AI Standardisation Watch

    Edition 15 · June 2026

    Edition 15 (June 2026): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 15, June 2026. The programme's centre of gravity shifts from drafting to decision.

    Pipeline at this issue

    prEN 18286quality management

    approved unanimously

    prEN 18228risk management

    enquiry to 30 Jul

    prEN 18229trustworthiness

    Part 1 to 20 Aug

    prEN 18282cybersecurity

    enquiry to 30 Jul

    prEN 18283bias management

    to Commission 1 Jul

    prEN 18284datasets

    working draft

    prEN 18285conformity assessment

    after Luxembourg

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 15, June 2026.

    AI Act timeline

    You are here · 2026-06-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · in force

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026 · next

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    less than a month to general application, including article 50 transparency duties

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Who writes what inside JTC 21

    Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.

    WG1

    Strategic advisory

    Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.

    Main deliverables

    prCEN/CLC/TR 18347

    WG2

    Operational aspects

    Quality management, risk management and conformity assessment.

    Main deliverables

    EN 18286 · prEN 18228 · prEN 18285

    WG3

    Engineering aspects

    Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.

    Main deliverables

    prEN 18284 · prEN 18283 · ISO/IEC 24970

    WG4

    Foundational and societal aspects

    Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.

    Main deliverables

    prEN 18229-1 to 18229-5

    WG5

    Cybersecurity

    Security of AI systems; formed later than the other four groups.

    Main deliverables

    prEN 18282

    five working groups · one shared deadline

    Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.

    Three tracks, one legal difference

    Europe

    CEN-CENELEC JTC 21

    Harmonised standards written on request from the European Commission.

    • prEN 18228 risk
    • prEN 18286 quality
    • prEN 18229 trustworthiness

    Yes — once cited in the Official Journal

    International

    ISO/IEC JTC 1/SC 42

    Global AI standards, sometimes adopted in Europe, sometimes deliberately not.

    • ISO/IEC 42001
    • ISO/IEC TS 12791
    • ISO/IEC 24029

    No — may be referenced, but does not carry presumption

    Professional body

    IEEE

    Engineering practice standards developed outside the EU framework.

    • Ethically aligned design series
    • Transparency and privacy standards

    No — useful practice, no legal effect under the AI Act

    The turning point

    The Commission found ISO/IEC 42001 not aligned with the quality management system required by Article 17. EN 18286 became the dedicated European route instead — which is why the two tracks are not interchangeable.

    only the European track can give presumption of conformity

    Three standardisation tracks, and why only one of them carries presumption of conformity.

    Which standard answers which article
    Art. 9

    Risk management system

    prEN 18228

    ISO/IEC 23894

    Art. 10

    Data and data governance

    prEN 18284

    prEN 18283 · ISO/IEC TS 12791

    Art. 12

    Record-keeping and logging

    prEN 18229-1

    Art. 13

    Transparency to deployers

    prEN 18229-2

    ISO/IEC 12792

    Art. 14

    Human oversight

    prEN 18229-3

    Art. 15

    Accuracy and robustness

    prEN 18229-4 · 18229-5

    ISO/IEC 24029-2 · 4213

    Art. 15

    Cybersecurity

    prEN 18282

    ISO/IEC 27090

    Art. 17

    Quality management system

    prEN 18286

    Art. 43

    Conformity assessment

    prEN 18285

    left: the legal requirement · middle: the standard seeking presumption · right: standards referenced but without legal effect

    Which draft standard answers which requirement of the AI Act.

    The deadlines that moved
    ObligationOriginallyNow

    Standards delivery to the Commission

    30 April 2025

    Missed — request now expires 28 February 2027

    High-risk duties, Annex III use cases

    2 August 2026

    2 December 2027

    High-risk duties, Annex I products

    2 August 2027

    2 August 2028

    Prohibited practices and AI literacy

    2 February 2025

    2 February 2025 — unchanged

    General-purpose AI model obligations

    2 August 2025

    2 August 2025 — unchanged

    The duties were pushed back; the standards they depend on were not delivered on time either. The gap between the two is the story this newsletter keeps returning to.

    Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026

    The deadlines that moved, and where they landed.

    About this issue

    The newsletter is published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website, with ETUC providing the secretariat. As before, it notes that ongoing projects are confidential and that details should be requested from national standards bodies.

    News from the European Union

    Digital Omnibus. After the provisional trilogue agreement of 7 May 2026, the European Parliament approved the Digital Omnibus amending the AI Act in plenary on 16 June. The text confirms the postponement of the high-risk obligations: stand-alone high-risk systems in sensitive areas, including biometrics, critical infrastructure, education, employment, migration, asylum and border control, will be covered from 2 December 2027; AI systems that are safety components of products, such as lifts or toys, will be covered from 2 August 2028. The stated purpose of this sequencing is to have technical standards and other support tools in place before the rules apply. At the time of writing, Council endorsement and publication in the Official Journal were still pending.

    A new standardisation request on data quality. The Commission began consulting on a standardisation request for two European data quality standards, one on data quality metrics and one on collaborative data quality management, to be adopted by 1 November 2027. CEN-CENELEC, and JTC 21 in particular as the committee responsible for AI and data, will be closely involved.

    High-risk classification guidelines. A targeted consultation, open until 23 July, asked for feedback on the clarity and usefulness of the Commission's draft guidelines on classifying high-risk AI systems. The guidelines are meant to help providers, deployers and market surveillance authorities decide whether a system is high-risk, with practical examples across different areas and use cases.

    Council of Europe Framework Convention. The EU formally approved the Council of Europe Framework Convention on AI and Human Rights, Democracy and the Rule of Law on 21 April 2026. The Convention sets general principles and obligations to protect human rights, democracy and the rule of law across the AI lifecycle. Within the EU, it will be implemented exclusively through the AI Act and, where relevant, other Union law.

    CEN-CENELEC JTC 21

    Certification bodies. The proposal to adopt ISO/IEC 42006:2025 (requirements for bodies auditing and certifying AI management systems) as a European standard was approved, and the next step is public enquiry.

    WG1 (strategic advisory). Overview report. The technical report Overview and architecture of standards in support of the EU AI Act (prCEN/CLC/TR 18347) was mature. Its next step, approval by simple majority, depended on the outcome of a JTC 21 ballot on splitting the trustworthiness framework into five parts.

    Inclusiveness survey. Task Group Inclusiveness launched a survey of JTC 21 members on good practices for involving civil society in standardisation, especially in AI. Results will be presented at the next plenary, on 6–9 October 2026.

    Working group reports

    WG2 (operational aspects). Risk management (prEN 18228). The draft was at public enquiry through the national standards bodies until 30 July. It turns the requirements of Article 9 into an operational framework, and the newsletter described it as the first cross-sectoral AI risk management standard built on product-safety concepts such as intended purpose and reasonably foreseeable misuse. It also described it as the first global standard to address fundamental rights risks explicitly, anchored in the EU Charter. More than 150 experts from 34 countries contributed, and since April 2024 over 2,500 comments had been resolved by consensus in some 380 hours of meetings. The Commission's preliminary assessment found it a valid candidate for harmonisation under Article 9.

    Quality management system (EN 18286). The draft was approved unanimously and was expected to become the first published standard under the standardisation request. It specifies requirements and guidance for a quality management system for organisations providing AI systems, designed to support regulatory compliance. Conformity assessment (prEN 18285): work was moving quickly, helped by contributions made after the Luxembourg workshop in late April.

    WG3 (engineering aspects). Bias (prEN 18283). After the comment period, the editors prepared a disposition of comments. Technical compromises were reached at a hybrid comment resolution meeting on 1–2 June, with further meetings planned until 18 June. The draft was due to go to the Commission for review on 1 July.

    Data (prEN 18284). The updated working draft of Quality and governance of data in AI systems was still in preparation, with discussion focused on the data lifecycle and the data quality model. Two subgroups, one for editing and one for comments, had been set up, and collected comments were being resolved.

    Computer vision. The standard on evaluation methods for accurate computer vision systems (prEN 18281) was rejected in its current form at public enquiry, which closed on 11 June. It is not mandated under the request, but it matters because it is cross-referenced by the accuracy standard, which is. The taxonomy of computer vision tasks (prEN 18288) was at public enquiry until 16 July.

    Natural language processing. Committee draft feedback on ISO/IEC 23282 (evaluation of NLP systems) and ISO/IEC TR 23281 (overview of NLP tasks), both in parallel development under ISO lead, was under review. Logging (ISO/IEC 24970): technical comments from the DIS ballot were resolved, and the document was sent for its final draft (FDIS) ballot. AI methods and capabilities (ISO/IEC 42102): the framework for characterising AI system methods and capabilities, developed jointly under ISO lead, reached the enquiry stage.

    WG4 (foundational and societal aspects). Trustworthiness framework. prEN 18229 then consisted of three work items: Part 1 (logging), Part 2 (accuracy and robustness) and Part 3 (transparency and human oversight). A JTC 21 ballot was under way on splitting it into five parts: logging, transparency, human oversight, accuracy and robustness. Logging had been reviewed by the Commission and was at public enquiry until 20 August. Transparency was still under discussion in the working group, focusing on assessment methods, transparency mechanisms, terminology, and interplay with the risk management, quality management and cybersecurity standards. Human oversight was also still under discussion, focusing on the feasibility of oversight, reaction times, observation periods, and interplay with the same standards. Accuracy and robustness remained in drafting, with the Commission having commented on the very first version.

    Other WG4 work. AI ethicists (EN 18274): the formal vote on competence requirements for AI ethics professionals closed with 100% approval. Continuing projects covered specifications for upskilling on AI ethics and for tools to handle ethical issues, a technical report on risk management in critical digital infrastructure, and EN 18287, Frugal AI: guidelines and metrics for the environmental impact of AI.

    WG5 (cybersecurity). prEN 18282, Cybersecurity specifications for AI systems, was at public enquiry until 30 July, and the Commission's preliminary assessment found it a valid candidate for harmonisation. It covers organisational and technical measures to secure high-risk AI systems throughout their lifecycle, proportionate to the circumstances and risks. For AI-specific vulnerabilities, this includes measures to prevent, detect, respond to, resolve and control attacks such as data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws. It also provides objective criteria for deciding whether a given measure adequately meets a specific vulnerability-related goal.

    ISO/IEC JTC 1/SC 42

    The SC 42 plenary met in Singapore on 20–24 April 2026. The committee's portfolio now covers about 150 standards, technical specifications and technical reports, published or in development.

    New preliminary work items. Frontier AI risk management and impact assessment will explore the characteristics of frontier AI models and systems and whether to standardise additional provisions on their risks and impacts, including for public safety and security. Context for AI systems will explore data requirements and approaches for describing, managing, using and sharing context in AI systems, including AI agents, identify gaps, assess the feasibility and priority of new standards, and recommend new work. Safety of AI models, systems and applications will explore safety objectives and constraints, including for public safety and security, how safety interacts with other trustworthiness characteristics (including the limits of traditional safety), and how safety should be handled across the lifecycle and the value chain.

    WG2 (data). ISO/IEC TR 5259-6 (visualisation framework for data quality) was being published, and the committee draft of ISO/IEC TR 42103 (synthetic data in AI systems) was out for comment.

    WG3 (trustworthiness). ISO/IEC TR 42106 (differentiated benchmarking of AI quality characteristics) was being published, and ISO/IEC 42105 (human oversight) was ready for its final draft stage. The second edition of ISO/IEC 25059 (quality model for AI systems) had its DIS comments reviewed and was open for a preview until 15 June before final approval. The DIS ballot on ISO/IEC 24029-3 (robustness of neural networks) closed with approval, and the DIS of ISO/IEC 25029 (AI-enhanced nudging) was at final enquiry. The committee draft of ISO/IEC TS 22443 (societal concerns and ethical considerations) was approved, and a committee draft of ISO/IEC TS 25571 (template for documenting ethical issues) was out for consultation.

    WG4 (use cases). A working draft of ISO/IEC 25589 (framework for human-machine teaming) was available, with committee draft stage expected in July. The 234 committee draft comments on ISO/IEC TR 42109 (human-machine teaming use cases) were being discussed. A new project, ISO/IEC 25880, on organisational implementation of human-machine teaming, was approved. A revised ISO/IEC TR 24030 on AI use cases, with 53 candidate use cases submitted so far, was expected to reach committee draft stage by July.

    Other groups. Testing: ISO/IEC TS 42119-2 (overview of testing AI systems) was published, and ISO/IEC TS 42119-3 (verification and validation analysis) was registered for final approval. Health informatics: the committee draft of ISO/IEC TR 18988 (AI in health informatics) was approved. Functional safety: comments on the committee drafts of the three-part ISO/IEC TS 22440 were under review. Conformity assessment schemes: the committee draft of ISO/IEC 42007 was in comment resolution. AI methods and capabilities: ISO/IEC DIS 42102 was at enquiry in parallel in CEN-CENELEC.

    Fora

    On 14 April 2026, the Commission, with ITU and the UN Office of the High Commissioner for Human Rights, held a seminar on human rights and ICT standardisation. It discussed how technical standards can help ensure AI is developed and deployed consistently with human rights, including privacy, data protection, non-discrimination, access to impartial information and the right to work. The report and slides are available through StandICT.eu.

    The issue also pointed to IEEE's AI activities (more than 100 AI-related standards, more than 10 AI journals including IEEE Transactions on Artificial Intelligence, and more than 100 AI conferences). Upcoming conferences in summer 2026 included the World Congress on Computational Intelligence (Maastricht, 21–26 June), the Cloud Summit (Washington, 25–26 June), the International Conference on Human-Machine Systems (Singapore, 1–3 July), a conference on sustainable AI for social impact (Hyderabad, 13–14 August), a conference on computational intelligence in bioinformatics (Athens, 31 August–2 September), and the International Conference on Responsible AI (Melbourne, 3–5 September).

    Nice to know, useful to read

    The Seoul Statement. At the International AI Standards Summit in December 2025, organised by IEC, ISO and ITU, hosted by Korea's standards agency (KATS) and held in partnership with the UN Office on Digital and Emerging Technologies, OHCHR and the OECD, the three organisations issued the Seoul Statement. It commits them to incorporating socio-technical dimensions into standards development, deepening understanding of how international standards interact with human rights, strengthening an inclusive multistakeholder community for AI standards, and enhancing public-private cooperation on AI capacity building.

    ANEC on computer vision. A factsheet on prEN 18281 supports common methods for evaluating the accuracy, reliability, robustness and fairness of computer vision systems in areas such as biometrics, age estimation, retail, driver assistance and medical imaging. It insists that testing must represent diverse demographic groups and real-world conditions to prevent bias, discrimination and safety risks.

    Magnifica Humanitas. Pope Leo XIV's encyclical on safeguarding the human person in the age of AI acknowledges the benefits of AI, warns of its threats and stresses the need for regulation.

    EESC opinion. On 29 April, the European Economic and Social Committee adopted an opinion on the EU standardisation strategy in the context of the revision of Regulation (EU) No 1025/2012. It calls for stronger participation by SMEs, trade unions and civil society, greater transparency in the European standardisation system, and better coordination of EU positions in international standards bodies. UNESCO reported to SC 42 on its work, including its recommendations on the ethics of AI and on the ethics of neurotechnology.

    My reading

    This is the most consequential issue in the series. Three of the core harmonised standards were now at or past public enquiry: risk management and cybersecurity, both with a preliminary Commission finding that they are valid candidates for harmonisation, and quality management, approved unanimously after failing its enquiry vote in January. The logging part of the trustworthiness framework was also at enquiry. For the first time, the programme's centre of gravity had shifted from drafting to decision.

    The claims made for prEN 18228 deserve attention. A risk management standard that is cross-sectoral, built on the product-safety concepts of intended purpose and reasonably foreseeable misuse, and that addresses fundamental rights risks anchored in the Charter is exactly what critics said standards could not deliver. Whether it succeeds will be judged on the text now at enquiry, not on the description. But the ambition is on record.

    Two setbacks are worth keeping in view. The computer vision evaluation standard was rejected at enquiry, and although it is not itself mandated, the accuracy standard relies on it. And the trustworthiness framework was still being reorganised, from three work items towards five parts, with transparency, human oversight, accuracy and robustness all still in discussion or drafting. Those are the requirements closest to how people actually experience AI systems, and they are the ones furthest from completion.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    June 2026Where it stands now
    Omnibus approved by Parliament; Council endorsement pendingThe Council adopted the text on 29 June 2026. It was published as Regulation (EU) 2026/1744 and entered into force on 27 July 2026, with the dates reported in the newsletter.
    EN 18286 approved unanimously, expected to be first publishedApproved on 12 July 2026 and published as EN 18286:2026 in July, the first harmonised-standard candidate under the request to be published. Citation in the Official Journal is outstanding.
    prEN 18228 and prEN 18282 at public enquiry until 30 JulyBoth enquiries have closed. Comment resolution and formal vote are the next steps.
    Ballot on splitting prEN 18229 into five partsA JTC 21 project editor reported at the end of July that the series now has five parts. The public enquiry on Part 1 (logging) ran until 20 August 2026. Part 3 (human oversight) reached enquiry in July, with comments open until 22 September 2026.
    prEN 18283 to the Commission on 1 JulyI have not confirmed its current status.
    prEN 18281 rejected at enquiryI have not confirmed how the working group will proceed. The accuracy part of the trustworthiness series refers to it.
    Next JTC 21 plenary, 6–9 October 2026According to press reports on a draft, the Commission is expected to present its proposal for a revision of Regulation (EU) No 1025/2012 in the same week, on 6 October 2026.
    Programme deadlinesCEN-CENELEC aims for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027.
    Transparency obligationsArticle 50 obligations were not postponed by the Omnibus. Article 50(2) applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026.

    Stages for the prEN drafts are drawn from the newsletter, public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    All 16 editions are listed in the news feed.