Silvia, one thing I took from this is that companies need to keep track of more than which standard they used. They also need to know what status that standard had when they relied on it.
A draft, a published standard and an OJ-cited standard may all be useful, but they do not seem to mean the same thing legally. And if that status changes later, the organization needs to know which earlier decisions depended on it and whether they now need to be revisited.
That made me think again about the boundary we discussed. A governance system can identify that something changed and that a decision needs to be reopened, but the decision about what to do next still has to come from inside the organization.
Is that a fair reading of the practical problem you are describing?
Yes, that's a fair reading. Draft, published, and cited in the Official Journal are three different legal positions, and the record should show which one applied when you relied on it. Version and date, not just the name.
You're right about the boundary too. A system can tell you something changed. Whether what you did still holds is a judgment someone has to make, and write down.
Thanks for your article. What strikes me most is the operational consequence. Organizations cannot simply “wait for the standards”, they need to build governance now, document the reasoning behind decisions, and be able to show why a given interpretation was reasonable at a given point in time.
It reinforces something I strongly believe: good AI governance is not a static compliance layer added at the end. It is an operating capability ... one that has to absorb regulatory uncertainty, evolving standards and changing technical realities without paralysing execution.
Thank you, Tam. Agreed. AI governance is not a compliance layer added at the end, but a process you keep running, and right now it has to keep running while the standards underneath it are still moving.
"A European standard normally passes two stages before publication: a public consultation and then a formal vote by the national standards bodies. Under the new measures, a draft that clears the consultation can go straight to publication. The vote is skipped. "
The first stage (Enquiry) is not just a public consultation; it is also a vote by national bodies. The second vote can always be skipped if no technical changes are made since the first vote. The change that has actually happened is that technical changes are not permitted (usually) after the first vote if it is approved in that first vote.
The actual effect of the change has been that the standards have so far failed the first vote. Hence, restoring the procedure to the normal one.
Thanks for the correction on the first stage, Adam. I wanted to simplify it for the reader and I made it looser than it should be. Fixed now.
On the second, what I was working from was the October announcement, which frames direct publication as something being allowed under exceptional and temporary measures. That made it read as new.
Interesting that they have failed the first vote. I didn't know that. I should be reading your newsletter more closely.
None of it changes the conclusion though. Nothing is cited in the Official Journal yet. And I would say that failing the first vote makes it worse, not better.
The gap now has a documented schedule attached to it. CEN and CENELEC said on 23 October 2025 that their Technical Boards, meeting 14 to 16 October, adopted exceptional measures to get the AI Act deliverables out by Q4 2026: direct publication after a positive Enquiry with the Formal Vote skipped, plus a small drafting group to finish six of the most delayed drafts.
Two things follow for the person writing the number. The safe harbour is dated rather than open-ended. And the first published versions will carry Enquiry comments deferred to a later revision, so early conformity gets built on a standard already scheduled to change.
The delay changed how much time the standards have, not whether they exist. The Council gave final approval to the Digital Omnibus on AI on 29 June 2026, and its press release fixes new application dates for the high-risk rules: 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for high-risk systems embedded in products.
The same text moves the other way elsewhere. The grace period for providers to implement transparency solutions for artificially generated content was cut from six months to three, with the deadline now 2 December 2026. The gap you describe stays open longer for accuracy and closes sooner for labelling.
Thanks for tracking EN 18286 this precisely, the published-versus-officially-cited distinction is exactly what gets flattened in coverage of this Act.
There's a mirror-image version of the error you're describing, on the deadline side rather than the standards side. When the Digital Omnibus pushed Annex III high-risk obligations to December 2027, a Deloitte survey found most enterprises read that as broad relief, while Article 50's transparency obligations (disclosure, watermarking, deepfake labeling) were never deferred and are being enforced now, including the first EUR15M fine, against a retailer's emotion-recognition deployment. Same underlying mistake in both directions: a piece of regulatory motion (a deferral, a publication) gets treated as a change in legal status, when the actual trigger is a specific act, an Official Journal citation on your side, a recital's narrow carve-out on this one, that most organizations aren't checking directly. Your recommendation to document reliance contemporaneously is the right defense against either version.
Silvia, one thing I took from this is that companies need to keep track of more than which standard they used. They also need to know what status that standard had when they relied on it.
A draft, a published standard and an OJ-cited standard may all be useful, but they do not seem to mean the same thing legally. And if that status changes later, the organization needs to know which earlier decisions depended on it and whether they now need to be revisited.
That made me think again about the boundary we discussed. A governance system can identify that something changed and that a decision needs to be reopened, but the decision about what to do next still has to come from inside the organization.
Is that a fair reading of the practical problem you are describing?
Yes, that's a fair reading. Draft, published, and cited in the Official Journal are three different legal positions, and the record should show which one applied when you relied on it. Version and date, not just the name.
You're right about the boundary too. A system can tell you something changed. Whether what you did still holds is a judgment someone has to make, and write down.
Thanks for your article. What strikes me most is the operational consequence. Organizations cannot simply “wait for the standards”, they need to build governance now, document the reasoning behind decisions, and be able to show why a given interpretation was reasonable at a given point in time.
It reinforces something I strongly believe: good AI governance is not a static compliance layer added at the end. It is an operating capability ... one that has to absorb regulatory uncertainty, evolving standards and changing technical realities without paralysing execution.
Thank you, Tam. Agreed. AI governance is not a compliance layer added at the end, but a process you keep running, and right now it has to keep running while the standards underneath it are still moving.
"A European standard normally passes two stages before publication: a public consultation and then a formal vote by the national standards bodies. Under the new measures, a draft that clears the consultation can go straight to publication. The vote is skipped. "
The first stage (Enquiry) is not just a public consultation; it is also a vote by national bodies. The second vote can always be skipped if no technical changes are made since the first vote. The change that has actually happened is that technical changes are not permitted (usually) after the first vote if it is approved in that first vote.
The actual effect of the change has been that the standards have so far failed the first vote. Hence, restoring the procedure to the normal one.
Thanks for the correction on the first stage, Adam. I wanted to simplify it for the reader and I made it looser than it should be. Fixed now.
On the second, what I was working from was the October announcement, which frames direct publication as something being allowed under exceptional and temporary measures. That made it read as new.
Interesting that they have failed the first vote. I didn't know that. I should be reading your newsletter more closely.
None of it changes the conclusion though. Nothing is cited in the Official Journal yet. And I would say that failing the first vote makes it worse, not better.
The gap now has a documented schedule attached to it. CEN and CENELEC said on 23 October 2025 that their Technical Boards, meeting 14 to 16 October, adopted exceptional measures to get the AI Act deliverables out by Q4 2026: direct publication after a positive Enquiry with the Formal Vote skipped, plus a small drafting group to finish six of the most delayed drafts.
Two things follow for the person writing the number. The safe harbour is dated rather than open-ended. And the first published versions will carry Enquiry comments deferred to a later revision, so early conformity gets built on a standard already scheduled to change.
The delay changed how much time the standards have, not whether they exist. The Council gave final approval to the Digital Omnibus on AI on 29 June 2026, and its press release fixes new application dates for the high-risk rules: 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for high-risk systems embedded in products.
The same text moves the other way elsewhere. The grace period for providers to implement transparency solutions for artificially generated content was cut from six months to three, with the deadline now 2 December 2026. The gap you describe stays open longer for accuracy and closes sooner for labelling.
Thanks for tracking EN 18286 this precisely, the published-versus-officially-cited distinction is exactly what gets flattened in coverage of this Act.
There's a mirror-image version of the error you're describing, on the deadline side rather than the standards side. When the Digital Omnibus pushed Annex III high-risk obligations to December 2027, a Deloitte survey found most enterprises read that as broad relief, while Article 50's transparency obligations (disclosure, watermarking, deepfake labeling) were never deferred and are being enforced now, including the first EUR15M fine, against a retailer's emotion-recognition deployment. Same underlying mistake in both directions: a piece of regulatory motion (a deferral, a publication) gets treated as a change in legal status, when the actual trigger is a specific act, an Official Journal citation on your side, a recital's narrow carve-out on this one, that most organizations aren't checking directly. Your recommendation to document reliance contemporaneously is the right defense against either version.