RatedWithAI

RatedWithAI

Accessibility scanner

EU AI ActSeptember 11, 2026

The Standards Are Late. The Obligations Are Not.

Harmonised standards are the mechanism that was supposed to turn the EU AI Act's abstract requirements into testable clauses. They arrived behind the deadlines they were meant to serve. That does not postpone anything — it moves the burden of proof onto you, article by article, until a citation appears in the Official Journal.

Article 40
Conformity with a cited harmonised standard creates a presumption — nothing else does
OJ Citation
A published EN is not usable until the reference is cited in the Official Journal
Burden Shift
Without the presumption, every design judgement is individually contestable

What the Standards Were Supposed To Do

The EU AI Act is written the way product-safety legislation in the Union is always written: the legal text states essential requirements in general terms, and a separate standardisation system turns those terms into clauses an engineer can test against. The Act says a high-risk system must achieve an appropriate level of accuracy, robustness and cybersecurity. It does not say what metric, what threshold, what test set, or what constitutes an adversarial condition. That was always the standard's job.

The Commission issued a standardisation request to CEN and CENELEC, whose joint technical committee on artificial intelligence took on the work. The output is a family of European standards covering risk management, data governance and quality, transparency, human oversight, accuracy and robustness, quality management, and conformity assessment. Once each is published and its reference is cited in the Official Journal, Article 40 gives conformity with it a presumption of conformity with the corresponding requirement.

The schedule slipped. Writing testable clauses for systems whose behaviour is statistical, whose training data is frequently not owned by the party being assessed, and whose failure modes are contested in the research literature turned out to be harder than the calendar assumed. Meanwhile the application dates in the Act did not move, because they are in the Act.

A Presumption Is Not the Requirement

This is the point most internal briefings get backwards. Companies read "the standards aren't ready" as "we can't be expected to comply yet." The legal structure says the opposite. The duty to have a risk management system, to govern training data, to produce an Annex IV technical file, to design logging in, and to make human oversight effective are all free-standing. The harmonised standard is an optional route to demonstrating you met them.

What the missing citation costs you is evidential leverage. With a presumption, the argument ends at "we conform to the cited standard" and an authority that disagrees must rebut it. Without one, every choice in your file is a separate conversation: why that accuracy metric, why that test population, why that oversight design, why that threshold for a serious incident. You will win most of those conversations if you documented your reasoning. You will lose all of them if your file says the decision was made without recording why.

There is also a supply-side effect. Notified bodies assessing high-risk systems in the categories that require third-party involvement need a yardstick too. In the absence of cited standards they assess against the Act's requirements directly, which makes assessment slower, more expensive, and more variable between bodies. Book that capacity on the assumption the review takes longer than the brochure says.

What Fills the Gap: Evidence of State of the Art

Where the Act asks for something to be appropriate, adequate, or in line with the generally acknowledged state of the art, the test in the absence of a standard is what a competent organisation in your field would have done with the knowledge available at the time. That is demonstrable, and it is demonstrated with references, not adjectives.

The four evidence types that substitute for a citation

  • Draft European standards. Working drafts from the relevant technical committee show the direction the requirement is settling in. Record the draft version and date you built against, and which clauses you adopted.
  • International standards with an explicit mapping. Management-system and risk standards for AI give you process discipline. Their value in a file comes from the mapping table you write that says which Act requirement each clause addresses — and, crucially, which requirements they do not reach.
  • Sector practice and regulator guidance. Where a sector regulator has published expectations for model validation, monitoring, or documentation, meeting them is direct evidence about what competent practice looks like in your field.
  • Your own test record. The measurements, the population they were taken on, the conditions varied, the results that were worse than you expected, and what you changed. A file containing only successful runs reads as a marketing document.

Write the File in the Shape of the Articles

The single decision that determines how much the eventual citation costs you is structural. If your technical documentation is organised as a narrative — a compliance whitepaper with sections named after your product's features — then when the final standard lands, nobody can tell which paragraph answers which clause, and the re-mapping is a rewrite.

If it is organised as a register keyed to the Act's articles, with each entry holding the requirement, the evidence, the owner, the date, and the source you relied on, then the arrival of a cited standard is a gap analysis against a clause list. You add a column. Teams that did this for the risk management system and the quality management system absorb the change without a programme.

The Interim Register: Seven Columns

  1. Requirement — the article and the specific sentence, quoted.
  2. Interpretation — what you decided it means for this system, in one paragraph.
  3. Basis — the draft standard clause, international standard clause, regulator guidance, or literature you relied on, with version and date.
  4. Evidence — the artefact that shows you did it: a test report, a data sheet, a log sample, a sign-off.
  5. Residual gap — what you know you have not fully demonstrated, stated plainly.
  6. Owner and date — a named person and when the entry was last examined.
  7. Re-check trigger — the event that makes this entry stale: a citation in the Official Journal, a model retrain, a change of intended purpose.

Column five is the one people delete. It is the one that helps you most. A file that records a known gap and an owner reads as a functioning risk management system. A file with no gaps reads as one that was never actually run.

The Day the Citation Lands

A harmonised standard becomes usable when its reference is cited in the Official Journal, not when CEN-CENELEC publishes it and not when your national standards body adopts it. Between publication and citation there is a window in which the document exists, is purchasable, and confers no presumption at all. Track the citation, not the publication.

When it does land, three things follow. Your register gets a clause-mapping column and a list of deltas. Anything that was justified only by a draft clause that changed materially needs its evidence re-examined. And your vendor conversations change: you can now ask suppliers to state conformity with a named standard rather than to describe their process, which is a far cheaper question to evaluate at renewal.

None of that is possible if the intervening period was spent waiting. The companies that will convert a citation into a presumption in weeks are the ones that already hold a test record, a data governance description, and an oversight design — written down, dated, and owned.

Frequently Asked Questions

Our vendor says they are 'aligned with emerging EU AI Act standards'. Is that worth anything?

As a claim, no. Ask which document, which version, which clauses, and what evidence exists for each. Alignment with an unpublished draft is a statement about intent. If the vendor cannot name the draft and the clauses, what you have is a marketing sentence that will not survive a single question from a market surveillance authority — and under a deployer's duty to use the system according to its instructions, their vagueness becomes your problem.

Should we wait for the standards before starting the technical file?

No, for a practical reason beyond the legal one: the file's expensive parts are the test records, the data documentation and the change history, and all three are retrospective. You cannot go back and measure a model as it was eighteen months ago. Whatever the final clause structure says, it will ask for evidence that only exists if you were collecting it at the time.

Does conformity with a harmonised standard mean we are definitely compliant?

It means the corresponding requirement is presumed met, to the extent the standard covers it. A citation in the Official Journal can carry restrictions that limit which requirements the presumption reaches, and a standard never covers whether you classified the system correctly in the first place. Classification, intended purpose, and role allocation stay your judgement regardless of what you conform to.

We are outside the EU. Does the standards delay change anything for us?

Only in that it makes the evidence burden heavier at the moment your product reaches the EU market. The territorial reach of the Act follows the placing on the market and the use of outputs in the Union, not your establishment. A provider outside the Union also has to appoint an authorised representative, and that representative will ask for the same file.

How does this interact with common specifications?

Common specifications are the Commission's fallback where standardisation does not deliver in time, adopted by implementing act and carrying the same presumption. They are designed to be temporary and replaced once harmonised standards exist. Plan for either arriving, which in practice means keeping the register instrument-agnostic: requirement first, source second.

Start With the Register, Not the Standard

Pick your highest-exposure system and spend a day building the seven-column register for it. Most teams discover that between a third and a half of the rows already have evidence sitting in an engineering ticket, a model card, or a validation notebook — it has simply never been indexed against a legal requirement.

The rows that come back empty are your actual programme. They will still be empty on the day the citation is published, and that is the day the presumption becomes available to everyone who prepared for it.