Edition 7 · February 2025
Edition 7 (February 2025): the essence
AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 7, February 2025.
prEN 18286quality management
to Commission
prEN 18228risk management
to Commission
prEN 18229trustworthiness
to Commission
prEN 18282cybersecurity
to Commission
prEN 18283bias management
to Commission
prEN 18284datasets
to Commission
prEN 18285conformity assessment
drafting
not started · drafting · enquiry · approved · cited in OJ
Status of the AI Act deliverables as described in Edition 7, February 2025.
1 Aug 2024
AI Act enters into force
2 Feb 2025
Prohibited practices and AI literacy apply
2 Aug 2025
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
5 months to gpai model obligations, governance and penalties apply
You are here · 2025-02-28
1 Aug 2024 · in force
AI Act enters into force
2 Feb 2025 · in force
Prohibited practices and AI literacy apply
2 Aug 2025 · next
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
5 months to gpai model obligations, governance and penalties apply
filled = already in force · hollow = still ahead · flag = date of this issue
Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.
01 · Provider
Develops or places the system on the market
- Risk and quality management
- Technical documentation
- Conformity assessment, CE marking, registration
02 · Importer
Brings a third-country system into the Union
- Verifies assessment and documentation
- Checks marking and representative
- Keeps records, cooperates with authorities
03 · Distributor
Makes the system available down the chain
- Checks marking and accompanying documents
- Acts on non-conformity it becomes aware of
- Storage and transport conditions
04 · Deployer
Uses the system under its own authority
- Follows instructions, ensures human oversight
- Input data relevance, log keeping
- FRIA where required (Article 27)
The chain can flip · Article 25
A deployer, importer or distributor becomes the provider — with every provider duty attached — when it puts its own name or trade mark on a high-risk system, changes its intended purpose, or substantially modifies it.
Authorised Representative
Appointed by a third-country provider
- Holds documentation for ten years
- Point of contact for authorities
Operator
Umbrella term covering every role in the chain
- Used where a duty applies regardless of role
duties travel left to right along the chain
How duties travel along the supply chain, and where a role changes hands.
Inclusiveness survey
146/195
75% of eligible JTC 21 members and observers answered the spring 2025 survey.
120+
Turin plenary
participants from 21 countries
150+
Bath plenary
participants from 20+ countries
800+
ISO/IEC SC 42
registered experts, 70 national bodies
350+
Civil society webinars
participants at the largest sessions
Newsletter reach, edition by edition
figures as reported in the newsletter
Who takes part, and how far the work reaches.
About this issue
The newsletter now reached more than 250 direct recipients, in addition to LinkedIn downloads. Alongside the ETUC page and the LinkedIn group, issues are also linked from the new public JTC 21 website, jtc21.eu. ETUC continues to provide the secretariat.
In memoriam
The issue is dedicated to Renaud di Francesco, who died suddenly at the end of 2024. As chair of the JTC 21 WG2 task group responsible for the risk management standard, he was remembered as an effective and collaborative leader who handled difficult discussions with wisdom and humour, looked for workable compromises, and consistently supported inclusiveness in standards development.
News from the European Union
The third meeting of the High-Level Forum on European Standardisation took place in Brussels on 29 January 2025, chaired by Stéphane Séjourné. It reviewed the Forum's working groups and the annual Union work programme, and discussed priorities for the rest of the mandate. The Forum also published two reports: a final report on alignment between European and international standards, using the machinery sector as a case study, and recommendations on funding European participation in international standardisation, with attention to EU strategic interests, SMEs and industrial policy.
The second draft of the General-Purpose AI Code of Practice was published after a consultation involving around 1,000 participants, including Member State representatives and international observers, and working group meetings in November 2024. The Code is meant to help providers of general-purpose AI models show compliance across the model lifecycle, particularly for models released after 2 August 2025, when the relevant obligations apply. A third draft was expected in mid-February 2025.
The AI Office ran a targeted consultation to prepare guidelines on the definition of an AI system and on prohibited practices, ahead of the prohibitions applying on 2 February 2025. The Commission then published its guidelines on prohibited AI practices. They cover harmful manipulation and deception, harmful exploitation of vulnerabilities, social scoring, individual criminal offence risk assessment and prediction, untargeted scraping to build facial recognition databases, emotion recognition, biometric categorisation, and real-time remote biometric identification.
CEN-CENELEC JTC 21
Public website. JTC 21 launched jtc21.eu, explaining what the committee is and does, how to follow project status, how to contact it, what the AI Act is, and who can join.
First drafts sent to the Commission. A preliminary set of six standards was sent to the Commission as working documents, to report progress on the standardisation request and invite feedback: the AI trustworthiness framework, AI risk management, cybersecurity specifications for AI systems, concepts, measures and requirements for managing bias, quality and governance of datasets, and the quality management system for AI Act regulatory purposes. A second list set out the published European and international standards referenced by these six. Further submissions were expected.
Annex ZA. All five working groups were giving increasing attention to Annex ZA, the part of each harmonised standard that maps its clauses to the provisions of the AI Act.
Lifecycle perspective. ANEC had made a series of contributions on how standards should address each phase of the product lifecycle, from inception to retirement, mainly to the WG4 trustworthiness standard but also in WG2 (risk management) and WG3. A new work item, Stakeholder life cycle, was proposed in WG1. It would explain the AI Act's definitions and the supporting harmonised standards to stakeholders worldwide, supporting interoperability between ISO/IEC and CEN-CENELEC standards, and map the roles and responsibilities of different stakeholders across the AI system and product lifecycle, including in risk management and quality. ANEC's AI expert Pete Eisenegger, an early advocate of the lifecycle approach, retired in January 2025, and ANEC was looking for a new expert to represent consumers in AI standardisation.
Onboarding and liaisons. Task Group Inclusiveness published a welcome package for new working group members in December 2024, listing documents that explain how standards are made and the vocabulary involved. The NoLeFa project, a consortium of two public bodies, three SMEs and a European research network working on testing infrastructure for trustworthy AI and on reducing compliance burdens for SMEs, was granted liaison status.
WG1 (strategic advisory) prepared CEN-CENELEC's response to the amended standardisation request, stressing the need for sufficient time to prepare the standards. Its Technical Coherence Forum was working on common definitions of AI terms for use across all working groups.
WG2 (operational aspects) published the technical report CEN/CLC/TR 17894:2024 on conformity assessment in December 2024. It reviews current methods and practices for conformity assessment of AI systems, including tools, assets and acceptability conditions, and covers products, services, processes, management systems and organisations from both horizontal and sector-specific perspectives. Work continued on a full European standard on conformity assessment, on quality management and on risk management, with committee drafts on the last two expected to go to vote shortly.
WG3 (engineering aspects) noted that CEN/CLC/TR 18115:2024 on data governance and quality addresses inclusivity and accessibility in its subclause 9.5, and that accessibility also appears in ISO/IEC 25059 (quality model for AI systems) and ISO/IEC 5259-2 (data quality measures). Work continued on logging, natural language processing and robustness.
WG4 (foundational and societal aspects) circulated a first draft of the AI trustworthiness framework, which drew more than 2,000 comments from national standards bodies. The comment list was substantially consolidated, weekly resolution meetings were being held, and an updated draft was due in February. The draft technical report CEN/CLC/TR 18145 on environmentally sustainable AI was accepted, with comments still to resolve, and the working draft on competence requirements for AI ethics professionals was in comment resolution. Other active work covered tools for handling ethical aspects across the AI lifecycle, upskilling on AI ethics, "frugal AI" in liaison with ISO, IEEE, ITU, the OECD and the AI Action Summit, and a document on implementing protections for fundamental rights across the AI lifecycle.
WG5 (cybersecurity) launched a committee draft ballot in January 2025 and continued joint work with ISO/IEC JTC 1/SC 27 on AI security threats and mitigation.
ISO/IEC JTC 1/SC 42
SC 42 was working on more than 40 standards. ISO/IEC 5259-5, a data quality governance framework for analytics and machine learning, had been approved for publication. ISO/IEC 22443 on societal concerns and ethical considerations was receiving contributions from outside Europe. The amendments to ISO/IEC 22989 and ISO/IEC 23053 addressing generative AI were in comment resolution after ballot. A new working draft of ISO/IEC 25059 proposed new definitions on sustainability and environment, as well as on safety and quality in use.
New projects approved as technical specifications included terminology for domain engineering of AI systems (ISO/IEC 25566), guidance on risks in generative AI systems (ISO/IEC 25568), reliability of AI systems (ISO/IEC 25570) and a template for documenting the ethical implications of AI systems (ISO/IEC 25571). A framework for human-machine teaming (ISO/IEC 25589) was approved, work began on SME-oriented implementation guidance for ISO/IEC 42001 (ISO/IEC 25651), and a ballot opened on a process assessment model for AI system lifecycle processes (ISO/IEC 25704). A first draft of ISO/IEC 42105 on human oversight was out for comment, and work on ISO/IEC TR 42109 on human-machine teaming use cases had started with six cases, such as food ordering and delivery and planning of educational content.
IEEE
The issue pointed to IEEE's AI ethics and governance standards, available free of charge through the IEEE GET Program. They include IEEE 2089-2021 (age-appropriate digital services based on the 5Rights principles), 7000-2021 (addressing ethical concerns in system design), 7001-2021 (transparency of autonomous systems), 7002-2022 (data privacy process), 7003-2024 (algorithmic bias), 7005-2021 (transparent employer data governance), 7007-2021 (ontological standard for ethically driven robotics), 7009-2024 (fail-safe design of autonomous systems), 7010-2020 (impact on human well-being) and 7014-2024 (emulated empathy).
Fora
France hosted the AI Action Summit in Paris on 10–11 February 2025, in partnership with India, bringing together close to one hundred countries and more than a thousand representatives of industry and civil society. It closed a week of events that included an international scientific conference on AI, science and society at Institut Polytechnique de Paris on 6–7 February.
On 4 February, more than 350 people attended the webinar Implementing the EU AI Act through standards, organised by the UK AI Standards Hub and Task Group Inclusiveness. It presented the standardisation request with a focus on inclusiveness, risk management and fundamental rights, and a recording is available. A follow-up workshop to collect civil society input on the risk management standard was planned for 5 March.
Nice to know, useful to read
The IEC Academy launched a training module on gender-responsive standards, available to ISO and IEC experts in English, French, Spanish and Russian and based on joint ISO/IEC guidance.
On 9 January 2025, Corporate Europe Observatory published Bias baked in: How Big Tech sets its own AI standards. The report questions how the standards that will govern AI systems, and their compliance with fundamental rights obligations, are being developed, noting that standard-setting is being used for the first time to implement requirements on fundamental rights, fairness, trustworthiness and bias. The newsletter observed that the report goes to the core of Task Group Inclusiveness's work and included it for information.
South Korea passed its Basic Act on the Development of Artificial Intelligence and the Establishment of Trust, becoming the second jurisdiction after the EU to adopt comprehensive AI legislation.
My reading
The quiet headline of this issue is Annex ZA. Once working groups start mapping clauses to articles, the question shifts from "is this a good standard?" to "which legal obligation does this clause discharge, and under what conditions?". That mapping is where presumption of conformity will be won or lost, and it is also where gaps become visible.
The proposed Stakeholder life cycle item points in the same direction from another angle. Mapping roles and responsibilities across the lifecycle is, in substance, a statement of who must do what, when and on whose behalf. The more explicitly the standards state those duties, the easier it becomes to check whether the right party has met them.
Two numbers are also worth noting. More than 2,000 comments on a first draft say something about how contested the trustworthiness framework was. And the Corporate Europe Observatory report, which the newsletter carefully labelled "for information", shows that the legitimacy of using standards to operationalise fundamental rights was now being questioned openly from outside the process.
For the live status of each standard, see the Standards Explorer.
Since then (status September 2026)
| February 2025 | Where it stands now |
|---|---|
| CEN-CENELEC response to the amended request, asking for sufficient time | The amended request was adopted in June 2025 as C(2025)3871 (M/613), extending the timeline to 28 February 2027. The original deadline of 30 April 2025 was missed, and CEN-CENELEC adopted exceptional acceleration measures in October 2025. |
| Six draft standards sent to the Commission | Trustworthiness framework: now a five-part prEN 18229 series (logging, transparency, human oversight, accuracy, robustness); Part 1 has been through public enquiry and Part 3 reached it in July 2026. Risk management: prEN 18228, at public Enquiry. Cybersecurity: prEN 18282, at public Enquiry. Bias: prEN 18283 (drafting). Datasets: prEN 18284 (drafting). Quality management: EN 18286, approved on 12 July 2026. |
| Committee drafts on risk management and QMS "shortly" | The QMS draft went to public Enquiry from 30 October 2025 to January 2026 and was approved in July 2026. Citation in the Official Journal is outstanding. |
| Increasing focus on Annex ZA | EN 18286 contains an Annex ZA mapping its clauses to the AI Act, including Articles 17(1) and 11(1). Its exact legal effect will depend on the reference published in the Official Journal. |
| Full European standard on conformity assessment | prEN 18285 (drafting). |
| Third draft of the GPAI Code of Practice expected | The final Code was published in July 2025. GPAI obligations have applied since 2 August 2025. |
| Guidelines on prohibited practices published | Prohibitions have applied since 2 February 2025. The Commission also published guidelines on the definition of an AI system in February 2025. |
| High-Level Forum work on alignment and funding | A revision of Regulation (EU) No 1025/2012 is in the Commission's 2026 work programme, with a proposal expected in October 2026 according to press reports. |
| ISO/IEC 5259-5 approved for publication | Published as ISO/IEC 5259-5:2025. |
| South Korea's AI Basic Act passed | Entered into force on 22 January 2026. |
| Timeline for EU high-risk obligations | The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). |
Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.
Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.