JTC 21 and the race the deadline lost

Lesson 2 of 5 in The EU AI Act Interface: Harmonized Standards and the 42001 Playbook.

On 22 May 2023 — more than a year before the AI Act was even adopted — the Commission issued standardisation request C(2023)3215 to CEN and CENELEC, asking for European standards across ten areas mirroring the future Act’s essential requirements: risk management, data governance and quality, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management, and conformity assessment. Deadline: 30 April 2025.

The deadline was missed — comprehensively. Drafting AI standards proved harder than drafting the law they serve: the requests demand testable technical specifications for concepts (fairness, robustness, oversight) that the research community itself has not settled. In June 2025 the Commission amended the request rather than abandon the architecture. The body doing the work, CEN-CLC/JTC 21, musters several hundred experts across working groups, operating under an ‘international first’ policy: where a suitable ISO/IEC standard exists, adopt or adapt it as an EN (the EN ISO/IEC 5259 data-quality series came in this way); where none fits the Act’s specific legal demands, draft a home-grown EN.

The furthest-advanced home-grown deliverable is the one to know by name: prEN 18286, the AI quality management system standard written for Article 17 of the Act. It entered public enquiry on 30 October 2025 — the stage where national committees and the public comment on a full draft. Behind it, the trustworthiness framework, AI risk management, and conformity-assessment ENs remain in drafting.

The ten standardisation-request areas — status as of September 2026 (verify before relying; a single OJEU citation changes this board)
Requested areaAI Act anchorApproachStatus (Sept 2026)

Quality management

Art 17

Home-grown EN: prEN 18286 (42001-informed but written to the Act)

Public enquiry since 30 Oct 2025 — the furthest-advanced deliverable; not yet adopted, not cited

Risk management

Art 9

Home-grown EN (ISO/IEC 23894 informs but does not satisfy — the Act’s risk lens is health, safety, fundamental rights)

Drafting

Data governance & quality

Art 10

International first: EN ISO/IEC 5259 series (parts on data quality for analytics and ML) adopted as ENs; Act-specific supplements in work

Adopted ENs exist; Act-specific coverage still in drafting; nothing cited

Record keeping

Art 12

EN deliverable in the logging/traceability cluster

Drafting

Transparency

Art 13

EN deliverable on instructions for use and information to deployers

Drafting

Human oversight

Art 14

EN deliverable; no settled international equivalent to adopt

Drafting

Accuracy

Art 15

EN deliverable; ISO/IEC TS 4213 (classification performance) informs metrics

Drafting

Robustness

Art 15

EN deliverable; ISO/IEC 24029 series (neural-network robustness) informs

Drafting

Cybersecurity

Art 15

EN deliverable; leverages existing security standards plus AI-specific attack coverage (poisoning, evasion, extraction)

Drafting

Conformity assessment

Art 43

EN deliverable for assessment methodology

Drafting

Why does Europe not simply harmonise ISO/IEC 42001 and declare victory? Because of a mismatch you can now name precisely. 42001 is an organisation-level management-system standard: it disciplines how a company governs its AI portfolio — policies, risk process, roles, audits. The Act’s essential requirements are product-level: this particular high-risk system must have adequate accuracy, logging, oversight interfaces, data governance. An excellently governed organisation can still ship a non-conforming system, so an MSS certificate cannot carry a product presumption. The Commission and CEN assessed exactly this and concluded 42001 alone was insufficient — hence prEN 18286, which takes the management-system form but binds it to the Act’s Article 17 QMS duty and its product-level context.

The practical reading for 2026: 42001 is the scaffold, not the certificate of occupancy. Everything you built in the previous modules — the AIMS, the impact assessments, the Annex A controls — is the organisational machine that will produce Art 8–15 conformity evidence. It just is not, by itself, that evidence.

The legal clock vs the standards clock

  • 2021-04-21European Commission proposes the AI Act:

    The first comprehensive horizontal AI law: product-safety architecture, risk tiers, prohibited practices. Three years of negotiation begin.

  • 2023-05-22Commission issues the AI Act standardisation request:

    CEN/CENELEC JTC 21 is formally tasked with the harmonized standards for Arts 9–15 — the technical clock that must beat the legal clock.

  • 2023-12-08AI Act trilogue deal:

    After a 36-hour final negotiation — GPAI rules and biometric carve-outs the sticking points — Parliament, Council, and Commission agree the text.

  • 2024-08-01EU AI Act enters into force:

    Regulation (EU) 2024/1689 begins its phased application: prohibitions Feb 2025, GPAI Aug 2025, general application Aug 2026, high-risk tiers thereafter.

  • 2025-02-02AI Act prohibitions + AI literacy apply:

    The eight Art 5 bans (social scoring, workplace emotion recognition, untargeted face scraping…) become enforceable, alongside the Art 4 AI-literacy duty.

  • 2025-07-10EU GPAI Code of Practice published:

    Three chapters — transparency, copyright, safety & security — the practical compliance route for general-purpose model providers ahead of the August deadline.

  • 2025-08-02AI Act GPAI rules, governance, and penalties apply:

    Model-provider duties (Art 53), systemic-risk obligations (Art 55), the AI Office’s supervisory powers, and the penalty regime all go live.

  • 2025-11-19Digital Omnibus proposes AI Act simplification:

    The Commission’s package defers high-risk application dates — Annex III to 2 Dec 2027, Annex I to 2 Aug 2028 — among wider changes. Final adopted details: check current status.

  • 2026-08-02AI Act general application:

    The Act’s main body applies — transparency duties, governance structures, sandboxes operational in every Member State. High-risk tiers follow on the deferred schedule.

  • 2026-12-02Synthetic-content marking compliance deadline:

    Art 50(2) machine-readable marking and detectability duties for AI-generated content become enforceable (per the Omnibus schedule).

  • 2027-12-02High-risk rules apply — Annex III systems:

    The full Arts 8–15 + conformity-assessment stack becomes enforceable for use-case-based high-risk AI (hiring, credit, education, policing…). Deferred from Aug 2026 by the Omnibus.

  • 2027-08-02Legacy GPAI models must comply:

    Models placed on the market before August 2025 reach their compliance deadline for the Art 53/55 duties.

  • 2028-08-02High-risk rules apply — Annex I products:

    AI embedded in regulated products (machinery, medical devices, vehicles…) reaches full AI Act enforceability, aligned with sectoral conformity regimes.

Key terms: JTC 21, standardisation request, prEN 18286, international-first (standards policy), public enquiry

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.