Edition 3 · May 2024
Edition 3 (May 2024): the essence
AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 3, May 2024.
prEN 18286quality management
new work item
prEN 18228risk management
risk catalogue
prEN 18229trustworthiness
drafting
prEN 18282cybersecurity
drafting
prEN 18283bias management
drafting
prEN 18284datasets
drafting
prEN 18285conformity assessment
new work item
not started · drafting · enquiry · approved · cited in OJ
Status of the AI Act deliverables as described in Edition 3, May 2024.
1 Aug 2024
AI Act enters into force
2 Feb 2025
Prohibited practices and AI literacy apply
2 Aug 2025
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
2 months to ai act enters into force
You are here · 2024-05-31
1 Aug 2024 · next
AI Act enters into force
2 Feb 2025
Prohibited practices and AI literacy apply
2 Aug 2025
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
2 months to ai act enters into force
filled = already in force · hollow = still ahead · flag = date of this issue
Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.
Inclusiveness survey
146/195
75% of eligible JTC 21 members and observers answered the spring 2025 survey.
120+
Turin plenary
participants from 21 countries
150+
Bath plenary
participants from 20+ countries
800+
ISO/IEC SC 42
registered experts, 70 national bodies
350+
Civil society webinars
participants at the largest sessions
Newsletter reach, edition by edition
figures as reported in the newsletter
Who takes part, and how far the work reaches.
About this issue
The newsletter now reached more than 70 direct recipients. Edition 2 had been posted on the JTC 21 WG1 page on 15 March, and all issues are available through ETUC and the JTC 21 LinkedIn group. ETUC continues to provide the secretariat, and the next issue was planned for early July. The editors also clarified the scope: the newsletter covers only standards where the inclusion of societal stakeholders is expected, leaving aside the many purely technical documents written mainly for IT specialists.
News from the European Union
The European Parliament formally adopted the AI Act on 13 March 2024. The Commission was preparing its Annual Union Work Programme for standardisation, with several proposals on AI, data and cybersecurity, to be discussed by the "Sherpa" group of the High-Level Forum on European Standardisation on 14 May. The existing standardisation request on AI remained in force.
Four of the Forum's fifteen workstreams were highlighted.
WS2, fundamental rights. ANEC and BEUC held an invitation-only webinar on 20 March on where to draw the line between standards and fundamental rights. The discussion partly concerned the AI Act, which aims to protect fundamental rights while leaving room for interpretation to the experts drafting the standards.
WS3, peer review of national standards bodies. A workshop on strengthening national participation was announced for 5 June 2024 in Brussels and online, organised under the Forum with support from the Belgian FPS Economy. Its three panels covered barriers to accessing standardisation work, effective and balanced participation, and good practice, with recommendations for Member States and national standards bodies as the intended outcome.
WS5, civil society and SME inclusion in international standardisation. A report on the subject was in preparation, with ECOS and CEN-CENELEC as contact points.
WS12, artificial intelligence. The information videos on AI standardisation announced in Edition 2 had all been published.
What's new at CEN-CENELEC JTC 21
WG1 (strategic advisory). The "architecture of standards" document, which sets out how CEN-CENELEC will answer the Commission's request, had been voted on. Comments from several national standards bodies were being resolved.
WG2 (operational aspects) launched two new work item proposals: conformity assessment frameworks for AI systems, and quality management system requirements for regulatory purposes. On risk management, a full-day meeting in Berlin on 8 April brought the group close to agreeing a table of contents. The standard was to combine requirements derived from Article 9 of the AI Act with requirements reflecting the generally acknowledged state of the art in AI risk management, which Article 8(1) makes relevant. An annex, provisionally called the "Risk Catalogue", would set out that state of the art by listing AI risk sources, their potential harms and possible risk management measures. PLOT4ai, a practical library of AI threats developed by the Dutch privacy engineer Isabel Barberá, was being used to populate it, and the group also expected to draw on existing ISO risk management standards, including those for medical devices. To help newcomers contribute to the catalogue, Koen Holtman (NL) wrote a style guide on drafting useful expert submissions. It is designed to be shared outside JTC 21, so that external writing or consultation projects can feed into the committee through a participating expert.
WG3 (engineering aspects) had validated new work items on quality and governance of datasets and on managing bias. Work on natural language processing and on logging continued in partnership with ISO/IEC, under ISO lead.
WG4 (foundational and societal aspects) was drafting the trustworthiness framework, which will list the elements of trustworthiness and their associated requirements, with in-person meetings in Paris (26–27 March), Rome (14–15 May) and Brussels (9–10 July). It also launched preliminary work items on four topics. The first concerned impact assessment in the context of EU fundamental rights, intended to produce a technical report on the technical and organisational measures needed to safeguard those rights. The stated aim was not to standardise fundamental rights, but to help develop standards that serve them. The other three concerned guidelines on tools for managing ethical aspects of AI in organisations, tools and upskilling for AI ethics, and sustainable AI, a subject SC 42 is also addressing.
WG5 (cybersecurity) was noted for the record. The next plenary was scheduled for Bath, 3–7 June 2024, and readers were again directed to their national standards bodies and to the partner and liaison organisations representing SMEs, consumers, environmental groups, NGOs and workers.
Stakeholder input on AI trustworthiness
A separate item called for input to the draft trustworthiness framework ahead of its next development stage on 17 July 2024. The framework was described as the backbone of the whole architecture of AI standards: every other standard should refer to it and contribute to it. WG4 was working with a definition of trustworthiness as "the ability to meet stakeholder expectations in a verifiable way".
ANEC offered an example of what that means for consumers. In its view, consumer trustworthiness for software-based products that are frequently updated requires characterisation in two domains. The first is whether the implementation is fit for purpose in reasonably foreseeable use, which usually calls for detailed functional requirements per product type. The second is whether lifecycle activities are carried out by competent people doing the right things at the right time, so that consumers can trust that suppliers exercised due care throughout the lifecycle. Stakeholders were encouraged to state their own expectations while the draft was still open.
What's new at ISO/IEC JTC 1/SC 42
The SC 42 plenary took place in Seoul, 22–26 April 2024. In WG1, an SME handbook for ISO/IEC 42001 was being designed, and ISO/IEC 42005 on AI impact assessment was in its final stage, with comment resolution meetings planned until July. Generative AI was emerging as an area likely to drive new standards and revisions across SC 42.
In WG3 (trustworthiness), a technical specification on controllability of automated AI systems had been published. Specifications on a transparency taxonomy and on treatment of unwanted bias were in their last comment round. Guidance on societal and ethical concerns, trustworthiness facts and labels, guidance on human oversight, and nudging were at earlier stages. WG4 (use cases) was working on environmental sustainability, with a call for experts, as well as on beneficial AI systems and human-machine teaming. The next SC 42 plenary was set for Paris in October 2024, and the issue repeated the reminder that non-profit organisations can apply for Category C liaison.
More forums
The editors began mapping the wider landscape. Within CEN-CENELEC, JTC 13 on cybersecurity and data protection covers topics closely related to AI. In ISO/IEC JTC 1, SC 27 (information security, cybersecurity and privacy protection) and SC 39 (sustainability, IT and data centres) are relevant. IEC, IEEE, ITU and ETSI are active on the electrotechnical and telecoms side. UNESCO runs the Global AI Ethics and Governance Observatory and an expert group on implementing AI ethics. The World Economic Forum, the United Nations and the World Trade Organization are also active on AI, and a Memorandum of Understanding on electronic business between IEC, ISO, ITU and UNECE, signed in 2000, has supported a standing expert group since then.
Nice to know
At CPDP 2024 in Brussels (22–24 May), ANEC organised a panel on 23 May, with support from the European AI & Society Fund, assessing how far governance and inclusiveness in AI standardisation had come. The chair of JTC 21, ETUC, Small Business Standards and the European Commission took part. The European Trade Union Institute (ETUI) published Artificial intelligence, labour and society in March 2024, an edited volume with contributions from academics and research activists worldwide. Small Business Standards announced the second edition of its Meeting Standards campaign for SMEs, 25–29 November 2024.
On 24 April, SaferAI and the Ada Lovelace Institute held a workshop in Brussels on how to develop the EU General-Purpose AI Code of Practice. More than 50 participants from civil society, standards bodies, the Commission and the Parliament, several of them active in JTC 21, took part. Three messages stood out: civil society should be involved early and substantively; accountability should build on what worked in the Code of Practice on Disinformation, such as third-party verification and quantitative reporting; and the Code should set quantitative risk thresholds defining acceptable risk, as other industries do.
Annex: video interviews from the Dublin plenary
The issue closes with an annex from NSAI (Ireland) listing 15 short video clips recorded at the 9th JTC 21 plenary in Dublin in February 2024. Heads of delegation and delegates from Denmark, Cyprus, Portugal, France, the Netherlands, Italy, Germany and Ireland answer questions such as which aspects of the AI Act they find most important, how industry uptake of AI standards can be encouraged, how national standards bodies have responded, and how developing AI standards differs from other ICT standardisation. Most clips exist both in the speaker's own language with English subtitles and in English. They are available on NSAI's YouTube channel.
My reading
Two decisions in this issue shaped what came later. The first is the new work item on quality management requirements for regulatory purposes. Only two months after Edition 2 reported a plan to adopt ISO/IEC 42001, WG2 opened a dedicated European route, the origin of today's EN 18286. The second is the risk management design, which ties the standard to the AI Act's reference to the state of the art and proposes to make that state of the art explicit in a catalogue of risk sources, harms and measures.
WG4's working definition deserves attention as well. If trustworthiness is the ability to meet stakeholder expectations in a verifiable way, then an expectation that has not been stated as a checkable condition cannot be verified. The invitation to stakeholders is therefore more than a consultation formality. It is the step where expectations either become testable requirements or remain aspirations.
For the live status of each standard, see the Standards Explorer.
Since then (status September 2026)
| May 2024 | Where it stands now |
|---|---|
| AI Act adopted by the European Parliament | Published as Regulation (EU) 2024/1689 and in force since 1 August 2024. The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). |
| Standardisation request "still stands" | Amended in June 2025 as C(2025)3871 (M/613), with an extended timeline to 28 February 2027. |
| New work item: QMS requirements for regulatory purposes | EN 18286 approved on 12 July 2026, the first JTC 21 AI Act standard to reach that point. Citation in the Official Journal is outstanding. |
| New work item: conformity assessment frameworks | prEN 18285 (drafting). |
| Risk management standard with a "Risk Catalogue" annex | prEN 18228, at public Enquiry (June 2026). |
| Work items validated: datasets and managing bias | prEN 18284 and prEN 18283 (both drafting). |
| Trustworthiness framework as the overarching standard | Developed as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026. |
| Preliminary work on fundamental rights impact assessment | The AI Act's own fundamental rights impact assessment for certain deployers (Article 27) applies together with the Annex III obligations, now from 2 December 2027. |
| GPAI Code of Practice under discussion | Published by the Commission in July 2025, with chapters on transparency, copyright, and safety and security. GPAI obligations have applied since 2 August 2025. |
| SC 42: controllability specification published | ISO/IEC TS 8200:2024. |
| SC 42: transparency taxonomy and unwanted bias in final comments | Published as ISO/IEC 12792:2025 and ISO/IEC TS 12791:2024. |
| SC 42: ISO/IEC 42005 in final stage | Published as ISO/IEC 42005:2025. |
| HLF work on inclusiveness and national participation | The Commission's evaluation found that the standardisation framework struggles with timeliness, inclusiveness and access. A revision of Regulation (EU) No 1025/2012 is in the 2026 work programme, with a proposal expected in October 2026 according to press reports. |
Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.
Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.