Skip to content
Topic Contested in court

AI Standards

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed to specifically address the role of harmonised standards and standardisation deliverables in the AI Act framework, including their development, adoption, and use in demonstrating compliance with AI system requirements.

52 linked items 16 Laws3 Guidance24 News9 Literature

Overview

16 sources · Jul 23, 2026

Legal Framework

The AI Act establishes a robust standardisation architecture through Articles 32 and 40, which together create the mechanism by which harmonised standards function as compliance instruments. Article 40 provides the legal basis for the Commission to request European standardisation organisations to develop harmonised standards and standardisation deliverables that support the AI Act's requirements. These standards translate the abstract obligations set out in the AI Act—covering risk management, data governance, transparency, technical documentation, and human oversight—into technical specifications that providers can implement.

Article 32 establishes a presumption of conformity for notified bodies. When a conformity assessment body demonstrates compliance with the criteria laid down in relevant harmonised standards whose reference numbers have been published in the Official Journal of the European Union, it is presumed to comply with the requirements set out in Article 31. This presumption applies only to the extent that the applicable harmonised standards cover those specific requirements. The rationale is clear: harmonised standards reduce regulatory uncertainty by creating a technical safe harbour, ensuring that conformity assessment bodies operate to consistent benchmarks across the internal market.

Key Developments

The standardisation process under the AI Act is still in its early stages, with standardisation requests being formulated to mandate CEN and CENELEC to develop the technical specifications needed. The European AI Office is expected to play a coordinating role in ensuring that standards align with the Act's risk-based approach, particularly for high-risk AI systems.

The EDPB has signalled increasing attention to AI privacy risks, particularly through its support for the Global Privacy Assembly's statement on AI-generated imagery and privacy protection. The EDPB's work on risk management methodologies for large language models reflects a growing convergence between data protection supervisory expectations and AI Act compliance, meaning that harmonised standards will likely need to account for GDPR interoperability.

Practical Guidance

  • Track Official Journal publications: Monitor which harmonised standards receive publication in the Official Journal, as only those referenced standards trigger the presumption of conformity under Article 32. Standards not yet referenced provide no legal safe harbour.
  • Map AI Act requirements to standardisation deliverables: Conduct a gap analysis between your AI system's obligations under the AI Act and the available or forthcoming harmonised standards, identifying where standards coverage exists and where it remains incomplete.
  • Engage with standardisation bodies: Participate in CEN/CENELEC technical committees developing AI standards to ensure your organisation's technical realities inform the specifications that will ultimately define compliance benchmarks.
  • Align conformity assessment preparation with Article 31 criteria: Notified bodies should structure their internal compliance programmes around Article 31 requirements, using harmonised standards as the primary compliance pathway where available and documenting gaps where standards are still under development.
  • Coordinate AI Act and GDPR compliance strategies: Given the EDPB's active scrutiny of AI privacy risks, ensure that harmonised standard implementation accounts for data protection obligations, particularly where standards address data governance and transparency requirements that overlap with GDPR principles.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 16
Art. 112(4)(c) adopted harmonised standards and common specifications developed to support this Regulation; AI Act Art. 112(6) By 2 August 2028 and every four years thereafter, the Commission shall submit a report on the review of the progress on the development of standardisa… AI Act Art. 3(28) ‘common specification’ means a set of technical specifications as defined in Article 2, point (4) of Regulation (EU) No 1025/2012, providing means to … AI Act Art. 17(1)(e) technical specifications, including standards, to be applied and, where the relevant harmonised standards are not applied in full or do not cover all … AI Act rec 121 Recital 121 — standardisation for regulatory compliance and innovation AI Act Jun 2024 art 40 Harmonised standards and standardisation deliverables AI Act Jun 2024 art 32 Presumption of conformity with requirements relating to notified bodies AI Act Jun 2024 art 42 Presumption of conformity with certain requirements AI Act Jun 2024 art 41 Common specifications AI Act Jun 2024 rec 150 Recital 150 — stakeholder advisory forum establishment and composition AI Act Jun 2024 rec 122 Recital 122 — high-risk AI compliance presumption AI Act Jun 2024 rec 117 Recital 117 — general-purpose AI model compliance codes AI Act Jun 2024 rec 174 Recital 174 — Commission review and evaluation obligations AI Act Jun 2024 rec 149 Recital 149 — AI Board establishment and advisory tasks AI Act Jun 2024 art 102 Amendment to Regulation (EC) No 300/2008 AI Act Jun 2024 art 105 Amendment to Directive 2014/90/EU AI Act Jun 2024 rec 81 Recital 81 — provider quality management system AI Act Jun 2024 rec 143 Recital 143 — SME innovation support and access AI Act Jun 2024 rec 27 Recital 27 — ethics guidelines for trustworthy AI AI Act Jun 2024 rec 139 Recital 139 — AI regulatory sandboxes innovation objectives AI Act Jun 2024
Guidance 3
§3 Adopted gait, fingerprints, DNA, voice, keystrokes and other biometric or behavioural signals - in any context. A ban is equally recommended on AI sys… EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) §74 One of the main pillars of the Proposal is certification. The certification system outlined in the Proposal is based on a structure of entities (Notif… EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) §76 The P ro posal is missing a clear relation to the data protection law as well as other EU and Member States law applicable to each ‘area’ of high - ri… EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) §79 At the same time, the legal framework for trustworthy AI would result complemented by the integration of CoCs, so as to foster trust in the use of thi… EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) edps joint opinion 52021 on the proposal for a regulation of the EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) EDPB Jun 2021 edps joint opinion 032022 on the proposal for a regulation on EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space EDPB Jul 2022 privacy risks and mitigations in llms SPE Programma - AI Privacy Risks & Mitigations Large Language Models (LLMs) (Isabel BARBERÁ) EDPB Apr 2025
News 24
European Data Protection Board AI-generated imagery and protection of privacy: EDPB supports joint Global Privacy Assembly’s statement European Data Protection Board Feb 2026 Electronic Frontier Foundation Smart AI Policy Means Examining Its Real Harms and Benefits Electronic Frontier Foundation Feb 2026 CNIL Artificial intelligence: the action plan of the CNIL CNIL May 2023 EDPS AEPD-EDPS Joint Paper - 10 Misunderstandings about Machine Learning EDPS Sep 2022 EDPS Gezamenlijk document van de AEPD en de EDPS: 10 misverstanden over machine learning. EDPS Sep 2022 NL EDPS Het EDPB en het EDPS: Het voorstel om online seksueel misbruik van kinderen te bestrijden, brengt serieuze risico's met zich mee voor fundamentele rechten. EDPS Jul 2022 NL European Digital Rights The EU’s home affairs chief wants to read your private messages European Digital Rights Mar 2023 SSRN Het reguleren van de risico's van kunstmatige intelligentie. SSRN Aug 2022 NL eucrim CJEU: PNR Directive Valid if Limited to the “Strictly Necessary” eucrim Aug 2022 eucrim HvJ: De PNR-richtlijn is geldig, mits deze beperkt blijft tot wat "strikt noodzakelijk" is. eucrim Aug 2022 NL SSRN Regulating the Risks of AI SSRN Aug 2022 ScienceDirect "Wat bewezen moest worden?" - Naar een typologie van het concept van uitleg voor het ontwerp van uitlegbare kunstmatige intelligentie. ScienceDirect Sep 2022 NL Datatilsynet De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen. Datatilsynet Sep 2022 NL Hunton Andrews Kurth De CNIL stelt een boete van 60 miljoen euro voor aan een Frans bedrijf dat zich bezighoudt met advertentietechnologie, vanwege het niet naleven van de AVG (Algemene Verordening Gegevensbescherming). Hunton Andrews Kurth Aug 2022 NL Hunton Andrews Kurth CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR Hunton Andrews Kurth Aug 2022 White Label Consultancy Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer White Label Consultancy Jan 2022 SSRN Manipulation by Algorithms. Exploring the Triangle of Unfair Commercial Practice, Data Protection, and Privacy Law SSRN Oct 2022 Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 AEPD De Autoriteit Persoonsgegevens publiceert een rapport over de risicoanalyse van de AVG (Algemene Verordening Gegevensbescherming). AEPD Oct 2022 NL SSRN Manipulatie door algoritmes. Een onderzoek naar de driehoek van oneerlijke commerciële praktijken, gegevensbescherming en privacyrecht. SSRN Oct 2022 NL Show 4 more →
Literature 9
SCRIPTed A Journal of Law Technology & Society General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain SCRIPTed A Journal of Law Technology & Society Jun 2026 FR Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026 Journal of AI Law and Regulation The EU Artificial Intelligence Act: Journal of AI Law and Regulation Jan 2024 International Journal of Law and Information Technology Artificial intelligence co-regulation? The role of standards in the EU AI Act International Journal of Law and Information Technology Jan 2024 AFMN Biomedicine REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT AFMN Biomedicine Jul 2026 Ethics & bioethics The ethics of regulation: Social contract insights on the 2024 European Union Artificial Intelligence Act Ethics & bioethics Jul 2026 Zeszyt Prawniczy UAM Use of Artificial Intelligence Tools by Law Enforcement Services in Light of the Artificial Intelligence Act Zeszyt Prawniczy UAM Dec 2025 Journal of Ethics and Emerging Technologies The Magician’s Eye Journal of Ethics and Emerging Technologies Jul 2026 European Economic Letters (EEL) "From Cookies to Context: Adapting Marketing Strategies in a Cookieless Digital Environment" European Economic Letters (EEL) Jun 2025