Published, but not yet a harmonised standard
EN 18286 exists, and it does not yet do the one thing the AI Act rewards a standard for doing. CEN and CENELEC approved EN 18286 "Artificial Intelligence - Quality Management System for EU AI Act Regulatory Purposes" in June 2026, and on 31 July 2026 CEN-CENELEC announced that EN 18286:2026 "has been published", calling it "the first standard in support of the implementation of the AI Act". Its draft, prEN 18286, entered public enquiry on 30 October 2025, which the Commission's standardisation page describes as the first harmonised standard for AI to reach that stage.
Publication by CEN-CENELEC and citation by the Commission are two separate acts. Article 40(1) gives the presumption of conformity only to harmonised standards "the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012". The CEN-CENELEC newsletter of 29 July 2026 states that "the European Commission is expected to publish the reference to the standard in the Official Journal of the European Union later in 2026". As at the date of this page, that reference has not been published.
The standard is not the obligation. The obligation is Article 17, and it binds every provider of a high-risk AI system through Article 16(c) whether or not EN 18286 is ever cited. If you are not yet sure your system is high-risk, settle that first with the classifier and the high-risk systems guide.
Article 17 point by point
Article 17(1) requires providers of high-risk AI systems to "put a quality management system in place that ensures compliance with this Regulation", documented "in a systematic and orderly manner in the form of written policies, procedures and instructions", and including "at least" the following aspects. The list is a floor, not a menu.
| Point | What Article 17(1) requires the system to include | Where it connects |
|---|---|---|
| (a) | A strategy for regulatory compliance, including compliance with conformity assessment procedures and procedures for managing modifications to the system | Article 43, including a new assessment on substantial modification under Article 43(4) |
| (b) | Techniques, procedures and systematic actions for design, design control and design verification | Annex IV point 2(b) design specifications |
| (c) | Techniques, procedures and systematic actions for development, quality control and quality assurance | Annex IV point 2(a) development methods |
| (d) | Examination, test and validation procedures before, during and after development, and how often they run | Article 9(6) to (8) testing, Annex IV point 2(g) |
| (e) | Technical specifications, including standards, and where harmonised standards are not applied in full or do not cover all Section 2 requirements, the means used to comply | Annex IV point 7 |
| (f) | Systems and procedures for data management, from acquisition and labelling to retention, for every data operation performed before and for the purpose of placing on the market | Article 10 |
| (g) | The risk management system referred to in Article 9 | Article 9 |
| (h) | Setting up, implementing and maintaining a post-market monitoring system in accordance with Article 72 | Article 72 |
| (i) | Procedures for reporting serious incidents in accordance with Article 73 | Article 73 |
| (j) | Handling communication with national competent authorities, other authorities, notified bodies, other operators, customers and other interested parties | Articles 20 and 21 |
| (k) | Systems and procedures for record-keeping of all relevant documentation and information | Articles 18 and 19 |
| (l) | Resource management, including security-of-supply related measures | No cross-reference in the text |
| (m) | An accountability framework setting out the responsibilities of management and other staff for every aspect above | No cross-reference in the text |
Three points carry more weight than their length suggests. Point (e) is the bridge to standards: it requires the system to record which technical specifications are applied and, wherever harmonised standards are not applied in full, the alternative means of meeting Section 2. While no AI Act standard is cited, that second limb is the one every provider is living in, and it mirrors Annex IV point 7, which the Annex IV technical documentation guide treats as a block that "converts" rather than goes blank. Point (a) makes change control a quality management duty, which matters because the Article 25 analysis in when fine-tuning makes you the provider turns on modifications. Point (i) ties the system to the incident clock set out in serious incident reporting under Article 73.
Proportionality, SMEs and small mid-caps
Article 17(2), as amended by the Digital Omnibus on AI, reads: "The implementation of the aspects referred to in paragraph 1 shall be proportionate to the size of the provider's organisation, in particular, if the provider is an SME, including a start-up, or an SMC. Providers shall, in any event, respect the degree of rigour and the level of protection required to ensure the compliance of their high-risk AI systems with this Regulation." An SMC is a small mid-cap enterprise as defined in point (2) of the Annex to Recommendation (EU) 2025/1099, under Article 3(14b).
Proportionality changes how the thirteen aspects are implemented, not whether they are. The second sentence closes off the reading that a small provider may drop an aspect, and nothing in Article 17(2) removes any of points (a) to (m).
A separate route sits in Article 63(1), also amended: SMEs, including start-ups, "may comply with certain elements of the quality management system required by Article 17 in a simplified manner", provided they have no partner enterprises or linked enterprises within the meaning of Recommendation 2003/361/EC. Which elements is left to Commission guidelines, and Article 63(2) states that the simplification does not exempt anyone from the other obligations, "including those established in Articles 9, 10, 11, 12, 13, 14, 15, 72 and 73". Note the scope difference: Article 17(2) names SMCs, Article 63(1) does not.
Two further paragraphs reshape the system for regulated sectors. Under Article 17(3), a provider already subject to quality management obligations "or an equivalent function" under sectoral Union law may include the Article 17 aspects in that existing system, and recital 81 extends the same logic to public authorities using national or regional quality systems. Under Article 17(4), a financial institution meets the obligation by complying with its internal governance rules under Union financial services law, "with the exception of paragraph 1, points (g), (h) and (i)", so risk management, post-market monitoring and incident reporting are not deemed fulfilled that way and must still meet Articles 9, 72 and 73. Article 9(10) does allow the Article 9 risk management aspects to be part of, or combined with, risk management procedures required under other Union law. The credit scoring guide covers the wider position of financial institutions.
How the Article 40 presumption would work
Once a reference is published, Article 40(1) presumes conformity "with the requirements set out in Section 2 of this Chapter ... to the extent that those standards cover those requirements". Two limits sit inside that sentence, and both matter for a quality management standard.
First, the presumption runs to the extent of coverage, nothing further. The standardisation request asks CEN and CENELEC to "describe, in each harmonised standard, the extent to which it covers one or several essential requirements" (recital 12 of Implementing Decision C(2025)3871), and the Commission uses that information when publishing a reference. What EN 18286 is presumed to cover will be fixed by its citation, not by its title.
Second, Article 40(1) speaks of Section 2 of Chapter III, which is Articles 8 to 15. Article 17 sits in Section 3. The standardisation request nonetheless asks for harmonised standards that include "detailed technical specifications of the essential requirements covered in Articles 9 to 15, and the requirements set out in Articles 17" (recital 10), and the Digital Omnibus added a subparagraph to Article 40(2) asking for deliverables to facilitate presumption of conformity with "Chapter III, Sections 2 and 3" alongside the Annex I sectoral legislation. The Regulation does not spell out how a presumption reaches Article 17 itself, so read the citation, when it comes, for exactly which provisions it lists.
This has a practical edge for biometrics. Article 43(1) lets an Annex III point 1 provider choose Annex VI internal control only where, "in demonstrating the compliance of a high-risk AI system with the requirements set out in Section 2", it has applied harmonised standards or common specifications. A quality management standard is drafted for Article 17, which sits outside Section 2, so unless its citation lists Section 2 requirements, EN 18286 alone should not be assumed to open the Annex VI route. The conformity assessment article sets out the full Article 43 logic.
The fallback does not exist either. Article 41(1) lets the Commission adopt common specifications by implementing act only where a standardisation request has failed in one of four listed ways and no reference "is expected to be published within a reasonable period". Recital 121 calls them "an exceptional fall back solution". No Article 41 common specifications have been adopted.
The standardisation request behind it
EN 18286 was written under a Commission mandate. Commission Implementing Decision C(2025)3871 of 23 June 2025 requests CEN and CENELEC to draft harmonised standards and European standardisation deliverables in support of the AI Act, and repealed the original request, Implementing Decision C(2023)3215. Recital 6 records why: CEN and CENELEC had reported "significant delays" in September 2024, and the request had to reflect the final text of the Regulation.
| Feature of C(2025)3871 | What the decision says |
|---|---|
| Addressees | CEN and CENELEC (Article 6) |
| Coverage | Articles 9 to 15 and Article 17, with deliverables also supporting Article 43 (recitals 10 and 11) |
| Drafting deadline | 31 August 2025 (Article 1(1)) |
| Final report | 31 August 2025 (Article 3(2)) |
| Expiry | 28 February 2027 (Article 5) |
| Predecessor | C(2023)3215, repealed (Article 4) |
The Commission's standardisation page lists the ten areas the request covers: risk management, governance and quality of datasets, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management and conformity assessment. Quality management is the first to produce a published standard. The drafting deadline in Article 1(1) has passed without the full set, and the request itself expires on 28 February 2027.
EN 18286 and ISO/IEC 42001
The question most teams ask first is whether an existing ISO/IEC 42001 certificate covers this. The primary sources do not answer it. Neither the CEN-CENELEC announcements, nor the Commission's standardisation page, nor C(2025)3871 states how EN 18286 relates to ISO/IEC 42001, and this page does not describe the internal clause structure of EN 18286, which no primary source cited here sets out.
What the primary sources do say is general. Article 40(3) asks participants in standardisation to take into account "existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests". The Commission's page notes that international standards, "when available and aligned with EU requirements, can become European harmonised standards", and that ISO/IEC SC 42 is developing AI standards with European participation. None of that converts an ISO/IEC 42001 certificate into an Article 17 quality management system. The test remains the thirteen points of Article 17(1), so map your existing management system against them one by one rather than relying on a certificate.
What to check now
The Article 17 obligation applies with the rest of the high-risk regime: from 2 December 2027 for standalone Annex III systems and from 2 August 2028 for Annex I embedded products under Article 113(c), as the timeline sets out. Annex VI point 2 has the provider verify "that the established quality management system is in compliance with the requirements of Article 17", and Annex VII point 3.1(d) requires an application to a notified body to include quality management documentation that "shall cover all the aspects listed under Article 17". Either way the system has to exist before the assessment. Work through these in order.
- Confirm you are a provider of a high-risk system. Article 17 binds providers. A deployer's duties sit in Article 26, as the provider versus deployer guide explains.
- Map your current quality system against points (a) to (m). Each point either has a written policy, procedure or instruction, or it is a gap. Article 17(1) asks for documents, not intentions.
- Record the point (e) position honestly. Until a standard is cited, write down which specifications you apply, including EN 18286 if you use it, and how you meet each Section 2 requirement they do not cover.
- Check which proportionality route you can use. Article 17(2) for SMEs, start-ups and SMCs. Article 63(1) only for SMEs without partner or linked enterprises, once the Commission's guidelines say which elements qualify. Article 17(3) or 17(4) if a sectoral or financial services quality regime already applies.
- Watch the Official Journal for the EN 18286 reference, and read exactly which provisions it is cited against before relying on a presumption.
- Plan retention. Article 18(1)(b) requires the quality management documentation to be kept at the disposal of national competent authorities for 10 years after the system is placed on the market or put into service.
Failing to have an Article 17 system is a breach of Article 16(c), and Article 99(4)(a) sets fines for breaches of provider obligations under Article 16 of up to EUR 15 000 000 or, for an undertaking, 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher. A cited standard would change how you prove the system complies. It does not change whether you need one.