AI Standardisation Watch

    Edition 6 · December 2024

    Edition 6 (December 2024): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 6, December 2024.

    Pipeline at this issue

    prEN 18286quality management

    drafting

    prEN 18228risk management

    enquiry planned

    prEN 18229trustworthiness

    working draft

    prEN 18282cybersecurity

    drafting

    prEN 18283bias management

    drafting

    prEN 18284datasets

    drafting

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 6, December 2024.

    AI Act timeline

    You are here · 2024-12-31

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · next

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    less than a month to prohibited practices and ai literacy apply

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Risk tiers under the AI Act
    UnacceptableHigh riskTransparencyMinimal risk
    1. 01 · Unacceptablea handful of practices

      Social scoring · manipulative techniques · untargeted face scraping

      Prohibited (Article 5)

    2. 02 · High riska small but costly minority

      Recruitment · credit scoring · medical devices · critical infrastructure

      Full duties: risk and quality management, data, logging, oversight (Articles 8–29)

    3. 03 · Transparencya growing share of consumer systems

      Chatbots · emotion recognition · deepfakes · synthetic media

      Disclosure and marking duties (Article 50)

    4. 04 · Minimal riskthe great majority of software

      Spam filters · recommendation engines · most business software

      No specific duties; voluntary codes of conduct

    narrow top = strictest duties · wide base = most systems

    The four risk tiers the Act works with, and what each one triggers.

    Who writes what inside JTC 21

    Each Working group drafts specific deliverables. Horizontal work, such as inclusiveness or technical coherence, sits in a Task Group.

    WG1

    Strategic advisory

    Coherence of the work programme, terminology, inclusiveness, and the overview of standards supporting the AI Act.

    Main deliverables

    prCEN/CLC/TR 18347

    WG2

    Operational aspects

    Quality management, risk management and conformity assessment.

    Main deliverables

    EN 18286 · prEN 18228 · prEN 18285

    WG3

    Engineering aspects

    Datasets, bias, logging (with ISO/IEC), natural language processing and computer vision.

    Main deliverables

    prEN 18284 · prEN 18283 · ISO/IEC 24970

    WG4

    Foundational and societal aspects

    Trustworthiness framework (logging, transparency, human oversight, accuracy, robustness), ethics, environmental impact and fundamental rights.

    Main deliverables

    prEN 18229-1 to 18229-5

    WG5

    Cybersecurity

    Security of AI systems; formed later than the other four groups.

    Main deliverables

    prEN 18282

    five working groups · one shared deadline

    Who does what inside CEN-CENELEC JTC 21, and which drafts each group owns.

    About this issue

    Distribution was slightly delayed so that the issue could report on the JTC 21 plenary in Turin (4–6 November 2024). ETUC continues to provide the secretariat and manages the distribution list.

    News from the European Union

    The Commission was drafting an amendment to the AI standardisation request. It would spell out how the request relates to the relevant articles of the AI Act, Regulation (EU) 2024/1689, and resolve difficulties that had arisen during drafting, such as the definition of risk, which the Act defines as the combination of the probability of harm occurring and the severity of that harm. The Joint Research Centre published a policy brief, Harmonised Standards for the European AI Act, describing the key characteristics expected of the standards that will support the Act.

    The Commission announced more than one hundred initial signatories to the AI Pact, from multinationals to SMEs. The Pact encourages voluntary application of the Act's principles ahead of its application dates. Signatories commit to at least three core actions: an AI governance strategy for compliance, mapping of high-risk AI systems, and AI literacy among staff. More than half also pledged to ensure human oversight, mitigate risks and label certain AI-generated content.

    The first draft of the General-Purpose AI Code of Practice was published on 14 November 2024, closing the first of several drafting rounds planned until April 2025. It was written by independent experts appointed as chairs and vice-chairs of four thematic working groups at the kick-off on 30 September, and feedback meetings were held from 18 to 22 November. The AI Office also opened a multi-stakeholder consultation on how to apply the Act's definition of an AI system and its prohibited practices, addressed to providers, deployers, public authorities, researchers, trade unions, civil society, supervisory authorities and the general public.

    Two further items concerned standardisation policy more broadly. EDU4Standards.eu, a new Horizon Europe project led by Fraunhofer-Gesellschaft, brings together universities, standards bodies and SMEs to strengthen education in standardisation. On 12 November, four European Parliament committees heard Stéphane Séjourné, candidate for Executive Vice-President for Prosperity and Industrial Strategy, a portfolio that includes EU standardisation policy.

    CEN-CENELEC JTC 21

    The first published deliverable. JTC 21 published its first document, CEN/CLC/TR 18115:2024, Data governance and quality for AI within the European context, prepared by WG3. Project leader Domenico Natale highlighted its section on inclusiveness, which describes how the Italian public administration applies the Web Accessibility Directive (EU) 2016/2102 through national law. The example does not concern AI, but the organisational and technical rules it describes, illustrated with a diagram and an Italian case, are offered as a model for organising data governance and quality in AI systems.

    The Turin plenary. More than 120 participants from 21 European countries attended in person or online, together with the Commission and representatives of Japan, industry associations, consumers, workers and NGOs. The Commission announced further standardisation requests on biometrics and on resource performance from early 2025, with requirements for general-purpose AI to follow later, and urged the committee to accelerate work on the ten standards in the AI request. Liaison and partner reports came from ANEC, the 5Rights Foundation, Equinet, the Big Data Value Association, Digital Europe, OWASP and Small Business Standards.

    WG1 (strategic advisory) discussed key definitions to be used across all AI standards, and Task Group Inclusiveness reported on its work. The work programme was to concentrate from now on the standards within the request, with lower priority for other projects. A new work item on functional safety was proposed for joint development with SC 42.

    WG2 (operational aspects) was working on conformity assessment, quality management and risk management. A working draft of the risk management standard was expected to circulate for comments in late 2024 or early 2025, and the deadline for submitting it to CEN Enquiry was extended to August 2025.

    WG3 (engineering aspects) reported that all contributions received so far on the bias and datasets standards had been processed. It announced the start of work on computer vision (taxonomy and accuracy) and continued joint work with SC 42 on robustness, natural language processing and logging.

    WG4 (foundational and societal aspects) circulated a working draft of the AI trustworthiness framework for comments just after the plenary. The draft reflects ANEC's extensive input on the lifecycle of AI as a product or service on the market. Other work in progress covered environmentally sustainable AI, guidelines and metrics for the environmental impact of AI, competence requirements for AI ethics professionals, and AI-enhanced nudging in parallel with SC 42. Preliminary work items covered upskilling organisations on AI ethics, tools for handling ethical issues across the AI lifecycle, and impact assessment in the context of EU fundamental rights.

    WG5 (cybersecurity) agreed the structure of the cybersecurity standard, with a committee draft ballot expected in January 2025, and continued joint work with ISO/IEC JTC 1/SC 27 on AI security threats and mitigation.

    ISO/IEC JTC 1/SC 42

    More than 150 participants from at least 33 countries attended the SC 42 plenary in Versailles (7–11 October 2024), chaired by Wael Diab (USA). The subcommittee has 70 national standards bodies and more than 800 registered experts across five working groups: foundational standards, data, trustworthiness, use cases and applications, and computational approaches. Joint groups have been set up with SC 7 (software and systems engineering, including testing of AI systems and quality models where accessibility characteristics are included), ISO/TC 215 (health informatics), IEC SC 65A and TC 65 (functional safety), ISO/TC 37 (natural language processing) and CEN-CENELEC JTC 21. SC 42 had published 32 standards, 12 of them in the previous year, and had 44 active projects, 23 of them added since the last plenary.

    WG1. ISO/IEC 22989 (concepts and terminology, available free of charge) and ISO/IEC 23053 (framework for machine learning systems) were being amended to take account of generative AI. ISO/IEC 42005 (impact assessment) was expected to be published within weeks, and ISO/IEC 42006 (requirements for certification bodies) was at final ballot. The AI system logging standard was being developed jointly with JTC 21. New projects included ISO/IEC 42007, a framework for developing conformity assessment schemes for AI systems, jointly with ISO's conformity assessment committee (CASCO); implementation guidance for ISO/IEC 42001 aimed at SMEs; and a joint expert group with SC 27 on evaluation criteria and methodology for trustworthy AI systems.

    WG3. ISO/IEC 12791 (unwanted bias) and ISO/IEC 12792 (transparency taxonomy) were ready for publication. Work continued on ISO/IEC 6254 (explainability), ISO/IEC 42105 (human oversight), ISO/IEC 25029 (AI-enhanced nudging, jointly with JTC 21) and ISO/IEC 22443 (societal concerns and ethical considerations). New projects covered watermarking and labelling to help the public identify AI-generated output, a documentation template for the ethical implications of an AI system, and the reliability of AI systems.

    WG4 was preparing technical reports on environmental sustainability of AI systems (ISO/IEC TR 20226, draft expected soon), beneficial AI systems (TR 21221) and use cases of human-machine teaming (TR 25589).

    Forum

    On 6 December, ETUC and the Luxembourg union OGBL held an awareness event with the national standards body ILNAS on why standardisation matters for trade unions, covering the link between standards and legislation, the geopolitics of standards, and practical case studies. Equinet's high-level conference on equality bodies and the AI Act took place in Brussels and online on 12 December, supported by Unia, the Swedish Equality Ombudsman, the Norwegian Equality and Anti-Discrimination Ombud and Luminate. The DIGITAL SME Summit on 10 December in Brussels included a forum on strengthening Europe's standardisation expertise through education. The sixth Athens Roundtable on AI and the rule of law was held at the OECD in Paris on 9 December.

    Arnaud Latil (Sorbonne University) and Marion Ho-Dac coordinated two webinars with the AI Office, on 28 November and 17 December, presenting the AI Act to stakeholders in support of gradual implementation under the AI Pact. The UK AI Standards Hub and Task Group Inclusiveness announced a webinar for civil society on 4 February 2025 on the AI standardisation request, the role of JTC 21, the risk management standard, and fundamental rights.

    Nice to know, useful to read

    From January 2025, ISO and IEC committees were to start new projects and revisions on the Online Standards Development (OSD) platform by default, replacing the Word-based template unless an exemption is requested. CEN and CENELEC published a brochure on gender-responsive standardisation on 24 September 2024.

    Two French-language books were recommended. In L'éthique de l'intelligence artificielle expliquée à mon fils (Mimesis), JTC 21 WG4 convenor Enrico Panai discusses trustworthiness, risk and the work of an ethicist with his son. In Les normes à l'assaut de la démocratie (Odile Jacob), Jean-Denis Combrexelle, former president of the litigation section of the French Conseil d'État, former chief of staff to Prime Minister Élisabeth Borne and former director general of Labour, examines the political, legal and administrative mechanisms that multiply rules and lengthen texts in France and Europe. Note that the French normes covers legal and administrative norms in general, not only technical standards.

    My reading

    Two items in this issue deserve more weight than their placement suggests. The first is the Commission's plan to tie the standardisation request explicitly to the articles of the AI Act and to settle definitional questions such as the meaning of risk. That is the right direction: when the Act defines risk as the combination of probability and severity of harm, a risk management standard that works with a different concept will produce conformity that does not map cleanly onto the legal obligation. The WG2 subgroup on risk acceptability now had a legal anchor to work from.

    The second is the extension of the deadline for submitting the risk management draft to Enquiry to August 2025. With the request's original delivery date set at 30 April 2025, this was the first explicit sign in the newsletter that the timeline could not hold. It is also worth noting that JTC 21's first published deliverable was a technical report, a document type that cannot give a presumption of conformity.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    December 2024Where it stands now
    Amendment to the AI standardisation request in preparationAdopted in June 2025 as C(2025)3871 (M/613), replacing the original decision and extending the timeline to 28 February 2027.
    First draft of the GPAI Code of Practice; drafting planned until April 2025The final Code was published in July 2025, later than first planned. GPAI obligations have applied since 2 August 2025.
    AI Office consultation on the AI system definition and prohibited practicesProhibitions have applied since 2 February 2025. The Commission published guidelines on prohibited practices and on the definition of an AI system in February 2025.
    Hearing of Stéphane SéjournéConfirmed as Executive Vice-President; the new Commission took office on 1 December 2024. A revision of Regulation (EU) No 1025/2012 is expected to be proposed in October 2026, according to press reports.
    Risk management draft to CEN Enquiry by August 2025The original delivery deadline of 30 April 2025 was missed. prEN 18228 was at public Enquiry as of June 2026.
    WG5 committee draft ballot expected January 2025prEN 18282, at public Enquiry (June 2026).
    Working draft of the trustworthiness framework circulatedDeveloped as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026.
    Bias and datasets standards: all contributions processedprEN 18283 and prEN 18284 (both drafting). A working-draft consultation on prEN 18283 closed on 30 April 2026.
    WG2: quality management and conformity assessmentEN 18286 approved on 12 July 2026, with citation in the Official Journal outstanding. prEN 18285 (conformity assessment) in drafting.
    Commission urged faster delivery of the ten standardsIn October 2025, CEN-CENELEC adopted exceptional measures aiming for the prioritised deliverables to be available by Q4 2026. The Digital Omnibus on AI moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
    SC 42 watermarking and labelling project launchedRelevant to Article 50(2) of the AI Act, which applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026.
    ISO/IEC 42005 due within weeks; 42006 at final ballot; 12791 and 12792 readyPublished as ISO/IEC 42005:2025, ISO/IEC 42006:2025, ISO/IEC TS 12791:2024 and ISO/IEC 12792:2025.

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    All 16 editions are listed in the news feed.