JTC 21 and the race the deadline lost
Lesson 2 of 5 in The EU AI Act Interface: Harmonized Standards and the 42001 Playbook.
On 22 May 2023 — more than a year before the AI Act was even adopted — the Commission issued standardisation request C(2023)3215 to CEN and CENELEC, asking for European standards across ten areas mirroring the future Act’s essential requirements: risk management, data governance and quality, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management, and conformity assessment. Deadline: 30 April 2025.
The deadline was missed — comprehensively. Drafting AI standards proved harder than drafting the law they serve: the requests demand testable technical specifications for concepts (fairness, robustness, oversight) that the research community itself has not settled. In June 2025 the Commission amended the request rather than abandon the architecture. The body doing the work, CEN-CLC/JTC 21, musters several hundred experts across working groups, operating under an ‘international first’ policy: where a suitable ISO/IEC standard exists, adopt or adapt it as an EN (the EN ISO/IEC 5259 data-quality series came in this way); where none fits the Act’s specific legal demands, draft a home-grown EN.
The furthest-advanced home-grown deliverable is the one to know by name: prEN 18286, the AI quality management system standard written for Article 17 of the Act. It entered public enquiry on 30 October 2025 — the stage where national committees and the public comment on a full draft. Behind it, the trustworthiness framework, AI risk management, and conformity-assessment ENs remain in drafting.
| Requested area | AI Act anchor | Approach | Status (Sept 2026) |
|---|---|---|---|
Quality management | Art 17 | Home-grown EN: prEN 18286 (42001-informed but written to the Act) | Public enquiry since 30 Oct 2025 — the furthest-advanced deliverable; not yet adopted, not cited |
Risk management | Art 9 | Home-grown EN (ISO/IEC 23894 informs but does not satisfy — the Act’s risk lens is health, safety, fundamental rights) | Drafting |
Data governance & quality | Art 10 | International first: EN ISO/IEC 5259 series (parts on data quality for analytics and ML) adopted as ENs; Act-specific supplements in work | Adopted ENs exist; Act-specific coverage still in drafting; nothing cited |
Record keeping | Art 12 | EN deliverable in the logging/traceability cluster | Drafting |
Transparency | Art 13 | EN deliverable on instructions for use and information to deployers | Drafting |
Human oversight | Art 14 | EN deliverable; no settled international equivalent to adopt | Drafting |
Accuracy | Art 15 | EN deliverable; ISO/IEC TS 4213 (classification performance) informs metrics | Drafting |
Robustness | Art 15 | EN deliverable; ISO/IEC 24029 series (neural-network robustness) informs | Drafting |
Cybersecurity | Art 15 | EN deliverable; leverages existing security standards plus AI-specific attack coverage (poisoning, evasion, extraction) | Drafting |
Conformity assessment | Art 43 | EN deliverable for assessment methodology | Drafting |
Why does Europe not simply harmonise ISO/IEC 42001 and declare victory? Because of a mismatch you can now name precisely. 42001 is an organisation-level management-system standard: it disciplines how a company governs its AI portfolio — policies, risk process, roles, audits. The Act’s essential requirements are product-level: this particular high-risk system must have adequate accuracy, logging, oversight interfaces, data governance. An excellently governed organisation can still ship a non-conforming system, so an MSS certificate cannot carry a product presumption. The Commission and CEN assessed exactly this and concluded 42001 alone was insufficient — hence prEN 18286, which takes the management-system form but binds it to the Act’s Article 17 QMS duty and its product-level context.
The practical reading for 2026: 42001 is the scaffold, not the certificate of occupancy. Everything you built in the previous modules — the AIMS, the impact assessments, the Annex A controls — is the organisational machine that will produce Art 8–15 conformity evidence. It just is not, by itself, that evidence.
The legal clock vs the standards clock
- 2021-04-21 — European Commission proposes the AI Act:
The first comprehensive horizontal AI law: product-safety architecture, risk tiers, prohibited practices. Three years of negotiation begin.
- 2023-05-22 — Commission issues the AI Act standardisation request:
CEN/CENELEC JTC 21 is formally tasked with the harmonized standards for Arts 9–15 — the technical clock that must beat the legal clock.
- 2023-12-08 — AI Act trilogue deal:
After a 36-hour final negotiation — GPAI rules and biometric carve-outs the sticking points — Parliament, Council, and Commission agree the text.
- 2024-08-01 — EU AI Act enters into force:
Regulation (EU) 2024/1689 begins its phased application: prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026, high-risk tiers thereafter.
- 2025-02-02 — AI Act prohibitions + AI literacy apply:
The eight Art 5 bans (social scoring, workplace emotion recognition, untargeted face scraping…) become enforceable, alongside the Art 4 AI-literacy duty.
- 2025-07-10 — EU GPAI Code of Practice published:
Three chapters — transparency, copyright, safety & security — the practical compliance route for general-purpose model providers ahead of the August deadline.
- 2025-08-02 — AI Act GPAI rules, governance, and penalties apply:
Model-provider duties (Art 53), systemic-risk obligations (Art 55), the AI Office’s supervisory powers, and the penalty regime all go live.
- 2025-11-19 — Digital Omnibus proposes AI Act simplification:
The Commission’s package defers high-risk application dates — Annex III to 2 Dec 2027, Annex I to 2 Aug 2028 — among wider changes. Final adopted details: check current status.
- 2026-08-02 — AI Act general application:
The Act’s main body applies — transparency duties, governance structures, sandboxes operational in every Member State. High-risk tiers follow on the deferred schedule.
- 2026-12-02 — Synthetic-content marking compliance deadline:
Art 50(2) machine-readable marking and detectability duties for AI-generated content become enforceable (per the Omnibus schedule).
- 2027-12-02 — High-risk rules apply — Annex III systems:
The full Arts 8–15 + conformity-assessment stack becomes enforceable for use-case-based high-risk AI (hiring, credit, education, policing…). Deferred from Aug 2026 by the Omnibus.
- 2027-08-02 — Legacy GPAI models must comply:
Models placed on the market before August 2025 reach their compliance deadline for the Art 53/55 duties.
- 2028-08-02 — High-risk rules apply — Annex I products:
AI embedded in regulated products (machinery, medical devices, vehicles…) reaches full AI Act enforceability, aligned with sectoral conformity regimes.
Key terms: JTC 21, standardisation request, prEN 18286, international-first (standards policy), public enquiry
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.