The EU AI Act Harmonised Standards are technical specifications being developed to support compliance with the European Union's Artificial Intelligence Act (AI Act), a regulation that establishes a common regulatory and legal framework for artificial intelligence within the EU. The AI Act entered into force on 1 August 2024, with provisions phased in over 6 to 36 months. The harmonised standards are intended to offer practical, presumptive-conformity mechanisms for AI providers and deployers, translating the Act's risk-based obligations into measurable and auditable requirements. They are developed by European standardisation organisations, such as CEN and CENELEC, in response to a standardisation request from the European Commission, and are expected to play a crucial role in the Act's implementation, particularly for high-risk AI systems and general-purpose AI models.
The development of these standards is a collaborative effort involving industry experts, regulators, and other stakeholders. The process is overseen by the European Commission, which issues standardisation mandates, and the European Artificial Intelligence Board, which promotes national cooperation and ensures consistent application. The standards are not yet fully finalised as of 2025, but drafts and work programmes have been published, covering areas such as risk management, data governance, transparency, human oversight, and conformity assessment procedures. Once adopted, compliance with these harmonised standards will provide a presumption of conformity with the AI Act's requirements, easing the regulatory burden for organisations.
Background and Legal Framework
The AI Act, proposed by the European Commission on 21 April 2021, passed the European Parliament on 13 March 2024 and was unanimously approved by the EU Council on 21 May 2024. It covers most AI systems across a wide range of sectors, with exemptions for military, national security, research, and non-professional use. The Act classifies AI applications into four risk levels - unacceptable, high, limited, and minimal - plus a separate category for general-purpose AI. Unacceptable-risk applications, such as social scoring or real-time remote biometric identification in public spaces, are banned. High-risk applications, including those in health, education, recruitment, and law enforcement, must comply with security, transparency, and quality obligations, and undergo conformity assessments. Limited-risk applications, like deepfakes, have transparency obligations, while minimal-risk applications, such as spam filters, are not regulated. The Act also applies extraterritorially to providers outside the EU if they have users within the EU.
The harmonised standards are a key mechanism for operationalising these obligations. They are designed to be voluntary, but adherence offers a 'safe harbour' for compliance, reducing the need for case-by-case assessments by national authorities. The standards are being developed in alignment with international norms, such as ISO/IEC 42001, but tailored to the AI Act's specific requirements.
Development Process
The European Commission issued a standardisation request to CEN and CENELEC in 2023, asking them to draft harmonised standards for the AI Act. The request identified priority areas, including risk management, data quality, transparency, human oversight, and cybersecurity. The development process involves multiple technical committees, with input from industry, academia, civil society, and national standardisation bodies. Draft standards are subject to public consultation and revision before final adoption. As of 2025, several draft standards have been released for comment, but none have been formally adopted as harmonised standards under the AI Act. The timeline for finalisation is expected to extend into 2026, given the complexity and the need for alignment with the Act's phased implementation.
Key Areas of Standardisation
The harmonised standards cover several critical domains:
- Risk Management: Standards for identifying, assessing, and mitigating risks throughout the AI system lifecycle, including requirements for risk management systems and documentation.
- Data Governance: Specifications for data quality, including training, validation, and testing data, to ensure accuracy, completeness, and representativeness, and to address bias.
- Transparency: Requirements for informing users that they are interacting with an AI system, and for providing clear information about system capabilities and limitations.
- Human Oversight: Standards for designing AI systems that allow for human intervention, monitoring, and the ability to override decisions, particularly for high-risk applications.
- Conformity Assessment: Procedures for evaluating AI systems before market placement, including internal or third-party assessments, depending on the risk level.
- Cybersecurity: Measures to protect AI systems from attacks and ensure robustness, including adversarial testing for high-impact models.
These standards are intended to be technology-neutral, applicable to various AI techniques, including machine learning, deep learning, and generative AI systems like large language models.
General-Purpose AI and Foundation Models
A significant focus of the harmonised standards is on general-purpose AI, a category added in 2023 to address systems like ChatGPT. For open-source models, developers must publish a training data summary and a copyright policy, while closed-source models face broader transparency requirements. High-impact models that require more than 10^25 floating-point operations to train are considered to pose systemic risks and must undergo extra evaluations, including adversarial testing and incident reporting. The General-Purpose AI Code of Practice, published on 10 July 2025, complements the standards by outlining transparency, copyright, and safety measures. The harmonised standards will provide technical specifications to support these obligations, such as methods for calculating training compute and conducting model evaluations.
Relationship with Existing Regulations
The harmonised standards are designed to align with other EU regulations, such as the General Data Protection Regulation (GDPR) and the Product Liability Directive. They also consider international standards to facilitate global trade. For example, the standards on data governance draw on GDPR principles, and those on cybersecurity reference the EU Cybersecurity Act. This alignment aims to reduce duplication and ensure a coherent regulatory environment for AI.
Challenges and Controversies
Developing harmonised standards for the AI Act has faced challenges. One issue is the pace of technological change, particularly in generative AI, which may outpace standard-setting. Another is the balance between innovation and safety, as overly prescriptive standards could stifle development, while lax ones may fail to protect fundamental rights. There are also debates about the scope of standards for high-risk applications, with some stakeholders calling for more rigorous requirements, while others seek flexibility. Additionally, the voluntary nature of the standards raises questions about their effectiveness, as some organisations may choose not to comply, leading to inconsistent enforcement across the EU.
Future Outlook
As of 2025, the harmonised standards are still in development, with finalisation expected by 2026. The European Commission and standardisation bodies are working to ensure they are practical and up-to-date. Once adopted, the standards will be published in the Official Journal of the European Union, giving them legal effect. They are expected to evolve over time to address new AI applications and risks. The success of the AI Act will depend, in part, on the quality and adoption of these standards, which will shape how AI is developed and deployed in the EU and beyond.
Conclusion
The EU AI Act Harmonised Standards are a critical component of the EU's regulatory framework for AI, providing technical guidance to support compliance. They are being developed through a collaborative process and cover key areas such as risk management, data governance, and transparency. While challenges remain, the standards are poised to play a central role in ensuring that AI systems in the EU are safe, transparent, and respectful of fundamental rights. Their development reflects a broader trend towards standardisation in AI governance, with implications for global AI regulation.