISO/IEC 4213 (classification performance); prEN ISO/IEC 23282 (NLP evaluation); prEN 18281 (computer vision evaluation)
    Cybersecurity (Art. 15)prEN 18282
    Conformity assessment (Art. 43)prEN 18285

    A figure accompanying the technical report maps each area of the standardisation request to the standards expected to support it. It distinguishes standards that seek to provide presumption of conformity from referenced standards that do not. The figure notes that the Annex ZA of each harmonised standard gives the detailed mapping of clauses to legal requirements, and that presumption applies only after citation in the Official Journal.

    For the live status of each standard, see the Standards Explorer.

    Why drafts fail: see the vote overview.

    Since then (status September 2026)

    February 2026Where it stands now
    prEN 18286 failed its enquiry vote; reconsideration in London, 2–6 MarchThe standard recovered. Because the fast track applies only after a positive enquiry, it went through a formal vote and was approved on 12 July 2026, then published as EN 18286:2026 in July. Citation in the Official Journal is outstanding.
    prEN 18228 submitted to the Commission before enquiryprEN 18228 was at public Enquiry as of June 2026.
    prEN 18229-1 and 18229-2 submitted to the Commission before enquiryThe series was later restructured into five parts: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1, now titled Logging, went through public enquiry, with national comment windows reported to have closed in July–August 2026. Part 3 reached enquiry in July 2026.
    Datasets and bias drafts to the Commission by 15 June 2026Both were still in drafting as of June 2026. A working-draft consultation on prEN 18283 closed on 30 April 2026.
    Figure: prEN 18285 on conformity assessment not seeking presumptionprEN 18285 was still in drafting as of June 2026.
    prEN ISO/IEC 24970 at European enquiryJTC 21's December 2025 calendar assumed ISO publication in September 2026. I have not confirmed its current status.
    Deadlines for the harmonised standardsCEN-CENELEC aims for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    Guide on fundamental rights impact assessmentsThe AI Act's FRIA obligation for certain deployers (Article 27) applies together with the Annex III obligations, now from 2 December 2027.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Edition 12 · December 2025

    Edition 12 (December 2025): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 12, December 2025. Includes the delivery calendar presented at the Copenhagen plenary.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    enquiry to 22 Jan 2026

    prEN 18228risk management

    400+ requests

    prEN 18229trustworthiness

    enquiry planned Feb 2026

    prEN 18282cybersecurity

    full redraft

    prEN 18283bias management

    drafting

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    team relaunched

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 12, December 2025.

    AI Act timeline

    You are here · 2025-12-31

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · in force

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026 · next

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    7 months to general application, including article 50 transparency duties

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Who writes what inside JTC 21

    Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.

    WG1

    Strategic advisory

    Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.

    Main deliverables

    prCEN/CLC/TR 18347

    WG2

    Operational aspects

    Quality management, risk management and conformity assessment.

    Main deliverables

    EN 18286 · prEN 18228 · prEN 18285

    WG3

    Engineering aspects

    Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.

    Main deliverables

    prEN 18284 · prEN 18283 · ISO/IEC 24970

    WG4

    Foundational and societal aspects

    Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.

    Main deliverables

    prEN 18229-1 to 18229-5

    WG5

    Cybersecurity

    Security of AI systems; formed later than the other four groups.

    Main deliverables

    prEN 18282

    five working groups · one shared deadline

    Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.

    Where the disagreement sits

    Trustworthiness, first draft (comments reported February 2025) prEN 18229

    over 2,000 comments

    Restructured afterwards

    Risk management, committee draft prEN 18228

    1,300 comments

    Moved on to enquiry

    Quality management, committee draft prEN 18286

    1,100 comments

    Moved on to enquiry

    Quality management, public enquiry, January 2026 EN 18286

    1,288 comments

    Failed on both country count and weighted population

    Logging (prEN 18229-1), public enquiry, August 2026 prEN 18229-1

    443 comments

    Rejected on weighted population

    number of comments received on each draft · red marks a vote that did not pass

    How much friction each draft met during comment rounds and voting.

    The deadlines that moved
    ObligationOriginallyNow

    Standards delivery to the Commission

    30 April 2025

    Missed — request now expires 28 February 2027

    High-risk duties, Annex III use cases

    2 August 2026

    2 December 2027

    High-risk duties, Annex I products

    2 August 2027

    2 August 2028

    Prohibited practices and AI literacy

    2 February 2025

    2 February 2025 — unchanged

    General-purpose AI model obligations

    2 August 2025

    2 August 2025 — unchanged

    The duties were pushed back; the standards they depend on were not delivered on time either. The gap between the two is the story this newsletter keeps returning to.

    Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026

    The deadlines that moved, and where they landed.

    Who is actually in the room

    Inclusiveness survey

    146/195

    75% of eligible JTC 21 members and observers answered the spring 2025 survey.

    120+

    Turin plenary

    participants from 21 countries

    150+

    Bath plenary

    participants from 20+ countries

    800+

    ISO/IEC SC 42

    registered experts, 70 national bodies

    350+

    Civil society webinars

    participants at the largest sessions

    Newsletter reach, edition by edition

    70+
    Edition 3
    500+ views
    Edition 5
    250+
    Edition 7
    several hundred
    Edition 8

    figures as reported in the newsletter

    Who takes part, and how far the work reaches.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. It repeats the reminder that ongoing projects are confidential and that details should be requested from national standards bodies.

    News from the European Union

    Digital Omnibus proposal. On 19 November 2025, the Commission presented its package to reduce administrative and compliance burdens. For AI, it proposed to link the application of the high-risk rules to the availability of support tools, including harmonised standards, so that providers and deployers would only have to apply those rules once the tools and standards are in place. The proposal also included simplifications, more room for real-world testing and centralised oversight of certain AI systems. The newsletter expected the package not to affect the ongoing standardisation work in JTC 21 significantly. The proposals were sent to the Parliament and the Council.

    AI Act Service Desk. Since October 2025, the AI Office has run a service desk where stakeholders can submit questions on the AI Act in any official EU language, using an EU Login account, with replies by email.

    Code of Practice on AI-generated content. On 5 November, the Commission started work on a voluntary Code of Practice on marking and labelling AI-generated content, to help providers of generative AI meet Article 50(2) and deployers meet Article 50(4). It will encourage consistent, machine-readable and detectable marking of synthetic audio, images, video and text, and guide deployers of deepfakes and other AI-generated content on disclosing AI involvement, particularly for information of public interest.

    CEN-CENELEC JTC 21: the Copenhagen plenary

    The 13th plenary took place in Copenhagen from 18 to 21 November 2025, with around 200 registered participants from 22 European countries and observers from Japan and Canada. Civil society was represented by ANEC, ETUC and Small Business Standards, and by non-profit organisations including Equinet, the 5Rights Foundation and ForHumanity. Others, such as SaferAI, took part through national delegations.

    The Commission's message. DG CONNECT again stressed the tight delivery timelines. Its representatives attributed the significant delays largely to a shortage of technical expertise and supported the Technical Board's acceleration decisions. They confirmed that the Commission will carry out HAS assessments, the checks that determine whether a standard is eligible for harmonisation, on all mandated standards before they go to public enquiry. DG CONNECT also presented the Omnibus package and said guidance on reporting serious incidents was being prepared.

    The delivery calendar

    A new calendar was presented in Copenhagen, based on strictly time-boxed comment resolution. The newsletter stressed that it reflected the situation at the time and would be updated regularly. The calendar notes that publication by CEN-CENELEC is not the same as citation in the Official Journal, which may take weeks or months longer.

    A second chart set out JTC 21's assumptions about four supporting ISO/IEC standards that are not candidates for citation in the Official Journal. The planned ISO publication dates were ISO/IEC TS 4213 (classification performance metrics) on 9 July 2026, ISO/IEC 24029-3 (statistical methods for assessing robustness) on 28 August 2026, ISO/IEC 23282 (evaluation of NLP systems) on 11 September 2026, and ISO/IEC 24970 (AI system logging) on 22 September 2026. The editors of ISO/IEC TS 4213 and ISO/IEC 23282 expected to skip the final draft stage and save about four and a half months.

    Public enquiry is open to any stakeholder in a CEN-CENELEC member country, including those who are not members of their national standards body. National comment periods vary and may close before the overall deadline, so stakeholders should check their national body's timetable early.

    Working group reports

    WG1 (strategic advisory). Task Group Inclusiveness presented the results of its survey of JTC 21 participants, covering country representation, gender balance, stakeholder interests, standardisation experience, time commitment, and familiarity with the AI Act and with health, safety and fundamental rights issues. It also proposed measures to strengthen inclusiveness. The technical report on the overview and architecture of standards was expected at enquiry in early 2026. The Technical Coherence Forum agreed to work on three things: cross-cutting technical issues; common terminology, including finding new gaps by analysing the wording of provisions across projects; and worked examples showing how provisions are routed from one project to another.

    WG2 (operational aspects). Quality management system. prEN 18286 was the first deliverable under the standardisation request to reach public enquiry, closing 22 January 2026. ISO/IEC 42001. prEN ISO/IEC 42001 was at enquiry for direct adoption from 20 November 2025 to 12 February 2026. The newsletter stated plainly that ISO/IEC 42001 does not cover all the AI Act's quality management requirements, and that EN 18286 is expected to meet them in full and serve as the harmonised standard.

    Risk management. More than 400 reconsideration requests were being worked through, together with a review of the annexes and of the scope to clarify which entities the standard applies to, with a target of mid-December for the draft. A separate risk catalogue project will start in 2026, building on contributions set aside to speed up the main standard.

    Conformity assessment. The editorial team was relaunched, with a draft due in December and public enquiry targeted for February 2026. The deliverable will address the requirements of Article 43.

    WG3 (engineering aspects). Logging. ISO/IEC DIS 24970 on AI system logging, describing common capabilities, requirements and an information model for logging events, was at enquiry until 10 February 2026. Robustness. The DIS ballot on ISO/IEC 24029-3, on selecting, applying and managing statistical methods to assess the robustness of neural networks, was open.

    Natural language processing. Committee draft consultations on ISO/IEC TR 23281 and ISO/IEC 23282 ran until 12 December. ISO/IEC TR 23281 maps AI tasks and functionalities for analysing and generating natural language, including competing terminologies and the effects of language diversity. ISO/IEC 23282 defines evaluation methods for NLP systems, with guidance on selecting, implementing and interpreting them.

    Computer vision. Working-draft consultations on prEN 18281 (evaluation methods for computer vision) and prEN 18288 (taxonomy of computer vision tasks) ran until 17 December.

    Datasets. Working drafts were expected in late 2025 or early 2026, and more contributions were needed. The standard will set guidance and requirements for creating and managing datasets, including design choices, data collection and preparation, and define metrics for representativeness, relevance, completeness and correctness.

    Bias. Working drafts were likewise expected in late 2025 or early 2026. The standard covers the assessment and treatment of bias, including bias unwanted by providers and deployers according to their specification of the AI system.

    WG4 (foundational and societal aspects). Work on the trustworthiness standards was speeding up, with two internal ballots being launched. prEN 18229-1 (Logging, transparency and human oversight) was expected at enquiry on 23 January 2026, and prEN 18229-2 (Accuracy and robustness) on 11 February 2026. The enquiry on prEN 18274 (Competence requirements for professional AI ethicists) closed on 11 December 2025. Work continued on environmental impact guidelines and metrics, upskilling on AI ethics, tools for ethical issues, fundamental rights impact assessment, and risk management in critical digital infrastructure.

    WG5 (cybersecurity). The Commission reviewed the working draft of the cybersecurity specifications and identified a series of improvements needed for it to qualify as a harmonised standard conferring presumption of conformity. The drafting team was undertaking a full redraft, aiming to issue a new version before Christmas, with comment resolution running until the end of January 2026.

    ISO/IEC JTC 1/SC 42

    ISO/IEC 12792:2025 on the transparency taxonomy of AI systems was published. Amendment 1 to ISO/IEC 22989 and to ISO/IEC 23053, both on generative AI, was approved with comments, completing the first set of foundational generative AI standards. The committee draft of ISO/IEC 25029 on AI-enhanced nudging was approved with comments. It covers definitions, concepts, use cases and requirements for designing responsible nudging mechanisms. The committee draft of ISO/IEC 42102, the taxonomy of AI system methods and capabilities developed jointly with JTC 21 under ISO lead, was also approved with comments.

    Several ballots were open. The DIS ballot on ISO/IEC 42105 (human oversight) ran from 24 November 2025 to 16 February 2026. The committee draft consultation on ISO/IEC 42007, a framework for developing conformity assessment and certification schemes for AI systems prepared with ISO CASCO, ran from 20 November 2025 to 29 January 2026. The committee draft of ISO/IEC TR 42109 (human-machine teaming use cases) was at ballot until 26 February 2026.

    Fora

    On 4 December, ANEC held an open webinar on consumer vulnerabilities and AI Act standards with Professor Malcolm Fisk (University of Central Lancashire, ANEC expert in JTC 21 WG1). On 1 December, CEN-CENELEC trained Annex III organisations on Annex Z, the mandatory cross-reference between a standard's clauses and the relevant EU legislation for any harmonised standard to be cited in the Official Journal; the recording and slides are online. The AI Office held three online workshops on 10–12 December on high-risk classification, covering, in turn, products under Annex I and related horizontal concepts; critical infrastructure, education, employment and essential services; and biometrics, law enforcement, migration and justice. The input will feed into the Commission's high-risk classification guidelines.

    Nice to know, useful to read

    AFNOR, with funding from EISMEA, is developing onboarding and training materials for current and future JTC 21 members, and invited everyone, whether active in JTC 21 or not, to answer a questionnaire on barriers to and needs in standardisation. Danish Standards published its DS PAS 2500 series in English, with practical guidance on transparency in automated decision-making, AI in public case management, bias management and AI literacy. ISO's policy brief on using international standards for responsible AI was recommended again. French researchers published a free Academic Guide to AI Act Compliance, edited by Marion Ho-Dac, Cécile Pellegrini and Bernard Long, which structures an AI Act compliance plan along the lines of ISO management system standards.

    My reading

    The Copenhagen calendar is the most concrete plan the series has published, and it is worth keeping next to the actual record. It placed almost every harmonised standard at public enquiry between February and May 2026 and at publication in the last week of December 2026. Datasets and bias came last, at April 2027, which is after the amended standardisation request expires on 28 February 2027.

    HAS assessment before enquiry. The Commission will run its eligibility check on every mandated standard before public enquiry. The cybersecurity redraft shows what that means in practice: problems are caught earlier, but the Commission's legal reading shapes the text before the public sees it.

    The two-track management system picture is now explicit. ISO/IEC 42001 is being adopted, but only EN 18286 is expected to serve as the harmonised standard for Article 17.

    A frank diagnosis. The Commission attributed the delays mainly to a shortage of technical expertise. That fits the Technical Board's decision to rely on small groups of experts already active, and it sits uneasily with the inclusiveness agenda that this newsletter exists to serve.

    The Copenhagen delivery calendar

    DeliverablePlanned public enquiryPlanned final votePlanned CEN-CENELEC publication
    Quality management system31 Oct 2025 – 23 Jan 202617 May – 12 Jul 202610 Sep 2026
    Trustworthiness framework, Part 115 Feb – 10 May 20261 Sep – 27 Oct 202626 Dec 2026
    Trustworthiness framework, Part 215 Feb – 10 May 20261 Sep – 27 Oct 202626 Dec 2026
    Risk management13 Feb – 8 May 202630 Aug – 25 Oct 202624 Dec 2026
    Cybersecurity15 Feb – 10 May 20261 Sep – 27 Oct 202626 Dec 2026
    Conformity assessment17 Feb – 12 May 20263 Sep – 29 Oct 202628 Dec 2026
    Computer vision12 Feb – 7 May 202629 Aug – 24 Oct 202623 Dec 2026
    Datasets15 Jun – 7 Sep 202630 Dec 2026 – 24 Feb 202725 Apr 2027
    Bias15 Jun – 7 Sep 202630 Dec 2026 – 24 Feb 202725 Apr 2027
    Technical report on overview and architecture10 Jan – 4 Apr 20265 Jun 2026

    Publication by CEN-CENELEC is not the same as citation in the Official Journal, which may take weeks or months longer. The calendar reflected the situation in November 2025 and was to be updated regularly.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    December 2025Where it stands now
    QMS: planned final vote 17 May – 12 July 2026, publication 10 September 2026The only standard that kept to the calendar. EN 18286 was approved on 12 July 2026 and published as EN 18286:2026 in July. Citation in the Official Journal is outstanding.
    Trustworthiness framework: Parts 1 and 2 at enquiry from February 2026The series was restructured into five parts (logging, transparency, human oversight, accuracy, robustness). Part 1 (now titled Logging) went through public enquiry, with national comment windows reported to have closed in July–August 2026. Part 3 (human oversight) reached enquiry in July 2026.
    Risk management and cybersecurity: enquiry from mid-February 2026Both prEN 18228 and prEN 18282 were at public Enquiry as of June 2026, some months behind the calendar.
    Conformity assessment: enquiry from February 2026prEN 18285 was still in drafting as of June 2026.
    Datasets and bias: working drafts early 2026, enquiry from June 2026Both were still in drafting as of June 2026. A working-draft consultation on prEN 18283 (bias) closed on 30 April 2026.
    Datasets and bias publication planned after the request expiresThe amended standardisation request (M/613) expires on 28 February 2027. CEN-CENELEC aims for the prioritised deliverables to be available by Q4 2026.
    Omnibus proposal linking high-risk rules to available standardsAdopted as Regulation (EU) 2026/1744 and in force since 27 July 2026. The adopted text sets application dates of 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.
    Code of Practice on marking and labelling AI-generated contentArticle 50 obligations were not postponed. Article 50(2) applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026.
    Commission's HAS assessments before enquiryEN 18286 contains an Annex ZA mapping its clauses to the AI Act. Its exact legal effect will depend on the reference published in the Official Journal.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Edition 11 · November 2025

    Edition 11 (November 2025): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 11, November 2025.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    from 30 Oct 2025

    prEN 18228risk management

    clauses 3-5

    prEN 18229trustworthiness

    parts approved

    prEN 18282cybersecurity

    to preview

    prEN 18283bias management

    working draft

    prEN 18284datasets

    working draft

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 11, November 2025.

    AI Act timeline

    You are here · 2025-11-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · in force

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026 · next

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    8 months to general application, including article 50 transparency duties

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Is the system high risk?
    1. 01 · Article 5

      Is the practice on the prohibited list?

      Yes

      Prohibited

      It cannot be placed on the market or used at all.

      No

      Continue

      Go to step 02.

    2. 02 · Annex I

      Is the system a safety component of a product covered by Annex I, or such a product itself?

      Yes

      High risk

      Where third-party conformity assessment is required under that product law.

      No

      Continue

      Go to step 03.

    3. 03 · Annex III

      Does the use fall in one of the listed Annex III areas?

      Yes

      Presumed high risk

      Test the exceptions in step 04.

      No

      Continue

      Skip to step 05.

    4. 04 · Article 6(3)

      Does an exception apply — narrow procedural task, human review support, pattern detection, or preparatory work?

      Yes

      Not high risk

      But the provider must document the assessment and register the system.

      No

      High risk

      Full Chapter III duties apply.

    5. 05 · Article 50

      Does the system interact with people, generate synthetic content, recognise emotions, or produce deepfakes?

      Yes

      Transparency duties

      Disclosure and machine-readable marking.

      No

      No specific duties

      General law still applies.

    work top to bottom · the first branch that ends the path decides the classification

    The classification path a provider walks before deciding which duties apply.

    The deadlines that moved
    ObligationOriginallyNow

    Standards delivery to the Commission

    30 April 2025

    Missed — request now expires 28 February 2027

    High-risk duties, Annex III use cases

    2 August 2026

    2 December 2027

    High-risk duties, Annex I products

    2 August 2027

    2 August 2028

    Prohibited practices and AI literacy

    2 February 2025

    2 February 2025 — unchanged

    General-purpose AI model obligations

    2 August 2025

    2 August 2025 — unchanged

    The duties were pushed back; the standards they depend on were not delivered on time either. The gap between the two is the story this newsletter keeps returning to.

    Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026

    The deadlines that moved, and where they landed.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. It repeats the reminder that all ongoing projects are confidential and that details should be requested from national standards bodies.

    News from the European Union

    Transparency obligations. The Commission's consultation on guidelines and a Code of Practice for the AI Act's transparency obligations ran from 4 September to 9 October 2025. It drew input from providers and deployers of interactive and generative AI, biometric categorisation and emotion recognition systems, public and private organisations, researchers, civil society, supervisory authorities and citizens.

    Digital Omnibus. A call for evidence, open until 14 October, gathered research and good practice on simplifying EU rules on data, cybersecurity and AI ahead of the Commission's Digital Omnibus.

    Serious incidents. The Commission published draft guidance and a reporting template for serious incidents involving high-risk AI systems. Stakeholders were asked, until 7 November, how the proposed measures interact with existing incident reporting regimes.

    High-Level Forum. The mandate of the High-Level Forum on European Standardisation was extended by three years (Commission Decision C(2025) 5964 of 10 September 2025). The Forum identifies standardisation priorities for EU policy and legislation and addresses horizontal issues such as international leadership, education and skills. Its Sherpa subgroups do the preparatory work, and one of its fifteen workstreams is dedicated to AI.

    CEN-CENELEC JTC 21

    Plenary. The next plenary was announced for Copenhagen, 18–21 November 2025, with a report to follow in Edition 12.

    Technical Board decisions. The CEN-CENELEC Technical Board, which oversees the standards programme and its delivery, took two decisions to support JTC 21.

    Pause on new work (30 September). While recognising that some proposals respond to market needs, the Board postponed the registration of any new work item not directly linked to the AI standardisation request (M/593 and its amendment). The pause lasts until public enquiry on the mandated standards is complete, meaning that the responsible working group must finish resolving the enquiry comments before starting any new proposal.

    Exceptional acceleration measures (14–16 October). Where the public enquiry vote is positive, draft standards may be published directly without a formal vote. JTC 21 was also asked to set up small drafting groups of already active experts to finalise six of the most delayed drafts, before returning them to the working groups for information and final comments.

    The newsletter noted that some experts in the working groups had concerns about these decisions, and that the JTC 21 chair, with the convenors and project leaders, had prepared an implementation plan taking those concerns into account.

    WG1 (strategic advisory). The new work item for a technical report, Overview and architecture of standards in support of the EU AI Act, was approved with comments, now being resolved. The report is intended to help organisations prepare for the harmonised standards and to soften the effect of publication delays. It will explain what to expect, provide essential terminology, concepts and background, and describe the technical nature of the requirements, such as those on design, development, monitoring and documentation.

    WG2 (operational aspects). On 14 October, WG2 reached unanimous agreement on the draft of the quality management system standard supporting Article 17. The draft was submitted to public enquiry, open until 22 January 2026. On risk management, the group had resolved the reconsideration requests on clause 3 (definitions) and clause 4 (requirements for the risk management system), and was working through those on clause 5 (the risk management process).

    WG3 (engineering aspects). Working drafts of the datasets standard and the bias standard were tentatively expected in December 2025, and a committee draft on computer vision in November. Two natural language processing documents developed in parallel under ISO lead, ISO/IEC TR 23281 (overview of NLP tasks and functionalities) and prEN ISO/IEC 23282 (evaluation methods for accurate NLP systems), were out for committee draft consultation. The draft international standard ISO/IEC 24970 on AI system logging was registered on 17 September, with a three-month ballot opening on 18 November, and WG3 experts were encouraged to work with their national bodies on it. A draft international standard ballot on ISO/IEC 24029-3 (statistical methods for assessing the robustness of neural networks) was expected in November.

    WG4 (foundational and societal aspects). A new work item for a European standard on guidelines and metrics for the environmental impact of AI systems and services was approved with comments. New scopes were approved for two parts of the trustworthiness framework: prEN 18229-1, Logging, transparency and human oversight, providing terminology, concepts, requirements and guidance on transparency, logging and human oversight of AI systems, primarily intended for organisations placing AI systems on the market or putting them into service, and not sector-specific; and prEN 18229-2, Accuracy and robustness, providing terminology, concepts, requirements and guidance on the accuracy and robustness of AI systems, with the rest of the scope identical to Part 1.

    In addition, prEN 18274, Competence requirements for professional AI ethicists, was at public enquiry from 18 September to 11 December 2025.

    WG5 (cybersecurity). WG5 completed its alignment discussions with the other working groups. The draft Cybersecurity specifications for AI systems was shared with the JTC 21 leadership and the Commission for preview before public enquiry.

    ISO/IEC JTC 1/SC 42

    The SC 42 plenary took place in Sydney, 20–24 October 2025. No newsletter contributors attended in person, so the report draws on meeting documents and covers only items relevant to civil society.

    Published. ISO/IEC TS 6254:2025 (explainability and interpretability), ISO/IEC TR 21221 (beneficial AI systems) and ISO/IEC 42006:2025 (requirements for certification bodies). ISO/IEC 12792 (transparency taxonomy) was ready for publication after significant administrative delays.

    WG1 (foundational standards). Work continued on the taxonomy of AI methods and capabilities (ISO/IEC 42102), AI system logging, implementation guidance for ISO/IEC 42001 (ISO/IEC 42003), a reporting framework for AI incidents (ISO/IEC 25870) and an SME handbook for ISO/IEC 42001. New amendments to ISO/IEC 22989 and ISO/IEC 23053 will add concepts and terminology for agentic AI.

    WG2 (data). Work continued on a visualisation framework for data quality (ISO/IEC TR 5259-6) and on output data quality for generative AI applications (ISO/IEC 25590).

    WG3 (trustworthiness). Advanced stages: ISO/IEC 42105 on human oversight was at final ballot, and the committee draft of ISO/IEC 25029 on AI-enhanced nudging was accepted with comments. Under development: governance and management of human oversight (ISO/IEC 18966), societal and ethical concerns (ISO/IEC TS 22443), risks in generative AI (ISO/IEC TS 25568) and a template for documenting ethical issues (ISO/IEC TS 25571). New projects: trustworthiness fact labels (ISO/IEC 42117), management and governance aspects of AI resilience assessment (ISO/IEC 25864-2) and reliability assessment (ISO/IEC TS 25570).

    WG4 (use cases). Work continued on a framework for human-machine teaming (ISO/IEC 25589) and on human-machine teaming use cases (ISO/IEC TR 42109).

    Joint working groups. On testing, two technical specifications were close to publication: ISO/IEC TS 42119-2 (overview of testing AI systems) and TS 42119-3 (verification and validation analysis). Parts on red teaming (TS 42119-7) and quality assessment of prompt-based generative text systems (TS 42119-8) were in development, and a process assessment model for AI lifecycle processes (ISO/IEC 25704) was to follow. On functional safety, the three-part ISO/IEC TS 22440 series (requirements, guidance, examples) was under development.

    Sector-specific work. A joint working group for financial services was preparing ISO/AWI TR 24492 on standardisation needs for AI in that sector. A healthcare joint working group was working on healthcare terminology (ISO/IEC 22989-2) and AI in health informatics (ISO/IEC TR 18988), with new projects planned on bias in healthcare organisations, classification and use cases of generative AI in healthcare, and safety and reliability evaluation of generative AI in healthcare.

    Fora

    On 3 October 2025, ANEC held a public webinar on fundamental rights and AI Act standards from a consumer protection perspective. It presented a Fundamental Rights Checklist for assessing whether AI standards adequately protect consumer and human rights, and a case study on AI in financial services showed the practical tensions between risk management, bias prevention and trustworthiness. The materials and checklist are available on ANEC's website.

    The CEN-CENELEC Harmonised Standards Compliance Team announced online training for Annex III organisations on Annex ZA, the annex that cross-references a candidate harmonised standard to the relevant EU legislation, for 1 December 2025. Small Business Standards ran the third edition of its Meeting Standards week for SMEs, 17–21 November 2025.

    Nice to know, useful to read

    European Ombudswoman Teresa Anjinho opened an inquiry into how the Commission ensures transparency, inclusiveness and accountability in the adoption of harmonised standards for AI. ISO published a policy brief on how consensus-based international standards turn high-level AI principles into practical requirements. And a global call for AI "red lines", launched at the 80th UN General Assembly with the support of more than 300 prominent individuals and more than 90 organisations, urged governments to agree enforceable international limits on AI by the end of 2026.

    My reading

    This issue records the moment the governance of AI standardisation itself changed. The Technical Board's two decisions pull in the same direction. New work outside the standardisation request is frozen until the mandated standards have passed enquiry, which in practice sidelines most of WG4's ethics and fundamental rights projects. And the acceleration package lets a positive enquiry lead straight to publication and hands the six most delayed drafts to small groups of experts already involved.

    Both decisions are understandable given the deadlines. Both also narrow participation at exactly the moment the Ombudswoman opened an inquiry into the transparency and inclusiveness of the process. The newsletter's brief note that some experts had concerns, and that the chair had prepared an implementation plan in response, is worth reading carefully. Speed and inclusiveness were now openly in tension, and speed had been given priority.

    Two details are also worth flagging. The approved scopes for prEN 18229 are aimed primarily at organisations placing AI systems on the market or putting them into service, which is a provider-centred framing similar to that of EN 18286. And SC 42's decision to add terminology for agentic AI to its foundational standards is an early sign that the vocabulary on which the harmonised standards rest will keep moving.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    November 2025Where it stands now
    QMS draft at public enquiry until 22 January 2026EN 18286 was approved on 12 July 2026, the first JTC 21 AI Act standard to reach that point. Citation in the Official Journal is outstanding.
    Risk management: reconsideration requests being resolvedprEN 18228 was at public Enquiry as of June 2026.
    Cybersecurity draft shared for preview before enquiryprEN 18282 was at public Enquiry as of June 2026.
    prEN 18229 in two parts (logging, transparency and human oversight; accuracy and robustness)The structure changed again in 2026. According to a JTC 21 project editor, the series now has five parts: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached enquiry in July 2026.
    Datasets and bias working drafts expected in December 2025prEN 18284 and prEN 18283 were still in drafting as of June 2026. A working-draft consultation on prEN 18283 closed on 30 April 2026.
    Technical Board acceleration measuresCEN-CENELEC aims for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027.
    Call for evidence for the Digital OmnibusThe Commission proposed the Digital Omnibus on AI on 19 November 2025. It was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, moving high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    Ombudswoman inquiry into AI harmonised standardsRegistered as case 1974/2025/MIK and opened on 26 September 2025, following a complaint by Corporate Europe Observatory about undisclosed participants, unpublished minutes and unbalanced representation. The Ombudswoman's 2025 annual report lists it among her main AI inquiries. I have not found a published outcome.
    ISO/IEC 12792 ready for publication after delaysPublished by ISO in November 2025 and adopted as EN ISO/IEC 12792:2025.
    Consultation on transparency guidelines and a Code of PracticeArticle 50 obligations were not postponed by the Omnibus. Article 50(2) applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Edition 10 · September 2025

    Edition 10 (September 2025): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 10, September 2025.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    1100+ comments

    prEN 18228risk management

    1300+ comments

    prEN 18229trustworthiness

    split in two

    prEN 18282cybersecurity

    enquiry soon

    prEN 18283bias management

    drafting

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    version 4.0

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 10, September 2025.

    AI Act timeline

    You are here · 2025-09-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · in force

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026 · next

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    10 months to general application, including article 50 transparency duties

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. As in the previous issue, it reminds readers that all ongoing projects are confidential, that details can be requested from national standards bodies, and that every European standard goes through public enquiry before adoption.

    News from the European Union

    General-purpose AI rules apply. The AI Act's obligations for providers of general-purpose AI models have applied since 2 August 2025, including transparency and copyright requirements. Models already on the market before that date have until 2 August 2027 to comply, and providers of models with systemic risk, such as risks to fundamental rights, to safety, or of loss of control, face additional obligations. The Commission published guidelines on who must comply and on the scope of the obligations. Under these guidelines, models trained with more than 10^23 FLOP that can generate language are indicatively treated as general-purpose AI models. The Commission also published a template for the public summary of training data.

    GPAI Code of Practice. The Code was published on 10 July 2025. Developed by independent experts through a multi-stakeholder process, it is a voluntary tool covering safety, transparency and copyright, and the Commission and the AI Board have confirmed it as an adequate means for providers to demonstrate compliance. Major model providers had begun to sign it, gaining greater legal certainty and lower administrative burden than proving compliance by other means.

    Transparency obligations. The Commission opened a consultation, running until 2 October 2025, to prepare guidelines and a Code of Practice on transparent AI systems. These will help providers and deployers detect and label AI-generated or manipulated content, and meet the obligation to inform people when they interact with an AI system, when they are exposed to emotion recognition or biometric categorisation, and when content has been generated or manipulated by AI. A parallel call invited stakeholders to take part in drafting the Code.

    High-risk AI. A public consultation from 6 June to 18 July 2025 collected practical examples and questions to inform the Commission's forthcoming guidelines on classifying high-risk AI systems, on the related requirements and obligations, and on responsibilities along the AI value chain. Results were not yet available when the newsletter went out.

    Advisory Forum. In July the Commission opened applications, until 14 September, for the AI Act Advisory Forum. The Forum will give the Commission independent technical advice on implementation, including standardisation, and will complement the scientific panel, which advises the AI Office and, on request, national market surveillance authorities on general-purpose AI. CEN, CENELEC and ETSI will be members.

    Standardisation policy. On 25 July, the High-Level Forum on European Standardisation endorsed its recommendation for the 2026 Annual Union Work Programme. AI standardisation features prominently, covering the development, evaluation and governance of AI systems, general-purpose AI, sustainable AI and alignment with the AI Act, alongside cybersecurity, digital trust and data interoperability. For the first time, the recommendation was also published in the Commission's notification system. On 23 June, the Commission published its evaluation of Regulation (EU) No 1025/2012 with the supporting study, concluding an 18-month process, and opened a call for evidence for the impact assessment of a revision then expected in mid-2026.

    CEN-CENELEC JTC 21

    Plenary. The 13th plenary was announced for Copenhagen, 18–21 November 2025.

    Commission feedback. In a reply dated 19 June to JTC 21's six-monthly progress report, the Commission stressed the importance of keeping to the timeline, noted progress on inclusiveness while underlining its continued importance, and emphasised the interplay between standards. The newsletter pointed out that Commission documents can be requested through its access-to-documents portal.

    Functional safety. JTC 21 agreed to take part in the parallel development, under ISO lead, of ISO/IEC 22440 on functional safety and AI systems, in three parts: requirements, guidance, and application examples.

    WG1 (strategic advisory) proposed a new technical report, Overview and architecture of standards in support of the AI Act. Its purpose is to prepare organisations for the harmonised standards and to mitigate possible publication delays, by explaining what is coming, providing basic terminology, concepts and materials, and describing the nature of the requirements (design, development, monitoring, documentation). It will gather in one document the elements already agreed across the JTC 21 projects. Separately, the proposal to adopt ISO/IEC 42001 directly as a European standard was approved with 21 votes in favour, some with comments, none against and 5 abstentions.

    WG2 (operational aspects) was working on three standards. The conformity assessment framework, combining guidance and requirements, reached internal draft version 4.0 in August. The risk management standard, setting requirements and practical guidance for addressing and mitigating risk across the AI lifecycle, received more than 1,300 comments on its committee draft, with resolution starting in September. The risk catalogue, originally planned as an annex, will become a separate document. The quality management system standard for providers of high-risk AI systems received more than 1,100 comments on its committee draft, and resolution meetings were under way.

    WG3 (engineering aspects). Work on quality and governance of datasets was well advanced, with recent contributions on data modification plans, data poisoning and data versioning. The managing bias standard was also well advanced, with a structure covering bias management requirements, how bias manifests in AI systems, examples, and bias assessment. Joint work under ISO lead continued on ISO/IEC 23282 (evaluation methods for natural language processing systems, measuring the quality of results to assess functional suitability) and on ISO/IEC 24940 (terms and definitions for computer vision). ISO/IEC 24970 on AI system logging, also under ISO lead, was at a fairly advanced stage, with comment resolution since August and a slightly narrower scope: describing common capabilities and setting requirements for logging events of AI systems.

    WG4 (foundational and societal aspects). Because its topics were progressing at different speeds, WG4 decided to split the trustworthiness framework into two parts. The more advanced part covers human oversight (Article 14), transparency (Article 13) and logging (Article 12, linked with the WG3 work), and further contributions, including from civil society, were still expected. The less advanced part covers accuracy and robustness (Article 15), meaning an AI system's ability to maintain performance under its operational conditions. The framework depends heavily on characteristics developed in WG2, WG3 and WG5.

    WG4's other projects are outside the standardisation request but relevant to civil society because of their ethical dimension, and their schedules will give way to the request. The European standard on competence requirements was being retitled from "AI ethicists professionals" to "professional AI ethicists". A technical specification on environmental impact guidelines and metrics was at work item activation ballot until 19 September. A specification on tools for handling ethical issues was being outlined before activation, and one on upskilling organisations was being re-evaluated to take account of AI literacy and professionalism, together with CEN TC 428. Technical reports on fundamental rights impact assessment and on risk management in critical digital infrastructure were being prepared for possible approval as preliminary work items at a future plenary.

    WG5 (cybersecurity). The cybersecurity specifications for AI systems were to be sent to public enquiry shortly. Because cybersecurity cuts across the programme, WG5 held dedicated meetings with the other working groups, especially on risk management and quality management, covering harmonised terminology, hazardous situations and how to integrate cybersecurity risk into the general risk management standard. A draft on this was available, with a ballot expected within weeks.

    Inclusiveness survey. JTC 21 surveyed its members in the second quarter of 2025 on origin, gender, represented interest, skills and time spent. Results were published internally in August, with a synthesis promised for the next issue.

    New liaison. AIRISE, a consortium of 14 organisations from 11 countries promoting AI in manufacturing, was granted liaison status. It focuses on helping SMEs adopt AI, through scientific support, shop-floor deployment and training, with the aim of reducing waste and carbon footprint while keeping production resilient.

    ISO/IEC JTC 1/SC 42

    The next SC 42 plenary was set for Sydney, 20–24 October 2025. Following a Canadian contribution at the April plenary on lowering barriers to participation, SC 42 ran a survey until 5 September on how national bodies onboard and retain experts, with proposals to follow.

    ISO/IEC 42006:2025 on requirements for certification bodies had been published, and ISO/IEC 12792 on the transparency taxonomy was being published and was expected to influence JTC 21's work.

    Human oversight. ISO/IEC 18966 (preliminary work item) will set requirements and guidance for managing and governing human oversight of AI systems. The committee draft of ISO/IEC 42105, guidance on human control and monitoring that extends ISO/IEC TS 8200 on controllability, was approved with comments.

    Societal and ethical concerns. A committee draft of ISO/IEC 22443 was in preparation, giving organisations guidance on identifying and addressing societal concerns and ethical considerations across the AI lifecycle.

    Beneficial AI. The draft technical report ISO/IEC TR 21221 on beneficial AI systems was approved with comments. It describes functional, economic, environmental, social, societal, cultural, intellectual and personal benefits as perceived by stakeholders, with illustrative use cases.

    Foundational standards. Amendments to ISO/IEC 22989 and ISO/IEC 23053 addressing generative AI were at ballot until November. A new edition of ISO/IEC TR 24030 (use cases) was in comment resolution, and a revision of ISO/IEC 25059 (quality models for AI systems) was at final approval.

    Nudging and human-machine teaming. The committee draft of ISO/IEC 25029 on AI-enhanced nudging, including requirements for designing responsible nudging mechanisms, had gone to ballot. ISO/IEC 25589 (concepts for human-machine teaming) was in drafting, and ISO/IEC 25880 on organisational implementation of human-machine teaming was at a preliminary stage.

    Incident reporting. A new project, ISO/IEC 25870, was approved to establish a common framework for reporting AI incidents across jurisdictions and sectors.

    Implementing ISO/IEC 42001. A committee draft of ISO/IEC 42003 was in progress, giving guidance for organisations of any size, including SMEs, on implementing ISO/IEC 42001, including competencies for AI management system professionals.

    Trustworthiness fact labels. A new project, ISO/IEC 42117, will set principles and general requirements for AI trustworthiness statements and the programmes that produce them, including self-declared claims and trustworthiness fact labels.

    Fora

    The recording of the June online bootcamp on harmonised standards, covering the vademecum on European standardisation, drafting principles, normative references and Annex ZA, is available on YouTube; the slides are restricted to CEN-CENELEC members. ANEC announced a webinar on AI standards and fundamental rights for 3 October 2025, including a practical checklist for assessing whether an AI product respects fundamental rights and a group exercise, aimed at civil society, academia and public institutions. For World Standards Day (14 October), ISO/IEC JTC 1 planned virtual workshops on 15 and 16 October on privacy, AI and consumer protection. The ITU-led AI for Good Global Summit took place in Geneva on 8–11 July 2025, with the next edition set for 7–10 July 2026.

    National outreach included an event on AI ethics standards planned by the Malta Digital Innovation Authority for the last quarter of 2025. The Swedish Institute for Standards planned a presentation on ethical AI at the E-Government Days in November and a training course on AI management systems for spring 2026.

    Nice to know, useful to read

    ISO/IEC and CEN-CENELEC deliverables are now prepared exclusively on the Online Standards Development (OSD) platform, with training offered for leaders, authors and voters, orientation sessions, self-paced e-learning, and a webinar on OSD release 5.0 on 13 October 2025. A gender-responsive standardisation toolkit combines the CEN-CENELEC brochure with an ISO/IEC assessment form for checking whether gender differences may affect a new or revised standard.

    The AIQI Consortium, an international platform of quality infrastructure organisations, released a free self-paced course on ISO/IEC 42001 and was surveying AI assurance in supply chains. The issue also pointed to the ISO and UNDP guidelines, published in September 2024, on how organisations can manage and strengthen their contributions to the UN Sustainable Development Goals.

    My reading

    The comment counts are the story of this issue: more than 1,300 on the risk management draft and more than 1,100 on the quality management draft, after more than 2,000 on the trustworthiness framework earlier in the year. They reflect real engagement, but also how much of the substance was still contested at committee draft stage.

    Three decisions point towards managing delay rather than avoiding it. WG1's overview report is explicitly designed to help organisations prepare in case the harmonised standards arrive late. Moving the risk catalogue out of the risk management standard slims the normative core that must pass the Commission's assessment. And splitting the trustworthiness framework lets the more mature parts move ahead of accuracy and robustness.

    The approval of ISO/IEC 42001 as a European standard, without a single vote against, confirms the two-track picture noted in the previous issue. Europe will have one management system standard for general AI governance and another written specifically for Article 17. Within weeks of this issue, CEN-CENELEC adopted exceptional acceleration measures and the Commission proposed the Digital Omnibus. The Commission's June letter stressing the timeline reads, in hindsight, as the last warning before both.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    September 2025Where it stands now
    QMS committee draft with more than 1,100 commentsThe draft went to public enquiry from 30 October 2025 to January 2026, and EN 18286 was approved on 12 July 2026. Citation in the Official Journal is outstanding.
    Risk management committee draft with more than 1,300 commentsprEN 18228 was at public Enquiry as of June 2026.
    Cybersecurity specifications "shortly" to public enquiryprEN 18282 was at public Enquiry as of June 2026.
    Trustworthiness framework split into two partsThe split did not stop at two parts. The series now has five parts: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Conformity assessment framework at internal draft 4.0prEN 18285 (drafting).
    Datasets and bias standards well advancedprEN 18284 and prEN 18283 (both drafting). A working-draft consultation on prEN 18283 closed on 30 April 2026.
    Commission urging adherence to the timelineOn 23 October 2025, CEN-CENELEC adopted exceptional measures aiming for the prioritised deliverables to be available by Q4 2026, including a faster route to publication after a positive enquiry. On 19 November 2025, the Commission proposed the Digital Omnibus on AI, adopted as Regulation (EU) 2026/1744, which moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    ISO/IEC 42001 approved for adoption as a European standardThe Commission found ISO/IEC 42001 not aligned with the quality management system required by Article 17. EN 18286 is the dedicated route to Article 17.
    Consultation on transparency guidelines and a Code of PracticeArticle 50 obligations were not postponed by the Omnibus. Article 50(2) applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026.
    High-Level Forum recommendation on the 2026 work programmeThe 2026 Annual Union Work Programme for European standardisation was published in the Official Journal in March 2026.
    Revision of Regulation 1025/2012 "expected in mid-2026"The date has slipped. According to press reports, the Commission is expected to present a proposal in October 2026, including common specifications as a fallback and a tighter definition of "harmonised standard".
    ISO/IEC 12792 being publishedPublished as ISO/IEC 12792:2025.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    Edition 9 · June 2025

    Edition 9 (June 2025): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 9, June 2025.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    ballot

    prEN 18228risk management

    risk catalogue

    prEN 18229trustworthiness

    split decided

    prEN 18282cybersecurity

    drafting

    prEN 18283bias management

    drafting

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 9, June 2025.

    AI Act timeline

    You are here · 2025-06-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · next

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    less than a month to gpai model obligations, governance and penalties apply

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    From draft to legal effect
    1. A working group writes a first draft against the Commission's request.

    2. National members comment. Thousands of comments are normal at this stage.

    3. Before enquiry, the Commission assesses whether the draft is eligible to become a harmonised standard (HAS assessment).

    4. National standards bodies comment and vote. The draft can fail on the number of countries in favour or on the weighted population in favour.

    5. After a positive enquiry, the draft may be published without a formal vote (CEN-CENELEC Technical Board, October 2025). After a negative enquiry, comments are resolved and a formal vote is held, as happened with EN 18286.

    6. 06Published as ENnot yet binding

      The standard exists and can be bought and applied — but it carries no legal effect yet.

    7. The Commission publishes the reference of the standard in the Official Journal.

    8. Only now does following the standard show compliance with the AI Act requirement it covers.

    A finished standard and a standard that gives presumption of conformity are two different things. So far, most of the delay has come before publication: drafts reached enquiry months later than planned, and every enquiry vote on a core draft has been negative. EN 18286 is the first to be published; its citation in the Official Journal is still pending.

    steps 01–06 are technical work · steps 07–08 are what makes it law-relevant

    How a European standard travels from draft to legal effect.

    Three tracks, one legal difference

    Europe

    CEN-CENELEC JTC 21

    Harmonised standards written on request from the European Commission.

    • prEN 18228 risk
    • prEN 18286 quality
    • prEN 18229 trustworthiness

    Yes — once cited in the Official Journal

    International

    ISO/IEC JTC 1/SC 42

    Global AI standards, sometimes adopted in Europe, sometimes deliberately not.

    • ISO/IEC 42001
    • ISO/IEC TS 12791
    • ISO/IEC 24029

    No — may be referenced, but does not carry presumption

    Professional body

    IEEE

    Engineering practice standards developed outside the EU framework.

    • Ethically aligned design series
    • Transparency and privacy standards

    No — useful practice, no legal effect under the AI Act

    The turning point

    The Commission found ISO/IEC 42001 not aligned with the quality management system required by Article 17. EN 18286 became the dedicated European route instead — which is why the two tracks are not interchangeable.

    only the European track can give presumption of conformity

    Three standardisation tracks, and why only one of them carries presumption of conformity.

    Where the disagreement sits

    Trustworthiness, first draft (comments reported February 2025) prEN 18229

    over 2,000 comments

    Restructured afterwards

    Risk management, committee draft prEN 18228

    1,300 comments

    Moved on to enquiry

    Quality management, committee draft prEN 18286

    1,100 comments

    Moved on to enquiry

    Quality management, public enquiry, January 2026 EN 18286

    1,288 comments

    Failed on both country count and weighted population

    Logging (prEN 18229-1), public enquiry, August 2026 prEN 18229-1

    443 comments

    Rejected on weighted population

    number of comments received on each draft · red marks a vote that did not pass

    How much friction each draft met during comment rounds and voting.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. This issue opens with a reminder that all ongoing standardisation projects are confidential. Readers who want details on a specific standard should contact their national standards body, and every European standard goes through a public enquiry before final adoption.

    News from the European Union

    A standardisation request on a trusted data framework. The Commission was preparing a request to CEN and CENELEC for a trusted European data framework. It is expected to cover trusted data transactions, implementation of data catalogues, an implementation framework for semantic assets, quality assessment of internal data governance processes, and maturity assessment of common European data spaces. The request is separate from the AI request handled by JTC 21, but there are clear overlaps and potential synergies. Civil society representatives hoped inclusiveness would be written into it as a core requirement.

    Consultations and reports. In May 2025 the Commission consulted on the use of data for developing AI, on simplifying data rules and on international data flows, as input to its forthcoming Data Union Strategy. A report by the Centre for European Policy Studies (CEPS) for the AI Office analysed stakeholder feedback from the consultations on the AI system definition and prohibited practices. In April, the Commission had run a targeted consultation to inform guidelines clarifying the key concepts in the AI Act's provisions on general-purpose AI models. The AI Office also announced a call for tenders for technical assistance in monitoring compliance, focused on assessing risks from general-purpose AI models at Union level.

    A new strategic advisory group. In May 2025, CEN and CENELEC set up a Strategic Advisory Group on standardisation topics linked to EU legislation. It will identify cross-cutting requirements where CEN and CENELEC can provide strategic input and recommend how to address them more systematically, to make the system more flexible and responsive. AI is one of many areas it may cover.

    CEN-CENELEC JTC 21: the Stavanger plenary

    JTC 21 held its 11th plenary in Stavanger, Norway, on 12–15 May 2025, in hybrid format, with more than 160 participants. Alongside national standards bodies, it was attended by observers from Canada and Japan, the CEN-CENELEC Management Centre, professional and civil society organisations, and the Commission, which again stressed the urgency of delivering the standards on time.

    Published documents. The plenary reviewed the eleven AI documents CEN and CENELEC had published so far, most of them adoptions of ISO/IEC work: CEN/CLC/TR 17894:2024 on conformity assessment; EN ISO/IEC 22989:2023 on concepts and terminology; EN ISO/IEC 23053:2023 on the framework for machine learning systems; CEN/CLC/TR 18115:2024 on data governance and quality in the European context; CEN/CLC/TR 18145:2025 on environmentally sustainable AI; CEN/CLC ISO/IEC/TS 12791 on unwanted bias in classification and regression; EN ISO/IEC 25059:2024, the quality model for AI systems; EN ISO/IEC 23894:2024 on risk management guidance; CEN/CLC ISO/IEC/TR 24027:2023 on bias in AI systems and AI-aided decision making; CEN/CLC ISO/IEC/TR 24029-1:2023 on robustness of neural networks; and EN ISO/IEC 8183:2024 on the data life cycle framework.

    In addition, parts 1 to 4 of ISO/IEC 5259 on data quality for analytics and machine learning had received positive votes and were expected to be published shortly as European standards.

    WG1 (strategic advisory) updated the "architecture of standards" document describing the response to the Commission's request, with proposals for consistency across working groups on terminology, testing methods, interplay matrices and high-level requirements. It was also preparing a cross-cutting introductory document for future users of the harmonised standards, drawing on that architecture, stakeholder terminology and the introductory clauses of each standard. A survey of JTC 21 participants collected data on country, gender, represented interest and prior experience, with results due in June. WG1 discussed cooperation with ISO on ISO/IEC TS 22443 (societal concerns and ethical considerations). It was also agreed to ballot the direct adoption of ISO/IEC 42001 as a European standard.

    WG2 (operational aspects) reported good progress on the quality management system and risk management standards, whose committee drafts had both gone to ballot. Work was now concentrating on the interplay between standards and on the risk catalogue. The AI conformity assessment framework was expected to go to ballot by September 2025.

    WG3 (engineering aspects) had several committee draft ballots under way or planned: logging (in progress), natural language processing (June/July 2025), datasets and bias (August 2025), with a working draft on computer vision expected in September 2025. A committee draft of the taxonomy of AI system methods and capabilities, developed in parallel under ISO lead, was expected in November 2025. The plenary also decided to start parallel development, under ISO lead, of ISO/IEC 22440 on functional safety and AI systems.

    WG4 (foundational and societal aspects) had published the technical report on environmentally sustainable AI earlier in the year. The AI trustworthiness framework, a key deliverable under the request, was at committee draft stage, and WG4 was to decide by the end of June whether to split it into several parts, given the different pace of progress on its topics. Work items had been approved on impact assessment in the context of EU fundamental rights and on competence requirements for AI ethics professionals, the latter probably in cooperation with CEN-CENELEC TC 428 on ICT professionalism. Preliminary work items covered environmental impact metrics, upskilling on AI ethics, tools for handling ethical issues, and risk management in critical digital infrastructure. A possible new project on AI-intervention labelling, a label indicating that an application is AI-based, was under consideration.

    WG5 (cybersecurity) was in full comment resolution on cybersecurity specifications for AI systems, with public enquiry expected in July 2025. Because cybersecurity cuts across all the standards, WG5 held regular coordination meetings with the other working groups and worked with ETSI's Securing Artificial Intelligence committee (including its baseline cybersecurity requirements for AI models and systems) and with CEN-CENELEC JTC 13.

    Liaisons and partners. The number of external organisations involved with JTC 21 was growing. At the plenary, the partner organisations ANEC, ETUC and Small Business Standards reported on their work, as did the liaison organisations 5Rights Foundation and NoLeFa, the Commission-designated pilot preparing a future Union testing facility to support market surveillance under the AI Act. OWASP and the Big Data Value Association had sent reports that were not presented.

    ISO/IEC JTC 1/SC 42

    Since the New Delhi plenary covered in the previous issue, several SC 42 documents had moved forward. ISO/IEC 42005 on AI system impact assessment was published in May 2025. ISO/IEC 42006 on requirements for certification bodies was approved, with publication expected shortly. ISO/IEC 12792 (transparency taxonomy) was at final ballot after comment resolution. The draft technical specification ISO/IEC 6254 on explainability and interpretability was approved with comments, and the draft technical report ISO/IEC 20226 on environmental sustainability was approved for publication with corrections. The amendments to ISO/IEC 22989 and ISO/IEC 23053 on generative AI were in final review, with final ballot expected shortly.

    The committee draft consultation on ISO/IEC TS 22443 had closed, with cooperation with JTC 21 under consideration. Comments on ISO/IEC 42105 (human oversight) were being resolved in meetings planned for June and July, and ISO/IEC TR 42106 on differentiated benchmarking was ready for final ballot. Two new projects were formally approved: a machine learning model description framework (ISO/IEC 25623) and SME-oriented implementation guidance for ISO/IEC 42001 (ISO/IEC 25651).

    Fora

    Following the 4 February webinar, the UK AI Standards Hub and Task Group Inclusiveness held an invitation-only online workshop on 22 April. International civil society participants heard the project editors of the European risk management standard present its structure and were able to give their views.

    On 9 April, ANEC held a webinar on how AI standards can address risks to fundamental rights, looking at how the AI Act's risk-based approach relies on harmonised standards. Speakers from the EU Fundamental Rights Agency and ANEC discussed how to translate principles such as privacy and non-discrimination into technical requirements, and stressed the need for continuous risk assessment and for standards flexible enough to keep pace with AI.

    The CEN-CENELEC Management Centre scheduled an online "harmonisation bootcamp" for JTC 21 experts on 19 June 2025, covering the vademecum on European standardisation, drafting principles, normative references in harmonised standards, Annex ZA, and the common checklist.

    Nice to know, useful to read

    The JTC 21 website now includes a learning centre with links, webinars and training on standardisation. The ETUC Standardisation Committee marked ten years of work since 2015 to strengthen trade union participation in standardisation. Under its STAND project, ETUC published the handbook Standards at the Workplace and a video on trade unions and standardisation.

    ANEC's AI Taskforce, funded by the European AI & Society Fund, was set up in early February with nine consumer professionals from eight countries (Austria, Bulgaria, Cyprus, Germany, Greece, Italy, the Netherlands and Spain). It provides training so that members can take part in national mirror committees of JTC 21, and its members will join ANEC's AI experts in drafting comments on AI standards for use at national level.

    The Nordic standards bodies, Danish Standards, SIS (Sweden), Standard Norge, SFS (Finland) and Staðlaráð Íslands, produced a two-hour webinar, Decoding the AI Act: European Standards and the Future of AI Regulation, with a shorter PDF presentation. Speakers were Tatjana Evas (European Commission) on the status and timeline of the Act; Jesper Løffler Nielsen (Fokus Advokater) on the surrounding legal landscape; Ana Paula Gonzalez Torres (Aalto University and the Finnish Standards Association) on AI standards; Anders Kofod-Petersen (OptikosPrime and NTNU) on the SME perspective; and Luis Martinez (ASSA ABLOY) on compliance from a product perspective.

    My reading

    Stavanger captured the pipeline at its most optimistic. The plan was a cascade of ballots over summer and autumn 2025: logging under way, natural language processing in June or July, datasets and bias in August, conformity assessment in September, and cybersecurity at public enquiry in July. Very little of that timetable held. By October 2025, CEN-CENELEC needed exceptional measures, and the quality management standard became the first to reach public enquiry only at the end of that month.

    Two decisions deserve a note. WG4's pending choice on whether to split the trustworthiness framework explains the multi-part prEN 18229 series that exists today. And the decision to ballot ISO/IEC 42001 for adoption as a European standard, while a separate quality management standard was being written for the AI Act, means Europe will have two management system standards with different legal roles: one as a general AI management system, the other as the route to Article 17 compliance. Users will need to be clear about which one carries which function.

    The harmonisation bootcamp is also worth noticing. Its agenda (drafting principles, normative references, Annex ZA, the common checklist) lists the formal hurdles a standard must clear before the Commission will cite it. Those hurdles, more than technical content, are often what decides whether a standard gives presumption of conformity.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    June 2025Where it stands now
    Committee drafts on QMS and risk management at ballotThe QMS draft went to public enquiry from 30 October 2025, the first JTC 21 AI Act standard to do so, and EN 18286 was approved on 12 July 2026. Citation in the Official Journal is outstanding. prEN 18228 (risk management) was at public Enquiry as of June 2026.
    Cybersecurity specifications expected at public enquiry in July 2025That did not happen on schedule. prEN 18282 was at public Enquiry as of June 2026.
    Datasets and bias ballots planned for August 2025prEN 18284 and prEN 18283 were still in drafting as of June 2026. A working-draft consultation on prEN 18283 closed on 30 April 2026.
    Conformity assessment framework to ballot by September 2025prEN 18285 was still in drafting as of June 2026.
    WG4 to decide whether to split the trustworthiness frameworkThe framework was split, first into two parts in autumn 2025 and later into a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Commission urging timely deliveryIn October 2025, CEN-CENELEC adopted exceptional measures aiming for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    Ballot on adopting ISO/IEC 42001 as a European standardThe Commission found ISO/IEC 42001 not aligned with the quality management system required by Article 17. EN 18286 is the dedicated route to Article 17.
    Consultation on guidelines for general-purpose AI modelsThe Commission published guidelines for providers of general-purpose AI models and the final GPAI Code of Practice in July 2025. GPAI obligations have applied since 2 August 2025.
    Consultation for the Data Union StrategyThe Data Union Strategy was presented in November 2025, alongside the Digital Omnibus proposals.
    ISO/IEC 42006 approved; 12792 at final ballotPublished as ISO/IEC 42006:2025 and ISO/IEC 12792:2025.
    New CEN-CENELEC strategic advisory group on legislation-linked standardisationA revision of Regulation (EU) No 1025/2012 is in the Commission's 2026 work programme, with a proposal expected in October 2026 according to press reports.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    Edition 8 · April 2025

    Edition 8 (April 2025): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 8, April 2025.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    Commission feedback

    prEN 18228risk management

    Commission feedback

    prEN 18229trustworthiness

    Commission feedback

    prEN 18282cybersecurity

    Commission feedback

    prEN 18283bias management

    Commission feedback

    prEN 18284datasets

    Commission feedback

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 8, April 2025.

    AI Act timeline

    You are here · 2025-04-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · next

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    3 months to gpai model obligations, governance and penalties apply

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    About this issue

    The newsletter was now distributed to several hundred people and published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website. ETUC continues to provide the secretariat.

    News from the European Union

    Annual Union Work Programme 2025. On 20 March 2025, the Commission published the 2025 work programme for European standardisation, C(2025) 1654, with 78 actions. Its policy priorities include bio-based and wood-derived products, critical raw materials for electric vehicle batteries, qualification of materials for small modular reactors, the EU Digital Identity Wallet, the EU Trusted Data Framework, and quantum technology including post-quantum cryptography. The digital actions also cover cybersecurity requirements for products with digital elements, interoperability of data processing services, virtual and augmented reality, intermediary digital services, and data dictionaries in engineering, alongside continued support for EU AI policy through JTC 21.

    AI Act governance. The AI Board held its third meeting on 24 March. The AI Office updated it on the guidelines on the AI system definition and prohibited practices, the third draft of the General-Purpose AI Code of Practice, and the call for the scientific panel. The Commission had adopted the implementing act establishing that panel on 11 March. The panel will advise on governance and enforcement and can alert the AI Office to risks posed by general-purpose AI models, and a call for expressions of interest was to follow.

    GPAI Code of Practice. The third draft was published on 11 March, marking the final drafting stage before the Code was finalised on the basis of stakeholder feedback. It set out two commitments on transparency and copyright for all providers of general-purpose AI models, and sixteen commitments on safety and security for providers of models with systemic risk, each supported by practical implementation measures.

    Funding. The EUACT-AI project opened a call, closing 27 March, to fund experts taking part in JTC 21, covering meeting participation, drafting and reporting.

    CEN-CENELEC JTC 21

    Plenary and timeline. The 11th plenary was announced for Stavanger, Norway, 12–15 May 2025, in hybrid format. The newsletter noted that the AI Act's main obligations were due to apply by August 2026, that JTC 21 was monitoring each standard's timeline closely, and that delays should nevertheless be expected. Draft standards were expected to enter public enquiry one after another over the summer.

    Task Group Inclusiveness. Cezara Popovici (ANEC) was appointed co-chair, alongside Philippe Saint-Aubin (ETUC).

    Working practices. In March, JTC 21 published two internal documents, available on request from the secretariat: best practice for working groups, aimed at improving the dynamics of large meetings, and a health and safety policy paper with advice on managing stress caused by heavy workloads.

    Commission feedback on the first drafts. The Commission had provided preliminary assessments of five of the six drafts JTC 21 submitted in February: the trustworthiness framework, risk management, cybersecurity specifications, quality and governance of datasets, the quality management system, and managing bias. The feedback had been shared with the working groups, which were integrating it into the drafts.

    Confidentiality. The newsletter reminded readers that draft standards are made public only at the enquiry stage, and that those interested in a particular draft should contact their national standards body. Most drafts were in comment resolution, with several expected to reach public enquiry within weeks or months.

    WG2 (operational aspects) was working on conformity assessment, quality management and risk management, all considered essential for the standardisation request, with committee draft ballots expected soon.

    WG3 (engineering aspects) was working on datasets, bias, computer vision, natural language processing, robustness and logging, the last with a committee draft ballot under way. A committee draft of the taxonomy of AI system methods and capabilities, developed with SC 42, was expected in July or August.

    WG4 (foundational and societal aspects) published CEN/CLC/TR 18145:2025 on environmentally sustainable AI in February. Its main task remained the trustworthiness framework, whose committee draft was still in comment resolution. Projects at earlier stages covered competence requirements for AI ethics professionals, tools for handling ethical aspects, upskilling on AI ethics, guidelines and metrics for the environmental impact of AI, fundamental rights considerations for AI providers, and risk management for critical infrastructure. A new preliminary work item on AI intervention labelling was proposed. It would link graphical symbols to the relevant AI concepts, to help people distinguish AI-generated, human-produced and hybrid content.

    WG5 (cybersecurity) continued work on cybersecurity specifications for AI systems, held a joint meeting with WG2 on where and how cybersecurity risks should be addressed, and continued joint work with SC 27 on AI security threats and mitigation.

    ISO/IEC JTC 1/SC 42

    The SC 42 plenary took place in New Delhi, 31 March to 4 April 2025. Given the cross-cutting nature of AI, SC 42 maintains regular contact with IEC, the United Nations, the OECD and the World Economic Forum, and with committees working on cinematography, particles, health informatics and financial services. The newsletter focused on documents of interest to civil society.

    WG1 (foundational standards). ISO/IEC 42005 (impact assessment) and ISO/IEC 42006 (requirements for certification bodies) had reached final draft stage, with publication possible later in 2025. ISO/IEC 24970 on AI system logging, developed jointly with JTC 21 under ISO lead, was out for committee draft consultation. Work continued on ISO/IEC 42102 (taxonomy of AI methods and capabilities), on the SME handbook for ISO/IEC 42001, and on amendments to ISO/IEC 22989 and ISO/IEC 23053 to address generative AI, now in committee draft comment resolution. Following contacts with the OECD, WG1 opened a new project on a common reporting framework for AI incidents.

    WG2 (data). Parts 1 to 5 of ISO/IEC 5259 on data quality had been published. Current work covered a visualisation framework for data quality (ISO/IEC TR 5259-6), output data quality for generative AI applications (ISO/IEC 25590), and an overview of synthetic data in AI systems (ISO/IEC TR 42103).

    WG3 (trustworthiness). ISO/IEC 12792 (transparency taxonomy) was ready for publication, and the committee draft of ISO/IEC 6254 on explainability and interpretability was under ballot. Work continued on oversight of AI systems (ISO/IEC 18966), societal and ethical concerns (ISO/IEC 22443), robustness of neural networks (ISO/IEC 24029-3), AI nudging mechanisms (ISO/IEC 25029), domain engineering terminology (ISO/IEC 25566), risks in generative AI (ISO/IEC 25568), reliability assessment (ISO/IEC 25570), a template for documenting ethical issues (ISO/IEC 25571), guidance on human oversight (ISO/IEC 42105), and differentiated benchmarking of AI quality characteristics (ISO/IEC 42106). A new project on trustworthiness fact labels (ISO/IEC 42117) was being launched.

    WG4 (use cases and applications). The second edition of ISO/IEC TR 24030 on AI use cases, published in 2024, includes 81 use cases in operation out of a collection of 187. Work continued on beneficial AI systems (ISO/IEC TR 21221, committee draft submitted), environmental sustainability of AI systems (ISO/IEC TR 20226, draft technical report ballot about to start), human-machine teaming use cases (ISO/IEC TR 42109) and a framework for human-machine teaming (ISO/IEC 25589). A new project was proposed on graphical symbols to distinguish AI-generated, human-produced and hybrid content, mirroring the JTC 21 proposal.

    Joint advisory groups. SC 42 created a joint advisory group with SC 39 on AI and sustainability, to develop a roadmap and recommend new projects, and another with ISO's conformity assessment committee (CASCO) on ISO/IEC 42007, a framework for developing conformity assessment schemes for AI systems.

    Fora

    Workstream 12 on AI of the High-Level Forum on European Standardisation met on 4 March to review outreach. SIS (Sweden), the Malta Digital Innovation Authority, BSI, Danish Standards, ANEC and ETUC all had events planned for 2025.

    The webinar Implementing the EU AI Act through Standards on 4 February, organised by the UK AI Standards Hub and Task Group Inclusiveness, drew more than 350 participants and focused on the European risk management standard. It was followed by a workshop on 22 April to gather civil society input on risk management. The AI Standards Hub Global Summit on 17–18 March discussed the role of standards in AI governance and how to make international AI standardisation more inclusive.

    Nice to know, useful to read

    The Commission updated its model contractual clauses for public procurement of AI. The update includes a full version for high-risk AI aligned with the AI Act, a customisable light version for other AI systems, and a commentary on how to use and adapt the clauses. The HSbooster.eu Standardisation Training Academy offers courses across many domains, including two on conformity assessment: its role in quality infrastructure, and conformity assessment schemes and systems.

    ANEC published a factsheet on the fundamentals of the upcoming trustworthiness standard. With funding from the European AI & Society Fund, it set up a pilot taskforce of consumer and civil society representatives, starting at the end of April and running until the end of 2025, to provide training and support national-level engagement in AI standardisation. On 9 April, ANEC held a webinar on human rights in AI standardisation with speakers from the EU Fundamental Rights Agency, attended by 78 participants.

    In March, ETUC published the handbook Standards at the workplace: What they are and why you need to know about them, explaining what standards are, how they affect working life and how trade unions can use them, together with a video on trade unions and standardisation.

    My reading

    Two items in this issue sit in some tension with each other. The Commission was already reviewing drafts and sending preliminary assessments back to the working groups before public enquiry. At the same time, the newsletter reminded readers that drafts are confidential until enquiry. The legal assessment of the standards therefore began at a stage where civil society could see neither the text nor the feedback. For a task group whose purpose is inclusiveness, that is a structural limit worth stating plainly.

    The publication of a health and safety paper on workload stress is also telling. It suggests a committee working at the edge of its capacity, only months before the timeline it was being asked to meet.

    On the content side, both JTC 21 and SC 42 opened work on symbols for distinguishing AI-generated, human-produced and hybrid content, and SC 42 started a project with the OECD on a common reporting framework for AI incidents. These connect directly to the transparency obligations and incident reporting in the AI Act, and they are examples of standards work that will be used well beyond the high-risk category.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    April 2025Where it stands now
    Drafts expected to enter public enquiry over summer 2025That timeline did not hold. The QMS draft entered public enquiry on 30 October 2025. By mid-2026, prEN 18228 (risk management) and prEN 18282 (cybersecurity) were at public Enquiry, prEN 18229-1 (logging) had been through public enquiry, and prEN 18229-3 (human oversight) reached it in July 2026. Most other deliverables were still in drafting.
    AI Act obligations due by August 2026The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Article 50 transparency obligations were not postponed.
    Commission feedback on the first draftsEN 18286 (QMS) was approved on 12 July 2026, the first JTC 21 AI Act standard to reach that point. Citation in the Official Journal is outstanding.
    Trustworthiness framework in comment resolutionDeveloped as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Bias and datasets work in progressprEN 18283 and prEN 18284 (both drafting).
    Conformity assessment work in progressprEN 18285 (drafting).
    Committee delays anticipatedIn October 2025, CEN-CENELEC adopted exceptional measures aiming for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027.
    Third draft of the GPAI Code of PracticeThe final Code was published in July 2025, with chapters on transparency, copyright, and safety and security. GPAI obligations have applied since 2 August 2025.
    ISO/IEC 42005 and 42006 at final draft; 12792 ready for publicationPublished as ISO/IEC 42005:2025, ISO/IEC 42006:2025 and ISO/IEC 12792:2025.
    Labelling of AI-generated content proposed in JTC 21 and SC 42Article 50(2) of the AI Act applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026.
    Cybersecurity requirements for products with digital elements in the work programmeUnder the Cyber Resilience Act, reporting obligations apply from 11 September 2026 and the main obligations from 11 December 2027.
    Work programme priorities under Regulation 1025/2012A revision of Regulation (EU) No 1025/2012 is in the Commission's 2026 work programme, with a proposal expected in October 2026 according to press reports.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    Edition 7 · February 2025

    Edition 7 (February 2025): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 7, February 2025.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    to Commission

    prEN 18228risk management

    to Commission

    prEN 18229trustworthiness

    to Commission

    prEN 18282cybersecurity

    to Commission

    prEN 18283bias management

    to Commission

    prEN 18284datasets

    to Commission

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 7, February 2025.

    AI Act timeline

    You are here · 2025-02-28

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · next

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    5 months to gpai model obligations, governance and penalties apply

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Who carries which duty

    01 · Provider

    Develops or places the system on the market

    • Risk and quality management
    • Technical documentation
    • Conformity assessment, CE marking, registration

    02 · Importer

    Brings a third-country system into the Union

    • Verifies assessment and documentation
    • Checks marking and representative
    • Keeps records, cooperates with authorities

    03 · Distributor

    Makes the system available down the chain

    • Checks marking and accompanying documents
    • Acts on non-conformity it becomes aware of
    • Storage and transport conditions

    04 · Deployer

    Uses the system under its own authority

    • Follows instructions, ensures human oversight
    • Input data relevance, log keeping
    • FRIA where required (Article 27)

    The chain can flip · Article 25

    A deployer, importer or distributor becomes the provider — with every provider duty attached — when it puts its own name or trade mark on a high-risk system, changes its intended purpose, or substantially modifies it.

    Authorised Representative

    Appointed by a third-country provider

    • Holds documentation for ten years
    • Point of contact for authorities

    Operator

    Umbrella term covering every role in the chain

    • Used where a duty applies regardless of role

    duties travel left to right along the chain

    How duties travel along the supply chain, and where a role changes hands.

    Who is actually in the room

    Inclusiveness survey

    146/195

    75% of eligible JTC 21 members and observers answered the spring 2025 survey.

    120+

    Turin plenary

    participants from 21 countries

    150+

    Bath plenary

    participants from 20+ countries

    800+

    ISO/IEC SC 42

    registered experts, 70 national bodies

    350+

    Civil society webinars

    participants at the largest sessions

    Newsletter reach, edition by edition

    70+
    Edition 3
    500+ views
    Edition 5
    250+
    Edition 7
    several hundred
    Edition 8

    figures as reported in the newsletter

    Who takes part, and how far the work reaches.

    About this issue

    The newsletter now reached more than 250 direct recipients, in addition to LinkedIn downloads. Alongside the ETUC page and the LinkedIn group, issues are also linked from the new public JTC 21 website, jtc21.eu. ETUC continues to provide the secretariat.

    In memoriam

    The issue is dedicated to Renaud di Francesco, who died suddenly at the end of 2024. As chair of the JTC 21 WG2 task group responsible for the risk management standard, he was remembered as an effective and collaborative leader who handled difficult discussions with wisdom and humour, looked for workable compromises, and consistently supported inclusiveness in standards development.

    News from the European Union

    The third meeting of the High-Level Forum on European Standardisation took place in Brussels on 29 January 2025, chaired by Stéphane Séjourné. It reviewed the Forum's working groups and the annual Union work programme, and discussed priorities for the rest of the mandate. The Forum also published two reports: a final report on alignment between European and international standards, using the machinery sector as a case study, and recommendations on funding European participation in international standardisation, with attention to EU strategic interests, SMEs and industrial policy.

    The second draft of the General-Purpose AI Code of Practice was published after a consultation involving around 1,000 participants, including Member State representatives and international observers, and working group meetings in November 2024. The Code is meant to help providers of general-purpose AI models show compliance across the model lifecycle, particularly for models released after 2 August 2025, when the relevant obligations apply. A third draft was expected in mid-February 2025.

    The AI Office ran a targeted consultation to prepare guidelines on the definition of an AI system and on prohibited practices, ahead of the prohibitions applying on 2 February 2025. The Commission then published its guidelines on prohibited AI practices. They cover harmful manipulation and deception, harmful exploitation of vulnerabilities, social scoring, individual criminal offence risk assessment and prediction, untargeted scraping to build facial recognition databases, emotion recognition, biometric categorisation, and real-time remote biometric identification.

    CEN-CENELEC JTC 21

    Public website. JTC 21 launched jtc21.eu, explaining what the committee is and does, how to follow project status, how to contact it, what the AI Act is, and who can join.

    First drafts sent to the Commission. A preliminary set of six standards was sent to the Commission as working documents, to report progress on the standardisation request and invite feedback: the AI trustworthiness framework, AI risk management, cybersecurity specifications for AI systems, concepts, measures and requirements for managing bias, quality and governance of datasets, and the quality management system for AI Act regulatory purposes. A second list set out the published European and international standards referenced by these six. Further submissions were expected.

    Annex ZA. All five working groups were giving increasing attention to Annex ZA, the part of each harmonised standard that maps its clauses to the provisions of the AI Act.

    Lifecycle perspective. ANEC had made a series of contributions on how standards should address each phase of the product lifecycle, from inception to retirement, mainly to the WG4 trustworthiness standard but also in WG2 (risk management) and WG3. A new work item, Stakeholder life cycle, was proposed in WG1. It would explain the AI Act's definitions and the supporting harmonised standards to stakeholders worldwide, supporting interoperability between ISO/IEC and CEN-CENELEC standards, and map the roles and responsibilities of different stakeholders across the AI system and product lifecycle, including in risk management and quality. ANEC's AI expert Pete Eisenegger, an early advocate of the lifecycle approach, retired in January 2025, and ANEC was looking for a new expert to represent consumers in AI standardisation.

    Onboarding and liaisons. Task Group Inclusiveness published a welcome package for new working group members in December 2024, listing documents that explain how standards are made and the vocabulary involved. The NoLeFa project, a consortium of two public bodies, three SMEs and a European research network working on testing infrastructure for trustworthy AI and on reducing compliance burdens for SMEs, was granted liaison status.

    WG1 (strategic advisory) prepared CEN-CENELEC's response to the amended standardisation request, stressing the need for sufficient time to prepare the standards. Its Technical Coherence Forum was working on common definitions of AI terms for use across all working groups.

    WG2 (operational aspects) published the technical report CEN/CLC/TR 17894:2024 on conformity assessment in December 2024. It reviews current methods and practices for conformity assessment of AI systems, including tools, assets and acceptability conditions, and covers products, services, processes, management systems and organisations from both horizontal and sector-specific perspectives. Work continued on a full European standard on conformity assessment, on quality management and on risk management, with committee drafts on the last two expected to go to vote shortly.

    WG3 (engineering aspects) noted that CEN/CLC/TR 18115:2024 on data governance and quality addresses inclusivity and accessibility in its subclause 9.5, and that accessibility also appears in ISO/IEC 25059 (quality model for AI systems) and ISO/IEC 5259-2 (data quality measures). Work continued on logging, natural language processing and robustness.

    WG4 (foundational and societal aspects) circulated a first draft of the AI trustworthiness framework, which drew more than 2,000 comments from national standards bodies. The comment list was substantially consolidated, weekly resolution meetings were being held, and an updated draft was due in February. The draft technical report CEN/CLC/TR 18145 on environmentally sustainable AI was accepted, with comments still to resolve, and the working draft on competence requirements for AI ethics professionals was in comment resolution. Other active work covered tools for handling ethical aspects across the AI lifecycle, upskilling on AI ethics, "frugal AI" in liaison with ISO, IEEE, ITU, the OECD and the AI Action Summit, and a document on implementing protections for fundamental rights across the AI lifecycle.

    WG5 (cybersecurity) launched a committee draft ballot in January 2025 and continued joint work with ISO/IEC JTC 1/SC 27 on AI security threats and mitigation.

    ISO/IEC JTC 1/SC 42

    SC 42 was working on more than 40 standards. ISO/IEC 5259-5, a data quality governance framework for analytics and machine learning, had been approved for publication. ISO/IEC 22443 on societal concerns and ethical considerations was receiving contributions from outside Europe. The amendments to ISO/IEC 22989 and ISO/IEC 23053 addressing generative AI were in comment resolution after ballot. A new working draft of ISO/IEC 25059 proposed new definitions on sustainability and environment, as well as on safety and quality in use.

    New projects approved as technical specifications included terminology for domain engineering of AI systems (ISO/IEC 25566), guidance on risks in generative AI systems (ISO/IEC 25568), reliability of AI systems (ISO/IEC 25570) and a template for documenting the ethical implications of AI systems (ISO/IEC 25571). A framework for human-machine teaming (ISO/IEC 25589) was approved, work began on SME-oriented implementation guidance for ISO/IEC 42001 (ISO/IEC 25651), and a ballot opened on a process assessment model for AI system lifecycle processes (ISO/IEC 25704). A first draft of ISO/IEC 42105 on human oversight was out for comment, and work on ISO/IEC TR 42109 on human-machine teaming use cases had started with six cases, such as food ordering and delivery and planning of educational content.

    IEEE

    The issue pointed to IEEE's AI ethics and governance standards, available free of charge through the IEEE GET Program. They include IEEE 2089-2021 (age-appropriate digital services based on the 5Rights principles), 7000-2021 (addressing ethical concerns in system design), 7001-2021 (transparency of autonomous systems), 7002-2022 (data privacy process), 7003-2024 (algorithmic bias), 7005-2021 (transparent employer data governance), 7007-2021 (ontological standard for ethically driven robotics), 7009-2024 (fail-safe design of autonomous systems), 7010-2020 (impact on human well-being) and 7014-2024 (emulated empathy).

    Fora

    France hosted the AI Action Summit in Paris on 10–11 February 2025, in partnership with India, bringing together close to one hundred countries and more than a thousand representatives of industry and civil society. It closed a week of events that included an international scientific conference on AI, science and society at Institut Polytechnique de Paris on 6–7 February.

    On 4 February, more than 350 people attended the webinar Implementing the EU AI Act through standards, organised by the UK AI Standards Hub and Task Group Inclusiveness. It presented the standardisation request with a focus on inclusiveness, risk management and fundamental rights, and a recording is available. A follow-up workshop to collect civil society input on the risk management standard was planned for 5 March.

    Nice to know, useful to read

    The IEC Academy launched a training module on gender-responsive standards, available to ISO and IEC experts in English, French, Spanish and Russian and based on joint ISO/IEC guidance.

    On 9 January 2025, Corporate Europe Observatory published Bias baked in: How Big Tech sets its own AI standards. The report questions how the standards that will govern AI systems, and their compliance with fundamental rights obligations, are being developed, noting that standard-setting is being used for the first time to implement requirements on fundamental rights, fairness, trustworthiness and bias. The newsletter observed that the report goes to the core of Task Group Inclusiveness's work and included it for information.

    South Korea passed its Basic Act on the Development of Artificial Intelligence and the Establishment of Trust, becoming the second jurisdiction after the EU to adopt comprehensive AI legislation.

    My reading

    The quiet headline of this issue is Annex ZA. Once working groups start mapping clauses to articles, the question shifts from "is this a good standard?" to "which legal obligation does this clause discharge, and under what conditions?". That mapping is where presumption of conformity will be won or lost, and it is also where gaps become visible.

    The proposed Stakeholder life cycle item points in the same direction from another angle. Mapping roles and responsibilities across the lifecycle is, in substance, a statement of who must do what, when and on whose behalf. The more explicitly the standards state those duties, the easier it becomes to check whether the right party has met them.

    Two numbers are also worth noting. More than 2,000 comments on a first draft say something about how contested the trustworthiness framework was. And the Corporate Europe Observatory report, which the newsletter carefully labelled "for information", shows that the legitimacy of using standards to operationalise fundamental rights was now being questioned openly from outside the process.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    February 2025Where it stands now
    CEN-CENELEC response to the amended request, asking for sufficient timeThe amended request was adopted in June 2025 as C(2025)3871 (M/613), extending the timeline to 28 February 2027. The original deadline of 30 April 2025 was missed, and CEN-CENELEC adopted exceptional acceleration measures in October 2025.
    Six draft standards sent to the CommissionTrustworthiness framework: now a five-part prEN 18229 series (logging, transparency, human oversight, accuracy, robustness); Part 1 has been through public enquiry and Part 3 reached it in July 2026. Risk management: prEN 18228, at public Enquiry. Cybersecurity: prEN 18282, at public Enquiry. Bias: prEN 18283 (drafting). Datasets: prEN 18284 (drafting). Quality management: EN 18286, approved on 12 July 2026.
    Committee drafts on risk management and QMS "shortly"The QMS draft went to public Enquiry from 30 October 2025 to January 2026 and was approved in July 2026. Citation in the Official Journal is outstanding.
    Increasing focus on Annex ZAEN 18286 contains an Annex ZA mapping its clauses to the AI Act, including Articles 17(1) and 11(1). Its exact legal effect will depend on the reference published in the Official Journal.
    Full European standard on conformity assessmentprEN 18285 (drafting).
    Third draft of the GPAI Code of Practice expectedThe final Code was published in July 2025. GPAI obligations have applied since 2 August 2025.
    Guidelines on prohibited practices publishedProhibitions have applied since 2 February 2025. The Commission also published guidelines on the definition of an AI system in February 2025.
    High-Level Forum work on alignment and fundingA revision of Regulation (EU) No 1025/2012 is in the Commission's 2026 work programme, with a proposal expected in October 2026 according to press reports.
    ISO/IEC 5259-5 approved for publicationPublished as ISO/IEC 5259-5:2025.
    South Korea's AI Basic Act passedEntered into force on 22 January 2026.
    Timeline for EU high-risk obligationsThe Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    Edition 6 · December 2024

    Edition 6 (December 2024): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 6, December 2024.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    drafting

    prEN 18228risk management

    enquiry planned

    prEN 18229trustworthiness

    working draft

    prEN 18282cybersecurity

    drafting

    prEN 18283bias management

    drafting

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 6, December 2024.

    AI Act timeline

    You are here · 2024-12-31

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · next

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    less than a month to prohibited practices and ai literacy apply

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Risk tiers under the AI Act
    UnacceptableHigh riskTransparencyMinimal risk
    1. 01 · Unacceptablea handful of practices

      Social scoring · manipulative techniques · untargeted face scraping

      Prohibited (Article 5)

    2. 02 · High riska small but costly minority

      Recruitment · credit scoring · medical devices · critical infrastructure

      Full duties: risk and quality management, data, logging, oversight (Articles 8–29)

    3. 03 · Transparencya growing share of consumer systems

      Chatbots · emotion recognition · deepfakes · synthetic media

      Disclosure and marking duties (Article 50)

    4. 04 · Minimal riskthe great majority of software

      Spam filters · recommendation engines · most business software

      No specific duties; voluntary codes of conduct

    narrow top = strictest duties · wide base = most systems

    The four risk tiers the Act works with, and what each one triggers.

    Who writes what inside JTC 21

    Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.

    WG1

    Strategic advisory

    Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.

    Main deliverables

    prCEN/CLC/TR 18347

    WG2

    Operational aspects

    Quality management, risk management and conformity assessment.

    Main deliverables

    EN 18286 · prEN 18228 · prEN 18285

    WG3

    Engineering aspects

    Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.

    Main deliverables

    prEN 18284 · prEN 18283 · ISO/IEC 24970

    WG4

    Foundational and societal aspects

    Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.

    Main deliverables

    prEN 18229-1 to 18229-5

    WG5

    Cybersecurity

    Security of AI systems; formed later than the other four groups.

    Main deliverables

    prEN 18282

    five working groups · one shared deadline

    Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.

    About this issue

    Distribution was slightly delayed so that the issue could report on the JTC 21 plenary in Turin (4–6 November 2024). ETUC continues to provide the secretariat and manages the distribution list.

    News from the European Union

    The Commission was drafting an amendment to the AI standardisation request. It would spell out how the request relates to the relevant articles of the AI Act, Regulation (EU) 2024/1689, and resolve difficulties that had arisen during drafting, such as the definition of risk, which the Act defines as the combination of the probability of harm occurring and the severity of that harm. The Joint Research Centre published a policy brief, Harmonised Standards for the European AI Act, describing the key characteristics expected of the standards that will support the Act.

    The Commission announced more than one hundred initial signatories to the AI Pact, from multinationals to SMEs. The Pact encourages voluntary application of the Act's principles ahead of its application dates. Signatories commit to at least three core actions: an AI governance strategy for compliance, mapping of high-risk AI systems, and AI literacy among staff. More than half also pledged to ensure human oversight, mitigate risks and label certain AI-generated content.

    The first draft of the General-Purpose AI Code of Practice was published on 14 November 2024, closing the first of several drafting rounds planned until April 2025. It was written by independent experts appointed as chairs and vice-chairs of four thematic working groups at the kick-off on 30 September, and feedback meetings were held from 18 to 22 November. The AI Office also opened a multi-stakeholder consultation on how to apply the Act's definition of an AI system and its prohibited practices, addressed to providers, deployers, public authorities, researchers, trade unions, civil society, supervisory authorities and the general public.

    Two further items concerned standardisation policy more broadly. EDU4Standards.eu, a new Horizon Europe project led by Fraunhofer-Gesellschaft, brings together universities, standards bodies and SMEs to strengthen education in standardisation. On 12 November, four European Parliament committees heard Stéphane Séjourné, candidate for Executive Vice-President for Prosperity and Industrial Strategy, a portfolio that includes EU standardisation policy.

    CEN-CENELEC JTC 21

    The first published deliverable. JTC 21 published its first document, CEN/CLC/TR 18115:2024, Data governance and quality for AI within the European context, prepared by WG3. Project leader Domenico Natale highlighted its section on inclusiveness, which describes how the Italian public administration applies the Web Accessibility Directive (EU) 2016/2102 through national law. The example does not concern AI, but the organisational and technical rules it describes, illustrated with a diagram and an Italian case, are offered as a model for organising data governance and quality in AI systems.

    The Turin plenary. More than 120 participants from 21 European countries attended in person or online, together with the Commission and representatives of Japan, industry associations, consumers, workers and NGOs. The Commission announced further standardisation requests on biometrics and on resource performance from early 2025, with requirements for general-purpose AI to follow later, and urged the committee to accelerate work on the ten standards in the AI request. Liaison and partner reports came from ANEC, the 5Rights Foundation, Equinet, the Big Data Value Association, Digital Europe, OWASP and Small Business Standards.

    WG1 (strategic advisory) discussed key definitions to be used across all AI standards, and Task Group Inclusiveness reported on its work. The work programme was to concentrate from now on the standards within the request, with lower priority for other projects. A new work item on functional safety was proposed for joint development with SC 42.

    WG2 (operational aspects) was working on conformity assessment, quality management and risk management. A working draft of the risk management standard was expected to circulate for comments in late 2024 or early 2025, and the deadline for submitting it to CEN Enquiry was extended to August 2025.

    WG3 (engineering aspects) reported that all contributions received so far on the bias and datasets standards had been processed. It announced the start of work on computer vision (taxonomy and accuracy) and continued joint work with SC 42 on robustness, natural language processing and logging.

    WG4 (foundational and societal aspects) circulated a working draft of the AI trustworthiness framework for comments just after the plenary. The draft reflects ANEC's extensive input on the lifecycle of AI as a product or service on the market. Other work in progress covered environmentally sustainable AI, guidelines and metrics for the environmental impact of AI, competence requirements for AI ethics professionals, and AI-enhanced nudging in parallel with SC 42. Preliminary work items covered upskilling organisations on AI ethics, tools for handling ethical issues across the AI lifecycle, and impact assessment in the context of EU fundamental rights.

    WG5 (cybersecurity) agreed the structure of the cybersecurity standard, with a committee draft ballot expected in January 2025, and continued joint work with ISO/IEC JTC 1/SC 27 on AI security threats and mitigation.

    ISO/IEC JTC 1/SC 42

    More than 150 participants from at least 33 countries attended the SC 42 plenary in Versailles (7–11 October 2024), chaired by Wael Diab (USA). The subcommittee has 70 national standards bodies and more than 800 registered experts across five working groups: foundational standards, data, trustworthiness, use cases and applications, and computational approaches. Joint groups have been set up with SC 7 (software and systems engineering, including testing of AI systems and quality models where accessibility characteristics are included), ISO/TC 215 (health informatics), IEC SC 65A and TC 65 (functional safety), ISO/TC 37 (natural language processing) and CEN-CENELEC JTC 21. SC 42 had published 32 standards, 12 of them in the previous year, and had 44 active projects, 23 of them added since the last plenary.

    WG1. ISO/IEC 22989 (concepts and terminology, available free of charge) and ISO/IEC 23053 (framework for machine learning systems) were being amended to take account of generative AI. ISO/IEC 42005 (impact assessment) was expected to be published within weeks, and ISO/IEC 42006 (requirements for certification bodies) was at final ballot. The AI system logging standard was being developed jointly with JTC 21. New projects included ISO/IEC 42007, a framework for developing conformity assessment schemes for AI systems, jointly with ISO's conformity assessment committee (CASCO); implementation guidance for ISO/IEC 42001 aimed at SMEs; and a joint expert group with SC 27 on evaluation criteria and methodology for trustworthy AI systems.

    WG3. ISO/IEC 12791 (unwanted bias) and ISO/IEC 12792 (transparency taxonomy) were ready for publication. Work continued on ISO/IEC 6254 (explainability), ISO/IEC 42105 (human oversight), ISO/IEC 25029 (AI-enhanced nudging, jointly with JTC 21) and ISO/IEC 22443 (societal concerns and ethical considerations). New projects covered watermarking and labelling to help the public identify AI-generated output, a documentation template for the ethical implications of an AI system, and the reliability of AI systems.

    WG4 was preparing technical reports on environmental sustainability of AI systems (ISO/IEC TR 20226, draft expected soon), beneficial AI systems (TR 21221) and use cases of human-machine teaming (TR 25589).

    Forum

    On 6 December, ETUC and the Luxembourg union OGBL held an awareness event with the national standards body ILNAS on why standardisation matters for trade unions, covering the link between standards and legislation, the geopolitics of standards, and practical case studies. Equinet's high-level conference on equality bodies and the AI Act took place in Brussels and online on 12 December, supported by Unia, the Swedish Equality Ombudsman, the Norwegian Equality and Anti-Discrimination Ombud and Luminate. The DIGITAL SME Summit on 10 December in Brussels included a forum on strengthening Europe's standardisation expertise through education. The sixth Athens Roundtable on AI and the rule of law was held at the OECD in Paris on 9 December.

    Arnaud Latil (Sorbonne University) and Marion Ho-Dac coordinated two webinars with the AI Office, on 28 November and 17 December, presenting the AI Act to stakeholders in support of gradual implementation under the AI Pact. The UK AI Standards Hub and Task Group Inclusiveness announced a webinar for civil society on 4 February 2025 on the AI standardisation request, the role of JTC 21, the risk management standard, and fundamental rights.

    Nice to know, useful to read

    From January 2025, ISO and IEC committees were to start new projects and revisions on the Online Standards Development (OSD) platform by default, replacing the Word-based template unless an exemption is requested. CEN and CENELEC published a brochure on gender-responsive standardisation on 24 September 2024.

    Two French-language books were recommended. In L'éthique de l'intelligence artificielle expliquée à mon fils (Mimesis), JTC 21 WG4 convenor Enrico Panai discusses trustworthiness, risk and the work of an ethicist with his son. In Les normes à l'assaut de la démocratie (Odile Jacob), Jean-Denis Combrexelle, former president of the litigation section of the French Conseil d'État, former chief of staff to Prime Minister Élisabeth Borne and former director general of Labour, examines the political, legal and administrative mechanisms that multiply rules and lengthen texts in France and Europe. Note that the French normes covers legal and administrative norms in general, not only technical standards.

    My reading

    Two items in this issue deserve more weight than their placement suggests. The first is the Commission's plan to tie the standardisation request explicitly to the articles of the AI Act and to settle definitional questions such as the meaning of risk. That is the right direction: when the Act defines risk as the combination of probability and severity of harm, a risk management standard that works with a different concept will produce conformity that does not map cleanly onto the legal obligation. The WG2 subgroup on risk acceptability now had a legal anchor to work from.

    The second is the extension of the deadline for submitting the risk management draft to Enquiry to August 2025. With the request's original delivery date set at 30 April 2025, this was the first explicit sign in the newsletter that the timeline could not hold. It is also worth noting that JTC 21's first published deliverable was a technical report, a document type that cannot give a presumption of conformity.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    December 2024Where it stands now
    Amendment to the AI standardisation request in preparationAdopted in June 2025 as C(2025)3871 (M/613), replacing the original decision and extending the timeline to 28 February 2027.
    First draft of the GPAI Code of Practice; drafting planned until April 2025The final Code was published in July 2025, later than first planned. GPAI obligations have applied since 2 August 2025.
    AI Office consultation on the AI system definition and prohibited practicesProhibitions have applied since 2 February 2025. The Commission published guidelines on prohibited practices and on the definition of an AI system in February 2025.
    Hearing of Stéphane SéjournéConfirmed as Executive Vice-President; the new Commission took office on 1 December 2024. A revision of Regulation (EU) No 1025/2012 is expected to be proposed in October 2026, according to press reports.
    Risk management draft to CEN Enquiry by August 2025The original delivery deadline of 30 April 2025 was missed. prEN 18228 was at public Enquiry as of June 2026.
    WG5 committee draft ballot expected January 2025prEN 18282, at public Enquiry (June 2026).
    Working draft of the trustworthiness framework circulatedDeveloped as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Bias and datasets standards: all contributions processedprEN 18283 and prEN 18284 (both drafting). A working-draft consultation on prEN 18283 closed on 30 April 2026.
    WG2: quality management and conformity assessmentEN 18286 approved on 12 July 2026, with citation in the Official Journal outstanding. prEN 18285 (conformity assessment) in drafting.
    Commission urged faster delivery of the ten standardsIn October 2025, CEN-CENELEC adopted exceptional measures aiming for the prioritised deliverables to be available by Q4 2026. The Digital Omnibus on AI moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    SC 42 watermarking and labelling project launchedRelevant to Article 50(2) of the AI Act, which applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026.
    ISO/IEC 42005 due within weeks; 42006 at final ballot; 12791 and 12792 readyPublished as ISO/IEC 42005:2025, ISO/IEC 42006:2025, ISO/IEC TS 12791:2024 and ISO/IEC 12792:2025.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    Edition 5 · September 2024

    Edition 5 (September 2024): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 5, September 2024. Includes, as an annex, the JTC 21 internal work programme dashboard as of 31 August 2024.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    dashboard

    prEN 18228risk management

    homegrown

    prEN 18229trustworthiness

    drafting

    prEN 18282cybersecurity

    homegrown

    prEN 18283bias management

    homegrown

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 5, September 2024.

    AI Act timeline

    You are here · 2024-09-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · next

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    4 months to prohibited practices and ai literacy apply

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Three tracks, one legal difference

    Europe

    CEN-CENELEC JTC 21

    Harmonised standards written on request from the European Commission.

    • prEN 18228 risk
    • prEN 18286 quality
    • prEN 18229 trustworthiness

    Yes — once cited in the Official Journal

    International

    ISO/IEC JTC 1/SC 42

    Global AI standards, sometimes adopted in Europe, sometimes deliberately not.

    • ISO/IEC 42001
    • ISO/IEC TS 12791
    • ISO/IEC 24029

    No — may be referenced, but does not carry presumption

    Professional body

    IEEE

    Engineering practice standards developed outside the EU framework.

    • Ethically aligned design series
    • Transparency and privacy standards

    No — useful practice, no legal effect under the AI Act

    The turning point

    The Commission found ISO/IEC 42001 not aligned with the quality management system required by Article 17. EN 18286 became the dedicated European route instead — which is why the two tracks are not interchangeable.

    only the European track can give presumption of conformity

    Three standardisation tracks, and why only one of them carries presumption of conformity.

    About this issue

    The newsletter had passed 500 LinkedIn impressions in the two months since the previous edition, and was now referenced in CEN-CENELEC's On the Spot magazine. Readers could register for the distribution list through ETUC, which continues to provide the secretariat. The next issue was planned for mid-November.

    News from the European Union

    The AI Act entered into force on 1 August 2024. The Commission released a video on the Act's objectives and the role of standardisation in achieving them, and opened a call for tender for a study on measuring and encouraging energy-efficient, low-emission AI systems in the EU. The AI Office launched a multi-stakeholder consultation on trustworthy general-purpose AI models, open until 18 September 2024, to inform both the first General-Purpose AI Code of Practice and the template for summarising the content used to train such models. In the European Parliament, the IMCO and LIBE committees set up a joint working group to monitor implementation of the Act.

    CEN-CENELEC JTC 21

    The next plenary was scheduled for Turin, 4–6 November 2024.

    The most significant decision reported was that JTC 21 declined joint development with ISO/IEC of two key standards required by the AI Act, on risk management and on trustworthiness, citing the specific European context. It also adopted two new work items to operationalise the Act and meet the standardisation request: a European standard on a quality management system for AI Act regulatory purposes, and a European AI conformity assessment framework. A further work item on a taxonomy of AI system methods and capabilities was registered.

    In WG2, work on risk management continued, with three subgroups set up on terminology, risk acceptability, and integration with existing risk management frameworks. In WG3, a work item was approved to adopt the ISO/IEC 5259 series on data quality directly as European standards, while work continued on logging and computer vision jointly with SC 42, and on datasets and bias. WG4 concentrated on trustworthiness, alongside fundamental rights and ethics (competence requirements for AI ethics professionals, tools for handling ethical issues, and upskilling organisations), and was exploring sustainable AI and its environmental impact. In WG5, the work item on cybersecurity specifications for AI systems was approved.

    Civil society contributions to the working groups were increasing. The issue highlighted ANEC documents on how AI standards relate to the phases of a product lifecycle, and Equinet documents on human oversight in the context of trustworthiness and risk management.

    JTC 21 publishes its internal dashboard

    Given the strong interest from industry, society and policymakers, JTC 21 took the unusual step of publishing a copy of its internal work programme dashboard, dated 31 August 2024. It shows which items are developed jointly with SC 42 and which are "homegrown" European work, much of which is designed to fill the gaps between the AI Act's requirements and what ISO/IEC standards already provide. The published dashboard carries no dates. CEN-CENELEC's live project dashboard does show some historical and estimated dates, but it is updated at irregular intervals. The newsletter added that, by the time of writing, every JTC 21 project supporting the standardisation request had passed the approval stage and was under drafting.

    The dashboard itself makes two points worth keeping in mind. First, its stage codes are only loosely correlated with the maturity of the content and the degree of consensus reached, so the formal stage is not a reliable predictor of completion. Second, comments and contributions must be routed through a national AI mirror committee or through one of the Annex III organisations (ANEC, ETUC, SBS). They cannot be introduced by CEN-CENELEC staff or the JTC 21 management team.

    What the dashboard shows, by area of the standardisation request

    Terminology and supporting standards. ISO/IEC 22989 (concepts and terminology) and ISO/IEC 23053 (framework for machine learning systems) had been adopted as European standards, with amendments to both in parallel development under ISO lead.

    Quality management and risk management. The adoption of ISO/IEC 42001 remained at a preliminary stage, approved with one negative national vote. The dashboard noted that it was unclear whether adoption was still needed, and that 42001 will not be harmonised by the Commission. In its place, a homegrown standard on a quality management system for regulatory purposes, building on several ISO/IEC standards including 42001, was under drafting. ISO/IEC 23894 (risk management guidance) had been adopted, and a homegrown AI risk management standard, replacing an earlier risk checklist item, was under drafting.

    Record-keeping and transparency. A standard on AI system logging (ISO/IEC 24970) and the transparency taxonomy (ISO/IEC 12792) were both in parallel development under ISO lead.

    Accuracy and robustness. The trustworthiness framework, a homegrown European standard, was under drafting and mapped to almost every area of the request. Accuracy threshold definition was to be covered inside it, and ISO/IEC TS 4213 on classification accuracy was to be referenced, not adopted, with its forthcoming update covering regression, recommendation and clustering. On robustness, ISO/IEC TR 24029-1 had been adopted, but because it is a technical report, a further deliverable was still needed; the dashboard noted that little additional content was available, since this is at the frontier of research. Work on the formal-methods and statistical-methods parts of ISO/IEC 24029 was at preliminary or early stages. Standards on evaluating natural language processing systems were in parallel development under ISO lead, and two work items on computer vision (evaluation methods and a task taxonomy) were at ballot until 12 September 2024.

    Data governance and bias. ISO/IEC 8183 (data life cycle framework) had been adopted. Parts 1, 3 and 4 of ISO/IEC 5259 had been published by ISO in July 2024 and were being adopted, with part 2 at final draft stage. A homegrown standard on quality and governance of datasets was under drafting, and the technical report CEN/CLC/TR 18115 on data governance and quality in the European context was at ballot until 29 August 2024. On bias, ISO/IEC TS 12791 was in its second ballot (19 June to 11 September 2024), and a homegrown standard on concepts, measures and requirements for managing bias was under drafting.

    Testing and conformity assessment. A possibly modified adoption of ISO/IEC 42006 (then at draft international standard stage) and of ISO/IEC 29119-11 on testing AI systems was under discussion. A standard on competence requirements for AI system auditors and professionals, and the homegrown AI conformity assessment framework, were under drafting.

    Cybersecurity. JTC 21 was contributing to ISO/IEC 27090 on AI security threats, with adoption as a technical report suggested. The homegrown cybersecurity specifications for AI systems were under drafting. The dashboard concluded that no harmonised standard on privacy protection is needed, since it is covered by the GDPR and existing standards such as ISO/IEC 27701, 29100, 29151 and 29134. How to assess conformity for AI-specific vulnerabilities was still open, including whether to align with the Cyber Resilience Act and whether assessment should sit alongside the requirements, as in EN 18031, or in a separate document. A question on this was pending with the Commission.

    Beyond the standardisation request (lower priority). This group included AI-enhanced nudging, in parallel development with dual European and Indian editorship; a technical report on green and sustainable AI, for which parallel development was rejected because the European work was already too advanced; a specification on metrics for the environmental impact of AI; the conformity assessment technical report CEN/CLC/TR 17894, at ballot until 24 October 2024; competence requirements for AI ethics professionals; specifications on upskilling in AI ethics and on tools for ethical issues; the adopted ISO/IEC TR 24027 (bias) and ISO/IEC 25059 (quality model for AI systems); a taxonomy of AI system methods and capabilities (ISO/IEC 42102); a reference architecture for knowledge engineering; and a preliminary item on impact assessment in the context of fundamental rights, with its form (technical report or European standard) and its relationship to 42001 still open. Guidelines on accuracy improvement were deferred as unnecessary for the request, an example of the committee's effort to keep the programme tight.

    ISO/IEC JTC 1/SC 42

    The next SC 42 plenary was set for Le Chesnay (France), 7–11 October 2024. Growing interest in generative AI was driving updates to ISO/IEC 22989 and ISO/IEC 23053, and a new project on guidance for addressing risks in generative AI systems had been proposed. ISO/IEC 42005 (impact assessment) was nearly complete, and ISO/IEC 12792 (transparency taxonomy), ISO/IEC 12791 (unwanted bias) and ISO/IEC 42006 (certification body requirements) were well advanced. Other topics in progress, mainly in WG1 and WG3, included uncertainty quantification, a taxonomy of AI methods and capabilities, human oversight, evaluation methods and criteria for trustworthiness, human-machine teaming, beneficial AI systems, reliability, societal and ethical concerns, the SME handbook for ISO/IEC 42001, and nudging.

    Forum

    Small Business Standards announced its annual Meeting Standards campaign for SMEs, 25–29 November 2024, with online and in-person events across Europe. Equinet announced a high-level conference in Brussels on 12 December 2024 on how equality bodies should respond to the AI Act, aimed at equality bodies, policymakers, civil society and experts on non-discrimination. The UK AI Standards Hub scheduled a webinar on 24 September 2024 on inclusive approaches to AI security standardisation, with speakers from the UK Department for Science, Innovation and Technology, ANEC and Enforce.

    Nice to know, useful to read

    The issue recommended a blog post by Kai Zenner, head of office and digital policy adviser to MEP Axel Voss, setting out the Commission's and the AI Office's responsibilities and deadlines under the AI Act. It also noted a California Senate bill that would require developers of AI models trained with more than USD 100 million of compute to adopt and disclose a safety and security plan against critical harms, pending the Governor's signature.

    My reading

    The published dashboard is the most useful document in the series so far. For the first time, it shows the architecture of the European response: which requirements are met by adopting ISO/IEC work and which need homegrown standards. The homegrown list is telling. Risk management, trustworthiness, quality management, datasets, bias, conformity assessment and cybersecurity are exactly the areas where the AI Act's requirements are most specific. The decision not to develop risk management and trustworthiness jointly with ISO/IEC, and the note that 42001 will not be harmonised, are the clearest statements yet of where Europe and the international track diverge.

    Two notes in the dashboard have aged well. The warning that formal stages are a poor predictor of completion was borne out when the April 2025 deadline was missed. And the open question on conformity assessment for AI-specific vulnerabilities illustrates a problem that will only grow: the AI Act, the Cyber Resilience Act and the GDPR each bring their own requirements and assessment logic, and someone has to decide which document carries which obligation.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    September 2024Where it stands now
    AI Act in force since 1 August 2024The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    AI Office consultation for the GPAI Code of PracticeThe Code of Practice was published in July 2025, together with the template for the public summary of training content. GPAI obligations have applied since 2 August 2025.
    All request-related projects "under drafting"The original deadline of 30 April 2025 was missed. By mid-2026, EN 18286 had been approved; prEN 18228 and prEN 18282 were at public Enquiry; prEN 18229-1 (logging) had been through public enquiry and prEN 18229-3 (human oversight) reached it in July 2026. Most other deliverables were still in drafting.
    Homegrown QMS for regulatory purposes; 42001 "will not be harmonised"EN 18286 approved on 12 July 2026. The Commission found 42001 not aligned with Article 17. Citation of EN 18286 in the Official Journal is outstanding.
    Homegrown risk management standardprEN 18228, at public Enquiry.
    Homegrown trustworthiness frameworkDeveloped as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Logging in parallel development with ISO (ISO/IEC 24970)The JTC 21 logging deliverable for Article 12 is now prEN 18229-1, Part 1 of the trustworthiness series, which has been through public enquiry. ISO/IEC 24970 continued separately in ISO/IEC JTC 1/SC 42.
    Homegrown datasets and bias standardsprEN 18284 and prEN 18283 (both drafting).
    Homegrown conformity assessment frameworkprEN 18285 (drafting).
    Homegrown cybersecurity specificationsprEN 18282, at public Enquiry.
    CEN/CLC/TR 18115 at ballotPublished in December 2024.
    ISO/IEC TS 12791 at second ballotPublished as ISO/IEC TS 12791:2024.
    ISO/IEC 42005, 42006 and 12792 nearly completePublished in 2025.
    California frontier model bill awaiting signatureSB 1047 was vetoed in September 2024. A narrower transparency law for frontier model developers, SB 53, was signed in September 2025.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    Edition 4 · July 2024

    Edition 4 (July 2024): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 4, July 2024.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    drafting

    prEN 18228risk management

    drafting

    prEN 18229trustworthiness

    drafting

    prEN 18282cybersecurity

    drafting

    prEN 18283bias management

    drafting

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 4, July 2024.

    AI Act timeline

    You are here · 2024-07-31

    1. 1 Aug 2024 · next

      AI Act enters into force

    2. 2 Feb 2025

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    less than a month to ai act enters into force

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    About this issue

    The newsletter restated its purpose: to enable broad stakeholder participation in European AI standards by sharing information on standardisation in CEN-CENELEC JTC 21, ISO/IEC JTC 1/SC 42 and other fora. Its content is reviewed by Task Group Inclusiveness but is non-binding. ETUC continues to provide the secretariat, contributions for the next issue were invited by 23 August, and publication was planned for early September. The newsletter was now also referenced in CEN-CENELEC's On the Spot magazine.

    News from the European Union

    The Commission opened a public consultation, running until 25 July 2024, on its evaluation of the Standardisation Regulation (EU) No 1025/2012. On 19 June it hosted the first high-level meeting of the future European AI Board, intended to drive implementation of the AI Act.

    The 7th Sherpa meeting of the High-Level Forum on European Standardisation (14 May) reviewed the draft 2025 Annual Union Work Programme, which contains several recommendations on AI. Digital Europe and Small Business Standards proposed new areas of focus for the Forum. The workstreams reported progress on fundamental rights and standards (WS2), peer review of national standards bodies (WS3), alignment of European and international standards (WS4), greater civil society inclusion (WS5), and AI (WS12). WS12 met on 28 June and reviewed awareness initiatives on AI standards by ANEC, ETSI, Digital Europe and the national standards bodies of Denmark, Ireland, Malta and Sweden, while the Commission presented the Enterprise Europe Network for SMEs. A new workstream on quantum technology (WS16) was launched.

    The Commission was also preparing a separate standardisation request for a European trusted data framework, covering five standards: data transactions, data catalogues, trusted ontologies and data models, quality assessment of internal data governance processes, and maturity assessment of common European data spaces. The request is independent of the AI request, but the two are clearly connected.

    On 14 May, the European social partners in the banking sector published a joint declaration on the employment aspects of AI, setting out how AI systems should be designed, implemented and operated.

    CEN-CENELEC JTC 21: the Bath plenary

    The plenary and working group meetings took place in Bath from 3 to 5 June, with decisions taken on 7 June. More than 150 participants from at least 20 European countries attended in person or online, joined by observers from Australia, Canada and Japan. Civil society was clearly present, with reports from ANEC, Equinet, ETUC, ForHumanity and Small Business Standards.

    DG CONNECT announced that a slightly updated standardisation request supporting the AI Act was being prepared. It noted that most provisions of the Act would apply by mid-2026 and some a year later, reminded participants how short the deadlines were, and urged the working groups to concentrate on producing usable harmonised standards. The chair and the convenors stressed the volume of work required and the need for new experts to join. Given the size of the AI community in CEN-CENELEC member countries, they argued, competent people should not be hard to find.

    The plenary launched a series of new projects. New work item proposals covered the direct adoption of the ISO/IEC 5259 series on data quality for analytics and machine learning, an AI conformity assessment framework, a quality management system for regulatory purposes, evaluation methods for accurate computer vision systems, a taxonomy of computer vision tasks, cybersecurity specifications for AI systems, and a taxonomy of AI system methods and capabilities. Preliminary work items covered guidelines and metrics for the environmental impact of AI, tools for handling ethical aspects across the AI lifecycle, and upskilling on AI ethics and social concerns in organisations.

    Participants noted an overall acceleration in risk management, conformity assessment and quality management (WG2), data management and logging (WG3), trustworthiness (WG4), and cybersecurity (WG5). After Bath, two international standards were proposed for adoption as European standards: ISO/IEC 25059 (quality model for AI systems) and ISO/IEC 12792 (transparency taxonomy of AI systems). The next plenary was scheduled for Turin, 4–6 November 2024.

    ISO/IEC JTC 1/SC 42

    In SC 42 WG1, two standards were close to adoption: AI system impact assessment, and requirements for bodies auditing and certifying AI systems. Work had begun on a standard for the reliability of AI systems. In WG3, the standards on bias and transparency were close to adoption, and a standard on logging was in full development. The SC 42 secretary had shared the SC 42 standards published between February 2023 and June 2024 with JTC 21, making them available to its members.

    More forums

    Equinet held meetings in 2024 on the gender impact of AI (11 April) and on practical and ethical issues in the use of AI in communication (29–30 May), with a webinar series on AI and gender equality planned for September.

    At CPDP in Brussels on 23 May, ANEC brought together the Commission, JTC 21, ETUC and Small Business Standards to assess inclusiveness in AI standardisation. The panel agreed that barriers to participation remain, and that more action, funding and training are needed for consumers and civil society to be properly represented. ANEC also presented its inclusiveness work under projects funded by the Mercator Foundation and the European AI & Society Fund. A recording is available.

    On 5 June, Small Business Standards and CEN-CENELEC co-organised the High-Level Forum workshop on national participation in standardisation, with support from the Belgian FPS Economy. Government representatives, national standards bodies and practitioners from SMEs, large companies, consumer and environmental organisations, trade unions and academia discussed access, participation and good practice.

    On 19 June, ANEC and BEUC held a virtual workshop on maximising civil society participation in AI standardisation, supported by the Mercator Foundation. More than 40 civil society participants heard an update from Antoine-Alexandre André of the AI Office and practical advice from Emilia Tantar, chair of JTC 21 WG2 and Small Business Standards representative, before discussing barriers and routes to engagement in breakout groups. CEN-CENELEC followed with a webinar on 27 June on involving societal stakeholders and SMEs in standards development, with presentations and a recording available online.

    Nice to know, useful to read

    The issue recommended the Future of Life Institute's biweekly EU AI Act Newsletter, then with 26,000 subscribers, and a paper by Christian Grafenauer of ANEC on protecting consumer rights through the AI Act and JTC 21 standards.

    It also noted three national developments on AI at work. In Spain, the main employers' organisations (CEOE and CEPYME) and the two largest trade unions (CCOO and UGT) concluded the binding 5th Agreement for Employment and Collective Bargaining, with a substantial section on human control of AI and the right to information about algorithms. In Italy, a government bill on AI, including two articles on AI in the workplace, was heading to Parliament. In Poland, a bill submitted on 11 June would extend the information employers must give trade unions on request, including the parameters of algorithms used to make decisions about employees, for example in profiling.

    My reading

    The Bath plenary marks the point where the programme's ambition and its capacity started to pull apart. The Commission asked for usable harmonised standards on a short deadline, while the plenary opened a long list of new work items and the leadership appealed for more experts. The acceleration reported at the time did not prevent the original April 2025 delivery deadline from being missed, which later led to CEN-CENELEC's exceptional measures and, indirectly, to the Digital Omnibus delay.

    The workplace items point to a parallel track. Rights to information about algorithms and human control over AI at work are being set through collective agreements and national legislation, not through standards. For providers and deployers this means two sources of obligations that need to be read together: the technical requirements in harmonised standards, and the information and control rights negotiated or legislated at national level.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    July 2024Where it stands now
    Public consultation on evaluating Regulation 1025/2012Evaluation published in June 2025 (SWD(2025)170). A revision is in the Commission's 2026 work programme, with a proposal expected in October 2026 according to press reports.
    First high-level meeting of the future AI BoardThe AI Act entered into force on 1 August 2024. The European Artificial Intelligence Board is established under Article 65.
    "Slightly updated" AI standardisation request in preparationAdopted in June 2025 as C(2025)3871 (M/613), replacing the original decision and extending the timeline to 28 February 2027.
    Most AI Act provisions to apply by mid-2026The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Transparency obligations under Article 50 were not postponed.
    Acceleration reported in WG2–WG5The original deadline of 30 April 2025 was missed. In October 2025, CEN-CENELEC adopted exceptional measures aiming for the prioritised deliverables to be available by Q4 2026.
    New work item: quality management system for regulatory purposesEN 18286 approved on 12 July 2026. Citation in the Official Journal is outstanding.
    New work item: AI conformity assessment frameworkprEN 18285 (drafting).
    New work item: cybersecurity specifications for AI systemsprEN 18282, at public Enquiry (June 2026).
    Acceleration in risk management, logging and trustworthinessprEN 18228 (risk management) was at public Enquiry as of June 2026. The trustworthiness framework is now a five-part prEN 18229 series: Part 1 (logging) has been through public enquiry, and Part 3 (human oversight) reached public enquiry in July 2026.
    ISO/IEC 12792 proposed for European adoptionPublished by ISO/IEC in 2025.
    SC 42: impact assessment and certification body requirements close to adoptionPublished as ISO/IEC 42005:2025 and ISO/IEC 42006:2025.
    SC 42: bias and transparency close to adoptionPublished as ISO/IEC TS 12791:2024 and ISO/IEC 12792:2025.
    Italian AI bill heading to ParliamentAdopted as Law No. 132 of 23 September 2025, including provisions on AI in the workplace.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    Edition 3 · May 2024

    Edition 3 (May 2024): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 3, May 2024.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    new work item

    prEN 18228risk management

    risk catalogue

    prEN 18229trustworthiness

    drafting

    prEN 18282cybersecurity

    drafting

    prEN 18283bias management

    drafting

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    new work item

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 3, May 2024.

    AI Act timeline

    You are here · 2024-05-31

    1. 1 Aug 2024 · next

      AI Act enters into force

    2. 2 Feb 2025

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    2 months to ai act enters into force

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Who is actually in the room

    Inclusiveness survey

    146/195

    75% of eligible JTC 21 members and observers answered the spring 2025 survey.

    120+

    Turin plenary

    participants from 21 countries

    150+

    Bath plenary

    participants from 20+ countries

    800+

    ISO/IEC SC 42

    registered experts, 70 national bodies

    350+

    Civil society webinars

    participants at the largest sessions

    Newsletter reach, edition by edition

    70+
    Edition 3
    500+ views
    Edition 5
    250+
    Edition 7
    several hundred
    Edition 8

    figures as reported in the newsletter

    Who takes part, and how far the work reaches.

    About this issue

    The newsletter now reached more than 70 direct recipients. Edition 2 had been posted on the JTC 21 WG1 page on 15 March, and all issues are available through ETUC and the JTC 21 LinkedIn group. ETUC continues to provide the secretariat, and the next issue was planned for early July. The editors also clarified the scope: the newsletter covers only standards where the inclusion of societal stakeholders is expected, leaving aside the many purely technical documents written mainly for IT specialists.

    News from the European Union

    The European Parliament formally adopted the AI Act on 13 March 2024. The Commission was preparing its Annual Union Work Programme for standardisation, with several proposals on AI, data and cybersecurity, to be discussed by the "Sherpa" group of the High-Level Forum on European Standardisation on 14 May. The existing standardisation request on AI remained in force.

    Four of the Forum's fifteen workstreams were highlighted.

    WS2, fundamental rights. ANEC and BEUC held an invitation-only webinar on 20 March on where to draw the line between standards and fundamental rights. The discussion partly concerned the AI Act, which aims to protect fundamental rights while leaving room for interpretation to the experts drafting the standards.

    WS3, peer review of national standards bodies. A workshop on strengthening national participation was announced for 5 June 2024 in Brussels and online, organised under the Forum with support from the Belgian FPS Economy. Its three panels covered barriers to accessing standardisation work, effective and balanced participation, and good practice, with recommendations for Member States and national standards bodies as the intended outcome.

    WS5, civil society and SME inclusion in international standardisation. A report on the subject was in preparation, with ECOS and CEN-CENELEC as contact points.

    WS12, artificial intelligence. The information videos on AI standardisation announced in Edition 2 had all been published.

    What's new at CEN-CENELEC JTC 21

    WG1 (strategic advisory). The "architecture of standards" document, which sets out how CEN-CENELEC will answer the Commission's request, had been voted on. Comments from several national standards bodies were being resolved.

    WG2 (operational aspects) launched two new work item proposals: conformity assessment frameworks for AI systems, and quality management system requirements for regulatory purposes. On risk management, a full-day meeting in Berlin on 8 April brought the group close to agreeing a table of contents. The standard was to combine requirements derived from Article 9 of the AI Act with requirements reflecting the generally acknowledged state of the art in AI risk management, which Article 8(1) makes relevant. An annex, provisionally called the "Risk Catalogue", would set out that state of the art by listing AI risk sources, their potential harms and possible risk management measures. PLOT4ai, a practical library of AI threats developed by the Dutch privacy engineer Isabel Barberá, was being used to populate it, and the group also expected to draw on existing ISO risk management standards, including those for medical devices. To help newcomers contribute to the catalogue, Koen Holtman (NL) wrote a style guide on drafting useful expert submissions. It is designed to be shared outside JTC 21, so that external writing or consultation projects can feed into the committee through a participating expert.

    WG3 (engineering aspects) had validated new work items on quality and governance of datasets and on managing bias. Work on natural language processing and on logging continued in partnership with ISO/IEC, under ISO lead.

    WG4 (foundational and societal aspects) was drafting the trustworthiness framework, which will list the elements of trustworthiness and their associated requirements, with in-person meetings in Paris (26–27 March), Rome (14–15 May) and Brussels (9–10 July). It also launched preliminary work items on four topics. The first concerned impact assessment in the context of EU fundamental rights, intended to produce a technical report on the technical and organisational measures needed to safeguard those rights. The stated aim was not to standardise fundamental rights, but to help develop standards that serve them. The other three concerned guidelines on tools for managing ethical aspects of AI in organisations, tools and upskilling for AI ethics, and sustainable AI, a subject SC 42 is also addressing.

    WG5 (cybersecurity) was noted for the record. The next plenary was scheduled for Bath, 3–7 June 2024, and readers were again directed to their national standards bodies and to the partner and liaison organisations representing SMEs, consumers, environmental groups, NGOs and workers.

    Stakeholder input on AI trustworthiness

    A separate item called for input to the draft trustworthiness framework ahead of its next development stage on 17 July 2024. The framework was described as the backbone of the whole architecture of AI standards: every other standard should refer to it and contribute to it. WG4 was working with a definition of trustworthiness as "the ability to meet stakeholder expectations in a verifiable way".

    ANEC offered an example of what that means for consumers. In its view, consumer trustworthiness for software-based products that are frequently updated requires characterisation in two domains. The first is whether the implementation is fit for purpose in reasonably foreseeable use, which usually calls for detailed functional requirements per product type. The second is whether lifecycle activities are carried out by competent people doing the right things at the right time, so that consumers can trust that suppliers exercised due care throughout the lifecycle. Stakeholders were encouraged to state their own expectations while the draft was still open.

    What's new at ISO/IEC JTC 1/SC 42

    The SC 42 plenary took place in Seoul, 22–26 April 2024. In WG1, an SME handbook for ISO/IEC 42001 was being designed, and ISO/IEC 42005 on AI impact assessment was in its final stage, with comment resolution meetings planned until July. Generative AI was emerging as an area likely to drive new standards and revisions across SC 42.

    In WG3 (trustworthiness), a technical specification on controllability of automated AI systems had been published. Specifications on a transparency taxonomy and on treatment of unwanted bias were in their last comment round. Guidance on societal and ethical concerns, trustworthiness facts and labels, guidance on human oversight, and nudging were at earlier stages. WG4 (use cases) was working on environmental sustainability, with a call for experts, as well as on beneficial AI systems and human-machine teaming. The next SC 42 plenary was set for Paris in October 2024, and the issue repeated the reminder that non-profit organisations can apply for Category C liaison.

    More forums

    The editors began mapping the wider landscape. Within CEN-CENELEC, JTC 13 on cybersecurity and data protection covers topics closely related to AI. In ISO/IEC JTC 1, SC 27 (information security, cybersecurity and privacy protection) and SC 39 (sustainability, IT and data centres) are relevant. IEC, IEEE, ITU and ETSI are active on the electrotechnical and telecoms side. UNESCO runs the Global AI Ethics and Governance Observatory and an expert group on implementing AI ethics. The World Economic Forum, the United Nations and the World Trade Organization are also active on AI, and a Memorandum of Understanding on electronic business between IEC, ISO, ITU and UNECE, signed in 2000, has supported a standing expert group since then.

    Nice to know

    At CPDP 2024 in Brussels (22–24 May), ANEC organised a panel on 23 May, with support from the European AI & Society Fund, assessing how far governance and inclusiveness in AI standardisation had come. The chair of JTC 21, ETUC, Small Business Standards and the European Commission took part. The European Trade Union Institute (ETUI) published Artificial intelligence, labour and society in March 2024, an edited volume with contributions from academics and research activists worldwide. Small Business Standards announced the second edition of its Meeting Standards campaign for SMEs, 25–29 November 2024.

    On 24 April, SaferAI and the Ada Lovelace Institute held a workshop in Brussels on how to develop the EU General-Purpose AI Code of Practice. More than 50 participants from civil society, standards bodies, the Commission and the Parliament, several of them active in JTC 21, took part. Three messages stood out: civil society should be involved early and substantively; accountability should build on what worked in the Code of Practice on Disinformation, such as third-party verification and quantitative reporting; and the Code should set quantitative risk thresholds defining acceptable risk, as other industries do.

    Annex: video interviews from the Dublin plenary

    The issue closes with an annex from NSAI (Ireland) listing 15 short video clips recorded at the 9th JTC 21 plenary in Dublin in February 2024. Heads of delegation and delegates from Denmark, Cyprus, Portugal, France, the Netherlands, Italy, Germany and Ireland answer questions such as which aspects of the AI Act they find most important, how industry uptake of AI standards can be encouraged, how national standards bodies have responded, and how developing AI standards differs from other ICT standardisation. Most clips exist both in the speaker's own language with English subtitles and in English. They are available on NSAI's YouTube channel.

    My reading

    Two decisions in this issue shaped what came later. The first is the new work item on quality management requirements for regulatory purposes. Only two months after Edition 2 reported a plan to adopt ISO/IEC 42001, WG2 opened a dedicated European route, the origin of today's EN 18286. The second is the risk management design, which ties the standard to the AI Act's reference to the state of the art and proposes to make that state of the art explicit in a catalogue of risk sources, harms and measures.

    WG4's working definition deserves attention as well. If trustworthiness is the ability to meet stakeholder expectations in a verifiable way, then an expectation that has not been stated as a checkable condition cannot be verified. The invitation to stakeholders is therefore more than a consultation formality. It is the step where expectations either become testable requirements or remain aspirations.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    May 2024Where it stands now
    AI Act adopted by the European ParliamentPublished as Regulation (EU) 2024/1689 and in force since 1 August 2024. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    Standardisation request "still stands"Amended in June 2025 as C(2025)3871 (M/613), with an extended timeline to 28 February 2027.
    New work item: QMS requirements for regulatory purposesEN 18286 approved on 12 July 2026, the first JTC 21 AI Act standard to reach that point. Citation in the Official Journal is outstanding.
    New work item: conformity assessment frameworksprEN 18285 (drafting).
    Risk management standard with a "Risk Catalogue" annexprEN 18228, at public Enquiry (June 2026).
    Work items validated: datasets and managing biasprEN 18284 and prEN 18283 (both drafting).
    Trustworthiness framework as the overarching standardDeveloped as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Preliminary work on fundamental rights impact assessmentThe AI Act's own fundamental rights impact assessment for certain deployers (Article 27) applies together with the Annex III obligations, now from 2 December 2027.
    GPAI Code of Practice under discussionPublished by the Commission in July 2025, with chapters on transparency, copyright, and safety and security. GPAI obligations have applied since 2 August 2025.
    SC 42: controllability specification publishedISO/IEC TS 8200:2024.
    SC 42: transparency taxonomy and unwanted bias in final commentsPublished as ISO/IEC 12792:2025 and ISO/IEC TS 12791:2024.
    SC 42: ISO/IEC 42005 in final stagePublished as ISO/IEC 42005:2025.
    HLF work on inclusiveness and national participationThe Commission's evaluation found that the standardisation framework struggles with timeliness, inclusiveness and access. A revision of Regulation (EU) No 1025/2012 is in the 2026 work programme, with a proposal expected in October 2026 according to press reports.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    Edition 2 · March 2024

    Edition 2 (March 2024): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 2, March 2024.

    Open this edition →

    Pipeline at this issue

    prEN 18286quality management

    not started

    prEN 18228risk management

    home-grown

    prEN 18229trustworthiness

    full drafting

    prEN 18282cybersecurity

    drafting

    prEN 18283bias management

    drafting

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    not started

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 2, March 2024.

    AI Act timeline

    You are here · 2024-03-31

    1. 1 Aug 2024 · next

      AI Act enters into force

    2. 2 Feb 2025

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    4 months to ai act enters into force

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    About this issue

    The first edition was well received and reached a wider audience. It was registered as a JTC 21 WG1 committee document (N332) and made available through the ETUC website and a LinkedIn group. ETUC continues to provide the secretariat, and the next issue was planned for early May 2024.

    The JTC 21 plenary, 12–16 February 2024

    More than 100 participants attended, in person or online. All five working groups reported progress, and the plenary took several formal decisions to move documents into drafting. The Commission presented the final changes to the AI Act ahead of its publication, and signalled that the standardisation request would be extended to new areas such as resource performance and energy consumption.

    WG1 (strategic advisory) worked on how horizontal standards, which apply across all sectors, interact with vertical standards for specific domains such as health and transport, and identified ways to avoid conflicts between the two. Its "architecture of standards" document, which sets out how CEN-CENELEC will answer the Commission's request, was put to ballot.

    WG2 (operational aspects) was balloting the European adoption of ISO/IEC TR 17894 on conformity assessment, alongside a new work item on conformity assessment requirements specific to the AI Act. On risk management, European adoption of ISO/IEC 23894 was proposed. Because that guidance predates the final AI Act and does not cover all of its requirements, a "home-grown" European standard to fill the gaps was also about to start. ISO/IEC 42001 was to be submitted for European adoption as the quality management reference. Parallel development under ISO lead was proposed for guidelines on testing AI-based systems and for requirements on bodies auditing and certifying AI systems.

    WG3 (engineering aspects) was in the final round of joint ISO/IEC and CEN-CENELEC adoption of the document on treatment of unwanted bias, and had started new work on concepts, measures and requirements for managing bias, possibly in parallel with ISO. On data, work began on datasets, to be followed by quality and governance of datasets and data quality for analytics and machine learning. A preliminary work item on a reference architecture for knowledge engineering was launched, and work continued on logging, natural language processing, robustness and computer vision.

    WG4 (foundational and societal aspects) reported that the trustworthiness framework was now in full drafting. The plenary decided to start a project on impact assessment in the context of EU fundamental rights. A draft on nudging was in progress, work on competence requirements for AI ethics professionals had begun, and a draft on green and sustainable AI was under ballot.

    WG5 (cybersecurity), newly created, was to start on ISO/IEC 27090, guidance on security threats and failures in AI systems, and to discuss technical responses to AI-specific vulnerabilities, in liaison with CEN-CENELEC JTC 13 on cybersecurity.

    Getting involved. Readers were pointed to their national standards bodies (Danish Standards, AFNOR, DIN, UNI, BSI and others), all of which have experts in the working groups, and to the partner and liaison organisations: Small Business Standards for SMEs, ANEC for consumers, ECOS for the environment, NGOs such as Adra-E, Equinet, 5Rights and ForHumanity, and ETUC for workers. The next plenaries were announced for Bath (3–7 June 2024) and November 2024, by which time most documents under the request were expected to be well advanced.

    ISO/IEC JTC 1/SC 42

    In SC 42 WG1, a handbook for SMEs implementing ISO/IEC 42001 was being prepared, and ISO/IEC 42005 on AI system impact assessment was in its final validation round. In WG3, AI transparency requirements were at a late stage and work on ethical aspects continued. Early discussions on human oversight distinguished two dimensions: how humans take part in the governance of AI as a process, and how a person can actually control or stop an application. Work on the environmental impact of AI ran in liaison with JTC 21 WG4. The issue also reminded non-profit organisations that they can apply for Category C liaison with SC 42, which gives access to working documents and expert meetings, by selecting the relevant working groups and submitting an application form per group to the SC 42 secretariat.

    News from the European institutions

    AI was a key part of the 2024 Annual Union Work Programme for European standardisation and was expected to stay high on the agenda for 2025. Workstream 12 on AI of the High-Level Forum on European Standardisation met on 27 February 2024 to review outreach actions. The Commission had also begun an evaluation of the Standardisation Regulation (EU) No 1025/2012, with a public consultation, surveys and interviews to follow.

    The most consequential item was the Court of Justice judgment of 5 March 2024 on access to harmonised standards. In 2018 the Commission had refused two non-profit organisations access to harmonised standards on toy safety, and the General Court upheld that refusal in 2021. On appeal, the Court of Justice found an overriding public interest in disclosure, because harmonised standards form part of EU law by virtue of their legal effects. The newsletter noted that the consequences for other harmonised standards, including the future AI standards, remained to be assessed.

    Resources and events for civil society

    ANEC and BEUC launched a webpage explaining why and how civil society organisations can engage in AI standardisation, written for newcomers who do not know where to start. ANEC organised an invitation-only webinar on 20 March 2024 on where to draw the line between standardisation and fundamental rights, and, ahead of World Consumer Rights Day (theme for 2024: fair and responsible AI for consumers), an online workshop on 12 March on influencing international AI standards. Further resources included a Danish Standards webinar supported by NSAI Ireland on the role of standards in EU AI legislation, NSAI information videos on AI standardisation with subtitles in seven languages, the HSbooster programme offering free standardisation support to EU-funded research projects, and the first 2024 Small Business Standards newsletter with a report from the JTC 21 plenary.

    Looking ahead, the issue flagged CPDP 2024 in Brussels (22–24 May), where ANEC would host a panel assessing how far inclusiveness measures in CEN-CENELEC had come, and where JTC 21 WG2 co-convenor Ansgar Koene would host a panel on inclusiveness in AI standards. It also noted the interim report of the UN AI Advisory Body, Governing AI for Humanity (December 2023), with a final report expected in mid-2024, and a new workstream at the UK AI Standards Hub, led by Alan Turing Institute researchers, on AI in recruitment and employment.

    My reading

    This issue records the point where the European route began to separate from the international one. ISO/IEC 23894 was judged insufficient for the AI Act and a European standard was planned to fill the gaps. For quality management, the plan at the time was still to adopt ISO/IEC 42001, a plan that was later reversed. The Court of Justice judgment deserves more attention than a single paragraph. If harmonised standards are part of EU law because of their legal effects, then the operational meaning of the AI Act's requirements will sit in texts that the public has a claim to read. That strengthens the case for standards that are not only accessible, but precise enough to be checked.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    March 2024Where it stands now
    AI Act "soon to be published"Published as Regulation (EU) 2024/1689 and in force since 1 August 2024. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    Request to be extended to resource performance and energyArticle 40(2) of the final Act requires standardisation requests to cover deliverables on reporting and documentation that improve AI systems' resource performance, such as energy consumption. The request itself was amended in June 2025 as C(2025)3871 (M/613).
    Home-grown European risk management standardprEN 18228, at public Enquiry (June 2026).
    ISO/IEC 42001 to be adopted for quality managementCourse changed. The Commission found 42001 not aligned with Article 17, and a dedicated standard was written instead. EN 18286 was approved on 12 July 2026; citation in the Official Journal is outstanding.
    New work item on AI Act conformity assessmentprEN 18285 (drafting).
    Requirements for audit and certification bodiesPublished as ISO/IEC 42006:2025.
    Concepts, measures and requirements for managing biasprEN 18283 (drafting).
    Quality and governance of datasetsprEN 18284 (drafting).
    Trustworthiness framework in full draftingDeveloped as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    WG5 starting on cybersecurityThe JTC 21 deliverable for Article 15 cybersecurity is prEN 18282, at public Enquiry.
    ISO/IEC 42005 in final validationPublished as ISO/IEC 42005:2025.
    Evaluation of Regulation 1025/2012Evaluation published in June 2025 (SWD(2025)170). A revision is in the Commission's 2026 work programme; according to press reports on a draft, a proposal is expected in October 2026, including common specifications as a fallback and a tighter definition of "harmonised standard".
    Court of Justice ruling on accessISO and IEC brought an action against the Commission before the General Court (Case T-631/24, filed December 2024). Access to standards is one of the issues the revision of Regulation 1025/2012 is expected to address.
    UN AI Advisory Body interim reportFinal report, Governing AI for Humanity, published in September 2024.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    Edition 1 · January 2024

    Edition 1 (January 2024): the essence

    The first issue of the AI Standardisation Inclusiveness Newsletter, condensed, with a note on what has happened since.

    Open this edition →

    Pipeline at this issue

    prEN 18229trustworthiness

    preliminary work item

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 1, January 2024.

    AI Act timeline

    You are here · 2024-01-31

    1. 1 Aug 2024 · next

      AI Act enters into force

    2. 2 Feb 2025

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    6 months to ai act enters into force

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Risk tiers under the AI Act
    UnacceptableHigh riskTransparencyMinimal risk
    1. 01 · Unacceptablea handful of practices

      Social scoring · manipulative techniques · untargeted face scraping

      Prohibited (Article 5)

    2. 02 · High riska small but costly minority

      Recruitment · credit scoring · medical devices · critical infrastructure

      Full duties: risk and quality management, data, logging, oversight (Articles 8–29)

    3. 03 · Transparencya growing share of consumer systems

      Chatbots · emotion recognition · deepfakes · synthetic media

      Disclosure and marking duties (Article 50)

    4. 04 · Minimal riskthe great majority of software

      Spam filters · recommendation engines · most business software

      No specific duties; voluntary codes of conduct

    narrow top = strictest duties · wide base = most systems

    The four risk tiers the Act works with, and what each one triggers.

    From draft to legal effect
    1. A working group writes a first draft against the Commission's request.

    2. National members comment. Thousands of comments are normal at this stage.

    3. Before enquiry, the Commission assesses whether the draft is eligible to become a harmonised standard (HAS assessment).

    4. National standards bodies comment and vote. The draft can fail on the number of countries in favour or on the weighted population in favour.

    5. After a positive enquiry, the draft may be published without a formal vote (CEN-CENELEC Technical Board, October 2025). After a negative enquiry, comments are resolved and a formal vote is held, as happened with EN 18286.

    6. 06Published as ENnot yet binding

      The standard exists and can be bought and applied — but it carries no legal effect yet.

    7. The Commission publishes the reference of the standard in the Official Journal.

    8. Only now does following the standard show compliance with the AI Act requirement it covers.

    A finished standard and a standard that gives presumption of conformity are two different things. So far, most of the delay has come before publication: drafts reached enquiry months later than planned, and every enquiry vote on a core draft has been negative. EN 18286 is the first to be published; its citation in the Official Journal is still pending.

    steps 01–06 are technical work · steps 07–08 are what makes it law-relevant

    How a European standard travels from draft to legal effect.

    Who writes what inside JTC 21

    Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.

    WG1

    Strategic advisory

    Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.

    Main deliverables

    prCEN/CLC/TR 18347

    WG2

    Operational aspects

    Quality management, risk management and conformity assessment.

    Main deliverables

    EN 18286 · prEN 18228 · prEN 18285

    WG3

    Engineering aspects

    Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.

    Main deliverables

    prEN 18284 · prEN 18283 · ISO/IEC 24970

    WG4

    Foundational and societal aspects

    Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.

    Main deliverables

    prEN 18229-1 to 18229-5

    WG5

    Cybersecurity

    Security of AI systems; formed later than the other four groups.

    Main deliverables

    prEN 18282

    five working groups · one shared deadline

    Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.

    Why the newsletter exists

    The Commission's 2023 standardisation request to CEN and CENELEC, Decision C(2023)3215, asked for a work programme of European standards supporting the AI Act. It also required appropriate representation and effective participation of stakeholders, SMEs and societal organisations included. Task Group Inclusiveness was created inside JTC 21 to make that requirement real, by keeping a wider audience informed about AI standardisation in CEN-CENELEC, in ISO/IEC JTC 1/SC 42 and in other fora. The European Trade Union Confederation (ETUC) provides the secretariat.

    The call to action

    The lead item concerned a preliminary work item for a European Standard on a Trustworthiness framework, with a ballot deadline of 23 January 2024. Civil society organisations were urged to contact their national standards bodies and influence how their country voted. The framework was intended to complement the standards that give presumption of conformity, addressing fitness for purpose in foreseeable use together with security, privacy, safety and inclusivity across the product lifecycle. The Task Group saw it as a foundation for further trustworthiness standards serving civil society.

    Policy context

    The issue noted the political agreement on the AI Act reached in December 2023. It also reported on the High-Level Forum on European Standardisation, established by Commission Decision C(2022) 6189. The Forum's plenary on 30 November 2023 received a pledge on education and skills in standardisation and reviewed the Annual Union Work Programme 2024, with AI among its priorities. The Forum's Workstream 12 on AI had held a webinar on the role of standards in the coming AI legislation a week earlier. DG GROW launched a European Standardisation Panel Survey on industry's standardisation needs arising from research and innovation. Finally, StandICT.eu was highlighted as a funding scheme (about EUR 2.9 million) for European experts working in international standards bodies, with AI among its three main target topics.

    The JTC 21 pipeline in early 2024

    Participation runs through national standards bodies and CEN-CENELEC partner and liaison organisations, and the next plenary was scheduled for Dublin in February 2024. The work was spread across five working groups.

    WG1 (strategic advisory) coordinated the response to the standardisation request and ran three task groups on inclusiveness, horizontal and vertical coordination, and technical coherence. WG2 (operational aspects) handled conformity assessment, a risk management standard and risk catalogue then under ballot, adoption and adaptation of SC 42 deliverables, and sector-specific challenges in areas such as healthcare and transport. WG3 (engineering aspects) worked on unwanted bias in machine learning, data governance and quality in the European context, logging, robustness of neural networks, testing guidelines, and natural language processing jointly with ISO. WG4 (foundational and societal aspects) covered sustainable AI, AI-enhanced nudging with ISO, trustworthiness characterisation, and competence requirements for AI ethics professionals. WG5 on cybersecurity for AI systems had just been formed, in November 2023, out of a former task group.

    ISO/IEC JTC 1/SC 42

    At the international level, the issue pointed to the SC 42 plenary in Seoul in April 2024, to the free availability of ISO/IEC 22989 on AI concepts and terminology, and to the publication of ISO/IEC 42001 on AI management systems in December 2023. Foundational work in progress included an SME guide to 42001, the treatment of generative AI, AI system impact assessment, requirements for bodies certifying AI management systems, and a taxonomy of AI methods and capabilities. The trustworthiness group was working on societal and ethical concerns, a transparency taxonomy, human oversight, explainability and bias.

    Inclusiveness in practice

    Several contributions showed what participation can look like. Algorithm Audit, a Dutch NGO, published a guide on using stakeholder panels to make bias testing standards more deliberative and transparent, and presented it in JTC 21. Accessibility was traced through the ISO/IEC 25000 (SQuaRE) quality models and into the draft technical report on data governance and quality for AI, which links to the EU Web Accessibility Directive. Small Business Standards was flagged as the voice of SMEs. ANEC, the European consumer voice in standardisation, held two outreach webinars in autumn 2023. There the Commission (DG CNECT) stressed stakeholder participation, fundamental rights and data protection, and alignment with EU values as key elements of the standardisation work. The DIN Consumer Council and Algorithm Audit shared their experience of organising at national level, and the free e-learning course at standards4all.eu was recommended for newcomers.

    My reading

    This first issue captures the moment civil society was told, clearly, that influence over AI standards is exercised in national mirror committees and not only in Brussels. The trustworthiness framework ballot was the first concrete test. The underlying question it raised is still open: how far fundamental-rights considerations can be carried by standards that are, for the most part, about processes and management systems.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    January 2024Where it stands now
    Political agreement on the AI ActRegulation (EU) 2024/1689 entered into force on 1 August 2024. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    Standardisation request C(2023)3215 (M/593)Repealed and replaced by C(2025)3871 (M/613), which expires on 28 February 2027.
    Trustworthiness framework (preliminary work item)Developed as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Risk management and risk catalogueprEN 18228, at public Enquiry.
    AI system loggingprEN 18229-1 (Part 1 of the trustworthiness series), which has been through public enquiry.
    Data governance and qualityTechnical report CEN/CLC/TR 18115 published in December 2024; normative work continues as prEN 18284 (drafting).
    Unwanted biasprEN 18283 (drafting).
    Conformity assessmentprEN 18285 (drafting).
    WG5 cybersecurityprEN 18282, at public Enquiry.
    Not yet on the list in 2024EN 18286 (quality management system, Article 17) approved on 12 July 2026, the first JTC 21 AI Act standard to reach that point. Citation in the Official Journal is still outstanding.
    SC 42: AI system impact assessmentPublished as ISO/IEC 42005:2025.
    SC 42: requirements for certification bodiesPublished as ISO/IEC 42006:2025.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.