Compliance

Harmonised Standard

A European standard requested by the European Commission that, once cited in the Official Journal, gives a rebuttable presumption of conformity with relevant EU harmonisation legislation.

Definition

Official/legal definition. Under the EU Artificial Intelligence Act, a harmonised standard is defined by reference to the European standardisation Regulation: it “means a harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012.” In turn Regulation (EU) No 1025/2012 defines a harmonised standard as “a European standard adopted on the basis of a request made by the Commission for the application of Union harmonisation legislation.” ([artificialintelligenceact.eu](https://artificialintelligenceact.eu/article/3/?utm_source=openai))

Context, scope and legal effect. Harmonised standards are voluntary technical specifications developed by recognised European Standardisation Organisations (notably CEN, CENELEC and ETSI) in response to a formal standardisation request from the European Commission. When the Commission assesses that a standard satisfies the objectives of the request it can publish a reference to that standard in the Official Journal of the European Union (OJEU). Once cited in the OJEU, compliance with the harmonised standard gives a presumption of conformity with the corresponding requirements of the EU legislative act (for the AI Act this is used to demonstrate conformity with many of the Title III requirements for high‑risk AI systems and related obligations). That presumption is rebuttable and applies only to the specific requirements the harmonised standard explicitly covers. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2012/1025/2023-07-09/eng?utm_source=openai))

Jurisdictional Variations.

  • European Union: The EU has a formal legal concept of a harmonised standard (Regulation 1025/2012, Article 2(1)(c)), explicitly referenced in the AI Act (Article 3(27) and the provisions on standards and presumption of conformity). Harmonised standards are created by ESOs following a Commission standardisation request and — once cited in the OJEU — provide the legal mechanism for a presumption that the corresponding legal requirements are met. ([artificialintelligenceact.eu](https://artificialintelligenceact.eu/article/3/?utm_source=openai))
  • United States: U.S. law and federal policy do not use the term harmonised standard in the EU sense. U.S. federal practice emphasizes voluntary consensus standards and frameworks (for AI, NIST’s AI RMF 1.0 is the leading voluntary framework). Executive Orders and agency guidance have encouraged development and use of standards and best practices, but there is no statutory mechanism that converts a privately developed standard into a nationwide legal presumption of conformity comparable to the EU model. (See NIST AI RMF; Executive Order 14110 and agency guidance such as FTC statements on algorithmic fairness and deceptive claims.) Note: some U.S. state laws (e.g., Colorado’s AI statute) expressly recognise compliance with recognised national or international frameworks (like NIST AI RMF or ISO/IEC 42001) as evidentiary safe harbors or affirmative defenses. ([studylib.net](https://studylib.net/doc/28018871/nist.ai.100-1?utm_source=openai))
  • International / Standards bodies: International organisations (ISO/IEC, OECD, UNESCO) publish principles and technical standards or terminologies relevant to AI (for example ISO/IEC 22989 for AI concepts and ISO/IEC management standards), and international policy instruments (OECD AI Principles, UNESCO Recommendation on the Ethics of AI) encourage harmonisation of norms and interoperability. Those instruments influence both EU standardisation requests and voluntary global practice, but they do not, by themselves, create the EU legal status of a harmonised standard. ([iso.org](https://www.iso.org/standard/74296.html?utm_source=openai))

Practical implications for businesses operating across jurisdictions. For companies placing AI products in the EU market, harmonised standards provide an efficient compliance route: following a cited harmonised standard substantially lowers regulatory risk because it creates a rebuttable presumption that the corresponding legal requirements are satisfied (e.g., aspects of risk management, data governance, transparency, human oversight and testing for high‑risk AI systems). However, companies must map which legal requirements are covered by the cited harmonised standard (often via an Annex‑type mapping inside the standard, commonly referred to as Annex ZA/ZZ) and maintain auditable evidence that the standard’s provisions are met in practice. Outside the EU, businesses cannot rely on a single harmonised‑standard mechanism; they should instead adopt leading voluntary frameworks (e.g., NIST AI RMF, ISO/IEC management and technical standards) and monitor whether EU harmonised standards incorporate or reference those international standards. Compliance programs should therefore be modular: adopt internationally recognised frameworks for global governance while implementing EU‑specific harmonised standards (or equivalent evidence) for market access in the EU. ([ai-watch.ec.europa.eu](https://ai-watch.ec.europa.eu/news/harmonised-standards-european-ai-act-2024-10-25_en?utm_source=openai))

Key requirements, criteria and examples.

  • Origin: adopted by a European standardisation organisation in response to a Commission standardisation request. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2012/1025/2023-07-09/eng?utm_source=openai))
  • Publication: the Commission must publish the reference in the Official Journal for the standard to confer presumption of conformity. ([eur-lex.europa.eu](https://eur-lex.europa.eu/eli/reg/2012/1025/oj?utm_source=openai))
  • Scope: presumption applies only to requirements explicitly covered by the harmonised standard; providers remain responsible for demonstrating compliance for uncovered requirements. ([resolve.cambridge.org](https://resolve.cambridge.org/core/journals/international-legal-materials/article/regulation-20241689-of-the-eur-parl-council-of-june-13-2024-eu-artificial-intelligence-act/64F1F6734F8C66CA3EEA149C9759194E?utm_source=openai))
  • Mapping: harmonised standards typically include a clause/annex mapping standard clauses to legal requirements (e.g., Annex ZA). Providers must keep evidence linking system controls to those clauses. ([completeaitraining.com](https://completeaitraining.com/news/pren-18286-explained-ai-act-qms-standard-in-public/?utm_source=openai))
Common examples: EN standards published under Commission request in other sectors (e.g., EN 301 549 for ICT accessibility) illustrate the mechanism; for the AI Act the first wave of AI‑specific harmonised standards and draft documents (e.g., prEN drafts such as draft QMS standards) are being developed by CEN/CENELEC/ETSI to support Title III requirements. ([blog.johner-institute.com](https://blog.johner-institute.com/regulatory-affairs/harmonized-standards/?utm_source=openai))

Cross‑references. Related concepts you will encounter when working with harmonised standards include: common specification (Commission‑adopted technical specification where harmonised standards are absent or insufficient), presumption of conformity (legal effect after OJEU citation), conformity assessment and CE marking where applicable. Under the AI Act these instruments interact: harmonised standards are the preferred industry‑led technical route, common specifications are a Commission backstop, and codes of practice may be used where appropriate (e.g., for general‑purpose AI models until harmonised standards are available). ([ai-act-service-desk.ec.europa.eu](https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-41?utm_source=openai))

Sources

  • EU AI Act Article 40
  • Regulation (EU) 1025/2012