WHAT THE ARTICLE IS ABOUT
The technical standards that translate legal requirements into practical compliance
Article 40 establishes the role of harmonised standards in demonstrating compliance with the EU AI Act. Where harmonised standards covering the Act’s requirements are published in the Official Journal of the EU, providers of high-risk AI systems that comply with those standards are presumed to meet the corresponding legal requirements — without needing to prove compliance separately through other means. This is the most practical compliance pathway for most providers.
WHAT IT SAYS
Published standards create a presumption of conformity
- High-risk AI systems that comply with harmonised standards published in the Official Journal are presumed to meet the requirements of Section 2 of Chapter III — the full technical requirements block covering Articles 9 to 15
- The same presumption applies to general-purpose AI models that comply with harmonised standards covering the relevant obligations in Chapter V
- The Commission must issue standardisation requests to European standardisation organisations — CEN, CENELEC, and ETSI — covering all relevant requirements without undue delay
- These standardisation requests must ensure that standards are clear, consistent with standards in related sectors, and support innovation and competitiveness
- The Commission must also request that standards are consistent with the existing EU harmonisation legislation listed in Annex I — ensuring no conflicts with medical devices, machinery, and other existing regulated product standards
- References to harmonised standards are published in the Official Journal of the EU — only standards with published references carry the presumption of conformity
WHO IS AFFECTED
All providers of high-risk AI systems and GPAI model providers
- Providers of high-risk AI systems — harmonised standards are their primary practical compliance pathway
- General-purpose AI model providers — standards will also cover relevant GPAI obligations
- European standardisation organisations CEN, CENELEC, and ETSI developing the standards
- Notified bodies who use harmonised standards as the benchmark for conformity assessments
- The European Commission issuing standardisation requests and publishing references
WHAT IT MEANS FOR SMES
Wait for the standards — then use them as your compliance roadmap
- Harmonised standards are the single most important practical development to monitor if you are building high-risk AI — they will translate the Act’s abstract requirements into specific, measurable technical criteria
- As of the Act’s application dates, relevant harmonised standards are still being developed — CEN-CENELEC Joint Technical Committee 21 (JTC 21) is leading AI standardisation in Europe
- Once standards are published in the Official Journal, compliance with them is the fastest and most straightforward route to demonstrating conformity — you do not need to build your own compliance framework from scratch
- Standards also reduce the cost and complexity of conformity assessment — notified bodies can assess against defined criteria rather than making subjective judgements
- Monitor the ISO/IEC 42001 AI management system standard and the CEN-CENELEC JTC 21 work programme — these are likely to form the foundation of EU harmonised standards for the AI Act
- In the meantime, aligning your practices with these emerging standards is prudent even before they are formally published
Related Articles
- Article 9 through 15 — Technical requirements (the requirements harmonised standards cover)
- Article 41 — Common specifications (the alternative where harmonised standards are absent)
- Article 42 — Presumption of conformity (the legal effect of complying with harmonised standards)
- Article 43 — Conformity assessment (how standards are used in the assessment procedure)
