Blog Post

The EU AI Act's Missing Standards: What to Do Before They Arrive

August 18, 2026

Table of Contents

Organizations preparing for the EU AI Act keep asking which standard to certify against, and the honest answer is that the ones that will matter are not finished. No harmonized standard has been cited in the Official Journal, and nothing available today confers presumption of conformity with the Act's requirements for high-risk systems.

Waiting is not an option the Act permits either. Article 17 requires a quality management system that specifies which technical standards are applied and, where harmonized standards are unavailable or incomplete, the means used instead. The regulation anticipated this situation and wrote an obligation for it. What follows covers where the standards stand today, why ISO/IEC 42001 is not the answer people assume, and what documenting your alternative means looks like.

Where the Standards Stand Today

A joint technical committee of the European standards bodies, established in 2021 and drawing several hundred experts across more than twenty countries, is producing the standards the Act will rely on. Progress is uneven and the terminology matters.

Published Is Not Cited

Two separate events have to occur. The European standards bodies finalize and publish a standard, then the Commission reviews it and decides whether to cite its reference in the Official Journal. Only the second event creates presumption of conformity, and citation is at the Commission's discretion rather than automatic. A standard can exist, be purchasable, be widely implemented, and confer nothing legally.

Draft Status Confers Nothing

Several deliverables sit at draft stages, with one at formal vote and others out for enquiry as of mid-2026. A draft European standard provides no presumption of conformity under Article 40, which attaches only to cited standards and only for the requirements those standards cover. Aligning to a draft still has value, since it builds the evidence base and shortens the eventual transition, and it is a readiness activity rather than a compliance one.

The Timeline Has Slipped Before

Availability targets have moved, with a Q4 2026 target sitting against an amended standardization request running into early 2027. Standards development typically takes two to four years, the committee is unusually large, and the Commission asked for standardization in areas where no state of the art existed. Delays in harmonized standards are not unprecedented in EU product legislation, and planning that assumes on-time delivery inherits the risk. The high-risk obligations themselves now land in December 2027 following the Digital Omnibus timeline change.

ISO 42001 Is Not the On-Ramp People Assume

The most consequential detail for anyone planning a certification route is that the European committee considered adopting ISO/IEC 42001 as the harmonized quality management standard and declined. It judged the international standard's objectives and definitions misaligned with what the Act requires of a quality management system, and wrote a bespoke European standard instead.

What That Means for a 42001 Program

The European standard builds on ISO/IEC 42001 rather than replacing it wholesale, adding requirements specific to regulatory compliance, high-risk system management and conformity assessment preparation. An organization holding ISO/IEC 42001 certification therefore holds most of the management system machinery and not the Act-specific content, which is a considerably better position than starting cold and a weaker one than conformity. Existing certification remains worth having for procurement, customer assurance and structure, and the case for certifying at all does not change.

The Quality Management System Is the Load-Bearing Piece

The Act treats the quality management system as the mechanism that ties everything else together, since it is where an organization records which standards it applies and what it does where standards fall short. That makes the QMS standard architecturally central rather than one deliverable among many, and it explains why the committee was unwilling to adopt an international standard that did not align precisely.

What Article 17 Requires While You Wait

The obligation is specific and widely overlooked. A provider's quality management system must specify the technical specifications and standards applied and, where harmonized standards are not applied in full or do not cover all the relevant requirements, the means used to ensure the system complies anyway.

Governance dashboard showing compliance readiness progress across the EU AI Act, NIST AI RMF, ISO 42001 and state-level AI regulations alongside an inventory of AI assets
Holding a scored position against several frameworks at once is what allows an organization to state which requirements each one covers and where it relies on something else.

Documenting Alternative Means Is the Deliverable

Reading that requirement as a burden misses what it offers. An organization that records, requirement by requirement, which standard or internal control it relies on and why that satisfies the essential requirement has produced exactly the artifact an assessor asks for. Doing it now turns the eventual arrival of cited standards into a substitution exercise rather than a new project.

Requirement-Level Mapping Beats Framework-Level Claims

A claim of alignment with a framework says nothing about which Act requirements are covered. Mapping at requirement level, so each essential requirement in Chapter III has a named source of assurance, produces something checkable and survives a standard being cited later. Compliance readiness assessed per requirement rather than per framework is the structure that makes the substitution cheap.

Where the Coverage Runs Thin

Some Act requirements have strong international precedent and some have almost none, which determines how much work documenting alternative means involves.

Assessment results identifying the governance control areas with the largest distance between current and target maturity
Naming the control areas furthest from target tells an organization where its alternative means documentation will need to work hardest.

Risk Management and Data Governance Have Precedent

Risk management processes, data governance practices, logging and human oversight all have established treatment in international standards and in NIST AI RMF, so pointing at an existing source of assurance is straightforward. An organization running a mature program can document these quickly because the underlying evidence already exists.

Bias and Robustness Are Where State of the Art Is Thin

Standards work on bias measurement sits at early drafting stages, which reflects the underlying reality that measurement methods are contested rather than settled. Accuracy, robustness and cybersecurity requirements for AI systems face similar difficulty. Documenting alternative means here involves stating a method, justifying it and recording its limitations, which is more demanding than citing a standard and more honest than claiming coverage. Programs already handling structured AI risk assessment have a starting point rather than a blank page.

The Conformity Assessment Infrastructure Is Also Incomplete

Standards are one half of the readiness problem and the assessment ecosystem is the other. Notified bodies require accreditation against standards defining competence for auditing AI management systems, and those standards are themselves in development. Organizations expecting to need third-party conformity assessment should plan for capacity constraints rather than assuming availability.

Most Annex III systems follow an internal control route where the provider assesses its own conformity and documents it, which reduces dependence on notified body capacity considerably. Confirming which route applies to each system is worth doing early, since it changes both the timeline and the documentation burden, and how conformity assessment differs from certification determines who examines the result.

What to Do This Quarter

Four actions are available now and none depends on a standard being cited.

  • Map at Requirement Level: Give each essential requirement a named source of assurance, whether a standard, an internal control or a documented method.
  • Record Alternative Means: Write down why each source satisfies the requirement, which is the Article 17 obligation rather than optional diligence.
  • Track the Drafts: Align to draft standards where they exist, treating it as readiness rather than compliance.

Confirming the conformity assessment route per system completes the set. Organizations doing all four hold a defensible position today and a short substitution exercise when citation arrives, which is the difference between planning and waiting. Institutions in regulated sectors have additional layers to reconcile, and defensibility under sector supervision raises the documentation bar further.

Do Not Claim Presumption You Do Not Have

The most avoidable error is describing a certification or an alignment as conformity in customer materials or investor communications. Presumption of conformity is a specific legal effect attaching to specific standards for specific requirements, and overstating it creates a disclosure exposure separate from any AI risk. Accurate language costs nothing and misstatement is difficult to retract.

Plan for Substitution, Not Arrival

The standards that will carry presumption of conformity under the EU AI Act are unfinished, the international management standard many organizations assumed would serve was explicitly not adopted for that purpose, and the regulation itself requires providers to document what they rely on in the meantime. Requirement-level mapping with named sources of assurance satisfies the obligation that exists today and converts the eventual arrival of cited standards into a swap rather than a fresh program. Kovrr's automated EU AI Act assessment tracks obligations article by article, which is the granularity that substitution requires.

To see which EU AI Act requirements your current controls already cover and where you would need to document alternative means, book a demo mapped to your own AI systems.

Or Amir

Product & Customer Growth Manager

EU AI Act Standards FAQs

Speak to an Expert

Are there harmonized standards for the EU AI Act yet?

Does ISO 42001 certification satisfy the EU AI Act?

What does the AI Act require while standards are unavailable?

Should we align to draft European standards?

Which AI Act requirements are hardest to cover without standards?

Will notified bodies be ready for conformity assessment?