Definition: Harmonised Standards (EU AI Act)
Harmonised standards are technical specifications developed by the European standardisation organisations CEN, CENELEC and ETSI at the European Commission’s request, which give AI providers a concrete route to demonstrate compliance with the essential requirements of the EU AI Act.
Core characteristics of harmonised standards
Harmonised standards translate the AI Act’s high-level legal requirements, such as risk management, data governance and human oversight, into testable technical specifications. They only take legal effect for presumption purposes once the European Commission publishes their reference in the Official Journal of the European Union.
- Drafted by CEN-CENELEC Joint Technical Committee 21 (JTC 21) and ETSI under a formal Commission standardisation request
- Cover Annex III high-risk system requirements: risk management, data quality, technical documentation, logging, transparency, human oversight, accuracy and cybersecurity
- Become legally relevant for a presumption of conformity only after Official Journal citation, not merely on publication
- Voluntary in principle, but the practical default path for providers seeking a lower-friction conformity assessment
Harmonised standards vs. conformity assessment
Harmonised standards and conformity assessment are related but distinct. A harmonised standard is the technical yardstick a provider can build to; conformity assessment is the overall procedure, internal or via a notified body, that verifies a high-risk AI system actually meets the requirements before it reaches the market. Building to a cited harmonised standard narrows and speeds up conformity assessment, because the provider no longer argues compliance from first principles. Without a cited standard, the same assessment has to reference the AI Act’s text directly, which takes longer and leaves more room for interpretation.
Importance of harmonised standards in enterprise AI
For providers of high-risk AI systems, harmonised standards are the difference between a predictable compliance path and a bespoke legal argument for every deployment. As of mid-2026, none of the roughly 30 AI Act deliverables drafted by JTC 21 had been cited in the Official Journal (CEN-CENELEC, 2026). Bitkom’s 2026 AI study found that a quarter of German companies had not engaged with the AI Act at all, and two-thirds of affected firms said they still need external help to implement it.
Methods and procedures for harmonised standards
Three distinct routes exist for building AI Act compliance evidence, since not every provider can rely on a cited standard yet.
Standardisation request and drafting
The European Commission issued its formal standardisation request to CEN and CENELEC on 22 May 2023, defining which AI Act articles JTC 21’s working groups had to translate into technical text.
- Working groups draft specifications covering risk management, data governance, documentation, transparency and post-market monitoring
- Drafts pass through public enquiry, national body voting and formal approval before publication as an EN standard
- The Commission then assesses the published EN against the standardisation request before deciding whether to cite it
Presumption of conformity route
Once the Commission cites a harmonised standard in the Official Journal, a provider that documents its system as built in accordance with that standard is legally presumed to meet the corresponding requirement. This shifts the burden of proof: a market surveillance authority would have to show the standard was misapplied to challenge conformity, rather than the provider justifying compliance from scratch. EN 18286:2026, the quality management system standard for AI Act regulatory purposes, cleared CEN-CENELEC approval in July 2026 and is the most advanced candidate, though it is not yet cited.
Documentation without a cited standard
Where no harmonised standard is cited, an AI provider can still reach conformity by mapping its technical documentation directly against Annex IV, often anchored to a private-sector baseline such as ISO/IEC 42001. This route demands more internal legal judgement and takes longer to defend in an audit, which is why most providers track JTC 21’s publication calendar rather than treating it as a permanent strategy.
Important KPIs for harmonised standards
Compliance teams track a mix of operational, strategic and quality indicators while the standards landscape is still forming.
Standards-tracking indicators
- Applicable JTC 21 deliverables published as EN standards: target complete visibility per product line
- Standards cited in the Official Journal relevant to your systems: zero across the market as of mid-2026
- Time between EN publication and a Commission citation decision: tracked per deliverable
- Internal documentation mapped to draft standards: percentage coverage
Strategic risk exposure
Tracking which Annex III use case categories a company’s systems fall into, and whether any rely on a standard still in draft, lets teams forecast audit readiness. Gartner has warned that a majority of organisations deploying high-risk AI in the EU will face at least one documentation gap tied to unresolved standards before the presumption route becomes usable.
Documentation quality
Beyond counting standards, teams should assess whether their documentation would survive scrutiny if no cited standard existed at all, since that remains the operative reality for nearly every AI Act obligation today.
Risk factors and controls for harmonised standards
The absence of cited standards creates specific risks that compliance and product teams need to manage actively.
Standards gap risk
Building a compliance programme entirely around a draft standard that later changes, or is never cited, wastes documentation effort and creates false confidence.
- Draft specifications can change materially between public enquiry and final publication
- A published EN standard is not automatically cited in the Official Journal
- Citation timing depends on Commission review capacity, not only technical readiness
Over-reliance on a single route
Providers who wait for a cited standard before starting any documentation risk missing deadlines that are not tied to standards readiness at all; the Digital Omnibus reform explicitly decoupled application dates from standards availability.
Fragmented internal ownership
When legal, product and quality teams each track standardisation news independently, conflicting interpretations of draft requirements reach engineering teams, which slows implementation and raises audit risk later.
Practical example
A 140-employee industrial sensor manufacturer in Baden-Württemberg builds a machine-vision quality-inspection module that qualifies as high-risk under Annex III. Its compliance lead cannot yet point to a cited harmonised standard, so the team builds technical documentation directly against Annex IV while mapping internal processes to ISO/IEC 42001 and the draft EN 18286 structure, so it can adopt the cited standard quickly once available. Superkind’s AI agents pull the underlying process logs, model version records and human-oversight decisions directly from the company’s existing quality system into one audit trail, instead of a compliance officer reconstructing that evidence manually across several tools.
- Centralised documentation trail spanning risk management, data lineage and human oversight decisions
- Mapping table showing which Annex IV sections rely on draft versus established standards
- Quarterly review of JTC 21 publication status against the company’s product roadmap
- Audit-ready evidence package that can be updated once a standard is cited
Current developments and effects
The harmonised standards landscape shifted materially in 2026, with direct consequences for how providers plan their compliance timeline.
Digital Omnibus decouples deadlines from standards readiness
The Digital Omnibus, Regulation (EU) 2026/1744, entered into force in July 2026 and pushed the deadline for standalone high-risk Annex III systems from 2 August 2026 to 2 December 2027, with AI embedded in already-regulated products moving to 2 August 2028.
- Application dates are now explicitly decoupled from standards readiness
- CEN-CENELEC targets its prioritised deliverables by the fourth quarter of 2026
- Article 50 transparency duties and GPAI provider obligations were not affected
First standard published, not yet cited
EN 18286:2026, the first AI Act harmonised standard to reach publication, cleared CEN-CENELEC approval in July 2026, but the Commission had not yet cited it in the Official Journal at the time of writing, so no standard currently grants a presumption of conformity.
Growing Mittelstand awareness gap
Bitkom’s 2026 AI study of 604 German companies found that a quarter had not engaged with the AI Act at all, even as active AI use among German firms jumped from 17% in 2024 to 41% in 2026, showing standards readiness and organisational readiness are moving at very different speeds.
Conclusion
Harmonised standards remain the intended fast lane to AI Act compliance, but that lane was still under construction through mid-2026, with the first standard published and none yet cited in the Official Journal. Providers of high-risk systems cannot wait for that citation before acting, because the Digital Omnibus deferral bought standard-setters more time without pausing the underlying legal requirements. The safer posture is documenting compliance against the regulation directly today, while mapping that documentation to draft standards so it converts cleanly once citation happens. As JTC 21’s deliverables clear the Official Journal through 2026 and 2027, providers who tracked this process closely will convert fastest to the lower-friction presumption of conformity route.
Frequently Asked Questions
What is the difference between a harmonised standard and CE marking?
A harmonised standard is a technical specification a provider can build to; CE marking is the visible declaration, affixed after a successful conformity assessment, that a system meets the AI Act’s requirements. Building to a cited standard makes reaching that marking faster and more predictable, but it remains a separate, later step.
Does my company have to use harmonised standards?
No. They are voluntary; a provider can always demonstrate compliance by documenting its system directly against the EU AI Act text and Annex IV. Most providers prefer a cited standard because it shifts the burden of proof, but until one is cited, direct documentation is the only available route.
Is this relevant for a Mittelstand company with under 200 employees?
Yes, if the company develops or substantially modifies a high-risk AI system, size does not exempt it from the underlying requirements. Given that no standard is cited yet, a 200-person manufacturer faces the same documentation burden as a large enterprise until JTC 21’s deliverables clear the Official Journal.
How does this connect to the EU AI Act’s 2026 deadline changes?
The Digital Omnibus moved the deadline for most standalone high-risk Annex III systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products to 2 August 2028. This gives CEN-CENELEC more time to get standards cited, but it does not remove the requirement to prepare documentation now.
What does it cost to prepare for harmonised standards compliance?
Costs vary by system complexity, but most Mittelstand providers spend on legal and quality-management consulting rather than on the standards themselves, which are purchased individually once published. Mapping existing quality processes to a draft standard like EN 18286 early is typically cheaper than a full retrofit after citation.
Do we need our own IT team to track standards developments?
No dedicated IT team is required, but someone in compliance, quality or legal needs to monitor JTC 21 and Official Journal publications, since citation timing drives when the presumption route becomes available. Many Mittelstand companies fold this into their existing AI provider compliance ownership rather than hiring a new role.