The Standards That Will Define AI Compliance
As the 2 August 2026 enforcement deadline for high-risk AI systems draws near, a critical question remains unresolved for many organizations: which technical standards should they follow to demonstrate compliance with the AI Act? The answer lies in the work of CEN-CENELEC Joint Technical Committee 21 (JTC 21), the body tasked with developing harmonized European standards that provide a legal presumption of conformity with the AI Act’s requirements.
Understanding this standards landscape is not optional. It is the difference between a smooth conformity assessment and months of additional engineering and documentation work. For providers of high-risk AI systems, the harmonized standards will effectively define what “good enough” looks like under Articles 9 through 15 of the AI Act.
What Harmonized Standards Do Under the AI Act
The AI Act establishes obligations for high-risk AI system providers across several domains: risk management (Article 9), data governance (Article 10), technical documentation (Article 11), record-keeping (Article 12), transparency to deployers (Article 13), human oversight (Article 14), accuracy and robustness (Article 15), and quality management (Article 17).
The AI Act does not prescribe specific technical methods for meeting these obligations. Instead, it relies on harmonized standards developed by recognized European standardization organizations. When a provider complies with a harmonized standard that has been published in the Official Journal of the European Union (OJEU), that provider benefits from a presumption of conformity with the corresponding AI Act requirements.
This presumption is powerful. It means that authorities must assume the provider has met its obligations unless they can demonstrate otherwise. Without harmonized standards, providers must prove compliance through alternative means, which is more costly, more time-consuming, and legally less certain.
The JTC 21 Work Programme
CEN-CENELEC JTC 21 was established in June 2021 and brings together over 300 experts from more than 20 countries. The committee operates through five working groups covering strategic advisory, operational aspects, engineering aspects, foundational and societal aspects, and cybersecurity for AI systems.
The European Commission issued a standardization request (mandate M/593) to CEN and CENELEC, asking them to develop harmonized standards supporting the AI Act. The key standards under development include:
1. AI Trustworthiness Framework
This standard establishes an overarching framework for trustworthy AI systems. It covers the foundational principles and requirements that underpin the AI Act’s risk-based approach, including transparency, accountability, and human agency.
2. AI Risk Management
This standard addresses the operational risks of AI systems throughout their lifecycle. It aligns closely with Article 9 of the AI Act, which requires providers to establish, implement, document, and maintain a risk management system. The standard draws on international work, particularly ISO/IEC 23894, adapted to meet European regulatory requirements.
3. AI Quality Management System
Corresponding to Article 17 of the AI Act, this standard defines the requirements for a quality management system specific to AI development and deployment. It covers compliance strategy, design controls, testing procedures, technical documentation, data governance, and post-market monitoring. For organizations already certified to ISO 9001, the AI-specific QMS standard will require additional processes tailored to machine learning and AI system lifecycle management.
4. AI Conformity Assessment
This standard provides methodologies for verifying that an AI system meets the requirements of the AI Act before being placed on the market. It covers both internal control (self-assessment) and third-party assessment involving notified bodies.
5. Sectoral and Technical Standards
Beyond the horizontal standards, JTC 21 is developing standards addressing specific technical aspects: dataset quality, bias measurement and mitigation, computer vision reliability, cybersecurity for AI systems, model robustness, logging requirements, and natural language processing performance. These standards support the detailed technical requirements embedded throughout the AI Act.
The Timing Problem
Here is the critical issue: as of July 2026, the harmonized standards have not yet been published in the OJEU. JTC 21 has been developing them, but the formal adoption and publication process takes time. The standards must be finalized, adopted by CEN and CENELEC members, and then referenced in the OJEU before they provide the presumption of conformity.
This creates a gap. The AI Act’s high-risk obligations become enforceable on 2 August 2026, but the harmonized standards that would simplify compliance may not all be available on that date.
How to Navigate the Gap
Organizations cannot wait for the harmonized standards to begin their compliance work. Instead, they should adopt a layered approach:
Layer 1: Use Available International Standards
Several international standards already provide relevant guidance, even without the formal European presumption of conformity:
- ISO/IEC 42001 (AI Management System): Provides a management system framework aligned with AI Act requirements.
- ISO/IEC 23894 (AI Risk Management): Offers risk management methodologies applicable to Article 9.
- ISO/IEC 23053 (Framework for AI Systems using ML): Establishes a framework for describing AI systems.
Using these standards demonstrates good faith compliance effort, even if they do not carry the formal presumption of conformity.
Layer 2: Map Directly to AI Act Requirements
For requirements not covered by available standards, providers must map directly to the AI Act’s text. This means reading Articles 9 through 17 and implementing processes that address each obligation point by point. While this approach requires more interpretation, it ensures that the provider’s compliance work aligns with the legal text itself.
Layer 3: Monitor JTC 21 Progress
Organizations should monitor JTC 21’s work programme and be prepared to align with harmonized standards as they become available. This requires tracking publication dates in the OJEU and updating internal compliance documentation accordingly.
The CE Marking Connection
High-risk AI systems must bear the CE marking before being placed on the EU market. The CE marking indicates that the product conforms with applicable EU legislation. For AI systems, this includes the AI Act and potentially other sectoral legislation (such as the Machinery Regulation, Medical Devices Regulation, or In Vitro Diagnostic Regulation).
The conformity assessment process for most high-risk AI systems involves internal control by the provider. The provider documents compliance in technical documentation, issues an EU declaration of conformity, and affixes the CE marking. For certain systems, particularly those used in biometric identification and categorization, a notified body must be involved in the assessment.
Once harmonized standards are published, compliance with them streamlines the CE marking process significantly. The provider can reference the standards in their technical documentation, satisfying the conformity assessment requirements more efficiently.
What This Means for Your Organization
If you are a provider of high-risk AI systems, take these steps now:
-
Adopt ISO/IEC 42001 as a baseline. Implement an AI management system aligned with this standard. When the harmonized European standard for AI QMS is published, you will need to adapt, but the core processes will be in place.
-
Conduct a standards gap analysis. Compare your current compliance documentation against the AI Act’s Articles 9 through 17. Identify where you rely on standards that may not yet exist in harmonized form.
-
Document your compliance rationale. For each design or process decision, document why it satisfies the AI Act’s requirements, even without a harmonized standard to reference. This documentation will be essential if authorities question your conformity assessment.
-
Engage with your notified body early. If your AI system requires third-party conformity assessment, contact a notified body now. The queue for assessments will grow as the deadline approaches.
-
Plan for standards migration. Build flexibility into your compliance framework so you can align with harmonized standards once they appear in the OJEU without rebuilding your entire documentation.
Conclusion
Harmonized standards are the missing piece of the AI Act compliance puzzle. When published, they will provide a clear technical pathway for demonstrating conformity. But organizations that wait for them before starting compliance work will not meet the August 2026 deadline. The right approach is to start with available international standards, build compliance processes directly from the AI Act’s text, and prepare to align with harmonized standards as they arrive.
The CE marking is not a formality. It is a legal declaration that your AI system meets EU requirements. Getting there requires technical work, documentation, and strategic decisions about standards adoption. Start now, and the harmonized standards will simplify your path when they arrive.
Jurista.ai tracks the latest developments in AI Act technical standards and helps organizations map their compliance gaps against current and upcoming requirements. Assess your compliance at jurista.ai.