AI Standards
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed to specifically address the role of harmonised standards and standardisation deliverables in the AI Act framework, including their development, adoption, and use in demonstrating compliance with AI system requirements.
Overview
16 sources · Jul 23, 2026Legal Framework
The AI Act establishes a robust standardisation architecture through Articles 32 and 40, which together create the mechanism by which harmonised standards function as compliance instruments. Article 40 provides the legal basis for the Commission to request European standardisation organisations to develop harmonised standards and standardisation deliverables that support the AI Act's requirements. These standards translate the abstract obligations set out in the AI Act—covering risk management, data governance, transparency, technical documentation, and human oversight—into technical specifications that providers can implement.
Article 32 establishes a presumption of conformity for notified bodies. When a conformity assessment body demonstrates compliance with the criteria laid down in relevant harmonised standards whose reference numbers have been published in the Official Journal of the European Union, it is presumed to comply with the requirements set out in Article 31. This presumption applies only to the extent that the applicable harmonised standards cover those specific requirements. The rationale is clear: harmonised standards reduce regulatory uncertainty by creating a technical safe harbour, ensuring that conformity assessment bodies operate to consistent benchmarks across the internal market.
Key Developments
The standardisation process under the AI Act is still in its early stages, with standardisation requests being formulated to mandate CEN and CENELEC to develop the technical specifications needed. The European AI Office is expected to play a coordinating role in ensuring that standards align with the Act's risk-based approach, particularly for high-risk AI systems.
The EDPB has signalled increasing attention to AI privacy risks, particularly through its support for the Global Privacy Assembly's statement on AI-generated imagery and privacy protection. The EDPB's work on risk management methodologies for large language models reflects a growing convergence between data protection supervisory expectations and AI Act compliance, meaning that harmonised standards will likely need to account for GDPR interoperability.
Practical Guidance
- Track Official Journal publications: Monitor which harmonised standards receive publication in the Official Journal, as only those referenced standards trigger the presumption of conformity under Article 32. Standards not yet referenced provide no legal safe harbour.
- Map AI Act requirements to standardisation deliverables: Conduct a gap analysis between your AI system's obligations under the AI Act and the available or forthcoming harmonised standards, identifying where standards coverage exists and where it remains incomplete.
- Engage with standardisation bodies: Participate in CEN/CENELEC technical committees developing AI standards to ensure your organisation's technical realities inform the specifications that will ultimately define compliance benchmarks.
- Align conformity assessment preparation with Article 31 criteria: Notified bodies should structure their internal compliance programmes around Article 31 requirements, using harmonised standards as the primary compliance pathway where available and documenting gaps where standards are still under development.
- Coordinate AI Act and GDPR compliance strategies: Given the EDPB's active scrutiny of AI privacy risks, ensure that harmonised standard implementation accounts for data protection obligations, particularly where standards address data governance and transparency requirements that overlap with GDPR principles.