Governance teams are struggling to build compliance programs for the AI Act without finalized technical standards. The European Commission requested these standards for high-risk provisions back in 2021, but it's now 2025, and the process is still behind schedule. If you're waiting for clarity before building your conformity assessment framework, you're not alone.
Do You Need These Standards to Comply with the AI Act?
No, you don't. Standards provide a presumption of conformity, meaning if you comply with a harmonized standard, authorities will assume you've met the legal requirement. However, standards are voluntary.
You can comply by interpreting the AI Act's legal text yourself. This might involve relying on legal opinions, industry guides, or frameworks from professional alliances. While this approach won't offer the presumption of conformity that harmonized standards do, it may be available sooner and more tailored to your needs.
The trade-off is that independent interpretation carries more enforcement risk. If an authority disagrees with your approach, you'll need to defend it without the protection of an officially approved standard. For high-risk systems, this is a significant exposure.
Who's Writing These Standards?
The European Commission requested the standards, but two European Standardisation Organizations (ESOs), CEN and CENELEC, are drafting them through a joint committee called CEN/CENELEC JTC21.
The ESOs coordinate National Standards Bodies (NSBs) from each EU member state. Each NSB represents government, industry, and civil society stakeholders at the national level. Technical experts from these bodies draft the standard text. They're volunteers, bound by confidentiality rules and a code of conduct to prioritize the EU community's benefit over national interests.
This can create friction. An expert funded by German industry stakeholders may receive conflicting guidance from their national committee while needing to prioritize EU-wide consensus. The process is designed for neutrality, but it's slow.
Why Is the Process Behind Schedule?
The standardization process involves six steps: Commission request, ESO drafting, enquiry (where NSBs vote and comment), formal vote, publication by the ESO, and finally assessment and citation by the Commission. Different AI Act standards are at different stages right now.
Delays often occur during the enquiry step. NSBs collect feedback from national stakeholders, and it's common for one country to request changes that conflict with another's position. The working group must resolve these conflicts, find compromise language, or reject comments outright. Rejecting comments risks "no" votes in the formal vote step, which can trigger a complete redraft.
Negative feedback during enquiry can force a reset where large sections are rewritten and resubmitted. Working groups sometimes resolve conflicts by omitting controversial material, which means the final standard may not fully cover what the Commission originally requested.
Additionally, experts are aligning with existing ISO/IEC international standards to avoid creating trade barriers under WTO rules. This alignment takes time, especially when international standards are evolving.
What If Standards Aren't Ready When Enforcement Starts?
You'll need to build your compliance program around the legal text and any existing guidance. For high-risk AI systems, this means focusing on Technical Documentation (Annex IV), risk management systems, data governance, and post-market monitoring based on your interpretation of Articles 9 through 15.
The risk is regulatory uncertainty. Without harmonized standards, you'll make judgment calls about what "appropriate" data governance means or what constitutes "sufficient" human oversight. Different notified bodies may interpret requirements differently during conformity assessment. You might pass assessment in one member state and face questions in another.
This isn't hypothetical. Market surveillance authorities will begin enforcement before all standards are finalized. If you're deploying high-risk systems, you need documentation that demonstrates your reasoning for every design choice, even when the official standard doesn't exist yet.
Should You Wait for Standards or Start Building Now?
Start now, but build in flexibility. Map your current approach to the AI Act's legal requirements. Document your risk assessment methodology, data quality controls, and human oversight mechanisms. When standards arrive, you'll need to gap-assess your framework against them.
Consider this: the first batch of standards covers high-risk system requirements. Additional standards for other AI Act provisions may come later. The General-Purpose AI Code of Practice follows a different process entirely. If you wait for every piece of guidance to finalize, you'll be starting compliance work when competitors are already certified.
The practical approach: implement controls that address the Act's objectives (safety, transparency, accountability) using established frameworks. ISO/IEC 42001 for AI Management Systems and NIST AI RMF provide structure even if they don't give you presumption of conformity. SR 11-7 model risk management principles translate well to AI Act risk management requirements. When EU standards publish, treat them as a validation checkpoint, not a starting line.
Where Can You Track Standard Development Progress?
CEN/CENELEC JTC21 publishes a work program showing which standards are in development and their current stage. Experts working in the committees are bound by confidentiality, so you won't see draft text or working group discussions. But you can see which standards have moved to enquiry or formal vote.
Watch for Commission guidance documents as well. Not everything will be clarified through standards. Some requirements will be detailed in interpretive guidance that doesn't go through the ESO process.
And track the reform discussion. There are controversies about whether the European standards system is fit for fast-moving technology. The Commission is considering reforms. If the process changes mid-stream, timelines will shift again.
Where to Go from Here
Don't let standards uncertainty paralyze your compliance planning. The AI Act's legal obligations are clear enough to begin building. Focus on risk management systems, technical documentation processes, and governance structures that will need to exist regardless of what the final standards say.
When standards do publish, you'll gap-assess and adjust. That's cheaper than waiting and building from scratch under enforcement pressure.



