The first AI Act standard is published. Presumption of conformity is not.
EN 18286 reached publication in July 2026, and publishing a European standard is not the same act as citing it in the Official Journal. What it settles is which records a high-risk provider will be asked for — and a quality management system is the one obligation that cannot be assembled after the fact.
The message arrives forwarded, usually with one line above it: the first AI Act standard is out. Somebody in the room says that this is what everyone has been waiting for, and the readiness programme that has been stalled on the absence of technical detail acquires a target to aim at.
The news is real. CEN and CENELEC published EN 18286 in July 2026 — “Artificial intelligence — Quality management system for EU AI Act regulatory purposes” — the first European standard developed under the Commission’s standardisation request to reach publication. It is written against Article 17, the article that requires a provider of a high-risk system to run a documented quality management system.
The inference drawn from it is usually wrong in two directions at once. Teams read publication as the start of a legal shelter that has not opened yet, and they read a quality management standard as a documentation exercise that can be run at the end. It is the reverse on both counts. The standard confers nothing today, and the thing it describes is the one obligation whose evidence has to be generated while the system is being built rather than reconstructed from it afterwards.
Publication and citation are two different events
Article 40(1) of the Act is specific about where the presumption comes from. It attaches to systems in conformity with “harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union” (Article 40). The operative clause is the references of which have been published. A standard that CEN and CENELEC have approved and put on sale has not, by that act, had its reference published anywhere.
The Commission describes the sequence in its own terms. After a standard is published, it reviews it substantively to assess whether it accurately reflects the legal provisions, and only then submits the reference for publication in the Official Journal (understanding the standardisation of the AI Act). The same page notes that a standard, once referenced, carries an annex mapping the requirements of the Act to the clauses of the standard. That annex is what scopes the shelter — presumption reaches the requirements the annex claims, and no further.
- 01 Drafted Written by JTC 21 under the standardisation request.
- 02 Published Approved by CEN and CENELEC. Buyable. EN 18286 is here.
- 03 Assessed The Commission checks it against the Act.
- 04 Cited Reference in the Official Journal. Presumption starts, scoped by the mapping annex.
So the practical position in August 2026 is that a provider can buy EN 18286, read it and work to it, and what they get for that is what the text itself gives them — a settled account of what the Commission asked the standardisers to specify for Article 17. That is worth having. It is not a defence, and describing it internally as one sets up a conversation with a market surveillance authority that nobody wants to have.
Why a quality management system is not a late deliverable
The second error costs more. Article 17(1) lists what the system has to cover, and the list is almost entirely composed of procedures rather than artefacts: procedures for record-keeping of relevant documentation and information, procedures for data management across acquisition, collection, analysis, labelling, storage, filtration, aggregation and retention, a post-market monitoring system, and an accountability framework setting out the responsibilities of management and staff (Article 17).
A procedure is evidenced by the records it produced while it was running. This is the structural difference between Article 17 and the technical documentation in Annex IV. Technical documentation is a description of a system, and a description can be written late — expensively, painfully, but it can be written, because the system still exists and can be inspected. A quality management system is a claim about how an organisation worked over a period, and the records that support it are dated. A design review that happened in September 2026 and was written up in 2028 is a different piece of evidence from one recorded at the time, and an auditor can tell which is which by looking at the dates.
This is why the deferral of the stand-alone high-risk obligations to 2 December 2027 under the Digital Omnibus on AI (Commission timeline) is less useful than it reads. A deadline that moves gives more time to write documents. It does not retrospectively create the audit trail that a quality management system is made of, because that trail can only be laid down by systems and people operating now, during the build that is already under way.
What to do with this before the citation lands
Four moves are available today, and none of them depends on knowing when or whether EN 18286 is referenced.
Buy the standard and read Article 17 alongside it. Not to adopt it, but to find out which of its clauses your existing engineering process already satisfies under a different name. Change control, design review and incident handling usually exist. The gap is normally data management and post-market monitoring, and it is better to know that now.
Turn on dated record-keeping in the places listed above. This is an architecture decision, not a policy decision. If the pipeline does not persist why a dataset version was selected, no policy document will make it appear later.
Ask suppliers a sharper question. When a vendor claims alignment to EN 18286, the useful follow-up is not whether they align but which clauses, and whether their answer depends on a reference in the Official Journal that has not appeared. A supplier who understands the difference is telling you something about how they will behave when the mapping annex turns out to cover less than everyone hoped.
Write down the accountability framework with names in it. Article 17 asks for responsibilities of management and staff. A framework naming roles that nobody occupies is the failure mode, and it is visible immediately to anyone reading it from outside.
What this does not tell you
It does not tell you that EN 18286 will be cited, or when, or with what mapping annex. The Commission’s assessment is a substantive review and it can conclude that a standard does not adequately reflect the requirements. Anyone planning on the assumption of a particular citation date is planning on something that has not happened.
It does not tell you whether your system is high-risk. That turns on Annex III and on the role you occupy, and it is a question that has to be answered for your system rather than for your sector.
Nothing here is legal advice, and no work of this kind produces a statement that an organisation meets the Act. The institute does not certify anyone, does not audit against a standard, and does not issue conformity opinions. Legal interpretation stays with your counsel, and formal conformity assessment stays with a notified body where one is required. What we do is establish which obligations plausibly attach, map what already exists against them, and name the evidence that does not exist yet.
The reason to act on this in August rather than in 2027 has nothing to do with the deadline. It is that the head of engineering signing off this quarter’s pipeline work is, without being asked, deciding whether the organisation will have contemporaneous records of its data and change decisions by the time the deferred deadline arrives. That decision is being made either way. It is worth making it on purpose.