Today the EU AI Act's high-risk system obligations take effect. Yet the harmonized standards that were supposed to define compliance—risk management protocols, technical documentation formats, conformity assessment procedures—do not exist. CEN-CENELEC Joint Technical Committee 21, tasked with drafting these standards in 2023, has produced only one published standard to date: EN 18286:2026, a quality management framework. The substantive technical specifications remain in draft.

This is not a minor administrative delay. Under the EU's New Legislative Framework, harmonized European standards (hENs) normally precede or coincide with legal force. The theory is straightforward: Parliament and Council set the safety objectives, standards bodies translate them into measurable technical requirements, and manufacturers follow those requirements to gain presumption of conformity. The AI Act inverts this timeline. Legal obligations are now in force while the standards that operationalize them are 18–36 months away from publication in the Official Journal.

Precedent suggests the gap will persist. The Machinery Directive and Medical Devices Regulation each experienced 2–4 year intervals between legal applicability and available hENs. During these vacuums, manufacturers relied on internal "state of the art" risk management, interpreted unevenly by national market surveillance authorities. Germany and France in particular have historically imposed stricter national criteria during such gaps. The risk is not merely uncertainty but fragmentation—Member States filling the void with divergent requirements that may later conflict with the harmonized standards once they arrive.

The burden now falls entirely on operators to define what "adequate" risk management means under Article 9 of the Act. Large providers with compliance departments and legal budgets can navigate this ambiguity; smaller deployers and startups face higher relative costs and greater exposure to enforcement variance across jurisdictions. The AI Act's global salience—its extraterritorial reach and its position as the first comprehensive AI regulation—amplifies the volatility of this gap. Where the GDPR's 2018 rollout had supervisory guidance to partially substitute for missing harmonized criteria, the AI Act moves faster than its institutional support structures.

Whether this gap proves to be a manageable transition or a structural flaw depends on what emerges from JTC 21 in the next 18 months. The committee's draft releases will signal whether the standards can catch up to the law, or whether the law will spend years operating in a regime of interpretive chaos.

Sources:
CEN-CENELEC Artificial Intelligence
Regulation (EU) 2024/1689 — Artificial Intelligence Act
European Commission — New Legislative Framework