By Rafael Luque Ocaña

EN 18286:2026 exists. The first European standard for the AI Act gives you no presumption of conformity — and it is not yours

CEN-CENELEC has published EN 18286:2026, on the provider's quality management system. Without an Official Journal citation it does not trigger Article 40.

This article is for anyone who deploys a high-risk AI system, or is going to, and has read that a European standard now exists that serves to show an authority that the system meets the AI Act. The standard exists: CEN-CENELEC announced in July 2026 that EN 18286:2026 "has been published". What needs clearing up is what that standard does for you. The short answer: for now, nothing with legal effect; and once it has some, it will still not be yours.

Getting there means separating three layers that usually arrive mixed up: who publishes the standard, what turns it into something the Regulation recognises, and who it is addressed to.

Who owes what: provider and deployerRegulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744Obligationand the articles it rests onProviderArt.3(3)DeployerArt.3(4)Technical requirements ofthe systemArts.9, 10, 13 and 15 · viaArt.16(a)Obligationrisk management, data,instructions for use,accuracy and cybersecurityTechnical documentation,QMS, conformityArts.11, 17, 18 and 43 · AnnexIVObligationdraw it up, keep it and putthe system through conformityassessmentRegistration in the EUdatabaseArt.49 · Annex III, exceptpoint 2Obligationregister itself and thesystem before placing on themarket or into serviceObligationonly public authorities andEU bodies, or persons actingon their behalfAutomatically generatedlogsArts.12, 19 and 26(6)Obligationdesign the system to generatethem; keep those under itscontrolObligationkeep those under its controlHuman oversightArts.14 and 26(2)Obligationdesign the system so it canbe effectively overseenObligationassign it to people with thecompetence, training andauthority, and supportUse per instructions; inputdataArt.26(1) and (4)Obligationinput data: to the extent itexercises control over itMonitoring the system inoperationArts.72 and 26(5)Obligationpost-market monitoring system(Art.72)Obligationmonitor per the instructions,inform the provider; if atrisk, suspend useSerious incidentsArts.73 and 26(5)Obligationreport them to the marketsurveillance authority(Art.73)Obligationprovider → importer ordistributor → authorities; nocontact, 73 mutatis mutandisInforming workers andaffected personsArt.26(7) and (11)Obligationworkers, if an employer;affected persons, if itdecides on them (Annex III)Fundamental rights impact(FRIA)Art.27Obligationpublic-law bodies or publicservices (except III.2) andAnnex III, 5(b) and (c)Transparency of certain AIsystemsArt.50Obligation50(1) interaction notice50(2) marking · with itsexceptionsObligation50(3) emotion recognition,biometric categorisation ·50(4) deep fakes, textAI literacyArt.4Obligationtake measures; no specificlevel of AI literacy of anyindividualObligationtake measures; no specificlevel of AI literacy of anyindividualAI Officerno article · a method roleInternal controlno direct legal basisInternal controlno direct legal basisObligation: the article imposes it on that roleInternal control: no direct legal basis—: not an obligation of that roleRegulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 · who owes each duty, not from when
Obligations by role, not by date: when each one applies is on the calendar. The high-risk rows only reach high-risk systems. The FRIA applies to bodies governed by public law and private entities providing public services — except Annex III, point 2 — and to deployers of Annex III, point 5(b) and (c) systems. The paragraphs of Article 50 carry exceptions, among them text that has undergone human review or editorial control.

The figure divides the AI Act's obligations between the provider and the deployer, one per row, with the articles they rest on. The highlighted row is technical documentation, the quality management system and conformity (Articles 11, 17, 18 and 43 and Annex IV): the provider's column says draw that documentation up, keep it and put the system through conformity assessment; the deployer's column is empty. EN 18286 belongs in that row.

First layer: a published European standard

European standards are drawn up and published by the European standardisation organisations; CEN and CENELEC are two of them. EN 18286:2026 is titled Artificial intelligence – Quality management system for EU AI Act regulatory purposes, and the note in which CEN-CENELEC announced its publication presents it as the first standard in support of the implementation of the AI Act.

Until recently it circulated as a draft, prEN 18286, and that is how we described it when we explained why the presumption of conformity still doesn't exist. It is now a European standard, with one caveat that takes up the second layer.

According to the same note, the standard specifies the requirements and gives guidance for defining, implementing and maintaining a quality management system "for organizations that provide AI systems". It is worth holding on to that subject, because it is the subject of the third layer.

Publishing a standard has technical effect from that day: anyone can acquire it, read it and apply it. What publication does not give it, on its own, is the effect the AI Act reserves for something else.

Second layer: no Official Journal citation, no presumption

Article 40(1) grants the presumption of conformity to high-risk AI systems — and to general-purpose AI models — that are in conformity with harmonised standards, or parts of them, "the references of which have been published in the Official Journal of the European Union". The presumption does not arise because the standard exists, nor because of its quality, nor because it was drawn up to support the Regulation. It arises from one specific, later fact: its reference appearing in the Official Journal.

In the case of EN 18286:2026, that fact had not occurred at the last check before this article was written, on 8 September 2026. Until it does, applying the standard does not trigger the Article 40 presumption for anyone: not for the provider that applies it, and still less for whoever buys from that provider.

And when it does occur, the presumption will come with the limit set by the same paragraph: it applies "to the extent that those standards cover those requirements or obligations". It is not a general seal on the system, but a presumption confined to what the standard covers.

And there is one point the Regulation does not settle. The standard was drawn up under the standardisation request for the quality management system of Article 17, which sits in Section 3 of Chapter III. The wording of Article 40(1) ties the presumption to conformity "with the requirements set out in Section 2 of this Chapter" — or, for general-purpose AI models, with the obligations of Chapter V — and how it operates on an obligation in Section 3 is not written in the Regulation.

That is why any message presenting EN 18286 as the route to showing an authority that a system meets the Regulation deserves a careful reading. Some presentations already call it a "harmonised standard". In the language of the AI Act that word carries a legal effect, and that effect depends on citation in the Official Journal, not on publication by CEN-CENELEC. It is not a question of vocabulary: it is the difference between a technical fact and a legal one.

Third layer: the standard belongs to the provider

The subject of the standard is the same as that of the article it develops. Article 17 opens like this: "Providers of high-risk AI systems shall put a quality management system in place". And among what that system must include, it lists "technical specifications, including standards, to be applied". A standard on quality management systems is therefore a tool for organising an obligation of the provider.

Paragraph 2, as worded by Regulation (EU) 2026/1744, adds a proportionality that matters to many of the companies reading this: the implementation of those aspects "shall be proportionate to the size of the provider’s organisation, in particular, if the provider is an SME, including a start-up, or an SMC". The proportionality belongs to the provider too.

If your company deploys a system someone else has developed, Article 17 does not ask you to set up a quality management system, and we have already explained why trying would make no sense: its content is product design, development and validation, decisions you did not take. EN 18286 inherits that condition. Implementing it on your own does not bring you closer to any obligation of yours.

The same goes for the technical documentation, which we cover in two separate articles: Annex IV as the index of someone else's document and who keeps that documentation.

What you can do with it as a deployer

The standard not being yours does not make it useless to you. For a deployer it is a reference for good practice: a public, orderly description of what a serious provider should have in its quality management system. That makes it a source of questions.

  • Ask whether the provider's quality management system draws on EN 18286, and which parts it covers. The answer need not be a yes or a no: Article 17 itself provides that, where the relevant harmonised standards are not applied in full or do not cover all the requirements, the system sets out the other means by which they are covered.
  • Ask in writing for what they can show you, alongside the other questions an AI provider should be able to answer.
  • Record the answer and its date. If the reference is ever published in the Official Journal, you will know which providers were already applying the standard, and since when.
  • Do not turn it into a task of your own. If your to-do list includes "implement EN 18286", check where that item came from.

And if the reference is published, your position will not change: you will still have no obligation to apply the standard, and what falls to you as a deployer will still depend on Article 26, not on the standard.

The difference between what the law requires and what is good practice is the one we explain in how we classify each obligation. And what is yours as a deployer — the assessments and the evidence of use — is what the high-risk module organises.

This article is for informational purposes only and does not constitute legal advice.

Frequently asked questions

Can I require EN 18286 from my provider?

You can ask for it in the contract: it is a purchasing decision, not a duty the AI Act places on you. What the Regulation asks of the provider of a high-risk system is a quality management system (Article 17), and the standard is one way of organising it. Until its reference is published in the Official Journal of the European Union, the provider applying it does not trigger the presumption of conformity in Article 40.

When will it have legal effect?

The presumption of conformity in Article 40 requires the reference of the standard to be published in the Official Journal of the European Union, and it applies only to the extent that the standard covers the requirements concerned. Publication by CEN-CENELEC is not enough. At the last check, on 8 September 2026, the reference of EN 18286:2026 did not appear in the Official Journal.

Is there an equivalent standard for deployers?

Not as an obligation. EN 18286 is addressed to organisations that provide AI systems, and the Article 17 quality management system belongs to the provider. For a deployer, the standard is a useful technical reference for knowing what to ask; a deployer's obligations run through Article 26.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (NIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es) or with the supervisory authority of your Member State (Article 77 GDPR). More information in the privacy policy.