
Blog Post
The EU AI Act's Missing Standards: What to Do Before They Arrive
August 18, 2026
Organizations preparing for the EU AI Act keep asking which standard to certify against, and the honest answer is that the ones that will matter are not finished. No harmonized standard has been cited in the Official Journal, and nothing available today confers presumption of conformity with the Act's requirements for high-risk systems.
Waiting is not an option the Act permits either. Article 17 requires a quality management system that specifies which technical standards are applied and, where harmonized standards are unavailable or incomplete, the means used instead. The regulation anticipated this situation and wrote an obligation for it. What follows covers where the standards stand today, why ISO/IEC 42001 is not the answer people assume, and what documenting your alternative means looks like.
Where the Standards Stand Today
A joint technical committee of the European standards bodies, established in 2021 and drawing several hundred experts across more than twenty countries, is producing the standards the Act will rely on. Progress is uneven and the terminology matters.
Published Is Not Cited
Two separate events have to occur. The European standards bodies finalize and publish a standard, then the Commission reviews it and decides whether to cite its reference in the Official Journal. Only the second event creates presumption of conformity, and citation is at the Commission's discretion rather than automatic. A standard can exist, be purchasable, be widely implemented, and confer nothing legally.
Draft Status Confers Nothing
Several deliverables sit at draft stages, with one at formal vote and others out for enquiry as of mid-2026. A draft European standard provides no presumption of conformity under Article 40, which attaches only to cited standards and only for the requirements those standards cover. Aligning to a draft still has value, since it builds the evidence base and shortens the eventual transition, and it is a readiness activity rather than a compliance one.
The Timeline Has Slipped Before
Availability targets have moved, with a Q4 2026 target sitting against an amended standardization request running into early 2027. Standards development typically takes two to four years, the committee is unusually large, and the Commission asked for standardization in areas where no state of the art existed. Delays in harmonized standards are not unprecedented in EU product legislation, and planning that assumes on-time delivery inherits the risk. The high-risk obligations themselves now land in December 2027 following the Digital Omnibus timeline change.
ISO 42001 Is Not the On-Ramp People Assume
The most consequential detail for anyone planning a certification route is that the European committee considered adopting ISO/IEC 42001 as the harmonized quality management standard and declined. It judged the international standard's objectives and definitions misaligned with what the Act requires of a quality management system, and wrote a bespoke European standard instead.
What That Means for a 42001 Program
The European standard builds on ISO/IEC 42001 rather than replacing it wholesale, adding requirements specific to regulatory compliance, high-risk system management and conformity assessment preparation. An organization holding ISO/IEC 42001 certification therefore holds most of the management system machinery and not the Act-specific content, which is a considerably better position than starting cold and a weaker one than conformity. Existing certification remains worth having for procurement, customer assurance and structure, and the case for certifying at all does not change.
The Quality Management System Is the Load-Bearing Piece
The Act treats the quality management system as the mechanism that ties everything else together, since it is where an organization records which standards it applies and what it does where standards fall short. That makes the QMS standard architecturally central rather than one deliverable among many, and it explains why the committee was unwilling to adopt an international standard that did not align precisely.
What Article 17 Requires While You Wait
The obligation is specific and widely overlooked. A provider's quality management system must specify the technical specifications and standards applied and, where harmonized standards are not applied in full or do not cover all the relevant requirements, the means used to ensure the system complies anyway.

Documenting Alternative Means Is the Deliverable
Reading that requirement as a burden misses what it offers. An organization that records, requirement by requirement, which standard or internal control it relies on and why that satisfies the essential requirement has produced exactly the artifact an assessor asks for. Doing it now turns the eventual arrival of cited standards into a substitution exercise rather than a new project.
Requirement-Level Mapping Beats Framework-Level Claims
A claim of alignment with a framework says nothing about which Act requirements are covered. Mapping at requirement level, so each essential requirement in Chapter III has a named source of assurance, produces something checkable and survives a standard being cited later. Compliance readiness assessed per requirement rather than per framework is the structure that makes the substitution cheap.
Where the Coverage Runs Thin
Some Act requirements have strong international precedent and some have almost none, which determines how much work documenting alternative means involves.

Risk Management and Data Governance Have Precedent
Risk management processes, data governance practices, logging and human oversight all have established treatment in international standards and in NIST AI RMF, so pointing at an existing source of assurance is straightforward. An organization running a mature program can document these quickly because the underlying evidence already exists.
Bias and Robustness Are Where State of the Art Is Thin
Standards work on bias measurement sits at early drafting stages, which reflects the underlying reality that measurement methods are contested rather than settled. Accuracy, robustness and cybersecurity requirements for AI systems face similar difficulty. Documenting alternative means here involves stating a method, justifying it and recording its limitations, which is more demanding than citing a standard and more honest than claiming coverage. Programs already handling structured AI risk assessment have a starting point rather than a blank page.
The Conformity Assessment Infrastructure Is Also Incomplete
Standards are one half of the readiness problem and the assessment ecosystem is the other. Notified bodies require accreditation against standards defining competence for auditing AI management systems, and those standards are themselves in development. Organizations expecting to need third-party conformity assessment should plan for capacity constraints rather than assuming availability.
Most Annex III systems follow an internal control route where the provider assesses its own conformity and documents it, which reduces dependence on notified body capacity considerably. Confirming which route applies to each system is worth doing early, since it changes both the timeline and the documentation burden, and how conformity assessment differs from certification determines who examines the result.
What to Do This Quarter
Four actions are available now and none depends on a standard being cited.
- Map at Requirement Level: Give each essential requirement a named source of assurance, whether a standard, an internal control or a documented method.
- Record Alternative Means: Write down why each source satisfies the requirement, which is the Article 17 obligation rather than optional diligence.
- Track the Drafts: Align to draft standards where they exist, treating it as readiness rather than compliance.
Confirming the conformity assessment route per system completes the set. Organizations doing all four hold a defensible position today and a short substitution exercise when citation arrives, which is the difference between planning and waiting. Institutions in regulated sectors have additional layers to reconcile, and defensibility under sector supervision raises the documentation bar further.
Do Not Claim Presumption You Do Not Have
The most avoidable error is describing a certification or an alignment as conformity in customer materials or investor communications. Presumption of conformity is a specific legal effect attaching to specific standards for specific requirements, and overstating it creates a disclosure exposure separate from any AI risk. Accurate language costs nothing and misstatement is difficult to retract.
Plan for Substitution, Not Arrival
The standards that will carry presumption of conformity under the EU AI Act are unfinished, the international management standard many organizations assumed would serve was explicitly not adopted for that purpose, and the regulation itself requires providers to document what they rely on in the meantime. Requirement-level mapping with named sources of assurance satisfies the obligation that exists today and converts the eventual arrival of cited standards into a swap rather than a fresh program. Kovrr's automated EU AI Act assessment tracks obligations article by article, which is the granularity that substitution requires.
To see which EU AI Act requirements your current controls already cover and where you would need to document alternative means, book a demo mapped to your own AI systems.
EU AI Act Standards FAQs
Speak to an ExpertAre there harmonized standards for the EU AI Act yet?
No standard has been cited in the Official Journal of the European Union, which is the event that creates presumption of conformity. The European standards bodies have deliverables at various stages, with one at formal vote and several out for enquiry as of mid-2026, against an availability target in late 2026 and an amended standardization request running into early 2027. Publication by the standards bodies and citation by the Commission are separate events, and citation is discretionary rather than automatic. Until citation occurs, nothing available confers presumption of conformity for high-risk system requirements.
Does ISO 42001 certification satisfy the EU AI Act?
No, and the reason is more specific than most summaries suggest. The European committee developing harmonized standards considered adopting ISO/IEC 42001 as the quality management standard and declined, judging its objectives and definitions misaligned with what the Act requires, so it wrote a bespoke European standard that builds on 42001 while adding regulatory compliance, high-risk system management and conformity assessment content. An organization certified against 42001 holds most of the management system machinery without the Act-specific requirements, which is a stronger position than starting cold and weaker than conformity.
What does the AI Act require while standards are unavailable?
Article 17 requires a provider's quality management system to specify the technical specifications and standards applied and, where harmonized standards are not applied in full or do not cover all relevant requirements, the means used to ensure the system complies regardless. The regulation therefore anticipated this situation and created an obligation for it, so waiting is not a compliant posture. Recording requirement by requirement which standard or internal control provides assurance, and why it satisfies the essential requirement, produces both the Article 17 artifact and the material an assessor will ask for.
Should we align to draft European standards?
Yes as a readiness activity, and it should not be described as compliance. A draft European standard carries no presumption of conformity, since presumption attaches only to standards whose references appear in the Official Journal and only for the requirements those standards cover. Aligning to a draft builds the evidence base and shortens the eventual transition, which turns citation into a substitution exercise rather than a new project. Standards content also changes between draft stages, so recording which draft version you aligned to matters.
Which AI Act requirements are hardest to cover without standards?
Risk management, data governance, logging and human oversight all have established treatment in international standards and in frameworks like NIST AI RMF, so pointing at an existing source of assurance is straightforward. Bias measurement is considerably harder, with standards work at early drafting stages because measurement methods remain contested rather than settled, and accuracy and robustness requirements face similar difficulty. Documenting alternative means for those involves stating a method, justifying it and recording its limitations, which the underlying data requirements make concrete.
Will notified bodies be ready for conformity assessment?
Capacity is a live concern, because notified bodies need accreditation against standards defining competence for auditing AI management systems and those standards are themselves in development. Organizations expecting to require third-party assessment should plan for constrained availability rather than assuming it. Most Annex III systems follow an internal control route where the provider assesses and documents its own conformity, which reduces that dependence substantially, so confirming which route applies to each system early changes both the timeline and the documentation burden.




