AI Standardisation Watch

    Edition 10 · September 2025

    Edition 10 (September 2025): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 10, September 2025.

    Pipeline at this issue

    prEN 18286quality management

    1100+ comments

    prEN 18228risk management

    1300+ comments

    prEN 18229trustworthiness

    split in two

    prEN 18282cybersecurity

    enquiry soon

    prEN 18283bias management

    drafting

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    version 4.0

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 10, September 2025.

    AI Act timeline

    You are here · 2025-09-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · in force

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026 · next

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    10 months to general application, including article 50 transparency duties

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. As in the previous issue, it reminds readers that all ongoing projects are confidential, that details can be requested from national standards bodies, and that every European standard goes through public enquiry before adoption.

    News from the European Union

    General-purpose AI rules apply. The AI Act's obligations for providers of general-purpose AI models have applied since 2 August 2025, including transparency and copyright requirements. Models already on the market before that date have until 2 August 2027 to comply, and providers of models with systemic risk, such as risks to fundamental rights, to safety, or of loss of control, face additional obligations. The Commission published guidelines on who must comply and on the scope of the obligations. Under these guidelines, models trained with more than 10^23 FLOP that can generate language are indicatively treated as general-purpose AI models. The Commission also published a template for the public summary of training data.

    GPAI Code of Practice. The Code was published on 10 July 2025. Developed by independent experts through a multi-stakeholder process, it is a voluntary tool covering safety, transparency and copyright, and the Commission and the AI Board have confirmed it as an adequate means for providers to demonstrate compliance. Major model providers had begun to sign it, gaining greater legal certainty and lower administrative burden than proving compliance by other means.

    Transparency obligations. The Commission opened a consultation, running until 2 October 2025, to prepare guidelines and a Code of Practice on transparent AI systems. These will help providers and deployers detect and label AI-generated or manipulated content, and meet the obligation to inform people when they interact with an AI system, when they are exposed to emotion recognition or biometric categorisation, and when content has been generated or manipulated by AI. A parallel call invited stakeholders to take part in drafting the Code.

    High-risk AI. A public consultation from 6 June to 18 July 2025 collected practical examples and questions to inform the Commission's forthcoming guidelines on classifying high-risk AI systems, on the related requirements and obligations, and on responsibilities along the AI value chain. Results were not yet available when the newsletter went out.

    Advisory Forum. In July the Commission opened applications, until 14 September, for the AI Act Advisory Forum. The Forum will give the Commission independent technical advice on implementation, including standardisation, and will complement the scientific panel, which advises the AI Office and, on request, national market surveillance authorities on general-purpose AI. CEN, CENELEC and ETSI will be members.

    Standardisation policy. On 25 July, the High-Level Forum on European Standardisation endorsed its recommendation for the 2026 Annual Union Work Programme. AI standardisation features prominently, covering the development, evaluation and governance of AI systems, general-purpose AI, sustainable AI and alignment with the AI Act, alongside cybersecurity, digital trust and data interoperability. For the first time, the recommendation was also published in the Commission's notification system. On 23 June, the Commission published its evaluation of Regulation (EU) No 1025/2012 with the supporting study, concluding an 18-month process, and opened a call for evidence for the impact assessment of a revision then expected in mid-2026.

    CEN-CENELEC JTC 21

    Plenary. The 13th plenary was announced for Copenhagen, 18–21 November 2025.

    Commission feedback. In a reply dated 19 June to JTC 21's six-monthly progress report, the Commission stressed the importance of keeping to the timeline, noted progress on inclusiveness while underlining its continued importance, and emphasised the interplay between standards. The newsletter pointed out that Commission documents can be requested through its access-to-documents portal.

    Functional safety. JTC 21 agreed to take part in the parallel development, under ISO lead, of ISO/IEC 22440 on functional safety and AI systems, in three parts: requirements, guidance, and application examples.

    WG1 (strategic advisory) proposed a new technical report, Overview and architecture of standards in support of the AI Act. Its purpose is to prepare organisations for the harmonised standards and to mitigate possible publication delays, by explaining what is coming, providing basic terminology, concepts and materials, and describing the nature of the requirements (design, development, monitoring, documentation). It will gather in one document the elements already agreed across the JTC 21 projects. Separately, the proposal to adopt ISO/IEC 42001 directly as a European standard was approved with 21 votes in favour, some with comments, none against and 5 abstentions.

    WG2 (operational aspects) was working on three standards. The conformity assessment framework, combining guidance and requirements, reached internal draft version 4.0 in August. The risk management standard, setting requirements and practical guidance for addressing and mitigating risk across the AI lifecycle, received more than 1,300 comments on its committee draft, with resolution starting in September. The risk catalogue, originally planned as an annex, will become a separate document. The quality management system standard for providers of high-risk AI systems received more than 1,100 comments on its committee draft, and resolution meetings were under way.

    WG3 (engineering aspects). Work on quality and governance of datasets was well advanced, with recent contributions on data modification plans, data poisoning and data versioning. The managing bias standard was also well advanced, with a structure covering bias management requirements, how bias manifests in AI systems, examples, and bias assessment. Joint work under ISO lead continued on ISO/IEC 23282 (evaluation methods for natural language processing systems, measuring the quality of results to assess functional suitability) and on ISO/IEC 24940 (terms and definitions for computer vision). ISO/IEC 24970 on AI system logging, also under ISO lead, was at a fairly advanced stage, with comment resolution since August and a slightly narrower scope: describing common capabilities and setting requirements for logging events of AI systems.

    WG4 (foundational and societal aspects). Because its topics were progressing at different speeds, WG4 decided to split the trustworthiness framework into two parts. The more advanced part covers human oversight (Article 14), transparency (Article 13) and logging (Article 12, linked with the WG3 work), and further contributions, including from civil society, were still expected. The less advanced part covers accuracy and robustness (Article 15), meaning an AI system's ability to maintain performance under its operational conditions. The framework depends heavily on characteristics developed in WG2, WG3 and WG5.

    WG4's other projects are outside the standardisation request but relevant to civil society because of their ethical dimension, and their schedules will give way to the request. The European standard on competence requirements was being retitled from "AI ethicists professionals" to "professional AI ethicists". A technical specification on environmental impact guidelines and metrics was at work item activation ballot until 19 September. A specification on tools for handling ethical issues was being outlined before activation, and one on upskilling organisations was being re-evaluated to take account of AI literacy and professionalism, together with CEN TC 428. Technical reports on fundamental rights impact assessment and on risk management in critical digital infrastructure were being prepared for possible approval as preliminary work items at a future plenary.

    WG5 (cybersecurity). The cybersecurity specifications for AI systems were to be sent to public enquiry shortly. Because cybersecurity cuts across the programme, WG5 held dedicated meetings with the other working groups, especially on risk management and quality management, covering harmonised terminology, hazardous situations and how to integrate cybersecurity risk into the general risk management standard. A draft on this was available, with a ballot expected within weeks.

    Inclusiveness survey. JTC 21 surveyed its members in the second quarter of 2025 on origin, gender, represented interest, skills and time spent. Results were published internally in August, with a synthesis promised for the next issue.

    New liaison. AIRISE, a consortium of 14 organisations from 11 countries promoting AI in manufacturing, was granted liaison status. It focuses on helping SMEs adopt AI, through scientific support, shop-floor deployment and training, with the aim of reducing waste and carbon footprint while keeping production resilient.

    ISO/IEC JTC 1/SC 42

    The next SC 42 plenary was set for Sydney, 20–24 October 2025. Following a Canadian contribution at the April plenary on lowering barriers to participation, SC 42 ran a survey until 5 September on how national bodies onboard and retain experts, with proposals to follow.

    ISO/IEC 42006:2025 on requirements for certification bodies had been published, and ISO/IEC 12792 on the transparency taxonomy was being published and was expected to influence JTC 21's work.

    Human oversight. ISO/IEC 18966 (preliminary work item) will set requirements and guidance for managing and governing human oversight of AI systems. The committee draft of ISO/IEC 42105, guidance on human control and monitoring that extends ISO/IEC TS 8200 on controllability, was approved with comments.

    Societal and ethical concerns. A committee draft of ISO/IEC 22443 was in preparation, giving organisations guidance on identifying and addressing societal concerns and ethical considerations across the AI lifecycle.

    Beneficial AI. The draft technical report ISO/IEC TR 21221 on beneficial AI systems was approved with comments. It describes functional, economic, environmental, social, societal, cultural, intellectual and personal benefits as perceived by stakeholders, with illustrative use cases.

    Foundational standards. Amendments to ISO/IEC 22989 and ISO/IEC 23053 addressing generative AI were at ballot until November. A new edition of ISO/IEC TR 24030 (use cases) was in comment resolution, and a revision of ISO/IEC 25059 (quality models for AI systems) was at final approval.

    Nudging and human-machine teaming. The committee draft of ISO/IEC 25029 on AI-enhanced nudging, including requirements for designing responsible nudging mechanisms, had gone to ballot. ISO/IEC 25589 (concepts for human-machine teaming) was in drafting, and ISO/IEC 25880 on organisational implementation of human-machine teaming was at a preliminary stage.

    Incident reporting. A new project, ISO/IEC 25870, was approved to establish a common framework for reporting AI incidents across jurisdictions and sectors.

    Implementing ISO/IEC 42001. A committee draft of ISO/IEC 42003 was in progress, giving guidance for organisations of any size, including SMEs, on implementing ISO/IEC 42001, including competencies for AI management system professionals.

    Trustworthiness fact labels. A new project, ISO/IEC 42117, will set principles and general requirements for AI trustworthiness statements and the programmes that produce them, including self-declared claims and trustworthiness fact labels.

    Fora

    The recording of the June online bootcamp on harmonised standards, covering the vademecum on European standardisation, drafting principles, normative references and Annex ZA, is available on YouTube; the slides are restricted to CEN-CENELEC members. ANEC announced a webinar on AI standards and fundamental rights for 3 October 2025, including a practical checklist for assessing whether an AI product respects fundamental rights and a group exercise, aimed at civil society, academia and public institutions. For World Standards Day (14 October), ISO/IEC JTC 1 planned virtual workshops on 15 and 16 October on privacy, AI and consumer protection. The ITU-led AI for Good Global Summit took place in Geneva on 8–11 July 2025, with the next edition set for 7–10 July 2026.

    National outreach included an event on AI ethics standards planned by the Malta Digital Innovation Authority for the last quarter of 2025. The Swedish Institute for Standards planned a presentation on ethical AI at the E-Government Days in November and a training course on AI management systems for spring 2026.

    Nice to know, useful to read

    ISO/IEC and CEN-CENELEC deliverables are now prepared exclusively on the Online Standards Development (OSD) platform, with training offered for leaders, authors and voters, orientation sessions, self-paced e-learning, and a webinar on OSD release 5.0 on 13 October 2025. A gender-responsive standardisation toolkit combines the CEN-CENELEC brochure with an ISO/IEC assessment form for checking whether gender differences may affect a new or revised standard.

    The AIQI Consortium, an international platform of quality infrastructure organisations, released a free self-paced course on ISO/IEC 42001 and was surveying AI assurance in supply chains. The issue also pointed to the ISO and UNDP guidelines, published in September 2024, on how organisations can manage and strengthen their contributions to the UN Sustainable Development Goals.

    My reading

    The comment counts are the story of this issue: more than 1,300 on the risk management draft and more than 1,100 on the quality management draft, after more than 2,000 on the trustworthiness framework earlier in the year. They reflect real engagement, but also how much of the substance was still contested at committee draft stage.

    Three decisions point towards managing delay rather than avoiding it. WG1's overview report is explicitly designed to help organisations prepare in case the harmonised standards arrive late. Moving the risk catalogue out of the risk management standard slims the normative core that must pass the Commission's assessment. And splitting the trustworthiness framework lets the more mature parts move ahead of accuracy and robustness.

    The approval of ISO/IEC 42001 as a European standard, without a single vote against, confirms the two-track picture noted in the previous issue. Europe will have one management system standard for general AI governance and another written specifically for Article 17. Within weeks of this issue, CEN-CENELEC adopted exceptional acceleration measures and the Commission proposed the Digital Omnibus. The Commission's June letter stressing the timeline reads, in hindsight, as the last warning before both.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    September 2025Where it stands now
    QMS committee draft with more than 1,100 commentsThe draft went to public enquiry from 30 October 2025 to January 2026, and EN 18286 was approved on 12 July 2026. Citation in the Official Journal is outstanding.
    Risk management committee draft with more than 1,300 commentsprEN 18228 was at public Enquiry as of June 2026.
    Cybersecurity specifications "shortly" to public enquiryprEN 18282 was at public Enquiry as of June 2026.
    Trustworthiness framework split into two partsThe split did not stop at two parts. The series now has five parts: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Conformity assessment framework at internal draft 4.0prEN 18285 (drafting).
    Datasets and bias standards well advancedprEN 18284 and prEN 18283 (both drafting). A working-draft consultation on prEN 18283 closed on 30 April 2026.
    Commission urging adherence to the timelineOn 23 October 2025, CEN-CENELEC adopted exceptional measures aiming for the prioritised deliverables to be available by Q4 2026, including a faster route to publication after a positive enquiry. On 19 November 2025, the Commission proposed the Digital Omnibus on AI, adopted as Regulation (EU) 2026/1744, which moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    ISO/IEC 42001 approved for adoption as a European standardThe Commission found ISO/IEC 42001 not aligned with the quality management system required by Article 17. EN 18286 is the dedicated route to Article 17.
    Consultation on transparency guidelines and a Code of PracticeArticle 50 obligations were not postponed by the Omnibus. Article 50(2) applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026.
    High-Level Forum recommendation on the 2026 work programmeThe 2026 Annual Union Work Programme for European standardisation was published in the Official Journal in March 2026.
    Revision of Regulation 1025/2012 "expected in mid-2026"The date has slipped. According to press reports, the Commission is expected to present a proposal in October 2026, including common specifications as a fallback and a tighter definition of "harmonised standard".
    ISO/IEC 12792 being publishedPublished as ISO/IEC 12792:2025.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    All 16 editions are listed in the news feed.