AI Standardisation Watch

    Edition 11 · November 2025

    Edition 11 (November 2025): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 11, November 2025.

    Pipeline at this issue

    prEN 18286quality management

    from 30 Oct 2025

    prEN 18228risk management

    clauses 3-5

    prEN 18229trustworthiness

    parts approved

    prEN 18282cybersecurity

    to preview

    prEN 18283bias management

    working draft

    prEN 18284datasets

    working draft

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 11, November 2025.

    AI Act timeline

    You are here · 2025-11-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · in force

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026 · next

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    8 months to general application, including article 50 transparency duties

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Is the system high risk?
    1. 01 · Article 5

      Is the practice on the prohibited list?

      Yes

      Prohibited

      It cannot be placed on the market or used at all.

      No

      Continue

      Go to step 02.

    2. 02 · Annex I

      Is the system a safety component of a product covered by Annex I, or such a product itself?

      Yes

      High risk

      Where third-party conformity assessment is required under that product law.

      No

      Continue

      Go to step 03.

    3. 03 · Annex III

      Does the use fall in one of the listed Annex III areas?

      Yes

      Presumed high risk

      Test the exceptions in step 04.

      No

      Continue

      Skip to step 05.

    4. 04 · Article 6(3)

      Does an exception apply — narrow procedural task, human review support, pattern detection, or preparatory work?

      Yes

      Not high risk

      But the provider must document the assessment and register the system.

      No

      High risk

      Full Chapter III duties apply.

    5. 05 · Article 50

      Does the system interact with people, generate synthetic content, recognise emotions, or produce deepfakes?

      Yes

      Transparency duties

      Disclosure and machine-readable marking.

      No

      No specific duties

      General law still applies.

    work top to bottom · the first branch that ends the path decides the classification

    The classification path a provider walks before deciding which duties apply.

    The deadlines that moved
    ObligationOriginallyNow

    Standards delivery to the Commission

    30 April 2025

    Missed — request now expires 28 February 2027

    High-risk duties, Annex III use cases

    2 August 2026

    2 December 2027

    High-risk duties, Annex I products

    2 August 2027

    2 August 2028

    Prohibited practices and AI literacy

    2 February 2025

    2 February 2025 — unchanged

    General-purpose AI model obligations

    2 August 2025

    2 August 2025 — unchanged

    The duties were pushed back; the standards they depend on were not delivered on time either. The gap between the two is the story this newsletter keeps returning to.

    Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026

    The deadlines that moved, and where they landed.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. It repeats the reminder that all ongoing projects are confidential and that details should be requested from national standards bodies.

    News from the European Union

    Transparency obligations. The Commission's consultation on guidelines and a Code of Practice for the AI Act's transparency obligations ran from 4 September to 9 October 2025. It drew input from providers and deployers of interactive and generative AI, biometric categorisation and emotion recognition systems, public and private organisations, researchers, civil society, supervisory authorities and citizens.

    Digital Omnibus. A call for evidence, open until 14 October, gathered research and good practice on simplifying EU rules on data, cybersecurity and AI ahead of the Commission's Digital Omnibus.

    Serious incidents. The Commission published draft guidance and a reporting template for serious incidents involving high-risk AI systems. Stakeholders were asked, until 7 November, how the proposed measures interact with existing incident reporting regimes.

    High-Level Forum. The mandate of the High-Level Forum on European Standardisation was extended by three years (Commission Decision C(2025) 5964 of 10 September 2025). The Forum identifies standardisation priorities for EU policy and legislation and addresses horizontal issues such as international leadership, education and skills. Its Sherpa subgroups do the preparatory work, and one of its fifteen workstreams is dedicated to AI.

    CEN-CENELEC JTC 21

    Plenary. The next plenary was announced for Copenhagen, 18–21 November 2025, with a report to follow in Edition 12.

    Technical Board decisions. The CEN-CENELEC Technical Board, which oversees the standards programme and its delivery, took two decisions to support JTC 21.

    Pause on new work (30 September). While recognising that some proposals respond to market needs, the Board postponed the registration of any new work item not directly linked to the AI standardisation request (M/593 and its amendment). The pause lasts until public enquiry on the mandated standards is complete, meaning that the responsible working group must finish resolving the enquiry comments before starting any new proposal.

    Exceptional acceleration measures (14–16 October). Where the public enquiry vote is positive, draft standards may be published directly without a formal vote. JTC 21 was also asked to set up small drafting groups of already active experts to finalise six of the most delayed drafts, before returning them to the working groups for information and final comments.

    The newsletter noted that some experts in the working groups had concerns about these decisions, and that the JTC 21 chair, with the convenors and project leaders, had prepared an implementation plan taking those concerns into account.

    WG1 (strategic advisory). The new work item for a technical report, Overview and architecture of standards in support of the EU AI Act, was approved with comments, now being resolved. The report is intended to help organisations prepare for the harmonised standards and to soften the effect of publication delays. It will explain what to expect, provide essential terminology, concepts and background, and describe the technical nature of the requirements, such as those on design, development, monitoring and documentation.

    WG2 (operational aspects). On 14 October, WG2 reached unanimous agreement on the draft of the quality management system standard supporting Article 17. The draft was submitted to public enquiry, open until 22 January 2026. On risk management, the group had resolved the reconsideration requests on clause 3 (definitions) and clause 4 (requirements for the risk management system), and was working through those on clause 5 (the risk management process).

    WG3 (engineering aspects). Working drafts of the datasets standard and the bias standard were tentatively expected in December 2025, and a committee draft on computer vision in November. Two natural language processing documents developed in parallel under ISO lead, ISO/IEC TR 23281 (overview of NLP tasks and functionalities) and prEN ISO/IEC 23282 (evaluation methods for accurate NLP systems), were out for committee draft consultation. The draft international standard ISO/IEC 24970 on AI system logging was registered on 17 September, with a three-month ballot opening on 18 November, and WG3 experts were encouraged to work with their national bodies on it. A draft international standard ballot on ISO/IEC 24029-3 (statistical methods for assessing the robustness of neural networks) was expected in November.

    WG4 (foundational and societal aspects). A new work item for a European standard on guidelines and metrics for the environmental impact of AI systems and services was approved with comments. New scopes were approved for two parts of the trustworthiness framework: prEN 18229-1, Logging, transparency and human oversight, providing terminology, concepts, requirements and guidance on transparency, logging and human oversight of AI systems, primarily intended for organisations placing AI systems on the market or putting them into service, and not sector-specific; and prEN 18229-2, Accuracy and robustness, providing terminology, concepts, requirements and guidance on the accuracy and robustness of AI systems, with the rest of the scope identical to Part 1.

    In addition, prEN 18274, Competence requirements for professional AI ethicists, was at public enquiry from 18 September to 11 December 2025.

    WG5 (cybersecurity). WG5 completed its alignment discussions with the other working groups. The draft Cybersecurity specifications for AI systems was shared with the JTC 21 leadership and the Commission for preview before public enquiry.

    ISO/IEC JTC 1/SC 42

    The SC 42 plenary took place in Sydney, 20–24 October 2025. No newsletter contributors attended in person, so the report draws on meeting documents and covers only items relevant to civil society.

    Published. ISO/IEC TS 6254:2025 (explainability and interpretability), ISO/IEC TR 21221 (beneficial AI systems) and ISO/IEC 42006:2025 (requirements for certification bodies). ISO/IEC 12792 (transparency taxonomy) was ready for publication after significant administrative delays.

    WG1 (foundational standards). Work continued on the taxonomy of AI methods and capabilities (ISO/IEC 42102), AI system logging, implementation guidance for ISO/IEC 42001 (ISO/IEC 42003), a reporting framework for AI incidents (ISO/IEC 25870) and an SME handbook for ISO/IEC 42001. New amendments to ISO/IEC 22989 and ISO/IEC 23053 will add concepts and terminology for agentic AI.

    WG2 (data). Work continued on a visualisation framework for data quality (ISO/IEC TR 5259-6) and on output data quality for generative AI applications (ISO/IEC 25590).

    WG3 (trustworthiness). Advanced stages: ISO/IEC 42105 on human oversight was at final ballot, and the committee draft of ISO/IEC 25029 on AI-enhanced nudging was accepted with comments. Under development: governance and management of human oversight (ISO/IEC 18966), societal and ethical concerns (ISO/IEC TS 22443), risks in generative AI (ISO/IEC TS 25568) and a template for documenting ethical issues (ISO/IEC TS 25571). New projects: trustworthiness fact labels (ISO/IEC 42117), management and governance aspects of AI resilience assessment (ISO/IEC 25864-2) and reliability assessment (ISO/IEC TS 25570).

    WG4 (use cases). Work continued on a framework for human-machine teaming (ISO/IEC 25589) and on human-machine teaming use cases (ISO/IEC TR 42109).

    Joint working groups. On testing, two technical specifications were close to publication: ISO/IEC TS 42119-2 (overview of testing AI systems) and TS 42119-3 (verification and validation analysis). Parts on red teaming (TS 42119-7) and quality assessment of prompt-based generative text systems (TS 42119-8) were in development, and a process assessment model for AI lifecycle processes (ISO/IEC 25704) was to follow. On functional safety, the three-part ISO/IEC TS 22440 series (requirements, guidance, examples) was under development.

    Sector-specific work. A joint working group for financial services was preparing ISO/AWI TR 24492 on standardisation needs for AI in that sector. A healthcare joint working group was working on healthcare terminology (ISO/IEC 22989-2) and AI in health informatics (ISO/IEC TR 18988), with new projects planned on bias in healthcare organisations, classification and use cases of generative AI in healthcare, and safety and reliability evaluation of generative AI in healthcare.

    Fora

    On 3 October 2025, ANEC held a public webinar on fundamental rights and AI Act standards from a consumer protection perspective. It presented a Fundamental Rights Checklist for assessing whether AI standards adequately protect consumer and human rights, and a case study on AI in financial services showed the practical tensions between risk management, bias prevention and trustworthiness. The materials and checklist are available on ANEC's website.

    The CEN-CENELEC Harmonised Standards Compliance Team announced online training for Annex III organisations on Annex ZA, the annex that cross-references a candidate harmonised standard to the relevant EU legislation, for 1 December 2025. Small Business Standards ran the third edition of its Meeting Standards week for SMEs, 17–21 November 2025.

    Nice to know, useful to read

    European Ombudswoman Teresa Anjinho opened an inquiry into how the Commission ensures transparency, inclusiveness and accountability in the adoption of harmonised standards for AI. ISO published a policy brief on how consensus-based international standards turn high-level AI principles into practical requirements. And a global call for AI "red lines", launched at the 80th UN General Assembly with the support of more than 300 prominent individuals and more than 90 organisations, urged governments to agree enforceable international limits on AI by the end of 2026.

    My reading

    This issue records the moment the governance of AI standardisation itself changed. The Technical Board's two decisions pull in the same direction. New work outside the standardisation request is frozen until the mandated standards have passed enquiry, which in practice sidelines most of WG4's ethics and fundamental rights projects. And the acceleration package lets a positive enquiry lead straight to publication and hands the six most delayed drafts to small groups of experts already involved.

    Both decisions are understandable given the deadlines. Both also narrow participation at exactly the moment the Ombudswoman opened an inquiry into the transparency and inclusiveness of the process. The newsletter's brief note that some experts had concerns, and that the chair had prepared an implementation plan in response, is worth reading carefully. Speed and inclusiveness were now openly in tension, and speed had been given priority.

    Two details are also worth flagging. The approved scopes for prEN 18229 are aimed primarily at organisations placing AI systems on the market or putting them into service, which is a provider-centred framing similar to that of EN 18286. And SC 42's decision to add terminology for agentic AI to its foundational standards is an early sign that the vocabulary on which the harmonised standards rest will keep moving.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    November 2025Where it stands now
    QMS draft at public enquiry until 22 January 2026EN 18286 was approved on 12 July 2026, the first JTC 21 AI Act standard to reach that point. Citation in the Official Journal is outstanding.
    Risk management: reconsideration requests being resolvedprEN 18228 was at public Enquiry as of June 2026.
    Cybersecurity draft shared for preview before enquiryprEN 18282 was at public Enquiry as of June 2026.
    prEN 18229 in two parts (logging, transparency and human oversight; accuracy and robustness)The structure changed again in 2026. According to a JTC 21 project editor, the series now has five parts: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached enquiry in July 2026.
    Datasets and bias working drafts expected in December 2025prEN 18284 and prEN 18283 were still in drafting as of June 2026. A working-draft consultation on prEN 18283 closed on 30 April 2026.
    Technical Board acceleration measuresCEN-CENELEC aims for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027.
    Call for evidence for the Digital OmnibusThe Commission proposed the Digital Omnibus on AI on 19 November 2025. It was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, moving high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    Ombudswoman inquiry into AI harmonised standardsRegistered as case 1974/2025/MIK and opened on 26 September 2025, following a complaint by Corporate Europe Observatory about undisclosed participants, unpublished minutes and unbalanced representation. The Ombudswoman's 2025 annual report lists it among her main AI inquiries. I have not found a published outcome.
    ISO/IEC 12792 ready for publication after delaysPublished by ISO in November 2025 and adopted as EN ISO/IEC 12792:2025.
    Consultation on transparency guidelines and a Code of PracticeArticle 50 obligations were not postponed by the Omnibus. Article 50(2) applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    All 16 editions are listed in the news feed.