# AI Standards — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/harmonised-standards-ai
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed to specifically address the role of harmonised standards and standardisation deliverables in the AI Act framework, including their development, adoption, and use in demonstrating compliance with AI system requirements.

## Overview

## Legal Framework

The AI Act establishes a robust standardisation architecture through Articles 32 and 40, which together create the mechanism by which harmonised standards function as compliance instruments. Article 40 provides the legal basis for the Commission to request European standardisation organisations to develop harmonised standards and standardisation deliverables that support the AI Act's requirements. These standards translate the abstract obligations set out in the AI Act—covering risk management, data governance, transparency, technical documentation, and human oversight—into technical specifications that providers can implement.

Article 32 establishes a presumption of conformity for notified bodies. When a conformity assessment body demonstrates compliance with the criteria laid down in relevant harmonised standards whose reference numbers have been published in the Official Journal of the European Union, it is presumed to comply with the requirements set out in Article 31. This presumption applies only to the extent that the applicable harmonised standards cover those specific requirements. The rationale is clear: harmonised standards reduce regulatory uncertainty by creating a technical safe harbour, ensuring that conformity assessment bodies operate to consistent benchmarks across the internal market.

## Key Developments

The standardisation process under the AI Act is still in its early stages, with standardisation requests being formulated to mandate CEN and CENELEC to develop the technical specifications needed. The European AI Office is expected to play a coordinating role in ensuring that standards align with the Act's risk-based approach, particularly for high-risk AI systems.

The EDPB has signalled increasing attention to AI privacy risks, particularly through its support for the Global Privacy Assembly's statement on AI-generated imagery and privacy protection. The EDPB's work on risk management methodologies for large language models reflects a growing convergence between data protection supervisory expectations and AI Act compliance, meaning that harmonised standards will likely need to account for GDPR interoperability.

## Practical Guidance

- **Track Official Journal publications**: Monitor which harmonised standards receive publication in the Official Journal, as only those referenced standards trigger the presumption of conformity under Article 32. Standards not yet referenced provide no legal safe harbour.
- **Map AI Act requirements to standardisation deliverables**: Conduct a gap analysis between your AI system's obligations under the AI Act and the available or forthcoming harmonised standards, identifying where standards coverage exists and where it remains incomplete.
- **Engage with standardisation bodies**: Participate in CEN/CENELEC technical committees developing AI standards to ensure your organisation's technical realities inform the specifications that will ultimately define compliance benchmarks.
- **Align conformity assessment preparation with Article 31 criteria**: Notified bodies should structure their internal compliance programmes around Article 31 requirements, using harmonised standards as the primary compliance pathway where available and documenting gaps where standards are still under development.
- **Coordinate AI Act and GDPR compliance strategies**: Given the EDPB's active scrutiny of AI privacy risks, ensure that harmonised standard implementation accounts for data protection obligations, particularly where standards address data governance and transparency requirements that overlap with GDPR principles.

## Legislation (full text of key provisions)

### Harmonised standards and standardisation deliverables

*Source: AI Act, aiact-art-40-en, 2024-06-12 — https://overview.legal/posts/92589*

### Presumption of conformity with requirements relating to notified bodies

*Source: AI Act, aiact-art-32-en, 2024-06-12 — https://overview.legal/posts/92508*

Where a conformity assessment body demonstrates its conformity with the criteria laid down in the relevant harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, it shall be presumed to comply with the requirements set out in Article 31 in so far as the applicable harmonised standards cover those requirements.

### Presumption of conformity with certain requirements

*Source: AI Act, aiact-art-42-en, 2024-06-12 — https://overview.legal/posts/92625*

### Common specifications

*Source: AI Act, aiact-art-41-en, 2024-06-12 — https://overview.legal/posts/92601*

### Amendment to Regulation (EC) No 300/2008

*Source: AI Act, aiact-art-102-en, 2024-06-12 — https://overview.legal/posts/93607*

In Article 4(3) of Regulation (EC) No 300/2008, the following subparagraph is added:‘When adopting detailed measures related to technical specifications and procedures for approval and use of security equipment concerning Artificial Intelligence systems within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), the requirements set out in Chapter III, Section 2, of that Regulation shall be taken into account.

### Amendment to Directive 2014/90/EU

*Source: AI Act, aiact-art-105-en, 2024-06-12 — https://overview.legal/posts/93613*

In Article 8 of Directive 2014/90/EU, the following paragraph is added:‘5. For Artificial Intelligence systems which are safety components within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council (*), when carrying out its activities pursuant to paragraph 1 and when adopting technical specifications and testing standards in accordance with paragraphs 2 and 3, the Commission shall take into account the requirements set out in Chapter III, Section 2, of that Regulation.

### Recital 121 — standardisation for regulatory compliance and innovation

*Source: AI Act, aiact-rec-121-en, 2024-06-12 — https://overview.legal/posts/93924*

Standardisation should play a key role to provide technical solutions to providers to ensure compliance with this Regulation, in line with the state of the art, to promote innovation as well as competitiveness and growth in the single market. Compliance with harmonised standards as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012 of the European Parliament and of the Council (41), which are normally expected to reflect the state of the art, should be a means for providers to demonstrate conformity with the requirements of this Regulation. A balanced representation of interests involving all relevant stakeholders in the development of standards, in particular SMEs, consumer organisations and environmental and social stakeholders in accordance with Articles 5 and 6 of Regulation (EU) No 1025/2012 should therefore be encouraged. In order to facilitate compliance, the standardisation requests should be issued by the Commission without undue delay. When preparing the standardisation request, the Commission should consult the advisory forum and the Board in order to collect relevant expertise. However, in the absence of relevant references to harmonised standards, the Commission should be able to establish, via implementing acts, and after consultation of the advisory forum, common specifications for certain requirements under this Regulation. The common specification should be an exceptional fall back solution to facilitate the provider’s obligation to comply with the requirements of this Regulation, when the standardisation request has not been accepted by any of the European standardisation organisations, or when the relevant harmonised standards insufficiently address fundamental rights concerns, or when the harmonised standards do not comply with the request, or when there are delays in the adoption of an appropriate harmonised standard. Where such a delay in the adoption of a harmonised standard is due to the technical complexity of that standard, this should be considered by the Commission before contemplating the establishment of common specifications. When developing common specifications, the Commission is encouraged to cooperate with international partners and international standardisation bodies.

### Recital 150 — stakeholder advisory forum establishment and composition

*Source: AI Act, aiact-rec-150-en, 2024-06-12 — https://overview.legal/posts/93982*

With a view to ensuring the involvement of stakeholders in the implementation and application of this Regulation, an advisory forum should be established to advise and provide technical expertise to the Board and the Commission. To ensure a varied and balanced stakeholder representation between commercial and non-commercial interest and, within the category of commercial interests, with regards to SMEs and other undertakings, the advisory forum should comprise inter alia industry, start-ups, SMEs, academia, civil society, including the social partners, as well as the Fundamental Rights Agency, ENISA, the European Committee for Standardization (CEN), the European Committee for Electrotechnical Standardization (CENELEC) and the European Telecommunications Standards Institute (ETSI).

### Recital 122 — high-risk AI compliance presumption

*Source: AI Act, aiact-rec-122-en, 2024-06-12 — https://overview.legal/posts/93926*

It is appropriate that, without prejudice to the use of harmonised standards and common specifications, providers of a high-risk AI system that has been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which the AI system is intended to be used, should be presumed to comply with the relevant measure provided for under the requirement on data governance set out in this Regulation. Without prejudice to the requirements related to robustness and accuracy set out in this Regulation, in accordance with Article 54(3) of Regulation (EU) 2019/881, high-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to that Regulation and the references of which have been published in the Official Journal of the European Union should be presumed to comply with the cybersecurity requirement of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover the cybersecurity requirement of this Regulation. This remains without prejudice to the voluntary nature of that cybersecurity scheme.

### Recital 117 — general-purpose AI model compliance codes

*Source: AI Act, aiact-rec-117-en, 2024-06-12 — https://overview.legal/posts/93916*

The codes of practice should represent a central tool for the proper compliance with the obligations provided for under this Regulation for providers of general-purpose AI models. Providers should be able to rely on codes of practice to demonstrate compliance with the obligations. By means of implementing acts, the Commission may decide to approve a code of practice and give it a general validity within the Union, or, alternatively, to provide common rules for the implementation of the relevant obligations, if, by the time this Regulation becomes applicable, a code of practice cannot be finalised or is not deemed adequate by the AI Office. Once a harmonised standard is published and assessed as suitable to cover the relevant obligations by the AI Office, compliance with a European harmonised standard should grant providers the presumption of conformity. Providers of general-purpose AI models should furthermore be able to demonstrate compliance using alternative adequate means, if codes of practice or harmonised standards are not available, or they choose not to rely on those.

## Guidance

### EDPB-EDPS Joint Opinion 5/2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)

*Source: EDPB, edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the-en, 2021-06-18 — https://overview.legal/posts/126016 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-52021-on-the-proposal-for-a-regulation-of-the_en*

1 Adopted EDPB - EDPS Joint Opinion 5 /2021 on the proposal for a Regulation of the European Parliament and of the Council laying down harmo nised rules on artificial i ntelligence (Artificial Intelligence Act) 18 June 2021 2 Adopted Executive Summary On 2 1 April 2021, the European Commission presented its Proposal for a Regulation of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (hereinafter “the Proposal”) . The EDPB and the EDPS welcome…

### EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space

*Source: EDPB, edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on-en, 2022-07-12 — https://overview.legal/posts/125922 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032022-on-the-proposal-for-a-regulation-on_en*

Adopted 1 EDPB - EDPS Joint Opinion 03 /2022 on the Proposal for a Regulation on the European Health Data Space Adopted on 12 July 2022 Adopted 2 Adopted 3 Executive Summary With this Joint Opinion, the EDPB and the EDPS aim to draw attention to a number of overarching concerns on the Proposal on the European Health Data Space and urge the co - legislature to take decisive action. The EDPB and the EDPS note that the Proposal ai ms at supporting individuals to take control of their own health…

### SPE Programma - AI Privacy Risks & Mitigations Large Language Models (LLMs) (Isabel BARBERÁ)

*Source: EDPB, ai-privacy-risks-and-mitigations-in-llms, 2025-04-21 — https://overview.legal/posts/50754 — original: https://edpb.europa.eu/system/files/2025-04/ai-privacy-risks-and-mitigations-in-llms.pdf*

"The AI Privacy Risks & Mitigations Large Language Models (LLMs) report puts forward a comprehensive risk management methodology for LLM systems with a number of practical mitigation measures for common privacy risks in LLM systems. In addition, the report provides use cases examples on the appli...

## Recent developments

### Artificial intelligence: the action plan of the CNIL

*Source: CNIL, 2023-05-16 — https://overview.legal/posts/6206 — original: https://www.cnil.fr/en/artificial-intelligence-action-plan-cnil#entry-5218*

The main thing is:

The CNIL has been undertaking work for several years to anticipate and respond to the issues raised by AI.
In 2023, it will extend its action on augmented cameras and wishes to expand its work to generative AIs, large language models and derived applications (especially chatbots).
Its action plan is structured around four strands:

to understand the functioning of AI systems and their impact on people;
enabling and guiding the development of privacy-friendly AI;
federate and

### Gezamenlijk document van de AEPD en de EDPS: 10 misverstanden over machine learning.

*Source: EDPS, 2022-09-19 — https://overview.legal/posts/51818*

De Europese Unie heeft kunstmatige intelligentie (AI) aangemerkt als een van de meest relevante technologieën van de 21e eeuw en benadrukt 1 het belang ervan in de strategie voor de digitale transformatie van de EU. AI heeft een breed scala aan toepassingen en kan bijdragen aan uiteenlopende gebieden, zoals het behandelen van chronische ziekten, het bestrijden van klimaatverandering of het anticiperen op cyberbeveiligingsrisico's.

### AEPD-EDPS Joint Paper - 10 Misunderstandings about Machine Learning

*Source: EDPS, 2022-09-19 — https://overview.legal/posts/6277 — original: https://edps.europa.eu/press-publications/press-news/news/2022/aepd-edps-joint-paper-10-misunderstandings-about-machine-learning#entry-450*

> The EU has identified artificial intelligence (AI) as one of the most relevant technologies of the 21st century and highlighted 1 its importance on the strategy for EU’s digital transformation. Having a wide range of applications, AI can contribute in areas as disparate as helping in the treatment of chronic diseases, fighting climate change or anticipating cybersecurity threats.

### Het EDPB en het EDPS: Het voorstel om online seksueel misbruik van kinderen te bestrijden, brengt serieuze risico's met zich mee voor fundamentele rechten.

*Source: EDPS, 2022-07-29 — https://overview.legal/posts/51845*

De Europese Autoriteit voor gegevensbescherming (EDPB) en de Europese Toezichthouder op het gebied van gegevensbescherming (EDPS) hebben een gezamenlijk advies aangenomen over het voorstel voor een verordening ter bestrijding van seksueel misbruik van kinderen.

### AI-generated imagery and protection of privacy: EDPB supports joint Global Privacy Assembly’s statement

*Source: European Data Protection Board, 2026-02-23 — https://overview.legal/posts/52723 — original: https://www.edpb.europa.eu/news/news/2026/ai-generated-imagery-and-protection-privacy-edpb-supports-joint-global-privacy_en*

Brussels, 23 February - EDPB Chair Anu Talus has signed a Joint Statement on AI-Generated Imagery and the Protection of Privacy on behalf of the EDPB. The statement, coordinated by the Global Privacy Assembly's (GPA) International Enforcement Cooperation Working Group (IEWG), represents the united position of 61 authorities across the world. This reflects the Board’s commitment to contributing to the global dialogue on data protection as outlined in the fourth pillar of its work programme 2026-2

## Literature

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

### The EU Artificial Intelligence Act:

*Source: Journal of AI Law and Regulation, 2024-01-01 — https://overview.legal/posts/132433 — original: https://doi.org/10.21552/aire/2024/1/11*

A I R e 1 | 2 0 2 4 9 8 O p i n i o n s T h e EU A r t i f i ci al I n t el l i gen ce A ct : A d v an ci n g I n n o v at i o n f o r T r u s t w o r t h y A I T a t j a n a E v a s * T h e E u r o p e a n U n i o n ’ s A r t i f i c i a l I n t e l l i g e n c e A c t ( A I A c t ) 1 i s o n e o f t h e m o s t w i d e l y d i s c u s s e d a n d a n t i c i p a t e d p i e c e s o f u p c o m i n g l e g i s l a t i o n s , c a p t u r i n g g l o b a l a t t e n t i o n w i t h i t s a p p r o a c h t o g o v e r n i n g u s e s o f A I t e c h n o l o g i e s . F o l l o w i n g i n t e n s e p r e p a r a t o r y w o r k , 2 a n d a l m o s t t h r e e y e a r s o f c o m p l e x p o l i t i c a l n e g o t i a t i o n s , c u l m i n a t i n g i n p o l i t i c a l a g r e e m e n t o n 8 D e c e m b e r 2023, t h e A I A c t i s s e t t o s h a p e g l o b a l r e g u l a t o r y s p a c e o n h o w w e i n n o v a t e , m a n a g e , a n d p e r c e i v e A I t e c h n o l o g i e s . T h i s o p i n i o n , d r a w i n g u p o n f i r s t - h a n d e x p e r i e n c e f r o m t h e A I A c t ’ s c o n c e p t u a l i s a t i o n , l e g a l d r a f t i n g , a n d n e g o

### Artificial intelligence co-regulation? The role of standards in the EU AI Act

*Source: International Journal of Law and Information Technology, 2024-01-01 — https://overview.legal/posts/132440 — original: https://doi.org/10.1093/ijlit/eaae011*

Abstract This article examines artificial intelligence (AI) co-regulation in the EU AI Act and the critical role of standards under this regulatory strategy. It engages with the foundation of democratic legitimacy in EU standardization, emphasizing the need for reform to keep pace with the rapid evolution of AI capabilities, as recently suggested by the European Parliament. The article highlights the challenges posed by interdisciplinarity and the lack of civil society expertise in standard-sett

### REGULATION OF APPLIED ARTIFICIAL INTELLIGENCE IN BIOMEDICAL ENGINEERING AS A HIGH-RISK ARTIFICIAL INTELLIGENCE SYSTEM IN THE EU AI ACT

*Source: AFMN Biomedicine, 2026-07-13 — https://overview.legal/posts/132435 — original: https://doi.org/10.65641/afmnai-2026-075*

lt;p style= quot;text-align: justify; quot; gt; lt;span class= quot;a_GcMg font-feature-liga-off font-feature-clig-off font-feature-calt-off text-decoration-none text-strikethrough-none quot; gt;Artificial intelligence (AI) represents a global phenomenon changing all spheres of human life. Biomedical engineering is no exception, as many AI systems are applied to biomedical engineering inventions. The European Union has enacted the new EU AI Act, one of the world amp;rsquo;s first laws on AI. The

## Related topics

- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **AI Act Procedures** — https://overview.legal/topics/ai-act-procedural-framework
  The 'Procedure' section of the AI Act establishes the overarching procedural framework and mechanisms for implementing and enforcing the regulation. This topic 
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **International Transfer** — https://overview.legal/topics/internationale-doorgifte
  Transfer of personal data outside the EU/EEA

---
Generated by overview.legal · https://overview.legal/topics/harmonised-standards-ai · 2026-08-22
