[IND] 4 min readOraCore Editors

Europe should standardise the AI Act through harmonised technical rul…

Europe should back the AI Act with harmonised standards, because legal text alone does not make AI systems safe or compliant.

Share LinkedIn
Europe should standardise the AI Act through harmonised technical rul…

10 key areas of AI compliance need harmonised standards to make the AI Act enforceable.

The EU is right to push the AI Act through harmonised standards, because legal obligations without technical standards are just expensive ambiguity.

Standards are what turn the AI Act from policy into practice. The Commission has already asked CEN and CENELEC to develop rules across ten areas, including risk management, governance, datasets, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management, and conformity assessment. That list matters because high-risk AI is not regulated by slogans. It is regulated by controls that engineers can implement, auditors can inspect, and buyers can demand.

First, standards make compliance usable

Get the latest AI news in your inbox

Weekly picks of model releases, tools, and deep dives — no spam, unsubscribe anytime.

No spam. Unsubscribe at any time.

For providers, the AI Act is only useful if it can be translated into engineering work. A standard gives teams a shared checklist and a defensible process. The Commission says harmonised standards offer legal certainty and reduced compliance costs, and that is the real point: a startup building a medical triage tool should not have to invent its own interpretation of governance, logging, and oversight just to ship in Europe.

Europe should standardise the AI Act through harmonised technical rul…

There is already a sign that this approach is becoming operational, not theoretical. On 30 October 2025, prEN 18286, the first harmonised AI standard, entered public enquiry as a quality management system for EU AI Act regulatory purposes. That is the right direction. A product-focused standard does more than reassure lawyers. It gives product, security, and compliance teams a common language for lifecycle controls, which is exactly what high-risk systems need before deployment.

Second, standards are the only credible path to scale

Europe likes to say it wants trustworthy AI that can compete globally. That claim only holds if compliance is portable. Harmonised standards can become de facto market benchmarks, which means a company that builds to EU rules is not just checking a local box. It is building to a framework that partners, regulators, and customers elsewhere can recognize.

The international angle is not a side note. ISO/IEC SC 42 is already producing AI standards, and the Commission explicitly wants an international-first approach when those standards align with EU law. That is the smartest part of the strategy. If Europe writes standards in isolation, it creates a compliance island. If it aligns with global bodies, it reduces fragmentation and gives European firms a better shot at selling across markets without duplicating controls for every jurisdiction.

The counter-argument

The strongest objection is that standards can lag the technology. AI systems change fast, while standard-setting is slow, consensus-heavy, and vulnerable to capture by incumbents. A rigid compliance framework can also push smaller companies toward box-ticking instead of real safety work, especially if the standards become too prescriptive or too expensive to follow.

Europe should standardise the AI Act through harmonised technical rul…

That critique is serious, and Europe should not pretend standards are a substitute for judgment. But it does not defeat the case for standardisation. The AI Act already allows providers to use other frameworks to show compliance, so harmonised standards are not the only route. They are the clearest route. The limit is obvious: standards must stay high-level enough to survive technical change, while still precise enough to support enforcement. That is a design problem, not a reason to abandon the model.

What to do with this

If you are an engineer, PM, or founder building AI for the EU, treat harmonised standards as part of product design, not a later legal task. Map your system against the ten requested areas now, especially data governance, logging, human oversight, and cybersecurity. If you wait for the final text and then scramble, you will pay in rework, delayed launches, and weaker trust. If you start early, you turn regulation into an operating advantage.