AI Standardisation Watch

    Edition 7 · February 2025

    Edition 7 (February 2025): the essence

    AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 7, February 2025.

    Pipeline at this issue

    prEN 18286quality management

    to Commission

    prEN 18228risk management

    to Commission

    prEN 18229trustworthiness

    to Commission

    prEN 18282cybersecurity

    to Commission

    prEN 18283bias management

    to Commission

    prEN 18284datasets

    to Commission

    prEN 18285conformity assessment

    drafting

    not started · drafting · enquiry · approved · cited in OJ

    Status of the AI Act deliverables as described in Edition 7, February 2025.

    AI Act timeline

    You are here · 2025-02-28

    1. 1 Aug 2024 · in force

      AI Act enters into force

    2. 2 Feb 2025 · in force

      Prohibited practices and AI literacy apply

    3. 2 Aug 2025 · next

      GPAI model obligations, governance and penalties apply

    4. 2 Aug 2026

      General application, including Article 50 transparency duties

    5. 2 Dec 2026

      Article 50(2) marking obligations apply to AI systems already on the market

    6. 28 Feb 2027

      Standardisation request M/613 expires

    7. 2 Aug 2027

      Deadline for general-purpose AI models placed on the market before 2 August 2025

    8. 2 Dec 2027

      Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)

    9. 2 Aug 2028

      Annex I high-risk duties apply (Digital Omnibus)

    5 months to gpai model obligations, governance and penalties apply

    filled = already in force · hollow = still ahead · flag = date of this issue

    Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.

    Who carries which duty

    01 · Provider

    Develops or places the system on the market

    • Risk and quality management
    • Technical documentation
    • Conformity assessment, CE marking, registration

    02 · Importer

    Brings a third-country system into the Union

    • Verifies assessment and documentation
    • Checks marking and representative
    • Keeps records, cooperates with authorities

    03 · Distributor

    Makes the system available down the chain

    • Checks marking and accompanying documents
    • Acts on non-conformity it becomes aware of
    • Storage and transport conditions

    04 · Deployer

    Uses the system under its own authority

    • Follows instructions, ensures human oversight
    • Input data relevance, log keeping
    • FRIA where required (Article 27)

    The chain can flip · Article 25

    A deployer, importer or distributor becomes the provider — with every provider duty attached — when it puts its own name or trade mark on a high-risk system, changes its intended purpose, or substantially modifies it.

    Authorised Representative

    Appointed by a third-country provider

    • Holds documentation for ten years
    • Point of contact for authorities

    Operator

    Umbrella term covering every role in the chain

    • Used where a duty applies regardless of role

    duties travel left to right along the chain

    How duties travel along the supply chain, and where a role changes hands.

    Who is actually in the room

    Inclusiveness survey

    146/195

    75% of eligible JTC 21 members and observers answered the spring 2025 survey.

    120+

    Turin plenary

    participants from 21 countries

    150+

    Bath plenary

    participants from 20+ countries

    800+

    ISO/IEC SC 42

    registered experts, 70 national bodies

    350+

    Civil society webinars

    participants at the largest sessions

    Newsletter reach, edition by edition

    70+
    Edition 3
    500+ views
    Edition 5
    250+
    Edition 7
    several hundred
    Edition 8

    figures as reported in the newsletter

    Who takes part, and how far the work reaches.

    About this issue

    The newsletter now reached more than 250 direct recipients, in addition to LinkedIn downloads. Alongside the ETUC page and the LinkedIn group, issues are also linked from the new public JTC 21 website, jtc21.eu. ETUC continues to provide the secretariat.

    In memoriam

    The issue is dedicated to Renaud di Francesco, who died suddenly at the end of 2024. As chair of the JTC 21 WG2 task group responsible for the risk management standard, he was remembered as an effective and collaborative leader who handled difficult discussions with wisdom and humour, looked for workable compromises, and consistently supported inclusiveness in standards development.

    News from the European Union

    The third meeting of the High-Level Forum on European Standardisation took place in Brussels on 29 January 2025, chaired by Stéphane Séjourné. It reviewed the Forum's working groups and the annual Union work programme, and discussed priorities for the rest of the mandate. The Forum also published two reports: a final report on alignment between European and international standards, using the machinery sector as a case study, and recommendations on funding European participation in international standardisation, with attention to EU strategic interests, SMEs and industrial policy.

    The second draft of the General-Purpose AI Code of Practice was published after a consultation involving around 1,000 participants, including Member State representatives and international observers, and working group meetings in November 2024. The Code is meant to help providers of general-purpose AI models show compliance across the model lifecycle, particularly for models released after 2 August 2025, when the relevant obligations apply. A third draft was expected in mid-February 2025.

    The AI Office ran a targeted consultation to prepare guidelines on the definition of an AI system and on prohibited practices, ahead of the prohibitions applying on 2 February 2025. The Commission then published its guidelines on prohibited AI practices. They cover harmful manipulation and deception, harmful exploitation of vulnerabilities, social scoring, individual criminal offence risk assessment and prediction, untargeted scraping to build facial recognition databases, emotion recognition, biometric categorisation, and real-time remote biometric identification.

    CEN-CENELEC JTC 21

    Public website. JTC 21 launched jtc21.eu, explaining what the committee is and does, how to follow project status, how to contact it, what the AI Act is, and who can join.

    First drafts sent to the Commission. A preliminary set of six standards was sent to the Commission as working documents, to report progress on the standardisation request and invite feedback: the AI trustworthiness framework, AI risk management, cybersecurity specifications for AI systems, concepts, measures and requirements for managing bias, quality and governance of datasets, and the quality management system for AI Act regulatory purposes. A second list set out the published European and international standards referenced by these six. Further submissions were expected.

    Annex ZA. All five working groups were giving increasing attention to Annex ZA, the part of each harmonised standard that maps its clauses to the provisions of the AI Act.

    Lifecycle perspective. ANEC had made a series of contributions on how standards should address each phase of the product lifecycle, from inception to retirement, mainly to the WG4 trustworthiness standard but also in WG2 (risk management) and WG3. A new work item, Stakeholder life cycle, was proposed in WG1. It would explain the AI Act's definitions and the supporting harmonised standards to stakeholders worldwide, supporting interoperability between ISO/IEC and CEN-CENELEC standards, and map the roles and responsibilities of different stakeholders across the AI system and product lifecycle, including in risk management and quality. ANEC's AI expert Pete Eisenegger, an early advocate of the lifecycle approach, retired in January 2025, and ANEC was looking for a new expert to represent consumers in AI standardisation.

    Onboarding and liaisons. Task Group Inclusiveness published a welcome package for new working group members in December 2024, listing documents that explain how standards are made and the vocabulary involved. The NoLeFa project, a consortium of two public bodies, three SMEs and a European research network working on testing infrastructure for trustworthy AI and on reducing compliance burdens for SMEs, was granted liaison status.

    WG1 (strategic advisory) prepared CEN-CENELEC's response to the amended standardisation request, stressing the need for sufficient time to prepare the standards. Its Technical Coherence Forum was working on common definitions of AI terms for use across all working groups.

    WG2 (operational aspects) published the technical report CEN/CLC/TR 17894:2024 on conformity assessment in December 2024. It reviews current methods and practices for conformity assessment of AI systems, including tools, assets and acceptability conditions, and covers products, services, processes, management systems and organisations from both horizontal and sector-specific perspectives. Work continued on a full European standard on conformity assessment, on quality management and on risk management, with committee drafts on the last two expected to go to vote shortly.

    WG3 (engineering aspects) noted that CEN/CLC/TR 18115:2024 on data governance and quality addresses inclusivity and accessibility in its subclause 9.5, and that accessibility also appears in ISO/IEC 25059 (quality model for AI systems) and ISO/IEC 5259-2 (data quality measures). Work continued on logging, natural language processing and robustness.

    WG4 (foundational and societal aspects) circulated a first draft of the AI trustworthiness framework, which drew more than 2,000 comments from national standards bodies. The comment list was substantially consolidated, weekly resolution meetings were being held, and an updated draft was due in February. The draft technical report CEN/CLC/TR 18145 on environmentally sustainable AI was accepted, with comments still to resolve, and the working draft on competence requirements for AI ethics professionals was in comment resolution. Other active work covered tools for handling ethical aspects across the AI lifecycle, upskilling on AI ethics, "frugal AI" in liaison with ISO, IEEE, ITU, the OECD and the AI Action Summit, and a document on implementing protections for fundamental rights across the AI lifecycle.

    WG5 (cybersecurity) launched a committee draft ballot in January 2025 and continued joint work with ISO/IEC JTC 1/SC 27 on AI security threats and mitigation.

    ISO/IEC JTC 1/SC 42

    SC 42 was working on more than 40 standards. ISO/IEC 5259-5, a data quality governance framework for analytics and machine learning, had been approved for publication. ISO/IEC 22443 on societal concerns and ethical considerations was receiving contributions from outside Europe. The amendments to ISO/IEC 22989 and ISO/IEC 23053 addressing generative AI were in comment resolution after ballot. A new working draft of ISO/IEC 25059 proposed new definitions on sustainability and environment, as well as on safety and quality in use.

    New projects approved as technical specifications included terminology for domain engineering of AI systems (ISO/IEC 25566), guidance on risks in generative AI systems (ISO/IEC 25568), reliability of AI systems (ISO/IEC 25570) and a template for documenting the ethical implications of AI systems (ISO/IEC 25571). A framework for human-machine teaming (ISO/IEC 25589) was approved, work began on SME-oriented implementation guidance for ISO/IEC 42001 (ISO/IEC 25651), and a ballot opened on a process assessment model for AI system lifecycle processes (ISO/IEC 25704). A first draft of ISO/IEC 42105 on human oversight was out for comment, and work on ISO/IEC TR 42109 on human-machine teaming use cases had started with six cases, such as food ordering and delivery and planning of educational content.

    IEEE

    The issue pointed to IEEE's AI ethics and governance standards, available free of charge through the IEEE GET Program. They include IEEE 2089-2021 (age-appropriate digital services based on the 5Rights principles), 7000-2021 (addressing ethical concerns in system design), 7001-2021 (transparency of autonomous systems), 7002-2022 (data privacy process), 7003-2024 (algorithmic bias), 7005-2021 (transparent employer data governance), 7007-2021 (ontological standard for ethically driven robotics), 7009-2024 (fail-safe design of autonomous systems), 7010-2020 (impact on human well-being) and 7014-2024 (emulated empathy).

    Fora

    France hosted the AI Action Summit in Paris on 10–11 February 2025, in partnership with India, bringing together close to one hundred countries and more than a thousand representatives of industry and civil society. It closed a week of events that included an international scientific conference on AI, science and society at Institut Polytechnique de Paris on 6–7 February.

    On 4 February, more than 350 people attended the webinar Implementing the EU AI Act through standards, organised by the UK AI Standards Hub and Task Group Inclusiveness. It presented the standardisation request with a focus on inclusiveness, risk management and fundamental rights, and a recording is available. A follow-up workshop to collect civil society input on the risk management standard was planned for 5 March.

    Nice to know, useful to read

    The IEC Academy launched a training module on gender-responsive standards, available to ISO and IEC experts in English, French, Spanish and Russian and based on joint ISO/IEC guidance.

    On 9 January 2025, Corporate Europe Observatory published Bias baked in: How Big Tech sets its own AI standards. The report questions how the standards that will govern AI systems, and their compliance with fundamental rights obligations, are being developed, noting that standard-setting is being used for the first time to implement requirements on fundamental rights, fairness, trustworthiness and bias. The newsletter observed that the report goes to the core of Task Group Inclusiveness's work and included it for information.

    South Korea passed its Basic Act on the Development of Artificial Intelligence and the Establishment of Trust, becoming the second jurisdiction after the EU to adopt comprehensive AI legislation.

    My reading

    The quiet headline of this issue is Annex ZA. Once working groups start mapping clauses to articles, the question shifts from "is this a good standard?" to "which legal obligation does this clause discharge, and under what conditions?". That mapping is where presumption of conformity will be won or lost, and it is also where gaps become visible.

    The proposed Stakeholder life cycle item points in the same direction from another angle. Mapping roles and responsibilities across the lifecycle is, in substance, a statement of who must do what, when and on whose behalf. The more explicitly the standards state those duties, the easier it becomes to check whether the right party has met them.

    Two numbers are also worth noting. More than 2,000 comments on a first draft say something about how contested the trustworthiness framework was. And the Corporate Europe Observatory report, which the newsletter carefully labelled "for information", shows that the legitimacy of using standards to operationalise fundamental rights was now being questioned openly from outside the process.

    For the live status of each standard, see the Standards Explorer.

    Since then (status September 2026)

    February 2025Where it stands now
    CEN-CENELEC response to the amended request, asking for sufficient timeThe amended request was adopted in June 2025 as C(2025)3871 (M/613), extending the timeline to 28 February 2027. The original deadline of 30 April 2025 was missed, and CEN-CENELEC adopted exceptional acceleration measures in October 2025.
    Six draft standards sent to the CommissionTrustworthiness framework: now a five-part prEN 18229 series (logging, transparency, human oversight, accuracy, robustness); Part 1 has been through public enquiry and Part 3 reached it in July 2026. Risk management: prEN 18228, at public Enquiry. Cybersecurity: prEN 18282, at public Enquiry. Bias: prEN 18283 (drafting). Datasets: prEN 18284 (drafting). Quality management: EN 18286, approved on 12 July 2026.
    Committee drafts on risk management and QMS "shortly"The QMS draft went to public Enquiry from 30 October 2025 to January 2026 and was approved in July 2026. Citation in the Official Journal is outstanding.
    Increasing focus on Annex ZAEN 18286 contains an Annex ZA mapping its clauses to the AI Act, including Articles 17(1) and 11(1). Its exact legal effect will depend on the reference published in the Official Journal.
    Full European standard on conformity assessmentprEN 18285 (drafting).
    Third draft of the GPAI Code of Practice expectedThe final Code was published in July 2025. GPAI obligations have applied since 2 August 2025.
    Guidelines on prohibited practices publishedProhibitions have applied since 2 February 2025. The Commission also published guidelines on the definition of an AI system in February 2025.
    High-Level Forum work on alignment and fundingA revision of Regulation (EU) No 1025/2012 is in the Commission's 2026 work programme, with a proposal expected in October 2026 according to press reports.
    ISO/IEC 5259-5 approved for publicationPublished as ISO/IEC 5259-5:2025.
    South Korea's AI Basic Act passedEntered into force on 22 January 2026.
    Timeline for EU high-risk obligationsThe Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

    Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.

    Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.

    All 16 editions are listed in the news feed.