Edition 8 · April 2025
Edition 8 (April 2025): the essence
AI Standardisation Inclusiveness Newsletter, CEN-CENELEC JTC 21 Task Group Inclusiveness. Edition 8, April 2025.
prEN 18286quality management
Commission feedback
prEN 18228risk management
Commission feedback
prEN 18229trustworthiness
Commission feedback
prEN 18282cybersecurity
Commission feedback
prEN 18283bias management
Commission feedback
prEN 18284datasets
Commission feedback
prEN 18285conformity assessment
drafting
not started · drafting · enquiry · approved · cited in OJ
Status of the AI Act deliverables as described in Edition 8, April 2025.
1 Aug 2024
AI Act enters into force
2 Feb 2025
Prohibited practices and AI literacy apply
2 Aug 2025
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
3 months to gpai model obligations, governance and penalties apply
You are here · 2025-04-30
1 Aug 2024 · in force
AI Act enters into force
2 Feb 2025 · in force
Prohibited practices and AI literacy apply
2 Aug 2025 · next
GPAI model obligations, governance and penalties apply
2 Aug 2026
General application, including Article 50 transparency duties
2 Dec 2026
Article 50(2) marking obligations apply to AI systems already on the market
28 Feb 2027
Standardisation request M/613 expires
2 Aug 2027
Deadline for general-purpose AI models placed on the market before 2 August 2025
2 Dec 2027
Annex III high-risk duties and Article 27 FRIA apply (Digital Omnibus)
2 Aug 2028
Annex I high-risk duties apply (Digital Omnibus)
3 months to gpai model obligations, governance and penalties apply
filled = already in force · hollow = still ahead · flag = date of this issue
Where the AI Act stood when this issue appeared, and what was still ahead. Dates reflect the Digital Omnibus, Regulation (EU) 2026/1744.
About this issue
The newsletter was now distributed to several hundred people and published on the JTC 21 website, the JTC 21 LinkedIn group and the ETUC website. ETUC continues to provide the secretariat.
News from the European Union
Annual Union Work Programme 2025. On 20 March 2025, the Commission published the 2025 work programme for European standardisation, C(2025) 1654, with 78 actions. Its policy priorities include bio-based and wood-derived products, critical raw materials for electric vehicle batteries, qualification of materials for small modular reactors, the EU Digital Identity Wallet, the EU Trusted Data Framework, and quantum technology including post-quantum cryptography. The digital actions also cover cybersecurity requirements for products with digital elements, interoperability of data processing services, virtual and augmented reality, intermediary digital services, and data dictionaries in engineering, alongside continued support for EU AI policy through JTC 21.
AI Act governance. The AI Board held its third meeting on 24 March. The AI Office updated it on the guidelines on the AI system definition and prohibited practices, the third draft of the General-Purpose AI Code of Practice, and the call for the scientific panel. The Commission had adopted the implementing act establishing that panel on 11 March. The panel will advise on governance and enforcement and can alert the AI Office to risks posed by general-purpose AI models, and a call for expressions of interest was to follow.
GPAI Code of Practice. The third draft was published on 11 March, marking the final drafting stage before the Code was finalised on the basis of stakeholder feedback. It set out two commitments on transparency and copyright for all providers of general-purpose AI models, and sixteen commitments on safety and security for providers of models with systemic risk, each supported by practical implementation measures.
Funding. The EUACT-AI project opened a call, closing 27 March, to fund experts taking part in JTC 21, covering meeting participation, drafting and reporting.
CEN-CENELEC JTC 21
Plenary and timeline. The 11th plenary was announced for Stavanger, Norway, 12–15 May 2025, in hybrid format. The newsletter noted that the AI Act's main obligations were due to apply by August 2026, that JTC 21 was monitoring each standard's timeline closely, and that delays should nevertheless be expected. Draft standards were expected to enter public enquiry one after another over the summer.
Task Group Inclusiveness. Cezara Popovici (ANEC) was appointed co-chair, alongside Philippe Saint-Aubin (ETUC).
Working practices. In March, JTC 21 published two internal documents, available on request from the secretariat: best practice for working groups, aimed at improving the dynamics of large meetings, and a health and safety policy paper with advice on managing stress caused by heavy workloads.
Commission feedback on the first drafts. The Commission had provided preliminary assessments of five of the six drafts JTC 21 submitted in February: the trustworthiness framework, risk management, cybersecurity specifications, quality and governance of datasets, the quality management system, and managing bias. The feedback had been shared with the working groups, which were integrating it into the drafts.
Confidentiality. The newsletter reminded readers that draft standards are made public only at the enquiry stage, and that those interested in a particular draft should contact their national standards body. Most drafts were in comment resolution, with several expected to reach public enquiry within weeks or months.
WG2 (operational aspects) was working on conformity assessment, quality management and risk management, all considered essential for the standardisation request, with committee draft ballots expected soon.
WG3 (engineering aspects) was working on datasets, bias, computer vision, natural language processing, robustness and logging, the last with a committee draft ballot under way. A committee draft of the taxonomy of AI system methods and capabilities, developed with SC 42, was expected in July or August.
WG4 (foundational and societal aspects) published CEN/CLC/TR 18145:2025 on environmentally sustainable AI in February. Its main task remained the trustworthiness framework, whose committee draft was still in comment resolution. Projects at earlier stages covered competence requirements for AI ethics professionals, tools for handling ethical aspects, upskilling on AI ethics, guidelines and metrics for the environmental impact of AI, fundamental rights considerations for AI providers, and risk management for critical infrastructure. A new preliminary work item on AI intervention labelling was proposed. It would link graphical symbols to the relevant AI concepts, to help people distinguish AI-generated, human-produced and hybrid content.
WG5 (cybersecurity) continued work on cybersecurity specifications for AI systems, held a joint meeting with WG2 on where and how cybersecurity risks should be addressed, and continued joint work with SC 27 on AI security threats and mitigation.
ISO/IEC JTC 1/SC 42
The SC 42 plenary took place in New Delhi, 31 March to 4 April 2025. Given the cross-cutting nature of AI, SC 42 maintains regular contact with IEC, the United Nations, the OECD and the World Economic Forum, and with committees working on cinematography, particles, health informatics and financial services. The newsletter focused on documents of interest to civil society.
WG1 (foundational standards). ISO/IEC 42005 (impact assessment) and ISO/IEC 42006 (requirements for certification bodies) had reached final draft stage, with publication possible later in 2025. ISO/IEC 24970 on AI system logging, developed jointly with JTC 21 under ISO lead, was out for committee draft consultation. Work continued on ISO/IEC 42102 (taxonomy of AI methods and capabilities), on the SME handbook for ISO/IEC 42001, and on amendments to ISO/IEC 22989 and ISO/IEC 23053 to address generative AI, now in committee draft comment resolution. Following contacts with the OECD, WG1 opened a new project on a common reporting framework for AI incidents.
WG2 (data). Parts 1 to 5 of ISO/IEC 5259 on data quality had been published. Current work covered a visualisation framework for data quality (ISO/IEC TR 5259-6), output data quality for generative AI applications (ISO/IEC 25590), and an overview of synthetic data in AI systems (ISO/IEC TR 42103).
WG3 (trustworthiness). ISO/IEC 12792 (transparency taxonomy) was ready for publication, and the committee draft of ISO/IEC 6254 on explainability and interpretability was under ballot. Work continued on oversight of AI systems (ISO/IEC 18966), societal and ethical concerns (ISO/IEC 22443), robustness of neural networks (ISO/IEC 24029-3), AI nudging mechanisms (ISO/IEC 25029), domain engineering terminology (ISO/IEC 25566), risks in generative AI (ISO/IEC 25568), reliability assessment (ISO/IEC 25570), a template for documenting ethical issues (ISO/IEC 25571), guidance on human oversight (ISO/IEC 42105), and differentiated benchmarking of AI quality characteristics (ISO/IEC 42106). A new project on trustworthiness fact labels (ISO/IEC 42117) was being launched.
WG4 (use cases and applications). The second edition of ISO/IEC TR 24030 on AI use cases, published in 2024, includes 81 use cases in operation out of a collection of 187. Work continued on beneficial AI systems (ISO/IEC TR 21221, committee draft submitted), environmental sustainability of AI systems (ISO/IEC TR 20226, draft technical report ballot about to start), human-machine teaming use cases (ISO/IEC TR 42109) and a framework for human-machine teaming (ISO/IEC 25589). A new project was proposed on graphical symbols to distinguish AI-generated, human-produced and hybrid content, mirroring the JTC 21 proposal.
Joint advisory groups. SC 42 created a joint advisory group with SC 39 on AI and sustainability, to develop a roadmap and recommend new projects, and another with ISO's conformity assessment committee (CASCO) on ISO/IEC 42007, a framework for developing conformity assessment schemes for AI systems.
Fora
Workstream 12 on AI of the High-Level Forum on European Standardisation met on 4 March to review outreach. SIS (Sweden), the Malta Digital Innovation Authority, BSI, Danish Standards, ANEC and ETUC all had events planned for 2025.
The webinar Implementing the EU AI Act through Standards on 4 February, organised by the UK AI Standards Hub and Task Group Inclusiveness, drew more than 350 participants and focused on the European risk management standard. It was followed by a workshop on 22 April to gather civil society input on risk management. The AI Standards Hub Global Summit on 17–18 March discussed the role of standards in AI governance and how to make international AI standardisation more inclusive.
Nice to know, useful to read
The Commission updated its model contractual clauses for public procurement of AI. The update includes a full version for high-risk AI aligned with the AI Act, a customisable light version for other AI systems, and a commentary on how to use and adapt the clauses. The HSbooster.eu Standardisation Training Academy offers courses across many domains, including two on conformity assessment: its role in quality infrastructure, and conformity assessment schemes and systems.
ANEC published a factsheet on the fundamentals of the upcoming trustworthiness standard. With funding from the European AI & Society Fund, it set up a pilot taskforce of consumer and civil society representatives, starting at the end of April and running until the end of 2025, to provide training and support national-level engagement in AI standardisation. On 9 April, ANEC held a webinar on human rights in AI standardisation with speakers from the EU Fundamental Rights Agency, attended by 78 participants.
In March, ETUC published the handbook Standards at the workplace: What they are and why you need to know about them, explaining what standards are, how they affect working life and how trade unions can use them, together with a video on trade unions and standardisation.
My reading
Two items in this issue sit in some tension with each other. The Commission was already reviewing drafts and sending preliminary assessments back to the working groups before public enquiry. At the same time, the newsletter reminded readers that drafts are confidential until enquiry. The legal assessment of the standards therefore began at a stage where civil society could see neither the text nor the feedback. For a task group whose purpose is inclusiveness, that is a structural limit worth stating plainly.
The publication of a health and safety paper on workload stress is also telling. It suggests a committee working at the edge of its capacity, only months before the timeline it was being asked to meet.
On the content side, both JTC 21 and SC 42 opened work on symbols for distinguishing AI-generated, human-produced and hybrid content, and SC 42 started a project with the OECD on a common reporting framework for AI incidents. These connect directly to the transparency obligations and incident reporting in the AI Act, and they are examples of standards work that will be used well beyond the high-risk category.
For the live status of each standard, see the Standards Explorer.
Since then (status September 2026)
| April 2025 | Where it stands now |
|---|---|
| Drafts expected to enter public enquiry over summer 2025 | That timeline did not hold. The QMS draft entered public enquiry on 30 October 2025. By mid-2026, prEN 18228 (risk management) and prEN 18282 (cybersecurity) were at public Enquiry, prEN 18229-1 (logging) had been through public enquiry, and prEN 18229-3 (human oversight) reached it in July 2026. Most other deliverables were still in drafting. |
| AI Act obligations due by August 2026 | The Digital Omnibus on AI, Regulation (EU) 2026/1744, moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Article 50 transparency obligations were not postponed. |
| Commission feedback on the first drafts | EN 18286 (QMS) was approved on 12 July 2026, the first JTC 21 AI Act standard to reach that point. Citation in the Official Journal is outstanding. |
| Trustworthiness framework in comment resolution | Developed as a five-part prEN 18229 series: logging (Part 1), transparency (Part 2), human oversight (Part 3), accuracy (Part 4) and robustness (Part 5). Part 1 has been through public enquiry, and Part 3 reached public enquiry in July 2026. |
| Bias and datasets work in progress | prEN 18283 and prEN 18284 (both drafting). |
| Conformity assessment work in progress | prEN 18285 (drafting). |
| Committee delays anticipated | In October 2025, CEN-CENELEC adopted exceptional measures aiming for the prioritised deliverables to be available by Q4 2026. The amended standardisation request (M/613) expires on 28 February 2027. |
| Third draft of the GPAI Code of Practice | The final Code was published in July 2025, with chapters on transparency, copyright, and safety and security. GPAI obligations have applied since 2 August 2025. |
| ISO/IEC 42005 and 42006 at final draft; 12792 ready for publication | Published as ISO/IEC 42005:2025, ISO/IEC 42006:2025 and ISO/IEC 12792:2025. |
| Labelling of AI-generated content proposed in JTC 21 and SC 42 | Article 50(2) of the AI Act applies to new systems from 2 August 2026 and to systems already on the market from 2 December 2026. |
| Cybersecurity requirements for products with digital elements in the work programme | Under the Cyber Resilience Act, reporting obligations apply from 11 September 2026 and the main obligations from 11 December 2027. |
| Work programme priorities under Regulation 1025/2012 | A revision of Regulation (EU) No 1025/2012 is in the Commission's 2026 work programme, with a proposal expected in October 2026 according to press reports. |
Stages for the prEN drafts are drawn from public trackers and commentary as of mid-2026. Verify against the live CEN-CENELEC work programme before relying on them. No JTC 21 deliverable gives a presumption of conformity until its reference is cited in the Official Journal.
Correction, 15 September 2026: an earlier version of this table described prEN 18229 as a three-part series. It has been updated to reflect the current five-part structure.