Why standards exist — and who writes them
Lesson 1 of 5 in The AI Standards Landscape and Core Terminology (ISO/IEC 22989).
A law can tell you what you must achieve. It almost never tells you how. The EU AI Act demands that high-risk AI systems have "appropriate" risk management, "relevant" data governance, and "effective" human oversight — and then stops. Somebody has to translate those adjectives into checkable engineering and process detail. That somebody is the standards world.
A voluntary consensus standard is a documented agreement — produced by committees of industry, academic, and government experts through formal balloting — on how to do something well. It is not law. Nobody is fined for ignoring ISO/IEC 42001. But standards acquire teeth in three ways, and you will meet all three in this domain:
- Contracts point at them. A procurement clause saying "supplier shall maintain certification to ISO/IEC 42001" turns a voluntary document into a binding commercial obligation.
- Regulators point at them. Under the EU’s New Legislative Framework, a harmonised standard cited in the Official Journal grants presumption of conformity — follow the standard and you are presumed to meet the corresponding legal requirement. The law stays technology-neutral; the standard carries the technical detail.
- Courts and auditors point at them. "What would a reasonable organisation have done?" is increasingly answered by pointing at the published state of the art — which is what standards codify.
Who actually writes AI standards? The centre of gravity is a committee most people have never heard of: ISO/IEC JTC 1/SC 42.
Unpack the acronym from the outside in. ISO (the International Organization for Standardization, Geneva, founded 1947) and the IEC (International Electrotechnical Commission) jointly run JTC 1, their Joint Technical Committee for information technology, created in 1987. In 2017 JTC 1 established Subcommittee 42 — Artificial Intelligence, with its secretariat held by ANSI (the US member body). SC 42 held its first plenary in Beijing in April 2018 and now counts more than sixty participating and observing national bodies.
SC 42 organises its output through working groups, and knowing them helps you predict where any AI standard came from:
- WG 1 — Foundational standards: terminology (22989), the ML framework (23053), and the management system standard (42001).
- WG 2 — Data: the ISO/IEC 5259 data-quality series and big-data work.
- WG 3 — Trustworthiness: risk management (23894), trustworthiness (TR 24028), bias (TR 24027), robustness (24029 series).
- WG 4 — Use cases and applications: sector use-case catalogues.
- WG 5 — Computational approaches and characteristics: the mathematics under the hood.
SC 42 also works jointly with its siblings: with SC 27 (information security and privacy) on AI security, and with SC 40 (IT governance), which led ISO/IEC 38507 on board-level governance of AI. One committee family, one shared vocabulary — that is why the ecosystem interlocks so cleanly.
CEN/CENELEC JTC 21
Europe’s standards bodies CEN and CENELEC created JTC 21 (Artificial Intelligence) in 2021 as the committee that answers the European Commission’s standardisation requests for the AI Act. It gathers 300+ experts and follows an international-first policy: where a suitable ISO/IEC standard exists, adopt it as a European Norm (EN) — the EN ISO/IEC 5259 data-quality series is an example — and draft home-grown ENs only where the Act needs something ISO never wrote. JTC 21 is the bridge between the voluntary ISO world and binding EU law: only standards it delivers, once cited in the Official Journal, grant presumption of conformity.
NIST
The US National Institute of Standards and Technology is not a standards body in the ISO sense — it is a government agency that publishes voluntary frameworks. Its AI Risk Management Framework (AI RMF 1.0, January 2023) is the most influential: four functions (Govern, Map, Measure, Manage), no certification, no ballot, free to download. Where ISO/IEC 42001 gives you a certifiable management system, the AI RMF gives you a risk-thinking vocabulary. Many organisations run both: RMF for the thinking, 42001 for the auditable proof.
IEEE and ITU
The IEEE — an engineering professional body — writes standards through a different consensus process: its 7000 series tackles ethics-driven design (IEEE 7000 on value-based engineering, 7001 on transparency of autonomous systems), and its CertifAIEd programme offers ethics-focused assessments. The ITU, a UN agency, convenes focus groups (notably AI for Good) and standardises AI in telecommunications. Neither can grant EU presumption of conformity, but both feed ideas into the ISO/IEC pipeline — and into procurement checklists.
Key terms: voluntary consensus standard, harmonized standard, presumption of conformity, SC 42, JTC 1
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.