Edition 5 · September 2024
Edition 5 (September 2024): the essence
AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 5, September 2024. Includes, as an annex, the JTC 21 internal work programme dashboard as of 31 August 2024.
prEN 18286quality management
dashboard
prEN 18228risk management
homegrown
prEN 18229trustworthiness
drafting
prEN 18282cybersecurity
homegrown
prEN 18283bias management
homegrown
prEN 18284datasets
drafting
prEN 18285conformity assessment
drafting
not started · drafting · enquiry · approved · cited in OJ
Status of the AI Act deliverables as described in Edition 5, September 2024.
1 Aug 2024
AI Act enters into force
2 Feb 2025
Prohibited practices and AI literacy apply
2 Aug 2025
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
4 months to prohibited practices and ai literacy apply
You are here · 2024-09-30
1 Aug 2024 · in force
AI Act enters into force
2 Feb 2025 · next
Prohibited practices and AI literacy apply
2 Aug 2025
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
4 months to prohibited practices and ai literacy apply
filled = already in force · hollow = still ahead · flag = date of this issue
Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.
Europe
CEN-CENELEC JTC 21
Harmonised standards written on request from the European Commission.
- prEN 18228 risk
- prEN 18286 quality
- prEN 18229 trustworthiness
Yes — once cited in the Official Journal
International
ISO/IEC JTC 1/SC 42
Global AI standards, sometimes adopted in Europe, sometimes deliberately not.
- ISO/IEC 42001
- ISO/IEC TS 12791
- ISO/IEC 24029
No — may be referenced, but does not carry presumption
Professional body
IEEE
Engineering practice standards developed outside the EU framework.
- Ethically aligned design series
- Transparency and privacy standards
No — useful practice, no legal effect under the AI Act
The turning point
The Commission found ISO/IEC 42001 not aligned with the quality management system required by Article 17. EN 18286 became the dedicated European route instead — which is why the two tracks are not interchangeable.
only the European track can give presumption of conformity
Three standardisation tracks, and why only one of them carries presumption of conformity.
About this issue
The newsletter had passed 500 LinkedIn impressions in the two months since the previous edition, and was now referenced in CEN-CENELEC's On the Spot magazine. Readers could register for the distribution list through ETUC, which continues to provide the secretariat. The next issue was planned for mid-November.
News from the European Union
The AI Act entered into force on 1 August 2024. The Commission released a video on the Act's objectives and the role of standardisation in achieving them, and opened a call for tender for a study on measuring and encouraging energy-efficient, low-emission AI systems in the EU. The AI Office launched a multi-stakeholder consultation on trustworthy general-purpose AI models, open until 18 September 2024, to inform both the first General-Purpose AI Code of Practice and the template for summarising the content used to train such models. In the European Parliament, the IMCO and LIBE committees set up a joint working group to monitor implementation of the Act.
CEN-CENELEC JTC 21
The next plenary was scheduled for Turin, 4–6 November 2024.
The most significant decision reported was that JTC 21 declined joint development with ISO/IEC of two key standards required by the AI Act, on risk management and on trustworthiness, citing the specific European context. It also adopted two new work items to operationalise the Act and meet the standardisation request: a European standard on a quality management system for AI Act regulatory purposes, and a European AI conformity assessment framework. A further work item on a taxonomy of AI system methods and capabilities was registered.
In WG2, work on risk management continued, with three subgroups set up on terminology, risk acceptability, and integration with existing risk management frameworks. In WG3, a work item was approved to adopt the ISO/IEC 5259 series on data quality directly as European standards, while work continued on logging and computer vision jointly with SC 42, and on datasets and bias. WG4 concentrated on trustworthiness, alongside fundamental rights and ethics (competence requirements for AI ethics professionals, tools for handling ethical issues, and upskilling organisations), and was exploring sustainable AI and its environmental impact. In WG5, the work item on cybersecurity specifications for AI systems was approved.
Civil society contributions to the working groups were increasing. The issue highlighted ANEC documents on how AI standards relate to the phases of a product lifecycle, and Equinet documents on human oversight in the context of trustworthiness and risk management.
JTC 21 publishes its internal dashboard
Given the strong interest from industry, society and policymakers, JTC 21 took the unusual step of publishing a copy of its internal work programme dashboard, dated 31 August 2024. It shows which items are developed jointly with SC 42 and which are "homegrown" European work, much of which is designed to fill the gaps between the AI Act's requirements and what ISO/IEC standards already provide. The published dashboard carries no dates. CEN-CENELEC's live project dashboard does show some historical and estimated dates, but it is updated at irregular intervals. The newsletter added that, by the time of writing, every JTC 21 project supporting the standardisation request had passed the approval stage and was under drafting.
The dashboard itself makes two points worth keeping in mind. First, its stage codes are only loosely correlated with the maturity of the content and the degree of consensus reached, so the formal stage is not a reliable predictor of completion. Second, comments and contributions must be routed through a national AI mirror committee or through one of the Annex III organisations (ANEC, ETUC, SBS). They cannot be introduced by CEN-CENELEC staff or the JTC 21 management team.
What the dashboard shows, by area of the standardisation request
Terminology and supporting standards. ISO/IEC 22989 (concepts and terminology) and ISO/IEC 23053 (framework for machine learning systems) had been adopted as European standards, with amendments to both in parallel development under ISO lead.
Quality management and risk management. The adoption of ISO/IEC 42001 remained at a preliminary stage, approved with one negative national vote. The dashboard noted that it was unclear whether adoption was still needed, and that 42001 will not be harmonised by the Commission. In its place, a homegrown standard on a quality management system for regulatory purposes, building on several ISO/IEC standards including 42001, was under drafting. ISO/IEC 23894 (risk management guidance) had been adopted, and a homegrown AI risk management standard, replacing an earlier risk checklist item, was under drafting.
Record-keeping and transparency. A standard on AI system logging (ISO/IEC 24970) and the transparency taxonomy (ISO/IEC 12792) were both in parallel development under ISO lead.
Accuracy and robustness. The trustworthiness framework, a homegrown European standard, was under drafting and mapped to almost every area of the request. Accuracy threshold definition was to be covered inside it, and ISO/IEC TS 4213 on classification accuracy was to be referenced, not adopted, with its forthcoming update covering regression, recommendation and clustering. On robustness, ISO/IEC TR 24029-1 had been adopted, but because it is a technical report, a further deliverable was still needed; the dashboard noted that little additional content was available, since this is at the frontier of research. Work on the formal-methods and statistical-methods parts of ISO/IEC 24029 was at preliminary or early stages. Standards on evaluating natural language processing systems were in parallel development under ISO lead, and two work items on computer vision (evaluation methods and a task taxonomy) were at ballot until 12 September 2024.
Data governance and bias. ISO/IEC 8183 (data life cycle framework) had been adopted. Parts 1, 3 and 4 of ISO/IEC 5259 had been published by ISO in July 2024 and were being adopted, with part 2 at final draft stage. A homegrown standard on quality and governance of datasets was under drafting, and the technical report CEN/CLC/TR 18115 on data governance and quality in the European context was at ballot until 29 August 2024. On bias, ISO/IEC TS 12791 was in its second ballot (19 June to 11 September 2024), and a homegrown standard on concepts, measures and requirements for managing bias was under drafting.
Testing and conformity assessment. A possibly modified adoption of ISO/IEC 42006 (then at draft international standard stage) and of ISO/IEC 29119-11 on testing AI systems was under discussion. A standard on competence requirements for AI system auditors and professionals, and the homegrown AI conformity assessment framework, were under drafting.
Cybersecurity. JTC 21 was contributing to ISO/IEC 27090 on AI security threats, with adoption as a technical report suggested. The homegrown cybersecurity specifications for AI systems were under drafting. The dashboard concluded that no harmonised standard on privacy protection is needed, since it is covered by the GDPR and existing standards such as ISO/IEC 27701, 29100, 29151 and 29134. How to assess conformity for AI-specific vulnerabilities was still open, including whether to align with the Cyber Resilience Act and whether assessment should sit alongside the requirements, as in EN 18031, or in a separate document. A question on this was pending with the Commission.
Beyond the standardisation request (lower priority). This group included AI-enhanced nudging, in parallel development with dual European and Indian editorship; a technical report on green and sustainable AI, for which parallel development was rejected because the European work was already too advanced; a specification on metrics for the environmental impact of AI; the conformity assessment technical report CEN/CLC/TR 17894, at ballot until 24 October 2024; competence requirements for AI ethics professionals; specifications on upskilling in AI ethics and on tools for ethical issues; the adopted ISO/IEC TR 24027 (bias) and ISO/IEC 25059 (quality model for AI systems); a taxonomy of AI system methods and capabilities (ISO/IEC 42102); a reference architecture for knowledge engineering; and a preliminary item on impact assessment in the context of fundamental rights, with its form (technical report or European standard) and its relationship to 42001 still open. Guidelines on accuracy improvement were deferred as unnecessary for the request, an example of the committee's effort to keep the programme tight.
ISO/IEC JTC 1/SC 42
The next SC 42 plenary was set for Le Chesnay (France), 7–11 October 2024. Growing interest in generative AI was driving updates to ISO/IEC 22989 and ISO/IEC 23053, and a new project on guidance for addressing risks in generative AI systems had been proposed. ISO/IEC 42005 (impact assessment) was nearly complete, and ISO/IEC 12792 (transparency taxonomy), ISO/IEC 12791 (unwanted bias) and ISO/IEC 42006 (certification body requirements) were well advanced. Other topics in progress, mainly in WG1 and WG3, included uncertainty quantification, a taxonomy of AI methods and capabilities, human oversight, evaluation methods and criteria for trustworthiness, human-machine teaming, beneficial AI systems, reliability, societal and ethical concerns, the SME handbook for ISO/IEC 42001, and nudging.
Forum
Small Business Standards announced its annual Meeting Standards campaign for SMEs, 25–29 November 2024, with online and in-person events across Europe. Equinet announced a high-level conference in Brussels on 12 December 2024 on how equality bodies should respond to the AI Act, aimed at equality bodies, policymakers, civil society and experts on non-discrimination. The UK AI Standards Hub scheduled a webinar on 24 September 2024 on inclusive approaches to AI security standardisation, with speakers from the UK Department for Science, Innovation and Technology, ANEC and Enforce.
Nice to know, useful to read
The issue recommended a blog post by Kai Zenner, head of office and digital policy adviser to MEP Axel Voss, setting out the Commission's and the AI Office's responsibilities and deadlines under the AI Act. It also noted a California Senate bill that would require developers of AI models trained with more than USD 100 million of compute to adopt and disclose a safety and security plan against critical harms, pending the Governor's signature.
My reading
The published dashboard is the most useful document in the series so far. For the first time, it shows the architecture of the European response: which requirements are met by adopting ISO/IEC work and which need homegrown standards. The homegrown list is telling. Risk management, trustworthiness, quality management, datasets, bias, conformity assessment and cybersecurity are exactly the areas where the AI Act's requirements are most specific. The decision not to develop risk management and trustworthiness jointly with ISO/IEC, and the note that 42001 will not be harmonised, are the clearest statements yet of where Europe and the international track diverge.
Two notes in the dashboard have aged well. The warning that formal stages are a poor predictor of completion was borne out when the April 2025 deadline was missed. And the open question on conformity assessment for AI-specific vulnerabilities illustrates a problem that will only grow: the AI Act, the Cyber Resilience Act and the GDPR each bring their own requirements and assessment logic, and someone has to decide which document carries which obligation.
For the live status of each standard, see the Standards Explorer.
Since then (status September 2026)
| September 2024 | Where it stands now |
|---|---|
| AI Act in force since 1 August 2024 | The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). |
| AI Office consultation for the GPAI Code of Practice | The Code of Practice was published in July 2025, together with the template for the public summary of training content. GPAI obligations have applied since 2 August 2025. |
| All request-related projects "under drafting" | The original deadline of 30 April 2025 was missed. By mid-2026, EN 18286 had been approved; prEN 18228 and prEN 18282 were at public Enquiry; prEN 18229-1 (logging) had been through public enquiry and prEN 18229-3 (human oversight) reached it in July 2026. Most other deliverables were still in drafting. |
| Homegrown QMS for regulatory purposes; 42001 "will not be harmonised" | EN 18286 approved on 12 July 2026. The Commission found 42001 not aligned with Article 17. Citation of EN 18286 in the Official Journal is outstanding. |
| Homegrown risk management standard | prEN 18228, at public Enquiry. |
| Homegrown trustworthiness framework | Developed as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026. |
| Logging in parallel development with ISO (ISO/IEC 24970) | The JTC 21 logging deliverable for Article 12 is now prEN 18229-1, Part 1 of the trustworthiness series, which has been through public enquiry. ISO/IEC 24970 continued separately in ISO/IEC JTC 1/SC 42. |
| Homegrown datasets and bias standards | prEN 18284 and prEN 18283 (both drafting). |
| Homegrown conformity assessment framework | prEN 18285 (drafting). |
| Homegrown cybersecurity specifications | prEN 18282, at public Enquiry. |
| CEN/CLC/TR 18115 at ballot | Published in December 2024. |
| ISO/IEC TS 12791 at second ballot | Published as ISO/IEC TS 12791:2024. |
| ISO/IEC 42005, 42006 and 12792 nearly complete | Published in 2025. |
| California frontier model bill awaiting signature | SB 1047 was vetoed in September 2024. A narrower transparency law for frontier model developers, SB 53, was signed in September 2025. |
Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.
Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.