You have read Article 15 of the EU AI Act more times than you would like to admit.
It says your high-risk system needs an appropriate level of accuracy. It does not say what appropriate means. So you go looking, because eventually someone has to write a number into a document and it is going to be you.
The Commission guidance does not answer it. The law firm alerts do not answer it. The vendor says their product is compliant, which is not an answer to anything.
At some point you start to wonder whether you are missing something obvious.
You are not. The thing you are looking for has not been written yet.
The AI Act was designed to leave that gap. The regulation states the duty, a harmonized standard states how to meet it, and conforming to the standard earns you a presumption that you have satisfied the requirement it covers. That is a good design.
As of today the European Commission has not cited a single harmonized standard for the AI Act in the Official Journal. Citation is the step that gives a standard its legal effect, and it has not happened once.
In July the first European standard did arrive. EN 18286, on quality management systems, described by CEN-CENELEC on their own site as “the first harmonized European standard for the AI Act regulatory purposes.” Every part of that is accurate. It still confers nothing.
Your date is December 2, 2027. It no longer waits for any of this.
What the Presumption Is, Exactly
Article 40(1) says that a high-risk AI system which conforms to harmonized standards, or parts of them, the references to which have been published in the Official Journal, is presumed to be in conformity with the requirements set out in Section 2 of that Chapter, to the extent those standards cover those requirements.
There are three conditions though.
The first is publication of the reference in the Official Journal. Not drafting. Not approval by CEN-CENELEC. Not publication of the standard itself. The Commission assesses the standard against the request it made and then cites the reference in the OJ, and that is a separate act which happens afterward. EN 18286 has cleared every CEN-CENELEC stage. It has not cleared that one, and there is a Commission assessment and national transposition still to happen in between.
The second is coverage. A harmonized standard carries an Annex ZA, the table mapping the standard onto the specific legal provisions it supports. The presumption reaches exactly as far as that table and stops. A cited risk management standard answers Article 9. Your data governance obligations under Article 10 will regard it with polite indifference.
The third is the word presumed. It shifts the burden of proof. It does not end the argument. A market surveillance authority can still look at your system, decide it does not meet the requirement, and act on that, even if you followed the standard exactly. The AI Act has a whole procedure for it.
The standard itself is not permanent either. A Member State or the European Parliament can formally object to a harmonized standard, and the Commission can then narrow what it covers or pull the reference back out of the Official Journal.
None of that is a flaw. It is how CE marking has always worked. It is just a good deal less than “safe harbor” suggests to a board.
What Is Often Skipped in a Commentary
The AI Act splits its high-risk AI system duties into two kinds.
One set is about the system: it has to manage risk, use decent data, keep records, be transparent, allow human oversight, and be accurate, robust and secure. The other set is about you, the company placing it on the market or putting it into service: run a quality management system, keep the documentation, fix things when they go wrong.
Article 40 offers the presumption for the first set. Only the first set.
EN 18286 is a standard for the second set. It covers the quality management system.
So the first standard to reach publication is a standard for a duty the presumption does not obviously reach. Whether citing it in the Official Journal produces one anyway is a question the text does not answer, and I have not found anything authoritative that does. Common specifications would not solve it either, because Article 41 is written to the same scope.
Most commentary assumes the presumption attaches on citation and moves on. It may. The European Commission did ask for a quality management deliverable when it issued the standardization request, which says something about intent. But intent is not operative text, and this gets settled when the Commission decides whether, and how, to cite.
Where Everything Else Sits
As of August 23, 2026 one standard is finished, four drafts out for public comment, the rest is still being written.
The four out for comment cover risk management, cybersecurity, logging, and human oversight. (prEN 18228, 18282, and 18229 parts 1 and 3, if you want to go and look.) Still being written: transparency, accuracy, robustness, data quality, bias, and the conformity assessment framework itself.
Do not attach much weight to the count. It moves. The trustworthiness standard that was one document is now a five-part series, and there are ISO-derived standards on the same work program alongside the purpose-written ones. The Commission describes its request as covering ten key areas rather than a number of documents, which is the more useful way to hold it.
The number that matters is the other one. As of today the Commission has published no reference to a harmonized standard under the AI Act in the Official Journal.
The Commission issued its standardization request in May 2023, with 30 April 2025 as the deadline for CEN and CENELEC to deliver. That date passed with nothing delivered under the request. An amending request followed in June 2025, extending the timeline and adding quarterly progress reporting.
Then, in October 2025, CEN and CENELEC changed their own rules, in what they called exceptional and temporary measures.
A European standard goes through an enquiry stage, where the national standards bodies vote and comments come in, and then a second formal vote before publication. Under the October measures, a draft that passes enquiry can go straight to publication, and technical changes after that point are no longer allowed.
The consultation is still real, so this is not consensus abandoned. It is consensus on a shorter rope. But a standards body suspending its own approval vote is not a routine schedule adjustment, and it is the clearest signal available about how the timeline is actually going.
And note what “available by the end of 2026” is a target for. The document existing. Not the Commission citing it, which is a separate step and comes after.
The Condition That Was Proposed, and Removed
When the Commission proposed the Digital Omnibus on AI, it did not propose a simple postponement of the high-risk AI systems. According to the Council’s own account of the provisional agreement, the Commission had proposed adjusting the timeline by up to sixteen months, so that the rules would start to apply “once the Commission confirms the needed standards and tools are available.”
A conditional trigger. The obligations would begin when the means of complying with them existed.
Parliament and Council did not keep it. The agreed text replaced the trigger with fixed dates.
Those dates are now law. Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July and in force three days later.
It sets two. 2 December 2027 for high-risk systems that stand on their own, the ones on the Act’s list in Annex III. 2 August 2028 for high-risk AI built into products that already carry their own EU safety rules, medical devices among them.
The delay survived. The condition attached to it did not.
And the Regulation says why, in its own recitals. Recital 40 records that for the high-risk obligations in Chapter III, “the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardize the effective entry into application of those obligations.”
That is the EU stating, inside a binding instrument, that the standards are not ready. In the same instrument that removes the condition which would have waited for them.
There is a real argument for the choice. An open-ended trigger hands the Commission the power to postpone a regulation indefinitely by declining to confirm readiness, and gives businesses no date to plan against. Fixed dates are certainty, and certainty is what compliance teams have been asking for since 2024.
But it produces a specific result. The Commission’s version tied the start to whether the tools existed. The adopted version just picked a day.
The Fallback That Has Not Been Used
The AI Act does have a backup plan.
If the standards do not arrive, Article 41 lets the European Commission write the specifications itself. They are called common specifications, and they work the same way: follow them and you get the same presumption a harmonized standard would give you. A provider who would rather not use them has to show its own solutions are at least as good, which is real work, and that is the point.
The conditions for using it are not hypothetical. The Commission has to have asked for standards, the standards have to have missed their deadline, and nothing can be published in the Official Journal or expected there soon.
A request was issued. The deadline was missed. Nothing is cited.
As far as I have been able to establish, no common specifications have been adopted for the high-risk requirements. If that is right, the mechanism written into the AI Act for this exact situation is sitting unused while the situation it was written for continues.
It would not fix the quality management gap either. Common specifications are offered for the same set of duties as the presumption itself, the ones about the system rather than the ones about the company.
And the AI Act says the Commission may adopt them. Not shall. That one word is why there is no obligation on anyone to fix this, and no date by which it has to be fixed.
The One Box That Is Not Empty in the Same Way
Two other routes exist, and neither runs through the standards process. They are the only places where the answer to “can I get a presumption today” is not simply no.
Article 42 gives them both. If your system was trained and tested on data that reflects the specific setting it will actually be used in, it is presumed to meet that part of the data governance requirement. And if it holds a cybersecurity certificate issued under the EU’s cybersecurity certification framework, it is presumed to meet the cybersecurity requirement, as far as that certificate reaches.
The second one comes with a familiar condition. It only works where the references have been published in the Official Journal.
Same gate. A different queue.
What ISO 42001 and NIST Do Not Do
In the absence of something to build against, teams reach for what exists.
ISO/IEC 42001 is an AI management system standard. It is certifiable, genuinely useful, and an organization that holds it is doing real governance work. It carries no presumption of conformity under the AI Act.
It is not that an ISO standard cannot become a harmonized European standard. ISO standards are adopted as European standards routinely, and the committee writing the AI Act standards is doing exactly that with two of them. The reason is that they chose to write EN 18286 rather than adopt ISO/IEC 42001 for the quality management standard, and 42001 is not on their work program as a candidate for it.
The substance differs too. EN 18286 is built around obligations that come out of the AI Act rather than out of management system practice, including a strategy for regulatory compliance, the technical specifications and standards to be applied, and procedures for reporting serious incidents under Article 73. Those map onto Article 17(1). An ISO 42001 programme gives you a conceptual head start. It does not give you the evidence.
The NIST AI Risk Management Framework is a voluntary United States framework with no legal effect in the European Union. If your organization built its AI governance on NIST because that is where the guidance was in 2023, that work is not wasted, but it does not travel to Brussels on its own.
Both are evidence of a serious organization. Neither is evidence of conformity.
What to Actually Do
Five things, and none of them require you to predict whether CEN-CENELEC makes its target.
Read the drafts, and note which version you read. Four harmonized standards are out for public comment right now: risk management, cybersecurity, logging, and human oversight. A draft gives you no legal protection. It is still the best picture available of what the finished requirement will look like, and having built toward it is worth more than having waited. Write down which draft and which date, so that if the final version changes you can show your decision was current when you made it.
Start the quality management work now. EN 18286 is the one standard that is finished. Set aside the question of whether it will ever produce a presumption: the AI Act already requires you to record which standards and specifications you apply, so a published European standard is a useful thing to be able to point at. It is also the clearest published description of what a quality management system for high-risk AI is meant to contain.
Write down your own reasoning, and date it. The requirements apply on their own terms whether or not a standard ever arrives to explain them. So every time you decide what "appropriate" means for your AI system, write down what you decided, why, and when.
Do not buy presumption. If someone tells you their product delivers presumption of conformity, ask which standard, and in which issue of the Official Journal the reference was published. For harmonized standards there is no correct answer today. For the cybersecurity certification route there might be, which makes it the better question.
Watch the Official Journal, not the announcements. When a standard is published by CEN and CENELEC it generates press coverage. When the European Commission cites it, generally it does not. The second is the one that changes your legal position, so put a recurring check in the calendar rather than waiting to hear about it.
The Bargain
Underneath the procedure, the AI Act’s design for high-risk AI systems is a trade, and a sensible one.
The regulation states the requirement in general terms, because a regulation specifying test methodologies would be obsolete before it applied. The harmonized standard then states how to demonstrate it, written by people who understand the technology and updated as the technology moves. Meet the standard and you are presumed to comply. The regulator gets requirements that survive contact with the field. You get a route to certainty that does not depend on your own legal interpretation being correct.
That is the bargain. It is the only reason a phrase like “an appropriate level of accuracy” is a workable legal obligation rather than an invitation to litigate.
One half of it has been delivered. The requirements have been on the statute book since 2024, and they apply to your systems on 2 December 2027 regardless of what has been cited by then.
The other half was originally due in April 2025.
EN 18286 was approved on 12 July 2026. The Digital Omnibus was adopted on 8 July, four days earlier, and it amended Article 17 along the way. So the first AI Act standard to reach publication maps onto a version of the law that had changed the week before. Whatever the Commission is assessing when it decides on citation, it is not assessing a fixed target.
You are being measured against instructions that have not been issued, for a requirement that has not finished moving. That is not an oversight in the drafting. It is the timetable, as adopted.
Scope is where this becomes something you can use in a meeting: the regulation map, the role assignment, the vendor questions, the AI inventory spreadsheet, the AI policy template, with sources attached and kept current as the law changes.





Silvia, one thing I took from this is that companies need to keep track of more than which standard they used. They also need to know what status that standard had when they relied on it.
A draft, a published standard and an OJ-cited standard may all be useful, but they do not seem to mean the same thing legally. And if that status changes later, the organization needs to know which earlier decisions depended on it and whether they now need to be revisited.
That made me think again about the boundary we discussed. A governance system can identify that something changed and that a decision needs to be reopened, but the decision about what to do next still has to come from inside the organization.
Is that a fair reading of the practical problem you are describing?
Thanks for your article. What strikes me most is the operational consequence. Organizations cannot simply “wait for the standards”, they need to build governance now, document the reasoning behind decisions, and be able to show why a given interpretation was reasonable at a given point in time.
It reinforces something I strongly believe: good AI governance is not a static compliance layer added at the end. It is an operating capability ... one that has to absorb regulatory uncertainty, evolving standards and changing technical realities without paralysing execution.