Compliance

Common Specification

An EU-issued set of technical specifications that providers can follow to demonstrate compliance with certain AI Act requirements when harmonised standards are unavailable or inadequate.

Definition

Official/legal definition: A common specification is defined in the EU Artificial Intelligence Act as “a set of technical specifications as defined in Article 2, point (4) of Regulation (EU) No 1025/2012, providing means to comply with certain requirements established under this Regulation.” This definition appears in the Act’s definitions (Article 3) and the Act separately authorises the Commission to adopt implementing acts establishing common specifications where conditions in Article 41 are met. ([artificialintelligenceact.eu](https://artificialintelligenceact.eu/article/3/?utm_source=openai))

What the EU text does (practical summary): The AI Act gives the European Commission authority to issue common specifications by implementing act as a fallback mechanism when harmonised standards are not available, not accepted by European standardisation organisations, delayed, inadequate with respect to fundamental-rights protection, or otherwise do not meet a standardisation request. High‑risk AI systems or general‑purpose AI models that conform with relevant common specifications are presumed to meet the corresponding legal requirements in the Act; providers who do not follow common specifications must justify that their alternative technical solutions deliver an equivalent level of compliance. The Commission must consult advisory bodies and may repeal common specifications where harmonised standards covering the same requirements are later published. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Jurisdictional variations

European Union: The term is explicit and legalised in the EU AI Act (Regulation (EU) 2024/1689): the Act both defines “common specification” and sets out the procedure and limits for the Commission to adopt them (Article 3(28) and Article 41). In the EU framework, a common specification is an implementing‑act instrument that creates a presumption of conformity for covered requirements where harmonised standards are missing or insufficient; it is therefore a legally significant instrument tied directly to conformity assessment and CE‑style market mechanisms. ([artificialintelligenceact.eu](https://artificialintelligenceact.eu/article/3/?utm_source=openai))

United States (federal guidance and practice): U.S. federal frameworks do not use the specific statutory term “common specification” in the way the EU AI Act does. Instead, U.S. executive and standards initiatives rely on voluntary frameworks, agency guidance, technical profiles, and interagency directives to promote interoperable technical practices. Notably, the NIST AI Risk Management Framework (AI RMF 1.0) and related NIST activities produce voluntary guidance, playbooks, and profiles intended to harmonise practice and inform evaluation, but they do not create prescriptive implementing acts that produce a legal presumption of compliance like the EU common specification mechanism. Executive Order 14110 directs federal agencies to support development of consensus standards and evaluation resources, which functionally overlaps with the EU objective of common, interoperable technical rules but through voluntary/administrative U.S. instruments rather than EU‑style implementing acts. ([nist.gov](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10?utm_source=openai))

International standards and soft law: International instruments (OECD AI Principles), ISO/IEC standards (e.g., ISO/IEC 22989 for terminology and other ISO/IEC AI series standards), and UNESCO’s Recommendation on the Ethics of AI provide normative and technical guidance that supports interoperability and shared concepts, but they do not establish a legally binding, jurisdiction‑wide mechanism equivalent to the EU common specification. These instruments are often used as inputs to national or regional standards requests, and the EU text expressly contemplates cooperation with international standardisation bodies when developing common specifications. ([oecd.org](https://www.oecd.org/en/topics/ai-principles.html?utm_source=openai))

Context, scope and purpose: In the EU regime, common specifications sit within the AI Act’s conformity ecosystem as a targeted remedial tool to ensure that providers of high‑risk AI systems and covered general‑purpose models can demonstrably meet legal requirements even where harmonised standards (developed by recognised European standardisation organisations) are absent or defective for certain rights‑sensitive aspects. The mechanism is designed to be exceptional and time‑limited: it facilitates market access and compliance but yields to harmonised standards once those are adopted and published. The scope is limited to the requirements identified in the Act’s relevant chapters and the obligations referenced in Chapter V sections indicated by Article 41. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Practical implications for businesses operating across jurisdictions:

  • EU market actors must watch implementing acts and common‑specification implementing acts published by the Commission because conformity with those acts creates a presumption of compliance; following them can streamline conformity assessments and reduce regulatory risk. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
  • Non‑EU firms selling into the EU market should treat common specifications like de facto technical rules for compliance—failure to follow them requires documented technical justification demonstrating at least equivalent protection, which can be burdensome in audits or market‑surveillance proceedings. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
  • Organizations that operate in both the EU and the U.S. should map EU common specifications against U.S. voluntary standards/guidance (e.g., NIST profiles) to identify gaps and harmonisation opportunities; reliance on voluntary U.S. guidance alone will not create a legal presumption of conformity for EU regulatory purposes. ([nist.gov](https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10?utm_source=openai))
  • Because common specifications are intended as an exceptional fallback, businesses involved in standards development or standardisation requests should engage with European standardisation organisations and the Commission to influence harmonised standards development before the Commission resorts to common specifications. ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/recital-121?utm_source=openai))

Key requirements and criteria (Article 41-related mechanics):

  • The Commission may adopt common specifications by implementing act only where conditions are fulfilled, including: that the Commission has requested harmonised standards and the request was not accepted, standards are delayed, insufficiently address fundamental‑rights concerns, or do not comply with the request. (See Article 41 for the full procedural and consultative steps.) ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
  • Conformity with a common specification creates a presumption of conformity to the extent the specification covers particular requirements; where harmonised standards later are published covering the same items, the Commission may repeal the implementing act or relevant parts. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))
  • Providers who choose not to follow an applicable common specification must be able to justify that their technical solutions meet the same requirements to an equivalent level—this is an evidentiary obligation in the EU conformity framework. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng?utm_source=openai))

Examples and cross‑references: Examples of where the Commission might issue common specifications include technical measures for data governance, transparency records, robustness testing methods, or requirements for post‑market monitoring when harmonised standards are not yet in place. Related legal/technical concepts to consult when implementing compliance programs include: harmonised standard, technical specification (Regulation (EU) No 1025/2012, Article 2(4)), conformity assessment, implementing act, and the AI Act chapters on high‑risk AI requirements and obligations. Operators should also map NIST AI RMF profiles and ISO/IEC AI standards to any applicable EU common specifications to support cross‑jurisdictional compliance planning. ([digital.nemko.com](https://digital.nemko.com/ai-trust-hub?utm_source=openai))

Sources

  • EU AI Act Article 41
  • European Commission Implementing Acts