EN 18286 is published: the first AI Act harmonised standard, and what it does not give you yet
At the end of July 2026, CEN and CENELEC published EN 18286:2026 — "Artificial intelligence — Quality management system for EU AI Act regulatory purposes." It is the first European standard written specifically to serve the AI Act, and it is the one most directly tied to a concrete obligation: the quality management system that Article 17 requires of providers of high-risk AI systems.
That is genuinely a milestone. It is also the point at which a lot of vendor copy starts overstating what a published standard actually buys you. This post separates the two.
This is an information service to help you plan, not legal advice. For the obligations tied to your own AI use, see which apply to your company.
Published, assessed, cited: three different things
The word "harmonised" is doing a lot of work in the coverage of this release, and it is worth slowing down on the mechanism, because the legal effect attaches at the third step, not the first.
| Step | Who does it | Status for EN 18286 | Legal effect |
|---|---|---|---|
| 1. Standard developed and published | CEN / CENELEC (via JTC 21) | Done — EN 18286:2026, end of July 2026 | None on its own |
| 2. Commission assesses whether it meets the AI Act's objectives | European Commission | Not confirmed complete | None on its own |
| 3. Reference published in the Official Journal | European Commission | Not done | Presumption of conformity |
The Commission's own standardisation page describes the sequence plainly: once standards are published by CEN and CENELEC, the Commission assesses whether they meet the intended objectives and legal requirements of the AI Act, and only after that step are they referenced in the Official Journal.
Article 40 then supplies the consequence. High-risk AI systems in conformity with harmonised standards "the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012" are presumed to be in conformity with the corresponding requirements. The presumption is keyed to the Official Journal citation. Not to publication by the standards body.
That mechanism survived the Digital Omnibus intact — the amendment adds to Article 40; it does not change the presumption test in Article 40(1). What the Omnibus did add, at Article 40(2), is a duty on the Commission to request standardisation deliverables aimed at joint compliance: standards covering the AI Act's requirements and the Annex I product legislation together, so a provider of AI embedded in a regulated product can build against one set of standards for both regimes.
Which still tells you something about direction of travel: the legislator kept the presumption mechanism exactly as it was and asked for more standardisation deliverables — including joint ones spanning the AI Act and sectoral product law — rather than loosening the legal test. Expect more deliverables, on the same legal terms.
As of early September 2026, no AI Act harmonised standard has been cited in the Official Journal. So the honest position today is: EN 18286 exists, you can buy it, you can build against it, and it is the best available signal of what regulators will expect — but it does not yet flip any burden of proof.
Why the citation step is worth waiting for
Presumption of conformity is not a formality. It changes who has to prove what.
Without it, you demonstrate to a market surveillance authority that your quality management system satisfies Article 17, on your own evidence, in your own framing. With it, conformity is presumed, and an authority that disagrees has to make the case that your system falls short. For a provider of a high-risk system facing a national regulator, that is a materially different conversation.
This is the same structural point that makes the voluntary codes under the Act useful but limited, and it is worth being precise about it — the mechanism differs from one instrument to the next. See how the Digital Omnibus moved the high-risk deadlines for how the timing now lines up.
EN 18286 and ISO/IEC 42001 are not substitutes
The most common question from teams that already run an AI governance programme: we are certified to ISO/IEC 42001 — are we covered?
For AI Act purposes, no.
- ISO/IEC 42001 is an international, certifiable AI management system standard. It is a credible governance framework and a reasonable thing to hold.
- EN 18286 is a European standard whose purpose is regulatory: to implement Article 17 and to carry presumption of conformity once cited.
ISO/IEC 42001 is not a harmonised standard under the AI Act and is not cited in the Official Journal, so it confers no presumption of conformity. The two overlap substantially in structure and controls, and a mature 42001 programme is a strong head start — but it is a head start, not an equivalence. Treat the gap analysis between them as real work, not a mapping exercise you can wave through.
The timing, honestly
Two dates are easy to conflate here, and they point in opposite directions.
The standards machinery is live. Chapter III Section 5 of the Act — including Articles 40, 42 and 43, covering harmonised standards and conformity assessment — applies from 2 August 2026, along with the rest of the general application date. The framework for citing standards and for conformity assessment is operating now.
The obligation the standard serves is not. Article 17 binds providers of high-risk AI systems, and the Digital Omnibus deferred the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I embedded systems. If you are a high-risk provider, the quality management system duty is not enforceable against you today.
So there is time. What there is not, is a reason to wait for the deadline: a quality management system is typically a year-plus organisational build, and the standard that defines the target has only just landed. Teams that start against EN 18286 now will be building against the right specification. Teams that wait for the Official Journal citation will be building against it later, with less room.
If you are not yet sure whether your system is high-risk at all — the question that determines whether any of this reaches you — start with the high-risk classification test.
Smaller providers got a real concession — three of them
The Digital Omnibus made the quality management system materially lighter for smaller companies. All three changes are in the amending Regulation itself.
1. The simplified QMS route widened from microenterprises to SMEs. The original Article 63(1) offered the simplified route to microenterprises only. As replaced by Regulation (EU) 2026/1744, it lets SMEs, including start-ups, comply with certain elements of the Article 17 quality management system in a simplified manner — provided they have no partner or linked enterprises within the meaning of Recommendation 2003/361/EC.
The same paragraph obliges the Commission to develop guidelines on which elements may be simplified — so the detail is coming, and it is worth waiting for before designing around it.
2. Article 17's proportionality clause now names SMEs and SMCs expressly. Proportionality to the size of the provider's organisation was already in Article 17(2); the replaced paragraph adds the express reference to SMEs, start-ups and SMCs, which hardens the argument for a smaller provider. The limit carries over unchanged: providers must in any event respect the degree of rigour and the level of protection required — proportionate is not optional.
3. Simplified technical documentation. Under the amended Article 11(1), SMEs, start-ups and small mid-caps may provide the Annex IV elements in a simplified manner, the Commission must establish a form for it, and notified bodies must accept that form for the purposes of conformity assessment.
Note the third category: SMC, small mid-cap enterprise — companies that have outgrown the SME definition. The Omnibus extends several accommodations to them, so check whether you qualify before assuming you are in the large-enterprise bucket.
The wider signal: the official trackers are behind
Worth noting for anyone relying on free reference sites, including official ones.
CEN-CENELEC published EN 18286 at the end of July. The European Commission's own AI Act standardisation page, last updated 3 August 2026, still described prEN 18286 in terms of the public enquiry milestone it passed in October 2025. Meanwhile the Commission's AI Act Service Desk displays a Digital Omnibus disclaimer on Articles 17, 40, 63, 75 and 113 — "the text displayed on this page has not yet been updated to reflect those amendments" — more than a month after Regulation (EU) 2026/1744 entered into force.
None of this is a criticism of the institutions; the volume of change is high and the pages are catching up. It is a caution about method. If your compliance position is built on a snapshot of a reference page, your position ages without telling you. Start from which obligations apply to your company and verify each against the amended text.
What to do this quarter
- Get the standard and read it against what you already have. If you run ISO/IEC 42001, do a clause-level gap analysis rather than assuming coverage.
- Confirm your risk tier first. The Article 17 duty attaches to providers of high-risk systems. If you are not one, EN 18286 is optional good practice, not a target.
- Track the Official Journal citation, not the press release. The presumption of conformity begins on citation. That is the date worth having in your plan.
- Check your size classification before anything else. SME, start-up and SMC status now changes what Articles 17, 63 and 11 require of you. Read the amended text in Regulation (EU) 2026/1744 directly — the official article-by-article pages still display the pre-Omnibus wording.
- Do not describe yourself as "AI Act compliant" on the strength of a standard. No standard is cited yet, and compliance is assessed against the Regulation.
To see which obligations — and which risk tier — actually apply to your systems, answer a few questions about your AI use. To be told when EN 18286 is cited in the Official Journal, or when another standard lands, join the waitlist.
The official text is Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. This article is an information service to help you orient — it is not legal advice.
Frequently asked questions
Has EN 18286 been published?
Yes. CEN and CENELEC published EN 18286:2026, 'Artificial intelligence — Quality management system for EU AI Act regulatory purposes', at the end of July 2026. It is the first European standard developed specifically for AI Act regulatory purposes, and it supports the quality management system that Article 17 requires of providers of high-risk AI systems.
Does using EN 18286 make me compliant with the EU AI Act?
No, and not yet even presumptively. Article 40 grants presumption of conformity only to systems conforming to harmonised standards whose references have been published in the Official Journal of the European Union. As of early September 2026 no AI Act standard has been cited in the Official Journal. Until EN 18286 is assessed by the Commission and cited, applying it is good engineering evidence, not a legal presumption.
What is the difference between EN 18286 and ISO/IEC 42001?
ISO/IEC 42001 is an international, certifiable AI management system standard. EN 18286 is a European standard written for a regulatory purpose: to carry presumption of conformity with Article 17 of the AI Act once it is cited in the Official Journal. ISO/IEC 42001 is not a harmonised standard and confers no presumption of conformity. They overlap substantially but are not interchangeable for AI Act purposes.
Do I need a quality management system now, given the high-risk delay?
The Article 17 obligation itself binds providers of high-risk AI systems, and the Digital Omnibus deferred those obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I embedded systems. So the duty is not live today. The standards machinery in Articles 40, 42 and 43 does apply from 2 August 2026, which is why the build target exists before the deadline does.
See which obligations apply to your company → or join the waitlist
This is an information service, not legal advice.