The Regulation sets requirements in general terms: an “appropriate” risk management system, “relevant” data, effective human oversight. It does not say how to meet them. That is what standards are for, and it is where the real operational question sits: what counts as proof, and what does not?
As at 24 August 2026, the date of our last check, no harmonised standard reference had been published in the Official Journal of the European Union under Regulation (EU) 2024/1689, on four concordant official sources. The Article 40 presumption of conformity, the one the whole market invokes, is available to nobody.
Why do the standards arrive after the obligations?
The evidence infrastructure is in place before the obligations it serves. It is disorienting, and it explains why the subject feels both urgent and distant.
| What applies | Since / from |
|---|---|
| Notifying authorities and notified bodies, Articles 28 to 39 | 2 August 2025 |
| Standards, common specifications, presumptions, conformity assessment, Articles 40 to 46 | 2 August 2026 |
| The requirements all of this serves (Chapter III, Sections 1 to 3) for Annex III | 2 December 2027 |
| The same requirements, for Annex I | 2 August 2028 |
The postponement of the last two lines is the work of Regulation (EU) 2026/1744. The direct consequence for reading this page: the requirements in Articles 9, 10, 11 or 17 are not yet enforceable. What is in place is the machinery that will allow compliance with them to be demonstrated.
How do you prove compliance with the EU AI Act?
Through conformity assessment, because the shortcuts are closed. Five routes exist on paper, four of which are presumptions — the harmonised standard of Article 40, the common specifications of Article 41, the three specific presumptions of Article 42, and the one for notified bodies; no harmonised standard has its reference published, so the ordinary route is the only one that currently produces anything.
| Route | What it produces | Basis | Actual state |
|---|---|---|---|
| Harmonised standard with its reference published in the OJEU | Presumption of conformity, to the extent the standard covers the requirement | Art. 40 | None |
| Common specifications adopted by implementing act | The same presumption | Art. 41(3) | None identified |
| Specific presumptions: data representativeness, cybersecurity | A presumption targeted on one requirement | Art. 42 | Two are genuinely usable |
| Presumption for notified bodies themselves | Conformity with the requirements applicable to them: this concerns the bodies, not providers | Art. 32 | None: it too requires OJEU-published references |
| Conformity assessment, by internal control or by a third party | Compliance itself, not a presumption | Annexes VI and VII | The ordinary route |
The first four are shortcuts. The last is the road. A presumption lightens the demonstration; it does not replace it, and its absence prevents nobody from complying.
The Article 40 mechanism, its three conditions and the real state of the European standardisation programme have a page of their own: where the presumption of conformity stands.
Which presumptions are actually available today?
Article 42 opens three, and two of them depend on no publication at all.
Data representativeness. A system “trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used” is presumed to comply with Article 10(4). No standard, no certificate: the condition is in the facts.
Cyber resilience. Added by Regulation (EU) 2026/1744: where a high-risk system falls within the scope of Regulation (EU) 2024/2847 and the conditions of its Article 12(1) are met, it “shall be deemed to comply with the cybersecurity requirements set out in Article 15”. No further step.
The third remains theoretical: cybersecurity can also be demonstrated through certification or a statement of conformity under Regulation (EU) 2019/881, but only where the references of the scheme have been published in the Official Journal.
What proves nothing, despite appearances?
An ISO 42001 certificate, a non-harmonised European standard, a voluntary audit, a market label. None of them opens the Article 40 presumption, which requires a reference published in the Official Journal. This is the useful part of the page, and it runs against most of what the compliance market says.
An ISO/IEC 42001 certificate. It is the sector’s most heavily promoted credential, and it carries two disqualifications. The subject has its own page: what the certificate proves, and what it does not.
A published European standard whose reference is not in the Official Journal. EN 18286:2026, the first standard out of the CEN-CENELEC AI Act programme, has been published since July 2026 and opens no presumption.
A private technical standard. C2PA, Content Credentials and the rest are carried by industry consortia. The Regulation names none of them, and neither does the European code of practice, checked word by word across its thirty-eight pages.
A code of conduct under Article 95. Voluntary, no presumption, no adequacy procedure, no register. Not to be confused with the codes of practice in Articles 56 and 50(7), nor with the guidelines of Article 96.
A voluntary audit. It is worth what its framework and its author are worth. No legal effect of its own.
How does conformity assessment work?
For points 2 to 8 of Annex III (that is, the vast majority of use cases) the procedure is that of Annex VI, internal control, with no notified body. It is the most counter-intuitive point in the scheme, and it is reassuring.
Point 1 of Annex III, biometrics, is the exception, and the absence of standards hardens it. The Regulation in principle leaves a choice there between internal control and third-party assessment, but conditional on having applied harmonised standards or common specifications. Since none exist, the condition is met by nobody: assessment by a notified body is therefore imposed in fact. The choice the text offers is closed by the state of standardisation, not by its wording.
And that is where the real bottleneck appears.
As at 24 August 2026, the date of our last check, no French notified body could be identified under the Regulation.
The absence could not be established with certainty: the public database of Article 35 is the only verification instrument provided for, and it is the one that could not be read.
The European reference database has been absorbed into a platform that does not allow the list to be established: one cannot assert either that French notified bodies exist or that they do not. Any offer promising to have a system assessed by a notified body should be questioned on that point.
One relief valve exists: Article 46 allows a market surveillance authority to authorise, exceptionally, temporarily and for its own territory only, placing on the market before the assessment is complete. It does not apply to systems related to products in Annex I, Section A, which fall under their own sectoral derogations.
What to take from it
The absence of harmonised standards suspends nothing and excuses nothing. It changes the cost of the demonstration: without a presumption, your documentation will carry the burden on the day the requirements become applicable.
And that day is not far off. December 2027 for Annex III is the time it takes to build technical documentation, a quality management system and data governance, projects counted in quarters, not weeks.
Those waiting “for the standards to come out” are waiting for relief, not for an obligation.
What this section rests on
Articles 28 to 42 and 46 of Regulation (EU) 2024/1689 in the consolidated version of 27 July 2026, as amended by Regulation (EU) 2026/1744, the authentic text remaining the one published in the Official Journal. The conformity assessment procedures in Annexes VI and VII. The choice between internal control and third-party assessment rests on Article 43, whose text we have not reproduced word for word: the description here is a reading, and we say so rather than presenting it as a quotation. The state of harmonised standardisation is established on four official sources checked on 24 August 2026. It is a dated statement, rechecked at each update.
Sources. Regulation (EU) 2024/1689, consolidated text of 27 July 2026 and Regulation (EU) 2026/1744, both consulted on 27 August 2026. The Commission’s page on the code of practice on transparency of AI-generated content, consulted on the same date.
Frequently asked questions
Are harmonised standards mandatory?
No. They create no obligation: they open a presumption of conformity, which is a reversal of the burden of proof. A provider that does not apply them remains free to demonstrate compliance by other means, at the cost of justifying it, which is more expensive but perfectly lawful.
How many harmonised standards exist for the AI Act today?
None. As at 24 August 2026, the date of our last check, no harmonised standard reference had been published in the Official Journal of the European Union under Regulation (EU) 2024/1689. The Article 40 presumption is therefore available to nobody. European standards do exist, including EN 18286:2026, but a published European standard is not a harmonised standard.
Which presumptions of conformity does the Regulation provide?
Four families. Harmonised standards whose references are published in the Official Journal (Article 40). Common specifications adopted by implementing act (Article 41(3)). Specific presumptions on data representativeness and cybersecurity (Article 42). And a presumption for notified bodies themselves (Article 32). For general-purpose AI model providers, Article 53(4) adds the ability to rely on a code of practice until a harmonised standard is published.
Are the requirements these standards serve already applicable?
Not yet, and that is the paradox of this subject. The conformity assessment articles have applied since 2 August 2025 and 2 August 2026. But the Chapter III requirements they serve were postponed by Regulation (EU) 2026/1744 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. The evidence machinery is in place before the obligations it serves.
This content is a technical and regulatory information resource. It does not constitute legal advice.