CEN-CENELEC JTC 21: the EU's Harmonised Standards for the AI Act
10 min read · updated August 11, 2026
The EU AI Act, Regulation (EU) 2024/1689, sets out requirements for high-risk AI systems in terms like “appropriate level of accuracy, robustness and cybersecurity”. Nobody can be audited against that sentence. Harmonised standards are the mechanism that turns it into something testable, and Article 40 is the provision that gives them legal effect.
What a harmonised standard does legally
Under Article 40 of the AI Act, high-risk AI systems or general-purpose AI models that conform to harmonised standards, or parts of them, whose references have been published in the Official Journal of the European Union, are presumed to conform to the requirements those standards cover. Three parts of that sentence are load-bearing and each is regularly misread.
- “Whose references have been published in the Official Journal”. A standard drafted, balloted and published by CEN-CENELEC as an EN is not yet harmonised. The Commission must assess it against the standardisation request and cite it in the OJ. Until that citation exists, buying and following the standard is good engineering practice with no presumption attached.
- “Or parts of them”. The presumption is scoped to what the standard actually covers. A standard on risk management gives you a presumption about Article 9 and nothing about Article 10.
- “Presumed”. The presumption is rebuttable. A market surveillance authority can still find a compliant-by-standard system non-compliant, and Regulation (EU) No 1025/2012 contains a formal objection procedure for challenging a harmonised standard itself.
What the presumption is really worth is the shift in burden. With it, you demonstrate conformance to a published document. Without it, you construct your own interpretation of the regulation’s requirement, document why it is adequate, and defend that reasoning to a notified body or an authority. Both are possible; one is dramatically cheaper and more predictable. The regulation’s text is on EUR-Lex.
The standardisation request
European standards in support of legislation are not written speculatively. The Commission issues a standardisation request — a mandate — to the European standardisation organisations, setting out what is needed and by when. For the AI Act the request is M/593, addressed to CEN and CENELEC and issued in May 2023, before the regulation itself was finally adopted. It was subsequently amended, including to move deadlines.
The request matters because it is the yardstick the Commission uses when deciding whether to cite a finished standard. A standard that is technically excellent but does not address the requirement the request asked for will not be cited, and the request also carries the inclusiveness conditions — participation of relevant stakeholders including civil society and SMEs — that have been a live point of contention in this work. Assessment against these conditions is done by Commission-appointed consultants before citation, which is one of the less visible reasons the pipeline is slow.
What JTC 21 is producing
CEN-CENELEC Joint Technical Committee 21, “Artificial Intelligence”, was established in 2021 and is the committee doing the work. Its programme covers the ground the AI Act’s Chapter III Section 2 requirements need: a trustworthiness framework, risk management, quality management for AI systems, data governance and data quality, transparency and information for deployers, human oversight, accuracy and robustness, cybersecurity, and conformity assessment.
A recurring question is why the committee does not simply adopt existing ISO/IEC work, since SC 42 has already published on several of these topics. In some areas it has drawn on that work; in others it has judged the international documents insufficient for the specific requirement in the request — notably because European fundamental-rights framing is not what an international management standard is built around. That decision has consequences for anyone who assumed ISO/IEC 42001 certification would convert into an AI Act presumption. It does not. See what an ISO/IEC 42001 certificate does and does not establish.
It is worth being clear about the size of what is being attempted. Writing testable criteria for “appropriate accuracy” across every high-risk application in Annex III — from biometric identification to employment to critical infrastructure — is a harder standardisation problem than any of the product directives that used this mechanism before, because the hazard is not a physical failure mode with a measurable threshold.
Status and the timing problem
The original deadline in the standardisation request was in 2025, and it moved. Work has been published as drafts and technical specifications in several areas while the flagship standards remained in development, and the practical position for most of the period since the AI Act entered into force on 1 August 2024 has been that no harmonised standards for the Act were cited in the Official Journal.
The gap has become a policy problem rather than only a technical one. High-risk obligations under the Act have compliance dates fixed in the regulation, and the standards that were supposed to make them implementable have not arrived on the same schedule — which is the background to the Commission’s proposal, put forward in November 2025 as part of a wider digital simplification package, to make the application of certain high-risk rules depend on the availability of supporting standards and tools. That is a legislative proposal. It is not law, it must go through the Parliament and the Council, and it may be amended or dropped. Do not plan on the basis of it; plan on the dates in the regulation as it stands and follow the Act’s application timeline for what has actually changed.
What a provider does in the meantime
The absence of a cited standard does not suspend the obligation, and Article 41 gives the Commission the power to adopt common specifications by implementing act where harmonised standards are insufficient or delayed — a fallback that produces the same presumption by a different route.
Until either exists for your requirement, conformity is demonstrated the long way: read the article, decide what satisfying it means for your system, write down the reasoning, and keep the evidence. In practice that means leaning on the best available published material even though it carries no presumption — the ISO/IEC work for management and risk process, sector standards where your product already has them, and draft European standards where they exist, on the reasonable expectation that the final text will not be unrecognisable. Record which version of which draft you used and when; that record is the difference between a defensible position and an assertion.
Two things follow for procurement. First, a supplier claiming “AI Act compliance” today is making a claim that cannot yet rest on a presumption of conformity, so ask what it rests on instead. Second, contracts written now should anticipate that the technical criteria will be published later — a clause requiring conformance to harmonised standards once cited is more useful than one freezing today’s interpretation. See the clauses that carry this well.