Edition 11 · November 2025
Edition 11 (November 2025): the essence
AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 11, November 2025.
prEN 18286quality management
from 30 Oct 2025
prEN 18228risk management
clauses 3-5
prEN 18229trustworthiness
parts approved
prEN 18282cybersecurity
to preview
prEN 18283bias management
working draft
prEN 18284datasets
working draft
prEN 18285conformity assessment
drafting
not started · drafting · enquiry · approved · cited in OJ
Status of the AI Act deliverables as described in Edition 11, November 2025.
1 Aug 2024
AI Act enters into force
2 Feb 2025
Prohibited practices and AI literacy apply
2 Aug 2025
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
8 months to general application, including article 50 transparency duties
You are here · 2025-11-30
1 Aug 2024 · in force
AI Act enters into force
2 Feb 2025 · in force
Prohibited practices and AI literacy apply
2 Aug 2025 · in force
GPAI model obligations, governance and penalties apply
2 Aug 2026 · next
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
8 months to general application, including article 50 transparency duties
filled = already in force · hollow = still ahead · flag = date of this issue
Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.
01 · Article 5
Is the practice on the prohibited list?
YesProhibited
It cannot be placed on the market or used at all.
NoContinue
Go to step 02.
02 · Annex I
Is the system a safety component of a product covered by Annex I, or such a product itself?
YesHigh risk
Where third-party conformity assessment is required under that product law.
NoContinue
Go to step 03.
03 · Annex III
Does the use fall in one of the listed Annex III areas?
YesPresumed high risk
Test the exceptions in step 04.
NoContinue
Skip to step 05.
04 · Article 6(3)
Does an exception apply — narrow procedural task, human review support, pattern detection, or preparatory work?
YesNot high risk
But the provider must document the assessment and register the system.
NoHigh risk
Full Chapter III duties apply.
05 · Article 50
Does the system interact with people, generate synthetic content, recognise emotions, or produce deepfakes?
YesTransparency duties
Disclosure and machine-readable marking.
NoNo specific duties
General law still applies.
work top to bottom · the first branch that ends the path decides the classification
The classification path a provider walks before deciding which duties apply.
Standards delivery to the Commission
30 April 2025
Missed — request now expires 28 February 2027
High-risk duties, Annex III use cases
2 August 2026
2 December 2027
High-risk duties, Annex I products
2 August 2027
2 August 2028
Prohibited practices and AI literacy
2 February 2025
2 February 2025 — unchanged
General-purpose AI model obligations
2 August 2025
2 August 2025 — unchanged
The duties were pushed back; the standards they depend on were not delivered on time either. The gap between the two is the story this newsletter keeps returning to.
Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026
The deadlines that moved, and where they landed.
About this issue
The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. It repeats the reminder that all ongoing projects are confidential and that details should be requested from national standards bodies.
News from the European Union
Transparency obligations. The Commission's consultation on guidelines and a Code of Practice for the AI Act's transparency obligations ran from 4 September to 9 October 2025. It drew input from providers and deployers of interactive and generative AI, biometric categorisation and emotion recognition systems, public and private organisations, researchers, civil society, supervisory authorities and citizens.
Digital Omnibus. A call for evidence, open until 14 October, gathered research and good practice on simplifying EU rules on data, cybersecurity and AI ahead of the Commission's Digital Omnibus.
Serious incidents. The Commission published draft guidance and a reporting template for serious incidents involving high-risk AI systems. Stakeholders were asked, until 7 November, how the proposed measures interact with existing incident reporting regimes.
High-Level Forum. The mandate of the High-Level Forum on European Standardisation was extended by three years (Commission Decision C(2025) 5964 of 10 September 2025). The Forum identifies standardisation priorities for EU policy and legislation and addresses horizontal issues such as international leadership, education and skills. Its Sherpa subgroups do the preparatory work, and one of its fifteen workstreams is dedicated to AI.
CEN-CENELEC JTC 21
Plenary. The next plenary was announced for Copenhagen, 18–21 November 2025, with a report to follow in Edition 12.
Technical Board decisions. The CEN-CENELEC Technical Board, which oversees the standards programme and its delivery, took two decisions to support JTC 21.
Pause on new work (30 September). While recognising that some proposals respond to market needs, the Board postponed the registration of any new work item not directly linked to the AI standardisation request (M/593 and its amendment). The pause lasts until public enquiry on the mandated standards is complete, meaning that the responsible working group must finish resolving the enquiry comments before starting any new proposal.
Exceptional acceleration measures (14–16 October). Where the public enquiry vote is positive, draft standards may be published directly without a formal vote. JTC 21 was also asked to set up small drafting groups of already active experts to finalise six of the most delayed drafts, before returning them to the working groups for information and final comments.
The newsletter noted that some experts in the working groups had concerns about these decisions, and that the JTC 21 chair, with the convenors and project leaders, had prepared an implementation plan taking those concerns into account.
WG1 (strategic advisory). The new work item for a technical report, Overview and architecture of standards in support of the EU AI Act, was approved with comments, now being resolved. The report is intended to help organisations prepare for the harmonised standards and to soften the effect of publication delays. It will explain what to expect, provide essential terminology, concepts and background, and describe the technical nature of the requirements, such as those on design, development, monitoring and documentation.
WG2 (operational aspects). On 14 October, WG2 reached unanimous agreement on the draft of the quality management system standard supporting Article 17. The draft was submitted to public enquiry, open until 22 January 2026. On risk management, the group had resolved the reconsideration requests on clause 3 (definitions) and clause 4 (requirements for the risk management system), and was working through those on clause 5 (the risk management process).
WG3 (engineering aspects). Working drafts of the datasets standard and the bias standard were tentatively expected in December 2025, and a committee draft on computer vision in November. Two natural language processing documents developed in parallel under ISO lead, ISO/IEC TR 23281 (overview of NLP tasks and functionalities) and prEN ISO/IEC 23282 (evaluation methods for accurate NLP systems), were out for committee draft consultation. The draft international standard ISO/IEC 24970 on AI system logging was registered on 17 September, with a three-month ballot opening on 18 November, and WG3 experts were encouraged to work with their national bodies on it. A draft international standard ballot on ISO/IEC 24029-3 (statistical methods for assessing the robustness of neural networks) was expected in November.
WG4 (foundational and societal aspects). A new work item for a European standard on guidelines and metrics for the environmental impact of AI systems and services was approved with comments. New scopes were approved for two parts of the trustworthiness framework: prEN 18229-1, Logging, transparency and human oversight, providing terminology, concepts, requirements and guidance on transparency, logging and human oversight of AI systems, primarily intended for organisations placing AI systems on the market or putting them into service, and not sector-specific; and prEN 18229-2, Accuracy and robustness, providing terminology, concepts, requirements and guidance on the accuracy and robustness of AI systems, with the rest of the scope identical to Part 1.
In addition, prEN 18274, Competence requirements for professional AI ethicists, was at public enquiry from 18 September to 11 December 2025.
WG5 (cybersecurity). WG5 completed its alignment discussions with the other working groups. The draft Cybersecurity specifications for AI systems was shared with the JTC 21 leadership and the Commission for preview before public enquiry.
ISO/IEC JTC 1/SC 42
The SC 42 plenary took place in Sydney, 20–24 October 2025. No newsletter contributors attended in person, so the report draws on meeting documents and covers only items relevant to civil society.
Published. ISO/IEC TS 6254:2025 (explainability and interpretability), ISO/IEC TR 21221 (beneficial AI systems) and ISO/IEC 42006:2025 (requirements for certification bodies). ISO/IEC 12792 (transparency taxonomy) was ready for publication after significant administrative delays.
WG1 (foundational standards). Work continued on the taxonomy of AI methods and capabilities (ISO/IEC 42102), AI system logging, implementation guidance for ISO/IEC 42001 (ISO/IEC 42003), a reporting framework for AI incidents (ISO/IEC 25870) and an SME handbook for ISO/IEC 42001. New amendments to ISO/IEC 22989 and ISO/IEC 23053 will add concepts and terminology for agentic AI.
WG2 (data). Work continued on a visualisation framework for data quality (ISO/IEC TR 5259-6) and on output data quality for generative AI applications (ISO/IEC 25590).
WG3 (trustworthiness). Advanced stages: ISO/IEC 42105 on human oversight was at final ballot, and the committee draft of ISO/IEC 25029 on AI-enhanced nudging was accepted with comments. Under development: governance and management of human oversight (ISO/IEC 18966), societal and ethical concerns (ISO/IEC TS 22443), risks in generative AI (ISO/IEC TS 25568) and a template for documenting ethical issues (ISO/IEC TS 25571). New projects: trustworthiness fact labels (ISO/IEC 42117), management and governance aspects of AI resilience assessment (ISO/IEC 25864-2) and reliability assessment (ISO/IEC TS 25570).
WG4 (use cases). Work continued on a framework for human-machine teaming (ISO/IEC 25589) and on human-machine teaming use cases (ISO/IEC TR 42109).
Joint working groups. On testing, two technical specifications were close to publication: ISO/IEC TS 42119-2 (overview of testing AI systems) and TS 42119-3 (verification and validation analysis). Parts on red teaming (TS 42119-7) and quality assessment of prompt-based generative text systems (TS 42119-8) were in development, and a process assessment model for AI lifecycle processes (ISO/IEC 25704) was to follow. On functional safety, the three-part ISO/IEC TS 22440 series (requirements, guidance, examples) was under development.
Sector-specific work. A joint working group for financial services was preparing ISO/AWI TR 24492 on standardisation needs for AI in that sector. A healthcare joint working group was working on healthcare terminology (ISO/IEC 22989-2) and AI in health informatics (ISO/IEC TR 18988), with new projects planned on bias in healthcare organisations, classification and use cases of generative AI in healthcare, and safety and reliability evaluation of generative AI in healthcare.
Fora
On 3 October 2025, ANEC held a public webinar on fundamental rights and AI Act standards from a consumer protection perspective. It presented a Fundamental Rights Checklist for assessing whether AI standards adequately protect consumer and human rights, and a case study on AI in financial services showed the practical tensions between risk management, bias prevention and trustworthiness. The materials and checklist are available on ANEC's website.
The CEN-CENELEC Harmonised Standards Compliance Team announced online training for Annex III organisations on Annex ZA, the annex that cross-references a candidate harmonised standard to the relevant EU legislation, for 1 December 2025. Small Business Standards ran the third edition of its Meeting Standards week for SMEs, 17–21 November 2025.
Nice to know, useful to read
European Ombudswoman Teresa Anjinho opened an inquiry into how the Commission ensures transparency, inclusiveness and accountability in the adoption of harmonised standards for AI. ISO published a policy brief on how consensus-based international standards turn high-level AI principles into practical requirements. And a global call for AI "red lines", launched at the 80th UN General Assembly with the support of more than 300 prominent individuals and more than 90 organisations, urged governments to agree enforceable international limits on AI by the end of 2026.
My reading
This issue records the moment the governance of AI standardisation itself changed. The Technical Board's two decisions pull in the same direction. New work outside the standardisation request is frozen until the mandated standards have passed enquiry, which in practice sidelines most of WG4's ethics and fundamental rights projects. And the acceleration package lets a positive enquiry lead straight to publication and hands the six most delayed drafts to small groups of experts already involved.
Both decisions are understandable given the deadlines. Both also narrow participation at exactly the moment the Ombudswoman opened an inquiry into the transparency and inclusiveness of the process. The newsletter's brief note that some experts had concerns, and that the chair had prepared an implementation plan in response, is worth reading carefully. Speed and inclusiveness were now openly in tension, and speed had been given priority.
Two details are also worth flagging. The approved scopes for prEN 18229 are aimed primarily at organisations placing AI systems on the market or putting them into service, which is a provider-centred framing similar to that of EN 18286. And SC 42's decision to add terminology for agentic AI to its foundational standards is an early sign that the vocabulary on which the harmonised standards rest will keep moving.
For the live status of each standard, see the Standards Explorer.
Since then (status September 2026)
| November 2025 | Where it stands now |
|---|---|
| QMS draft at public enquiry until 22 January 2026 | EN 18286 was approved on 12 July 2026, the first JTC 21 AI Act standard to reach that point. Citation in the Official Journal is outstanding. |
| Risk management: reconsideration requests being resolved | prEN 18228 was at public Enquiry as of June 2026. |
| Cybersecurity draft shared for preview before enquiry | prEN 18282 was at public Enquiry as of June 2026. |
| prEN 18229 in two parts (logging, transparency and human oversight; accuracy and robustness) | The structure changed again in 2026. According to a JTC 21 project editor, the series now has five parts: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached enquiry in July 2026. |
| Datasets and bias working drafts expected in December 2025 | prEN 18284 and prEN 18283 were still in drafting as of June 2026. A working-draft consultation on prEN 18283 closed on 30 April 2026. |
| Technical Board acceleration measures | CEN-CENELEC aims for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027. |
| Call for evidence for the Digital Omnibus | The Commission proposed the Digital Omnibus on AI on 19 November 2025. It was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, moving high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). |
| Ombudswoman inquiry into AI harmonised standards | Registered as case 1974/2025/MIK and opened on 26 September 2025, following a complaint by Corporate Europe Observatory about undisclosed participants, unpublished minutes and unbalanced representation. The Ombudswoman's 2025 annual report lists it among her main AI inquiries. I have not found a published outcome. |
| ISO/IEC 12792 ready for publication after delays | Published by ISO in November 2025 and adopted as EN ISO/IEC 12792:2025. |
| Consultation on transparency guidelines and a Code of Practice | Article 50 obligations were not postponed by the Omnibus. Article 50(2) applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026. |
Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.