Edition 13 · February 2026
Edition 13 (February 2026): the essence
AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 13, February 2026. Includes a figure mapping AI Act requirements to the standards expected to support them.
prEN 18286quality management
enquiry failed
prEN 18228risk management
to Commission
prEN 18229trustworthiness
to Commission
prEN 18282cybersecurity
drafting
prEN 18283bias management
Delft workshop
prEN 18284datasets
Delft workshop
prEN 18285conformity assessment
drafting
not started · drafting · enquiry · approved · cited in OJ
Status of the AI Act deliverables as described in Edition 13, February 2026.
1 Aug 2024
AI Act enters into force
2 Feb 2025
Prohibited practices and AI literacy apply
2 Aug 2025
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
5 months to general application, including article 50 transparency duties
You are here · 2026-02-28
1 Aug 2024 · in force
AI Act enters into force
2 Feb 2025 · in force
Prohibited practices and AI literacy apply
2 Aug 2025 · in force
GPAI model obligations, governance and penalties apply
2 Aug 2026 · next
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
5 months to general application, including article 50 transparency duties
filled = already in force · hollow = still ahead · flag = date of this issue
Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.
01 · Provider
Develops or places the system on the market
- Risk and quality management
- Technical documentation
- Conformity assessment, CE marking, registration
02 · Importer
Brings a third-country system into the Union
- Verifies assessment and documentation
- Checks marking and representative
- Keeps records, cooperates with authorities
03 · Distributor
Makes the system available down the chain
- Checks marking and accompanying documents
- Acts on non-conformity it becomes aware of
- Storage and transport conditions
04 · Deployer
Uses the system under its own authority
- Follows instructions, ensures human oversight
- Input data relevance, log keeping
- FRIA where required (Article 27)
The chain can flip · Article 25
A deployer, importer or distributor becomes the provider — with every provider duty attached — when it puts its own name or trade mark on a high-risk system, changes its intended purpose, or substantially modifies it.
Authorised Representative
Appointed by a third-country provider
- Holds documentation for ten years
- Point of contact for authorities
Operator
Umbrella term covering every role in the chain
- Used where a duty applies regardless of role
duties travel left to right along the chain
How duties travel along the supply chain, and where a role changes hands.
Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.
Strategic advisory
Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.
Main deliverables
prCEN/CLC/TR 18347
Operational aspects
Quality management, risk management and conformity assessment.
Main deliverables
EN 18286 · prEN 18228 · prEN 18285
Engineering aspects
Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.
Main deliverables
prEN 18284 · prEN 18283 · ISO/IEC 24970
Foundational and societal aspects
Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.
Main deliverables
prEN 18229-1 to 18229-5
Cybersecurity
Security of AI systems; formed later than the other four groups.
Main deliverables
prEN 18282
five working groups · one shared deadline
Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.
Risk management system
prEN 18228
ISO/IEC 23894
Data and data governance
prEN 18284
prEN 18283 · ISO/IEC TS 12791
Record-keeping and logging
prEN 18229-1
—
Transparency to deployers
prEN 18229-2
ISO/IEC 12792
Human oversight
prEN 18229-3
—
Accuracy and robustness
prEN 18229-4 · 18229-5
ISO/IEC 24029-2 · 4213
Cybersecurity
prEN 18282
ISO/IEC 27090
Quality management system
prEN 18286
—
Conformity assessment
prEN 18285
—
left: the legal requirement · middle: the standard seeking presumption · right: standards referenced but without legal effect
Which draft standard answers which requirement of the AI Act.
Trustworthiness, first draft (comments reported February 2025) prEN 18229
over 2,000 comments
Restructured afterwards
Risk management, committee draft prEN 18228
1,300 comments
Moved on to enquiry
Quality management, committee draft prEN 18286
1,100 comments
Moved on to enquiry
Quality management, public enquiry, January 2026 EN 18286
1,288 comments
Failed on both country count and weighted population
Logging (prEN 18229-1), public enquiry, August 2026 prEN 18229-1
443 comments
Rejected on weighted population
number of comments received on each draft · red marks a vote that did not pass
How much friction each draft met during comment rounds and voting.
Standards delivery to the Commission
30 April 2025
Missed — request now expires 28 February 2027
High-risk duties, Annex III use cases
2 August 2026
2 December 2027
High-risk duties, Annex I products
2 August 2027
2 August 2028
Prohibited practices and AI literacy
2 February 2025
2 February 2025 — unchanged
General-purpose AI model obligations
2 August 2025
2 August 2025 — unchanged
The duties were pushed back; the standards they depend on were not delivered on time either. The gap between the two is the story this newsletter keeps returning to.
Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026
The deadlines that moved, and where they landed.
Inclusiveness survey
146/195
75% of eligible JTC 21 members and observers answered the spring 2025 survey.
120+
Turin plenary
participants from 21 countries
150+
Bath plenary
participants from 20+ countries
800+
ISO/IEC SC 42
registered experts, 70 national bodies
350+
Civil society webinars
participants at the largest sessions
Newsletter reach, edition by edition
figures as reported in the newsletter
Who takes part, and how far the work reaches.
About this issue
The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. As before, it notes that ongoing projects are confidential and that details should be requested from national standards bodies.
News from the European Union
High-Level Forum. The Forum's Sherpa subgroup, its main operational body, held its 12th meeting online on 10 February 2026. It discussed the Forum's work programme for 2026–2028, wrapped up the activities of its first mandate, and prepared the 4th Forum meeting, scheduled for 19 March in Brussels.
Final report of Workstream 12 on AI. The workstream aimed to raise awareness of the AI standards being developed under the Commission's request, encourage broader participation, and improve understanding of their scope. Its final report gives an overview of the outreach carried out on the AI Act, the standardisation request, and the role of JTC 21 working with ISO/IEC JTC 1/SC 42.
CEN-CENELEC JTC 21
Inclusiveness survey. The survey carried out in spring 2025 received 146 responses from the 195 eligible JTC 21 members and observers. The newsletter cautions that representativeness cannot be fully guaranteed, but says the results show strengths, gaps and opportunities for more equitable participation. A summary is on the JTC 21 website.
Next plenary. The next plenary was to be held online on 11–13 March 2026.
Overall progress. Work on the standards supporting the AI Act had accelerated considerably since December 2025.
WG1 (strategic advisory). The Commission reviewed the final version of the technical report Overview and architecture of standards in support of the AI Act before its public enquiry. The report presents the standards being prepared under the standardisation request C(2025) 3871 and explains how they relate to each other and to the requirements of the Act.
Working group reports
WG2 (operational aspects). Risk management. prEN 18228 was finalised in December 2025 and submitted to the Commission ahead of public enquiry, with a revised scope awaiting approval. It sets requirements and practical guidance for identifying, addressing and mitigating risk across the AI lifecycle, for a broad range of AI-based products and services, with explicit attention to vulnerable people. It covers risks to health and safety and to fundamental rights, with potential impacts on individuals, organisations, markets and society. It also sets out methods for determining whether a set of risk management measures can keep identified risks monitored and managed at an acceptable level.
Quality management system. The public enquiry on prEN 18286 closed at the end of January 2026, and the draft did not obtain the required approval, failing both the count of national members in favour and the weighted population criterion. It received 1,288 comments. The project editor had prepared proposed resolutions for all of them, and requests for reconsideration were to be handled at a five-day hybrid meeting in London from 2 to 6 March.
ISO/IEC 42001. The enquiry on direct adoption of ISO/IEC 42001 ran until 12 February. The newsletter repeated that it is not intended to be harmonised under the AI Act. EN 18286 is the candidate harmonised standard for the Act's requirements in this area, including those relating to health, safety and fundamental rights.
WG3 (engineering aspects). Bias. prEN 18283 defines concepts, measures and requirements for assessing and treating bias not intended by the provider or deployer under their specification of the AI system. It covers data-related bias, including bias in datasets used to develop, train or assess AI systems, and system or model bias arising from algorithmic factors such as design choices.
Datasets. prEN 18284 sets guidance and requirements for creating and managing datasets, including design choices, collection and preparation, and defines metrics for representativeness, relevance, completeness and correctness across training, validation and test data, for any AI technology.
Timeline for both. The two drafts were reviewed in depth at a three-day hybrid workshop in Delft in early January. Further adjustments were being made, with the aim of submitting them to the Commission ahead of public enquiry by 15 June 2026.
Natural language processing. ISO/IEC TR 23281 (overview of NLP tasks, including the effects of language diversity across all languages, dialects and variants, official or not) and prEN ISO/IEC 23282 (evaluation methods for NLP systems, including requirements on implementing metrics and on the technical resources used in evaluation) were both approved with comments.
Logging. prEN ISO/IEC 24970 was at European enquiry until 10 February, as a parallel project under SC 42 lead. It describes common capabilities, requirements and an information model for logging events in AI systems, for use together with a risk management system. Subject to a positive Commission assessment, it was expected to support Article 12 at least in part.
WG4 (foundational and societal aspects). prEN 18229-1 (Logging, transparency and human oversight). The revised draft with the editor's responses was circulated in December. Reconsideration requests were received until 4 January and reviewed on 7 and 9 January, after which the final working group version was sent to the Commission ahead of enquiry.
prEN 18229-2 (Accuracy and robustness). The revised draft was also circulated in December. Reconsideration requests closed on 27 January and were reviewed on 28 and 30 January, and the final version was due to go to the Commission at about the time the newsletter was published.
prEN 18274 (Competence requirements for professional AI ethicists). The draft was approved at enquiry with comments. It sets out the knowledge, skills and attitudes required of AI ethicists, including a strong understanding of European values and fundamental rights. The editor's proposed disposition of comments was published on 13 January, with further contributions invited until 5 February, reconsideration requests until 10 February, and discussion on 12 February.
WG5 (cybersecurity). COBALT, an EU Horizon project on cybersecurity certification of ICT using decentralised digital twins, was granted liaison status.
ISO/IEC JTC 1/SC 42 (selected work)
Ballots and advanced drafts. Data quality visualisation. The draft technical report ISO/IEC 5259-6, a visualisation framework for assessing the results of data quality measures, was at ballot until 19 February.
Robustness. ISO/IEC 24029-3, on statistical methods for assessing neural network robustness, was at ballot until 27 April.
Human oversight. ISO/IEC 42105 was at ballot until 19 February.
Nudging. Comment resolution on ISO/IEC 25029 was due to finish in early March, before a draft international standard ballot. The standard is meant to support both organisations using AI-enhanced nudges and those protecting consumers, workers and the public.
Conformity assessment schemes. The committee draft of the high-level framework for developing conformity assessment schemes for AI systems (listed here as ISO/IEC 42107) was approved with comments.
Human-machine teaming use cases. The draft technical report ISO/IEC 42109 was collecting use cases from many sectors, structured by relation type, objective, data characteristics, stakeholder considerations and trustworthiness considerations, in coordination with ISO/IEC 25589 and ISO/IEC 25880.
New projects. Human-machine teaming. A ballot on ISO/IEC 25880, requirements and guidance for organisational implementation of human-machine teaming, ran until 20 April.
Large language models. ISO/IEC 26200, a framework for evaluation, ethical use and interoperability of LLMs, was approved. It will cover testing methods, performance criteria, bias mitigation, risk management, security, sector-specific applications and regulatory alignment.
Bias in healthcare. ISO/IEC TS 26312, on how healthcare organisations should identify and address bias in AI during procurement, implementation and monitoring, was at new-project ballot. It covers algorithmic, data representation, labelling and deployment-related bias in clinician- and patient-facing applications. The newsletter noted that the healthcare sector is very active in AI standardisation.
Functional correctness. ISO/IEC 26582, on conformity assessment of the functional correctness of AI systems based on the ISO/IEC 25059 quality models, was at ballot until 29 April.
Fora
On 3 February, ANEC and the EU Fundamental Rights Agency held a webinar on FRA's report Assessing High-risk Artificial Intelligence: Fundamental Rights Risks. Based on interviews with providers, deployers and experts in education, employment, migration, law enforcement and public benefits, the report argues that a fundamental rights approach to AI is feasible and supports the trust needed for innovation and competitiveness.
Nice to know, useful to read
The issue pointed to NIST's Generative Artificial Intelligence Profile (NIST AI 600-1, July 2024) under the AI Risk Management Framework, and to a December 2025 report by the EU-funded law enforcement network CYCLOPES with standardisation recommendations based on practitioners' needs in fighting cybercrime.
It also highlighted a December 2025 guide by the Danish Institute for Human Rights and the European Center for Not-for-Profit Law on fundamental rights impact assessments under the AI Act. The guide treats the FRIA as a decision point before deployment, involving scoping, structured deliberation on the severity and likelihood of harms with affected people and rights experts, mitigation and monitoring, public transparency and thorough documentation. It stresses that FRIAs work best when embedded in an organisation-wide AI governance strategy with clear roles and resources.
My reading
The headline is easy to miss: the quality management standard, the first harmonised AI Act standard to reach public enquiry, failed its enquiry vote on both the number of national members and the weighted population criterion, with 1,288 comments. That matters for two reasons. It shows that national standards bodies were not willing to wave the first harmonised standard through, whatever the time pressure. And because the Technical Board's fast track to publication applies only after a positive enquiry, EN 18286 had to go the longer way, through reconsideration and a formal vote.
The figure on the last page deserves close reading. It confirms that EN 18286 is mapped not only to Article 17(1) but also to Articles 11(1) and 72, which is broader than a pure quality management standard. It shows prEN 18283 on bias and prEN 18285 on conformity assessment as referenced documents that do not seek presumption of conformity, with bias under Article 10 carried instead by the datasets standard. And it shows ISO/IEC 24970 on logging in the same non-presumptive role, even though the text says it may support Article 12 subject to the Commission's assessment. Readers relying on any of these standards for compliance should check which role each one is intended to play.
Finally, the new scope of prEN 18228 names fundamental rights risks explicitly and includes methods for judging whether residual risk is acceptable. That is a substantive answer, in the text of the standard itself, to the criticism that standards cannot carry fundamental rights obligations.
Which standards are meant to carry presumption of conformity
| AI Act requirement | Standard seeking presumption of conformity | Referenced standards not seeking presumption |
|---|---|---|
| Quality management (Art. 17) | prEN 18286, mapped to Art. 17(1), Art. 11(1) and Art. 72, and linked to prEN 18228 | — |
| Risk management (Art. 9) | prEN 18228 | — |
| Data quality (Art. 10) | prEN 18284 | prEN 18283 (bias management, Art. 10(2)(f)–(g)); ISO/IEC TS 12791:2024 |
| Record keeping (Art. 12) | prEN 18229-1 (Arts. 12–14) | prEN ISO/IEC 24970 (AI system logging) |
| Transparency (Art. 13) | prEN 18229-1 (Arts. 12–14) | ISO/IEC 12792 (transparency taxonomy) |
| Human oversight (Art. 14) | prEN 18229-1 (Arts. 12–14) | — |
| Robustness (Art. 15) | prEN 18229-2 | ISO/IEC 24029-2:2023 and ISO/IEC 24029-3 (neural network robustness) |
| Accuracy (Art. 15) | prEN 18229-2 | ISO/IEC 4213 (classification performance); prEN ISO/IEC 23282 (NLP evaluation); prEN 18281 (computer vision evaluation) |
| Cybersecurity (Art. 15) | prEN 18282 | — |
| Conformity assessment (Art. 43) | — | prEN 18285 |
A figure accompanying the technical report maps each area of the standardisation request to the standards expected to support it. It distinguishes standards that seek to provide presumption of conformity from referenced standards that do not. The figure notes that the Annex ZA of each harmonised standard gives the detailed mapping of clauses to legal requirements, and that presumption applies only after citation in the Official Journal.
For the live status of each standard, see the Standards Explorer.
Why drafts fail: see the vote overview.
Since then (status September 2026)
| February 2026 | Where it stands now |
|---|---|
| prEN 18286 failed its enquiry vote; reconsideration in London, 2–6 March | The standard recovered. Because the fast track applies only after a positive enquiry, it went through a formal vote and was approved on 12 July 2026, then published as EN 18286:2026 in July. Citation in the Official Journal is outstanding. |
| prEN 18228 submitted to the Commission before enquiry | prEN 18228 was at public Enquiry as of June 2026. |
| prEN 18229-1 and 18229-2 submitted to the Commission before enquiry | The series was later restructured into five parts: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1, now titled Logging, went through public enquiry, with national comment windows reported to have closed in July–August 2026. Part 3 reached enquiry in July 2026. |
| Datasets and bias drafts to the Commission by 15 June 2026 | Both were still in drafting as of June 2026. A working-draft consultation on prEN 18283 closed on 30 April 2026. |
| Figure: prEN 18285 on conformity assessment not seeking presumption | prEN 18285 was still in drafting as of June 2026. |
| prEN ISO/IEC 24970 at European enquiry | JTC 21's December 2025 calendar assumed ISO publication in September 2026. I have not confirmed its current status. |
| Deadlines for the harmonised standards | CEN-CENELEC aims for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). |
| Guide on fundamental rights impact assessments | The AI Act's FRIA obligation for certain deployers (Article 27) applies together with the Annex III obligations, now from 2 December 2027. |
Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.