Skip to content
Topic Contested in court

AI Standards

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed to specifically address the role of harmonised standards and standardisation deliverables in the AI Act framework, including their development, adoption, and use in demonstrating compliance with AI system requirements.

45 linked items 16 Laws8 Guidance10 News11 Literature

Overview

15 sources · Sep 25, 2026

Legal Framework

The AI Act establishes a two-tier standardisation architecture: harmonised standards as the primary compliance pathway, and common specifications as a fallback. Article 40 governs the presumption of conformity for high-risk AI systems and general-purpose AI models that comply with harmonised standards whose references are published in the OJ. Article 41 provides the Commission authority to adopt implementing acts establishing common specifications where standardisation requests have not yielded published standards within a reasonable period. Article 32 extends the same presumption logic to conformity assessment bodies themselves.

The rationale is straightforward: standardisation translates abstract legal requirements into technical specifications that providers can implement and auditors can verify. Recital 121 frames this as both a compliance mechanism and an innovation enabler:

"Compliance with harmonised standards as defined in Article 2, point (1)(c), of Regulation (EU) No 1025/2012 of the European Parliament and of the Council (41), which are normally expected to reflect the state of the art, should be a means for providers to demonstrate conformity with the requirements of this Regulation."
— AI Act Recital 121

Article 40(2) obliges the Commission to issue standardisation requests "without undue delay" covering all requirements in Section 2 of Chapter III, plus obligations under Chapter V Sections 2 and 3 for GPAI models. The Commission must specify that standards be "clear, consistent" with existing sectoral product safety standards under Annex I.

Key Developments

The standardisation infrastructure is still maturing. The EDPB-EDPS Joint Opinion 5/2021 flagged early that the certification system built on harmonised standards and common specifications differs structurally from GDPR certification under Articles 42–43, and questioned the relationship between the two regimes:

The EDPB-EDPS further recommended incorporating data minimisation and data protection by design into the conformity assessment prerequisites before CE marking is granted, given the fundamental rights interference of high-risk systems.

Implementation timelines themselves are now contested. The Commission's own simplification proposal acknowledges that delays in designating competent authorities and the absence of harmonised standards justify postponing application dates:

Status of the Debate

This topic is actively contested. The standardisation framework's legal architecture is settled in text — Articles 40 and 41 clearly establish the presumption-of-conformity mechanism and the fallback common specifications route. What is contested is the operational reality: no harmonised standards have yet been published in the OJ for the AI Act's high-risk requirements, and the Commission's own delay proposals confirm that the standardisation pipeline is not delivering on the "without undue delay" mandate. The boundary between harmonised standards and common specifications as compliance instruments remains unresolved in practice. A CJEU preliminary reference on whether reliance on common specifications in the absence of published standards satisfies the presumption of conformity under Article 40 would clarify the legal certainty gap. Until then, providers face ambiguity about what technical benchmarks actually trigger the presumption.

Practical Guidance

  • Monitor OJ publications for harmonised standard references — conformity with standards not yet referenced in the OJ does not trigger the Article 40 presumption. Track the Commission's standardisation request pipeline to anticipate which standards are in development.
  • Prepare for common specifications as interim compliance benchmarks — where standardisation requests have been issued but no standard is expected within a reasonable period, Article 41 common specifications may become the operative compliance reference. Build internal documentation frameworks that can adapt to either instrument.
  • Align with existing sectoral product safety standards — Article 40(2) requires consistency with standards developed under Annex I Union harmonisation legislation. Providers operating in regulated sectors (medical devices, machinery) should map AI Act requirements against existing CE marking obligations.
  • Document state-of-the-art compliance independently — in the absence of published harmonised standards, providers cannot rely on the presumption and must demonstrate conformity through their own technical documentation and risk management evidence under Chapter III Section 2.
  • Integrate data protection by design into conformity preparation — the EDPB-EDPS recommendations signal that notified bodies and market surveillance authorities will scrutinise GDPR alignment, even though the AI Act certification regime is formally distinct from GDPR certification.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section