Anyone approaching AI compliance today runs into a stack of acronyms that all look like competitors: ISO/IEC 42001, EN 18286, the IEEE 7000 series, a dozen SC 42 standards on risk, bias, cybersecurity, data quality. The typical CTO reaction is to look for the one that “solves the AI Act”, certify it and close the file. That is the most expensive mistake, because those acronyms are not on the same plane. You certify one convinced you have covered the legal obligation, and find out downstream that it covered a different problem.
The confusion comes from treating everything as an “AI standard”. In reality there are three distinct levels, and each answers a different question: what you must do (the regulation), how you govern the organization (management systems), how you do a single thing well (technical processes). A standard is only useful once you know which level it belongs to. This article lines up the three levels, places each standard where it actually sits, and hooks it to the AI Act article it serves to satisfy.
Level 1: the regulation says what, not how
The AI Act is a product safety regulation, not a code of good practice. For high-risk systems (Chapter III) it imposes specific obligations: a risk management system (art. 9), data governance (art. 10), technical documentation (art. 11), record-keeping (art. 12), transparency towards those who use the system (art. 13), human oversight (art. 14), accuracy, robustness and cybersecurity (art. 15), and a quality management system (art. 17).
The regulation says what is needed, never how to achieve it. The “how” is delegated to harmonized standards. Art. 40 sets out the key mechanism: whoever applies a harmonized standard — one published in the Official Journal of the European Union — enjoys a presumption of conformity. Translated for the CEO: it is the only legal shortcut. You apply the harmonized standard and the obligation is deemed satisfied, without having to demonstrate from scratch that you met the requirement. Every other standard, however authoritative, remains a tool, not a cover.
That distinction — harmonized or not — is the first thing to check in front of any acronym. It decides whether that standard gives you legal certainty or merely a method.
Level 2: management systems govern the organization
This is where the two most frequently confused standards live: ISO/IEC 42001 and EN 18286. Both are management systems, both use the high-level structure shared by ISO 9001 and ISO 27001 (Plan-Do-Check-Act cycle, the same clause skeleton). But they serve two different purposes, and that is the difference that counts.
ISO/IEC 42001:2023 is the artificial intelligence management system (AI Management System). It is international, certifiable right now, and it governs how an organization uses and develops AI in general: policies, roles, risk and impact assessment, controls. It is a mature governance framework. But it governs AI regardless of the AI Act; it is not calibrated on the Act’s specific requirements.
EN 18286 lives on the same plane, with one decisive difference: it is the European standard developed by the CEN-CENELEC JTC 21 committee tailored to art. 17 of the AI Act — the quality management system that a provider of high-risk AI must have. It reached the Enquiry stage in October 2025, the phase in which national bodies vote and comment. It is not yet harmonized nor published in the Official Journal, so today it does not yet grant a presumption of conformity. It will grant it once it is cited in the Official Journal, expected in the 2026-2027 window.
Hence the question every CTO asks: if I am certified to 42001, have I solved the AI Act? No. JTC 21 chose not to adopt 42001 as harmonized precisely because it governs AI in general and does not map the requirements of art. 17. The operational consequence is clear-cut: holding 42001 does not give you the presumption of conformity. It builds the skeleton onto which EN 18286 grafts with minimal friction — many controls and the logic of the cycle are shared — but the gap assessment against art. 17 has to be done anyway. Anyone certifying 42001 thinking the file is closed has done half the journey and does not know it.
Level 3: technical processes do one thing well
The third level is the toolbox. These are not management systems: they are the methods by which you produce the evidence the levels above require. Here the IEEE standards coexist with the technical part of the ISO/IEC SC 42 family.
IEEE does not have a management system like 42001. It has a family of process standards, born of the Ethically Aligned Design initiative, each dedicated to a single concern: IEEE 7000 (process for integrating ethical values into design), IEEE 7001 (transparency of autonomous systems), IEEE 7002 (data privacy process), IEEE 7003 (algorithmic bias), IEEE 7010 (well-being metrics), IEEE 3119 (procurement of automated decision systems, useful on the buyer side and for public administration). On top of these IEEE has also built a certification programme, CertifAIEd. They are voluntary, international, and none is harmonized in the EU: on their own they grant no presumption of conformity, but they tell the team how to implement transparency, bias and privacy in concrete terms.
On the ISO/IEC side, the SC 42 family covers the same level with standards closer to the industrial product world:
- Risk. ISO/IEC 23894:2023, guidance on AI risk management, aligned with ISO 31000. It is the natural reference for building the system required by art. 9.
- Concepts and terminology. ISO/IEC 22989:2022 fixes the vocabulary, ISO/IEC 23053:2022 the framework for machine-learning-based systems.
- Data quality. The ISO/IEC 5259 series (parts 1-5, 2024) covers measures, management and governance of data quality for analytics and ML. Direct material for art. 10.
- Bias. ISO/IEC TR 24027:2021 on bias in AI systems and in decision support, from data collection to evaluation.
- Robustness and cybersecurity. ISO/IEC TR 24029 (parts 1-2) on the robustness of neural networks, ISO/IEC 25059:2023 on the quality model for AI systems, and ISO/IEC 27090 (under development, expected 2026) on AI-specific cybersecurity threats and controls. Together they cover art. 15.
- Transparency. ISO/IEC 12792:2025 defines the taxonomy of transparency, and has already been adopted as EN ISO/IEC 12792:2025. Reference for art. 13.
- Impact. ISO/IEC 42005:2025, AI system impact assessment, useful both for art. 17 and for the fundamental rights impact assessment (art. 27).
- Life cycle and certification. ISO/IEC 5338:2023 on life cycle processes, and ISO/IEC 42006 (2025) on requirements for bodies certifying AI management systems, relevant to the conformity assessment of art. 43.
The practical point: none of these replaces the harmonized EN. But they are what you fill both 42001 and the future EN 18286 with, in technical substance. Art. 15 does not tell you how to measure robustness; ISO/IEC TR 24029 does. Art. 10 does not tell you how to measure data quality; the 5259 series does.
The table: where each standard sits
| Standard | Level | Subject | Status (Jul 2026) | AI Act | Presumption of conformity |
|---|---|---|---|---|---|
| EN 18286 | Management system | Quality management system for the AI Act | prEN, Enquiry stage | art. 17 | Not yet (awaiting Official Journal) |
| ISO/IEC 42001:2023 | Management system | AI Management System | Published, certifiable | general governance | No |
| ISO/IEC 42006 | Management system | Requirements for certification bodies | Published 2025 | art. 43 | No |
| ISO/IEC 23894:2023 | Technical process | AI risk management | Published | art. 9 | No |
| ISO/IEC 5259 (1-5) | Technical process | Data quality for ML | Published 2024 | art. 10 | No |
| ISO/IEC TR 24027:2021 | Technical process | Bias in AI systems | Published (TR) | art. 10, 15 | No |
| ISO/IEC TR 24029 (1-2) | Technical process | Neural network robustness | Published | art. 15 | No |
| ISO/IEC 27090 | Technical process | Cybersecurity of AI systems | Under development (2026) | art. 15 | No |
| ISO/IEC 25059:2023 | Technical process | AI quality model | Published | art. 15 | No |
| ISO/IEC 12792:2025 | Technical process | Transparency taxonomy | Published (also EN) | art. 13 | No |
| ISO/IEC 42005:2025 | Technical process | AI impact assessment | Published | art. 17, 27 | No |
| ISO/IEC 22989:2022 | Technical process | Concepts and terminology | Published | cross-cutting | No |
| ISO/IEC 5338:2023 | Technical process | Life cycle processes | Published | cross-cutting | No |
| IEEE 7000-2021 | Technical process | Value-based design | Published | cross-cutting | No |
| IEEE 7001-2021 | Technical process | Transparency of autonomous systems | Published | art. 13 | No |
| IEEE 7003-2024 | Technical process | Algorithmic bias | Published | art. 10 | No |
The column that decides everything is the last one. Only the harmonized EN, once published in the Official Journal, will move that “no” to “yes”. Everything else is quality method, not legal cover.
How to use this map
The starting mistake is getting certified to ISO/IEC 42001 thinking the AI Act is done. It is useful, it builds the skeleton, but it is half the road. The sensible sequence for an industrial manufacturer is a different one: build the management system already mapped onto art. 17, so that you can hook EN 18286 in once it becomes harmonized without redoing the work, and feed it with the right technical standards — ISO/IEC 23894 for risk, the 5259 series for data, TR 24029 and 27090 for robustness and cybersecurity, 12792 and IEEE 7001 for transparency.
The competitive leverage lies precisely in this asymmetry of timing. Whoever waits for the EN to be published before starting will arrive in the 2026-2027 window with a binder to build from scratch and the clock running. Whoever builds the AI Management System calibrated on art. 17 now arrives at the same date with the presumption of conformity within reach and the processes already validated. The difference between the two is not the standard they choose, it is when they decide which of the three levels they are working at.
Sources: CEN-CENELEC JTC 21 on prEN 18286; European Commission, AI Act standardisation; ISO/IEC 42005:2025; ISO/IEC JTC 1/SC 42; IEEE P7000 Projects.