AI Standardisation Watch

    Edition 1 · January 2024

    Edition 1 (January 2024): the essence

    The first issue of the AI Standardisation Inclusiveness Newsletter, condensed, with a note on what has happened since.

    Pipeline at this issue

    prEN 18229trustworthiness

    preliminary work item

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 1, January 2024.

    AI Act timeline

    You are here · 2024-01-31

    1. 1 Aug 2024 · next

      AI Act enters into force

    2. 2 Feb 2025

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    6 months to ai act enters into force

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Risk tiers under the AI Act
    UnacceptableHigh riskTransparencyMinimal risk
    1. 01 · Unacceptablea handful of practices

      Social scoring · manipulative techniques · untargeted face scraping

      Prohibited (Article 5)

    2. 02 · High riska small but costly minority

      Recruitment · credit scoring · medical devices · critical infrastructure

      Full duties: risk and quality management, data, logging, oversight (Articles 8–29)

    3. 03 · Transparencya growing share of consumer systems

      Chatbots · emotion recognition · deepfakes · synthetic media

      Disclosure and marking duties (Article 50)

    4. 04 · Minimal riskthe great majority of software

      Spam filters · recommendation engines · most business software

      No specific duties; voluntary codes of conduct

    narrow top = strictest duties · wide base = most systems

    The four risk tiers the Act works with, and what each one triggers.

    From draft to legal effect
    1. A working group writes a first draft against the Commission's request.

    2. National members comment. Thousands of comments are normal at this stage.

    3. Before enquiry, the Commission assesses whether the draft is eligible to become a harmonised standard (HAS assessment).

    4. National standards bodies comment and vote. The draft can fail on the number of countries in favour or on the weighted population in favour.

    5. After a positive enquiry, the draft may be published without a formal vote (CEN-CENELEC Technical Board, October 2025). After a negative enquiry, comments are resolved and a formal vote is held, as happened with EN 18286.

    6. 06Published as ENnot yet binding

      The standard exists and can be bought and applied — but it carries no legal effect yet.

    7. The Commission publishes the reference of the standard in the Official Journal.

    8. Only now does following the standard show compliance with the AI Act requirement it covers.

    A finished standard and a standard that gives presumption of conformity are two different things. So far, most of the delay has come before publication: drafts reached enquiry months later than planned, and every enquiry vote on a core draft has been negative. EN 18286 is the first to be published; its citation in the Official Journal is still pending.

    steps 01–06 are technical work · steps 07–08 are what makes it law-relevant

    How a European standard travels from draft to legal effect.

    Who writes what inside JTC 21

    Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.

    WG1

    Strategic advisory

    Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.

    Main deliverables

    prCEN/CLC/TR 18347

    WG2

    Operational aspects

    Quality management, risk management and conformity assessment.

    Main deliverables

    EN 18286 · prEN 18228 · prEN 18285

    WG3

    Engineering aspects

    Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.

    Main deliverables

    prEN 18284 · prEN 18283 · ISO/IEC 24970

    WG4

    Foundational and societal aspects

    Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.

    Main deliverables

    prEN 18229-1 to 18229-5

    WG5

    Cybersecurity

    Security of AI systems; formed later than the other four groups.

    Main deliverables

    prEN 18282

    five working groups · one shared deadline

    Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.

    Why the newsletter exists

    The Commission's 2023 standardisation request to CEN and CENELEC, Decision C(2023)3215, asked for a work programme of European standards supporting the AI Act. It also required appropriate representation and effective participation of stakeholders, SMEs and societal organisations included. Task Group Inclusiveness was created inside JTC 21 to make that requirement real, by keeping a wider audience informed about AI standardisation in CEN-CENELEC, in ISO/IEC JTC 1/SC 42 and in other fora. The European Trade Union Confederation (ETUC) provides the secretariat.

    The call to action

    The lead item concerned a preliminary work item for a European Standard on a Trustworthiness framework, with a ballot deadline of 23 January 2024. Civil society organisations were urged to contact their national standards bodies and influence how their country voted. The framework was intended to complement the standards that give presumption of conformity, addressing fitness for purpose in foreseeable use together with security, privacy, safety and inclusivity across the product lifecycle. The Task Group saw it as a foundation for further trustworthiness standards serving civil society.

    Policy context

    The issue noted the political agreement on the AI Act reached in December 2023. It also reported on the High-Level Forum on European Standardisation, established by Commission Decision C(2022) 6189. The Forum's plenary on 30 November 2023 received a pledge on education and skills in standardisation and reviewed the Annual Union Work Programme 2024, with AI among its priorities. The Forum's Workstream 12 on AI had held a webinar on the role of standards in the coming AI legislation a week earlier. DG GROW launched a European Standardisation Panel Survey on industry's standardisation needs arising from research and innovation. Finally, StandICT.eu was highlighted as a funding scheme (about EUR 2.9 million) for European experts working in international standards bodies, with AI among its three main target topics.

    The JTC 21 pipeline in early 2024

    Participation runs through national standards bodies and CEN-CENELEC partner and liaison organisations, and the next plenary was scheduled for Dublin in February 2024. The work was spread across five working groups.

    WG1 (strategic advisory) coordinated the response to the standardisation request and ran three task groups on inclusiveness, horizontal and vertical coordination, and technical coherence. WG2 (operational aspects) handled conformity assessment, a risk management standard and risk catalogue then under ballot, adoption and adaptation of SC 42 deliverables, and sector-specific challenges in areas such as healthcare and transport. WG3 (engineering aspects) worked on unwanted bias in machine learning, data governance and quality in the European context, logging, robustness of neural networks, testing guidelines, and natural language processing jointly with ISO. WG4 (foundational and societal aspects) covered sustainable AI, AI-enhanced nudging with ISO, trustworthiness characterisation, and competence requirements for AI ethics professionals. WG5 on cybersecurity for AI systems had just been formed, in November 2023, out of a former task group.

    ISO/IEC JTC 1/SC 42

    At the international level, the issue pointed to the SC 42 plenary in Seoul in April 2024, to the free availability of ISO/IEC 22989 on AI concepts and terminology, and to the publication of ISO/IEC 42001 on AI management systems in December 2023. Foundational work in progress included an SME guide to 42001, the treatment of generative AI, AI system impact assessment, requirements for bodies certifying AI management systems, and a taxonomy of AI methods and capabilities. The trustworthiness group was working on societal and ethical concerns, a transparency taxonomy, human oversight, explainability and bias.

    Inclusiveness in practice

    Several contributions showed what participation can look like. Algorithm Audit, a Dutch NGO, published a guide on using stakeholder panels to make bias testing standards more deliberative and transparent, and presented it in JTC 21. Accessibility was traced through the ISO/IEC 25000 (SQuaRE) quality models and into the draft technical report on data governance and quality for AI, which links to the EU Web Accessibility Directive. Small Business Standards was flagged as the voice of SMEs. ANEC, the European consumer voice in standardisation, held two outreach webinars in autumn 2023. There the Commission (DG CNECT) stressed stakeholder participation, fundamental rights and data protection, and alignment with EU values as key elements of the standardisation work. The DIN Consumer Council and Algorithm Audit shared their experience of organising at national level, and the free e-learning course at standards4all.eu was recommended for newcomers.

    My reading

    This first issue captures the moment civil society was told, clearly, that influence over AI standards is exercised in national mirror committees and not only in Brussels. The trustworthiness framework ballot was the first concrete test. The underlying question it raised is still open: how far fundamental-rights considerations can be carried by standards that are, for the most part, about processes and management systems.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    January 2024Where it stands now
    Political agreement on the AI ActRegulation (EU) 2024/1689 entered into force on 1 August 2024. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    Standardisation request C(2023)3215 (M/593)Repealed and replaced by C(2025)3871 (M/613), which expires on 28 February 2027.
    Trustworthiness framework (preliminary work item)Developed as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Risk management and risk catalogueprEN 18228, at public Enquiry.
    AI system loggingprEN 18229-1 (Part 1 of the trustworthiness series), which has been through public enquiry.
    Data governance and qualityTechnical report CEN/CLC/TR 18115 published in December 2024; normative work continues as prEN 18284 (drafting).
    Unwanted biasprEN 18283 (drafting).
    Conformity assessmentprEN 18285 (drafting).
    WG5 cybersecurityprEN 18282, at public Enquiry.
    Not yet on the list in 2024EN 18286 (quality management system, Article 17) approved on 12 July 2026, the first JTC 21 AI Act standard to reach that point. Citation in the Official Journal is still outstanding.
    SC 42: AI system impact assessmentPublished as ISO/IEC 42005:2025.
    SC 42: requirements for certification bodiesPublished as ISO/IEC 42006:2025.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    All 16 editions are listed in the news feed.