European product regulation runs on a mechanism that keeps the whole system oiled: harmonised standards. These are technical standards drawn up by the European standardisation bodies at the Commission's request and which, once cited in the Official Journal of the EU, grant a presumption of conformity: whoever meets them is presumed to meet the legal requirements they cover. It's the bridge between legal text and engineering. The AI Act has that mechanism built into Article 40. And as of today, that bridge still doesn't exist.
Where the standards stand
The work has been under way for some time. The joint technical committee CEN-CENELEC JTC 21 is developing the family of standards that will support the AI Act's high-risk requirements: quality management systems, risk management, accuracy, robustness, and more. The first in the series to move forward — the draft standard on quality management systems, prEN 18286 — went through public enquiry between late 2025 and January 2026. Others are following at different stages of development.
But drafting the standard is only the first half of the journey. The second is the European Commission deciding to cite it in the Official Journal, which is the act that triggers the presumption of conformity. That step comes later, is discretionary, and today is still absent: no harmonised standard in support of Regulation (EU) 2024/1689 has been cited in the Official Journal.
What that gap means in practice
The absence of cited harmonised standards has three practical consequences worth spelling out.
First: no route to a presumption of conformity with the AI Act exists today. No product, no system, no provider can rely on one, because the mechanism that creates it hasn't been activated. Meeting a draft standard, or a related international standard, can be a valuable good practice — but it doesn't grant the legal presumption.
Second: be sceptical of certain marketing claims. If a provider tells you their system is "conformant with the AI Act's harmonised standards", they're selling you something that technically can't exist yet. What a provider can honestly say today is that they work in line with the drafts under development or with international standards such as ISO/IEC 42001 — which are good practices, not legal presumptions. The difference isn't a nuance: it's the difference between a legal fact and an aspiration.
Third: this delay explains part of why high risk was postponed. The Digital Omnibus pushed back the high-risk obligations precisely because the infrastructure that makes them operable — harmonised standards included — hadn't arrived in time. The two are the same story told from two angles.
And in the meantime, what should a company do?
For the deployer of a high-risk system — or for whoever will be one once the calendar catches up — the absence of standards isn't an excuse to do nothing. It's an argument for doing what doesn't depend on them:
- Provider due diligence with concrete questions: which framework they follow, what state their assessments are in, what technical documentation they can show. A serious provider answers with precision; one who answers with grand labels gives themselves away.
- Your own evidence of use: system classification, human oversight, records. None of that waits on harmonised standards.
- Tracking the milestone: the publication of the first standards cited in the Official Journal will be one of the most important regulatory moments for high risk — it will change what can be demanded of providers and how conformity is demonstrated. It's exactly the kind of event worth keeping on watch, not discovering months late.
At Alethexis we track that milestone as part of the ongoing regulatory monitoring that feeds the high-risk module. When the bridge is activated, the difference will be made — once again — by whoever arrives with their part of the work already documented.
This article is for informational purposes only and does not constitute legal advice.