Harmonized standards as a prerequisite for the application of the EU AI Act

The importance of harmonized standards both for compliance with requirements and for conformity assessment of high-risk AI systems is best illustrated by the recent delayed application of the provisions of the AI ​​Act, primarily due to the delayed adoption of these standards. This conditionality is firmly supported by the presumption of compliance of high-risk AI systems with the AI ​​Act requirements insofar as they conform to harmonized standards, to the extent that those standards cover those requirements or obligations (Article 40 (1) of the AI Act).

The EU AI Act classifies AI systems that may have a significant harmful impact on health, safety and fundamental human rights in the category of high-risk AI systems, based on two rules.

  • According to Article 6(1), a high-risk is considered AI system that is safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in the Annex I, and the product concerned undergoes a third-party conformity assessment, with a view to the placing on the market or putting into service, pursuant to that relevant Union harmonisation legislation ( e.g. medical devices, in vitro diagnostic medical devices, lifts, toys, radio equipment…).
  • In addition, according to the rule of Article 6 (2), AI systems referred to in Annex III, and which are used in some specifically pre-defined areas, in light of their intended purpose, are considered high-risk (biometrics, insofar as their use is permitted under relevant Union or national law; critical infrastructure; education and vocational training; employment, workers’ management and access to self-employment; access to and enjoyment of essential public and private services; law enforcement; migration, asylum and border control management; administration of justice and democratic processes).

To mitigate the risks from these AI systems placed on the market or put into service and to ensure a high level of trustworthiness, the AI Act has laid down requirements that high-risk AI systems must comply with, taking into account their purpose, as well as the recognized state of the art in the field of AI and related technologies (Chapter III Section 2, Articles 9 to 15 of the AI Act). Also, a natural or legal person who is the provider (or considered to be a provider) of a high-risk AI system, must take responsibility for the placing on the market or the putting into service of a high-risk AI system, whereby the AI Act prescribes their obligations related to those AI systems (Chapter III Section 3, Articles 16 to 25 of the AI Act). 

Conformity assessment

Given their complexity and risks associated with them, high-risk AI systems are subject to a conformity assessment prior to their placing on the market or putting into service, as well as to monitoring throughout their lifecycle. 

  • For high-risk AI systems related to products covered by the Union harmonisation legislation (Article 6(1)), the provider shall follow the conformity assessment procedure required by the relevant Union harmonisation legislation, involving notified bodies, so-called third-party conformity assessment. In addition, the subject of assessment will also be compliance with the requirements for high-risk AI systems, set out in the AI Act (Section 2 of Chapter III), and the quality management system’s compliance with Article 17 of the AI Act. 
  • The conformity assessment of AI systems classified as high-risk pursuant to Article 6(2) and referred to in Annex III of the AI Act (eight specific areas) is carried out, as a general rule, by the provider under its own responsibility, with the only exception of AI systems intended to be used for biometrics. This means that for high-risk AI systems referred to in points 2 to 8 of Annex III, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body (Article 43 (2) of the AI Act).

Harmonised standards

The importance of harmonized standards both for compliance with requirements and for conformity assessment related to high-risk AI systems is best illustrated by the recent delayed implementation of the provisions of the AI Act, primarily due to the delayed adoption of these standards. This conditionality is firmly supported by the presumption of compliance of high-risk AI systems with the AI Act requirements insofar as they conform to harmonized standards, to the extent that those standards cover those requirements or obligations (Article 40 (1) of the AI Act).

European harmonised standards serve several crucial functions[1]:

  • Legal certainty and reduced compliance costs: The harmonised standards for the AI Act should help providers of AI systems to ensure and demonstrate compliance with legal requirements.
    • First, standards simplify compliance by translating legislative requirements into common technical language and thus provide a clear pathway to compliance for businesses of all sizes.
    • Second, standards facilitate the proof of compliance with legislative requirements. According to the Regulation (EU) No 1025/2012 on European standardisation[2], the application of European standards is voluntary. However, a product or system is presumed to satisfy the essential requirements of the relevant EU legislation if it complies with harmonised standards referenced in the Official Journal of the European Union (OJEU). This ‘presumption of conformity’ shifts the regulatory burden of proof on public authorities to disprove conformity. Likewise, the application of the harmonised standards as regards high-risk AI systems is not compulsory. The providers can choose any other framework to demonstrate compliance with the AI Act. However, harmonised standards referenced in the Official Journal of the EU provide legal certainty. Companies that applied harmonised standards are presumed to be compliant with the legislative requirements.
  • Market benchmarking: European harmonised standards often become de facto global benchmarks. The benchmarks and standards, which are being established today, will define the role of AI in our society for generations to come. For example, standards currently under development focused on setting methodologies for risk management and quality management are strong candidates to become market benchmarks in the future. By fostering the development of European harmonised standards, the EU can advance and lead the safe development and adoption of AI systems globally.
  • Innovation and competitiveness: European harmonised standards foster trust and market acceptance, enabling developers who adopt them to compete on a global scale while ensuring their solutions meet the highest safety standards.

The European Commission was already authorized by the AI Act (Article 40 (2) to issue, without undue delay, standardization requests covering all requirements set out in Section 2 of Chapter III.

The new Regulation on the simplification (Digital Omnibus on AI) restated and supplemented this provision by Commission authorization to request the European standardization organizations to develop standardization deliverables, including, as appropriate, harmonized standards, to facilitate the joint compliance and presumption of conformity with the requirements (that high-risk AI systems must comply with) or obligations (for providers of high-risk AI systems) set out in Chapter III, Sections 2 and 3 of the AI Act and the relevant requirements and obligations laid down in the Union harmonization legislation listed in Annex I to this Regulation.

The European Commission, by its Implementing Decision of 23.6.2025[3], requested that the European Committee for Standardisation (CEN) and the European Committee for Electrotechnical Standardisation (Cenelec) develop new harmonised standards and, if necessary, European standardisation deliverable(s) as regards high-risk AI systems. New harmonised standards have to be clear, consistent, including with the standards developed in the various sectors for products covered by the existing Union harmonisation legislation listed in Annex I, and aiming to ensure that high-risk AI systems placed on the market or put into service in the Union meet the relevant requirements or obligations laid down in this Regulation. New harmonised standards should cover:

  • requirements for high-risk AI systems:
    • risk management systems for AI systems ( Article 9)
    • governance and quality of datasets used to build AI systems (Article 10)
    • record-keeping through logging capabilities by AI systems (Article 12)
    • transparency and information provisions for users of AI systems (Article 13)
    • human oversight of AI systems (Article 14)
    • accuracy specifications for AI systems (Article 15)
    • robustness specifications for AI systems(Article 15)
    • cybersecurity specifications for AI systems(Article 15)
  • obligations of providers of high-risk AI systems
    • quality management systems for providers of AI systems, including post-market monitoring processes (Article 17), as well as
  • conformity assessment for AI systems (Article 43)

Where a harmonised standard is adopted by CEN and CENELEC, the Commission assesses whether they meet the intended objectives and legal requirements of the AI Act. After this final step, the standards are referenced in the Official Journal of the EU.

Relationship between EU harmonized standards and international standards

According to Article 40(3) of the AI Act, the participants in the standardisation process shall seek to promote investment and innovation in AI, including through increasing legal certainty, as well as the competitiveness and growth of the Union market, to contribute to strengthening global cooperation on standardisation and taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and to enhance multi-stakeholder governance ensuring a balanced representation of interests and the effective participation of all relevant stakeholders.  

  • European Standardization organizations and European companies are actively engaging with international standardization bodies and therefore contributing to developing a broader global framework of AI standards.
  • In addition,  European Standardization organizations do not develop harmonized standards in isolation. An ‘international first’ approach is one of the guiding principles of standardisation. This means international standards, when available and aligned with EU requirements, can become European harmonized standards.[4] This alignment is crucial to avoid regulatory fragmentation and to ensure that AI developers can operate across multiple markets without redundant compliance efforts.

However, if international standards do not align with the legal requirements of the AI Act, new EU harmonised standards will provide guidance on compliance. For example, although ISO/IEC 42001:2023 helps to set up an AI management system, its goals and definitions are not aligned with the quality management system that is required under the AI Act. This is why the Commission has requested the development of a new standard for a quality management system that focuses on regulatory compliance with the AI Act.[5]   

 

 

 

[1] https://digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation;
[2] Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council 
[3] Commission Implementing Decision of 23.6.2025 on a standardisation request to the European Committee for Standardisation and the European Committee for Electrotechnical Standardisation as regards high-risk AI-systems in support of Regulation (EU) 2024/1689 of the European Parliament and of the Council and repealing Implementing Decision C(2023)3215.
[4] https://digital-strategy.ec.europa.eu/en/faqs/understanding-standardisation-ai-act
[5] https://digital-strategy.ec.europa.eu/en/faqs/understanding-standardisation-ai-act