AI Standardisation Watch

    Edition 5 · September 2024

    Edition 5 (September 2024): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 5, September 2024. Includes, as an annex, the JTC 21 internal work programme dashboard as of 31 August 2024.

    Pipeline at this issue

    prEN 18286quality management

    dashboard

    prEN 18228risk management

    homegrown

    prEN 18229trustworthiness

    drafting

    prEN 18282cybersecurity

    homegrown

    prEN 18283bias management

    homegrown

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 5, September 2024.

    AI Act timeline

    You are here · 2024-09-30

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · next

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    4 months to prohibited practices and ai literacy apply

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Three tracks, one legal difference

    Europe

    CEN-CENELEC JTC 21

    Harmonised standards written on request from the European Commission.

    • prEN 18228 risk
    • prEN 18286 quality
    • prEN 18229 trustworthiness

    Yes — once cited in the Official Journal

    International

    ISO/IEC JTC 1/SC 42

    Global AI standards, sometimes adopted in Europe, sometimes deliberately not.

    • ISO/IEC 42001
    • ISO/IEC TS 12791
    • ISO/IEC 24029

    No — may be referenced, but does not carry presumption

    Professional body

    IEEE

    Engineering practice standards developed outside the EU framework.

    • Ethically aligned design series
    • Transparency and privacy standards

    No — useful practice, no legal effect under the AI Act

    The turning point

    The Commission found ISO/IEC 42001 not aligned with the quality management system required by Article 17. EN 18286 became the dedicated European route instead — which is why the two tracks are not interchangeable.

    only the European track can give presumption of conformity

    Three standardisation tracks, and why only one of them carries presumption of conformity.

    About this issue

    The newsletter had passed 500 LinkedIn impressions in the two months since the previous edition, and was now referenced in CEN-CENELEC's On the Spot magazine. Readers could register for the distribution list through ETUC, which continues to provide the secretariat. The next issue was planned for mid-November.

    News from the European Union

    The AI Act entered into force on 1 August 2024. The Commission released a video on the Act's objectives and the role of standardisation in achieving them, and opened a call for tender for a study on measuring and encouraging energy-efficient, low-emission AI systems in the EU. The AI Office launched a multi-stakeholder consultation on trustworthy general-purpose AI models, open until 18 September 2024, to inform both the first General-Purpose AI Code of Practice and the template for summarising the content used to train such models. In the European Parliament, the IMCO and LIBE committees set up a joint working group to monitor implementation of the Act.

    CEN-CENELEC JTC 21

    The next plenary was scheduled for Turin, 4–6 November 2024.

    The most significant decision reported was that JTC 21 declined joint development with ISO/IEC of two key standards required by the AI Act, on risk management and on trustworthiness, citing the specific European context. It also adopted two new work items to operationalise the Act and meet the standardisation request: a European standard on a quality management system for AI Act regulatory purposes, and a European AI conformity assessment framework. A further work item on a taxonomy of AI system methods and capabilities was registered.

    In WG2, work on risk management continued, with three subgroups set up on terminology, risk acceptability, and integration with existing risk management frameworks. In WG3, a work item was approved to adopt the ISO/IEC 5259 series on data quality directly as European standards, while work continued on logging and computer vision jointly with SC 42, and on datasets and bias. WG4 concentrated on trustworthiness, alongside fundamental rights and ethics (competence requirements for AI ethics professionals, tools for handling ethical issues, and upskilling organisations), and was exploring sustainable AI and its environmental impact. In WG5, the work item on cybersecurity specifications for AI systems was approved.

    Civil society contributions to the working groups were increasing. The issue highlighted ANEC documents on how AI standards relate to the phases of a product lifecycle, and Equinet documents on human oversight in the context of trustworthiness and risk management.

    JTC 21 publishes its internal dashboard

    Given the strong interest from industry, society and policymakers, JTC 21 took the unusual step of publishing a copy of its internal work programme dashboard, dated 31 August 2024. It shows which items are developed jointly with SC 42 and which are "homegrown" European work, much of which is designed to fill the gaps between the AI Act's requirements and what ISO/IEC standards already provide. The published dashboard carries no dates. CEN-CENELEC's live project dashboard does show some historical and estimated dates, but it is updated at irregular intervals. The newsletter added that, by the time of writing, every JTC 21 project supporting the standardisation request had passed the approval stage and was under drafting.

    The dashboard itself makes two points worth keeping in mind. First, its stage codes are only loosely correlated with the maturity of the content and the degree of consensus reached, so the formal stage is not a reliable predictor of completion. Second, comments and contributions must be routed through a national AI mirror committee or through one of the Annex III organisations (ANEC, ETUC, SBS). They cannot be introduced by CEN-CENELEC staff or the JTC 21 management team.

    What the dashboard shows, by area of the standardisation request

    Terminology and supporting standards. ISO/IEC 22989 (concepts and terminology) and ISO/IEC 23053 (framework for machine learning systems) had been adopted as European standards, with amendments to both in parallel development under ISO lead.

    Quality management and risk management. The adoption of ISO/IEC 42001 remained at a preliminary stage, approved with one negative national vote. The dashboard noted that it was unclear whether adoption was still needed, and that 42001 will not be harmonised by the Commission. In its place, a homegrown standard on a quality management system for regulatory purposes, building on several ISO/IEC standards including 42001, was under drafting. ISO/IEC 23894 (risk management guidance) had been adopted, and a homegrown AI risk management standard, replacing an earlier risk checklist item, was under drafting.

    Record-keeping and transparency. A standard on AI system logging (ISO/IEC 24970) and the transparency taxonomy (ISO/IEC 12792) were both in parallel development under ISO lead.

    Accuracy and robustness. The trustworthiness framework, a homegrown European standard, was under drafting and mapped to almost every area of the request. Accuracy threshold definition was to be covered inside it, and ISO/IEC TS 4213 on classification accuracy was to be referenced, not adopted, with its forthcoming update covering regression, recommendation and clustering. On robustness, ISO/IEC TR 24029-1 had been adopted, but because it is a technical report, a further deliverable was still needed; the dashboard noted that little additional content was available, since this is at the frontier of research. Work on the formal-methods and statistical-methods parts of ISO/IEC 24029 was at preliminary or early stages. Standards on evaluating natural language processing systems were in parallel development under ISO lead, and two work items on computer vision (evaluation methods and a task taxonomy) were at ballot until 12 September 2024.

    Data governance and bias. ISO/IEC 8183 (data life cycle framework) had been adopted. Parts 1, 3 and 4 of ISO/IEC 5259 had been published by ISO in July 2024 and were being adopted, with part 2 at final draft stage. A homegrown standard on quality and governance of datasets was under drafting, and the technical report CEN/CLC/TR 18115 on data governance and quality in the European context was at ballot until 29 August 2024. On bias, ISO/IEC TS 12791 was in its second ballot (19 June to 11 September 2024), and a homegrown standard on concepts, measures and requirements for managing bias was under drafting.

    Testing and conformity assessment. A possibly modified adoption of ISO/IEC 42006 (then at draft international standard stage) and of ISO/IEC 29119-11 on testing AI systems was under discussion. A standard on competence requirements for AI system auditors and professionals, and the homegrown AI conformity assessment framework, were under drafting.

    Cybersecurity. JTC 21 was contributing to ISO/IEC 27090 on AI security threats, with adoption as a technical report suggested. The homegrown cybersecurity specifications for AI systems were under drafting. The dashboard concluded that no harmonised standard on privacy protection is needed, since it is covered by the GDPR and existing standards such as ISO/IEC 27701, 29100, 29151 and 29134. How to assess conformity for AI-specific vulnerabilities was still open, including whether to align with the Cyber Resilience Act and whether assessment should sit alongside the requirements, as in EN 18031, or in a separate document. A question on this was pending with the Commission.

    Beyond the standardisation request (lower priority). This group included AI-enhanced nudging, in parallel development with dual European and Indian editorship; a technical report on green and sustainable AI, for which parallel development was rejected because the European work was already too advanced; a specification on metrics for the environmental impact of AI; the conformity assessment technical report CEN/CLC/TR 17894, at ballot until 24 October 2024; competence requirements for AI ethics professionals; specifications on upskilling in AI ethics and on tools for ethical issues; the adopted ISO/IEC TR 24027 (bias) and ISO/IEC 25059 (quality model for AI systems); a taxonomy of AI system methods and capabilities (ISO/IEC 42102); a reference architecture for knowledge engineering; and a preliminary item on impact assessment in the context of fundamental rights, with its form (technical report or European standard) and its relationship to 42001 still open. Guidelines on accuracy improvement were deferred as unnecessary for the request, an example of the committee's effort to keep the programme tight.

    ISO/IEC JTC 1/SC 42

    The next SC 42 plenary was set for Le Chesnay (France), 7–11 October 2024. Growing interest in generative AI was driving updates to ISO/IEC 22989 and ISO/IEC 23053, and a new project on guidance for addressing risks in generative AI systems had been proposed. ISO/IEC 42005 (impact assessment) was nearly complete, and ISO/IEC 12792 (transparency taxonomy), ISO/IEC 12791 (unwanted bias) and ISO/IEC 42006 (certification body requirements) were well advanced. Other topics in progress, mainly in WG1 and WG3, included uncertainty quantification, a taxonomy of AI methods and capabilities, human oversight, evaluation methods and criteria for trustworthiness, human-machine teaming, beneficial AI systems, reliability, societal and ethical concerns, the SME handbook for ISO/IEC 42001, and nudging.

    Forum

    Small Business Standards announced its annual Meeting Standards campaign for SMEs, 25–29 November 2024, with online and in-person events across Europe. Equinet announced a high-level conference in Brussels on 12 December 2024 on how equality bodies should respond to the AI Act, aimed at equality bodies, policymakers, civil society and experts on non-discrimination. The UK AI Standards Hub scheduled a webinar on 24 September 2024 on inclusive approaches to AI security standardisation, with speakers from the UK Department for Science, Innovation and Technology, ANEC and Enforce.

    Nice to know, useful to read

    The issue recommended a blog post by Kai Zenner, head of office and digital policy adviser to MEP Axel Voss, setting out the Commission's and the AI Office's responsibilities and deadlines under the AI Act. It also noted a California Senate bill that would require developers of AI models trained with more than USD 100 million of compute to adopt and disclose a safety and security plan against critical harms, pending the Governor's signature.

    My reading

    The published dashboard is the most useful document in the series so far. For the first time, it shows the architecture of the European response: which requirements are met by adopting ISO/IEC work and which need homegrown standards. The homegrown list is telling. Risk management, trustworthiness, quality management, datasets, bias, conformity assessment and cybersecurity are exactly the areas where the AI Act's requirements are most specific. The decision not to develop risk management and trustworthiness jointly with ISO/IEC, and the note that 42001 will not be harmonised, are the clearest statements yet of where Europe and the international track diverge.

    Two notes in the dashboard have aged well. The warning that formal stages are a poor predictor of completion was borne out when the April 2025 deadline was missed. And the open question on conformity assessment for AI-specific vulnerabilities illustrates a problem that will only grow: the AI Act, the Cyber Resilience Act and the GDPR each bring their own requirements and assessment logic, and someone has to decide which document carries which obligation.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    September 2024Where it stands now
    AI Act in force since 1 August 2024The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    AI Office consultation for the GPAI Code of PracticeThe Code of Practice was published in July 2025, together with the template for the public summary of training content. GPAI obligations have applied since 2 August 2025.
    All request-related projects "under drafting"The original deadline of 30 April 2025 was missed. By mid-2026, EN 18286 had been approved; prEN 18228 and prEN 18282 were at public Enquiry; prEN 18229-1 (logging) had been through public enquiry and prEN 18229-3 (human oversight) reached it in July 2026. Most other deliverables were still in drafting.
    Homegrown QMS for regulatory purposes; 42001 "will not be harmonised"EN 18286 approved on 12 July 2026. The Commission found 42001 not aligned with Article 17. Citation of EN 18286 in the Official Journal is outstanding.
    Homegrown risk management standardprEN 18228, at public Enquiry.
    Homegrown trustworthiness frameworkDeveloped as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Logging in parallel development with ISO (ISO/IEC 24970)The JTC 21 logging deliverable for Article 12 is now prEN 18229-1, Part 1 of the trustworthiness series, which has been through public enquiry. ISO/IEC 24970 continued separately in ISO/IEC JTC 1/SC 42.
    Homegrown datasets and bias standardsprEN 18284 and prEN 18283 (both drafting).
    Homegrown conformity assessment frameworkprEN 18285 (drafting).
    Homegrown cybersecurity specificationsprEN 18282, at public Enquiry.
    CEN/CLC/TR 18115 at ballotPublished in December 2024.
    ISO/IEC TS 12791 at second ballotPublished as ISO/IEC TS 12791:2024.
    ISO/IEC 42005, 42006 and 12792 nearly completePublished in 2025.
    California frontier model bill awaiting signatureSB 1047 was vetoed in September 2024. A narrower transparency law for frontier model developers, SB 53, was signed in September 2025.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    All 16 editions are listed in the news feed.