How law borrows standards: the New Legislative Framework

Lesson 1 of 5 in The EU AI Act Interface: Harmonized Standards and the 42001 Playbook.

The EU AI Act never tells you how many test cases prove a model ‘accurate’ or what a compliant logging schema looks like. That is deliberate. The Act follows the EU’s New Legislative Framework — the same regulatory architecture behind CE-marked toys, machinery, and medical devices: the law states essential requirements; standards supply the technical detail.

The machine has three moving parts. First, the legislature writes essential requirements into the regulation — for high-risk AI, that is Articles 8–15: risk management, data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy/robustness/cybersecurity. Second, the European Commission issues a standardisation request to the European standards organisations — for AI, to CEN and CENELEC, whose joint technical committee JTC 21 drafts European standards (ENs) answering each requirement. Third — and this is the step everything hinges on — the Commission assesses the finished standards and cites them in the Official Journal of the European Union (OJEU). Only then do they become harmonised standards in the legal sense, and only then does using them buy you the prize: a presumption of conformity — a rebuttable legal presumption that systems built to the standard meet the corresponding essential requirements.

Hold the asymmetry firmly: harmonised standards are voluntary. You may always demonstrate conformity your own way, arguing directly against the Act’s text. But the presumption reverses the burden in practice — with it, a market surveillance authority must show the standard did not deliver; without it, you must prove your bespoke approach does. That difference is why, in every NLF sector, harmonised standards become the de facto rulebook the moment they are cited.

Demonstrating conformity with an essential requirement (Arts 8–15)

  1. High-risk AI system must meet an essential requirement

    Say Art 15 accuracy/robustness/cybersecurity. The Act states the what; you need a defensible how.

  2. Harmonised standard cited in the OJEU for this requirement?

    Art 40. Citation in the Official Journal is the switch — a published EN that is not yet cited carries no presumption.

  3. Apply the harmonised EN

    Full or partial application; the presumption covers the requirements the standard (or the parts you applied) addresses.

  4. Presumption of conformity

    Rebuttable presumption that the covered essential requirements are met. Authorities carry the burden of showing otherwise.

  5. Common specifications adopted for this requirement?

    Art 41: if standards are absent, insufficient, or too slow, the Commission can adopt common specifications by implementing act — same presumption effect, but written by the regulator, not by consensus.

  6. Apply the common specifications

    Compliance with common specifications also yields a presumption of conformity for what they cover. Providers may deviate only with a justified equivalent solution.

  7. Demonstrate conformity directly against the Act

    First-principles evidence: your own methods, test regimes, and documentation arguing each Art 8–15 requirement is met — using state-of-the-art references (including ISO/IEC work) as persuasive but non-binding support.

  8. Conformity claimed — no presumption

    Perfectly legal, materially riskier: in any dispute you carry the full burden of proving your approach satisfies the essential requirements.

Key terms: New Legislative Framework, harmonized standard, presumption of conformity, common specifications, essential requirements

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.