Edition 1 · January 2024
Edition 1 (January 2024): the essence
The first issue of the AI Standardisation Inclusiveness Newsletter, condensed, with a note on what has happened since.
prEN 18229trustworthiness
preliminary work item
not started · drafting · enquiry · approved · cited in OJ
Status of the AI Act deliverables as described in Edition 1, January 2024.
1 Aug 2024
AI Act enters into force
2 Feb 2025
Prohibited practices and AI literacy apply
2 Aug 2025
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
6 months to ai act enters into force
You are here · 2024-01-31
1 Aug 2024 · next
AI Act enters into force
2 Feb 2025
Prohibited practices and AI literacy apply
2 Aug 2025
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
6 months to ai act enters into force
filled = already in force · hollow = still ahead · flag = date of this issue
Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.
01 · Unacceptable — a handful of practices
Social scoring · manipulative techniques · untargeted face scraping
Prohibited (Article 5)
02 · High risk — a small but costly minority
Recruitment · credit scoring · medical devices · critical infrastructure
Full duties: risk and quality management, data, logging, oversight (Articles 8–29)
03 · Transparency — a growing share of consumer systems
Chatbots · emotion recognition · deepfakes · synthetic media
Disclosure and marking duties (Article 50)
04 · Minimal risk — the great majority of software
Spam filters · recommendation engines · most business software
No specific duties; voluntary codes of conduct
narrow top = strictest duties · wide base = most systems
The four risk tiers the Act works with, and what each one triggers.
- 01Drafting
A working group writes a first draft against the Commission's request.
National members comment. Thousands of comments are normal at this stage.
Before enquiry, the Commission assesses whether the draft is eligible to become a harmonised standard (HAS assessment).
National standards bodies comment and vote. The draft can fail on the number of countries in favour or on the weighted population in favour.
After a positive enquiry, the draft may be published without a formal vote (CEN-CENELEC Technical Board, October 2025). After a negative enquiry, comments are resolved and a formal vote is held, as happened with EN 18286.
The standard exists and can be bought and applied — but it carries no legal effect yet.
The Commission publishes the reference of the standard in the Official Journal.
Only now does following the standard show compliance with the AI Act requirement it covers.
A finished standard and a standard that gives presumption of conformity are two different things. So far, most of the delay has come before publication: drafts reached enquiry months later than planned, and every enquiry vote on a core draft has been negative. EN 18286 is the first to be published; its citation in the Official Journal is still pending.
steps 01–06 are technical work · steps 07–08 are what makes it law-relevant
How a European standard travels from draft to legal effect.
Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.
Strategic advisory
Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.
Main deliverables
prCEN/CLC/TR 18347
Operational aspects
Quality management, risk management and conformity assessment.
Main deliverables
EN 18286 · prEN 18228 · prEN 18285
Engineering aspects
Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.
Main deliverables
prEN 18284 · prEN 18283 · ISO/IEC 24970
Foundational and societal aspects
Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.
Main deliverables
prEN 18229-1 to 18229-5
Cybersecurity
Security of AI systems; formed later than the other four groups.
Main deliverables
prEN 18282
five working groups · one shared deadline
Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.
Why the newsletter exists
The Commission's 2023 standardisation request to CEN and CENELEC, Decision C(2023)3215, asked for a work programme of European standards supporting the AI Act. It also required appropriate representation and effective participation of stakeholders, SMEs and societal organisations included. Task Group Inclusiveness was created inside JTC 21 to make that requirement real, by keeping a wider audience informed about AI standardisation in CEN-CENELEC, in ISO/IEC JTC 1/SC 42 and in other fora. The European Trade Union Confederation (ETUC) provides the secretariat.
The call to action
The lead item concerned a preliminary work item for a European Standard on a Trustworthiness framework, with a ballot deadline of 23 January 2024. Civil society organisations were urged to contact their national standards bodies and influence how their country voted. The framework was intended to complement the standards that give presumption of conformity, addressing fitness for purpose in foreseeable use together with security, privacy, safety and inclusivity across the product lifecycle. The Task Group saw it as a foundation for further trustworthiness standards serving civil society.
Policy context
The issue noted the political agreement on the AI Act reached in December 2023. It also reported on the High-Level Forum on European Standardisation, established by Commission Decision C(2022) 6189. The Forum's plenary on 30 November 2023 received a pledge on education and skills in standardisation and reviewed the Annual Union Work Programme 2024, with AI among its priorities. The Forum's Workstream 12 on AI had held a webinar on the role of standards in the coming AI legislation a week earlier. DG GROW launched a European Standardisation Panel Survey on industry's standardisation needs arising from research and innovation. Finally, StandICT.eu was highlighted as a funding scheme (about EUR 2.9 million) for European experts working in international standards bodies, with AI among its three main target topics.
The JTC 21 pipeline in early 2024
Participation runs through national standards bodies and CEN-CENELEC partner and liaison organisations, and the next plenary was scheduled for Dublin in February 2024. The work was spread across five working groups.
WG1 (strategic advisory) coordinated the response to the standardisation request and ran three task groups on inclusiveness, horizontal and vertical coordination, and technical coherence. WG2 (operational aspects) handled conformity assessment, a risk management standard and risk catalogue then under ballot, adoption and adaptation of SC 42 deliverables, and sector-specific challenges in areas such as healthcare and transport. WG3 (engineering aspects) worked on unwanted bias in machine learning, data governance and quality in the European context, logging, robustness of neural networks, testing guidelines, and natural language processing jointly with ISO. WG4 (foundational and societal aspects) covered sustainable AI, AI-enhanced nudging with ISO, trustworthiness characterisation, and competence requirements for AI ethics professionals. WG5 on cybersecurity for AI systems had just been formed, in November 2023, out of a former task group.
ISO/IEC JTC 1/SC 42
At the international level, the issue pointed to the SC 42 plenary in Seoul in April 2024, to the free availability of ISO/IEC 22989 on AI concepts and terminology, and to the publication of ISO/IEC 42001 on AI management systems in December 2023. Foundational work in progress included an SME guide to 42001, the treatment of generative AI, AI system impact assessment, requirements for bodies certifying AI management systems, and a taxonomy of AI methods and capabilities. The trustworthiness group was working on societal and ethical concerns, a transparency taxonomy, human oversight, explainability and bias.
Inclusiveness in practice
Several contributions showed what participation can look like. Algorithm Audit, a Dutch NGO, published a guide on using stakeholder panels to make bias testing standards more deliberative and transparent, and presented it in JTC 21. Accessibility was traced through the ISO/IEC 25000 (SQuaRE) quality models and into the draft technical report on data governance and quality for AI, which links to the EU Web Accessibility Directive. Small Business Standards was flagged as the voice of SMEs. ANEC, the European consumer voice in standardisation, held two outreach webinars in autumn 2023. There the Commission (DG CNECT) stressed stakeholder participation, fundamental rights and data protection, and alignment with EU values as key elements of the standardisation work. The DIN Consumer Council and Algorithm Audit shared their experience of organising at national level, and the free e-learning course at standards4all.eu was recommended for newcomers.
My reading
This first issue captures the moment civil society was told, clearly, that influence over AI standards is exercised in national mirror committees and not only in Brussels. The trustworthiness framework ballot was the first concrete test. The underlying question it raised is still open: how far fundamental-rights considerations can be carried by standards that are, for the most part, about processes and management systems.
For the live status of each standard, see the Standards Explorer.
Since then (status September 2026)
| January 2024 | Where it stands now |
|---|---|
| Political agreement on the AI Act | Regulation (EU) 2024/1689 entered into force on 1 August 2024. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). |
| Standardisation request C(2023)3215 (M/593) | Repealed and replaced by C(2025)3871 (M/613), which expires on 28 February 2027. |
| Trustworthiness framework (preliminary work item) | Developed as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026. |
| Risk management and risk catalogue | prEN 18228, at public Enquiry. |
| AI system logging | prEN 18229-1 (Part 1 of the trustworthiness series), which has been through public enquiry. |
| Data governance and quality | Technical report CEN/CLC/TR 18115 published in December 2024; normative work continues as prEN 18284 (drafting). |
| Unwanted bias | prEN 18283 (drafting). |
| Conformity assessment | prEN 18285 (drafting). |
| WG5 cybersecurity | prEN 18282, at public Enquiry. |
| Not yet on the list in 2024 | EN 18286 (quality management system, Article 17) approved on 12 July 2026, the first JTC 21 AI Act standard to reach that point. Citation in the Official Journal is still outstanding. |
| SC 42: AI system impact assessment | Published as ISO/IEC 42005:2025. |
| SC 42: requirements for certification bodies | Published as ISO/IEC 42006:2025. |
Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.
Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.