The First AI Act Standard Landed, and It Stops Short of Article 72
EN 18286:2026 was approved on 12 July 2026 and is the first European standard supporting the EU AI Act to reach publication. Annex ZA covers Article 17(1) and the first sentence of Article 11(1), and nothing else. The remaining subsections of Article 17 and the whole of Article 72 sit outside it, and the reference is not in the Official Journal yet, so the presumption of conformity is not available to anyone today.
EN 18286:2026, Artificial Intelligence, Quality management system for EU AI Act regulatory purposes, was approved by CEN-CENELEC on 12 July 2026 and has now been published. It is the first European standard developed in support of the AI Act to reach that milestone, which makes it the most consequential compliance document of the year for anyone placing a high risk AI system on the European market. We wrote in August that the standard was sitting at formal vote and that ISO 42001 certificate holders were assuming a shield they did not have. The first half of that has changed. The second half has not, and the reason why is buried in an annex that most of the coverage this week has not opened.
Start with the mechanism, because it governs everything else. Article 40(1) of the AI Act grants a presumption of conformity only to systems that conform to harmonised standards, or parts of them, whose references have been published in the Official Journal of the European Union. Approval by CEN-CENELEC is not that publication. Assessment by the Commission and citation in the Official Journal is a separate act that follows, and as of today EN 18286:2026 has not been cited. What exists right now is a well drafted 51 page European standard with national status across the CEN membership, which is genuinely useful and is not a legal shield. If a sales team is already writing that you conform to the harmonised standard for Article 17, that sentence is wrong in a way a regulator or a buyer counsel can check in about thirty seconds.
The shape of the document is worth knowing before you buy a copy. The normative content runs across clauses 4 to 10 and groups into four movements: govern, covering the quality management system itself, leadership, planning and support; realise, which is the large clause 8 covering the AI system lifecycle, risk management, design, verification and validation, data, continuous learning, identification, retirement and documentation; operate, covering placing on the market, the supply chain, monitoring, incidents and handling non compliance; and evaluate, covering management review and change planning. Adam Leon Smith, who sat in the drafting work, has described it as a deliberate architectural break from ISO 9001 and from EN ISO/IEC 42001. That phrase is the practical headline for most readers of this site. It means the document was not written so that your existing management system maps onto it cleanly, and anyone budgeting for an inheritance exercise rather than a mapping exercise has budgeted wrong.
Now the part that actually matters. Annex ZA is the table that tells you which legal requirements conformity to the standard will be deemed to satisfy once the citation lands, and its scope is narrower than the marketing around this standard suggests. Table ZA.1 covers Article 17(1), the quality management system duty with its list of elements running from the regulatory compliance strategy through design control, data management, testing, post market monitoring arrangements, incident reporting, communication with authorities, record keeping and the accountability framework. It also covers the first sentence of Article 11(1), which is the duty to draw up technical documentation before the system goes on the market. That is the whole of the coverage. The remaining subsections of Article 17 are not in it, and Article 72 is not in it either.
Article 72 is the post market monitoring obligation: the requirement to establish and document a monitoring system proportionate to the nature and risks of the system, and to operate it against a monitoring plan that forms part of the technical documentation. Read the two facts together and the consequence is specific. Article 17(1) requires that your quality management system include arrangements for post market monitoring, and conformity with EN 18286 will eventually be deemed to satisfy that. Article 72 requires that the monitoring system actually exist, be documented to the shape the Commission prescribes, and run. No harmonised standard currently offers a presumption for the second thing. You can be deemed to have the arrangements and still carry the full burden of proving the substance. When we mapped where evidence goes missing in AI governance programmes back in the ISO 42001 gap piece, the three clusters were post market monitoring, technical documentation kept current rather than written once, and traceability from a model version to the dataset and test results behind it. Annex ZA has now formally confirmed that the first of those sits outside the harmonised route, and the restriction to the first sentence of Article 11(1) means the second is only partly inside it.
The timing is tighter than it looks, and it is the argument against waiting. After the AI Omnibus political agreement of 7 May 2026, obligations for certain high risk systems apply from 2 December 2027, with AI embedded in regulated products such as lifts and toys following on 2 August 2028. That is roughly fourteen months from today for the first cohort. Nobody can tell you when the Official Journal citation for EN 18286 will appear, because the Commission assessment has no published deadline and the standard has to be judged as adequately covering the requirement before it can be cited. Building a programme on the assumption that the citation arrives early enough to be your compliance plan is a bet on an administrative process with no clock on it. Building the Article 17(1) evidence now, against a standard you can read today, converts the citation from a dependency into a bonus.
The framework mapping is more nuanced than the usual inheritance story, which is precisely why the architectural break matters. ISO 42001 remains the right lower layer and we have argued that consistently: it gives you the AI inventory with named owners, the impact assessment habit, lifecycle controls, supplier due diligence and incident handling, and none of that is wasted. What it does not do is discharge Article 17, because the Commission assessed 42001 against that requirement, found the goals and definitions were not aligned, and commissioned a bespoke standard instead, which is the document that just published. Treat EN 18286 as a complement that sits on top rather than a replacement underneath. ISO 27001 continues to carry the security half of the picture and feeds Article 15. SOC 2 is the framework that asks whether your controls operated across a period rather than on the day of the walkthrough, which is the right question for post market monitoring and the one you will be asked hardest. PCI DSS enters only if the system touches cardholder scope. Vanta, Drata, Secureframe, Sprinto, Thoropass and Hyperproof will all race to ship a mapped EN 18286 framework, and history says that mapping arrives within weeks of a citation and not meaningfully before it, because until then there is nothing to certify against and no auditor demand to serve. None of them will write your post market monitoring plan, because that artefact depends on knowing what your system does when it degrades, and only the team that built it knows that.
The work for this quarter is four things and they are all cheap while there is no deadline attached. Obtain the standard through your national body and read clause 8 and clause 9 properly, because that is where the delta against your current management system lives. Build the Article 17(1) map: lay your existing ISO 42001 Annex A evidence against the eleven elements in that subsection and record honestly which ones you could evidence to an assessor tomorrow and which ones you could only describe. Then open Article 72 as its own workstream, separate from the standards work, on the explicit understanding that no harmonised document is coming to carry it for you, and that a monitoring plan attached to a technical file is an engineering artefact rather than a policy. Finally, fix your external language: the accurate and defensible sentence is that you hold ISO 42001, that you are building against EN 18286:2026, and that you will claim presumption of conformity when and only when the reference is cited in the Official Journal. The ISO 42001 and ISO 27001 guides on this site cover the control families this work belongs in, the compliance readiness assessment will show you which of them you can currently evidence, and the policy templates library has the quality management and post market monitoring clauses to hang it on.
Editorial note: AES Tech reviews are independent. Some outbound links are affiliate links and are marked sponsored; they never change our rankings. See our disclosure.
Get the next post by email
One short email when something worth knowing ships. No spam, unsubscribe anytime.
Comments
Moderation policyLoading comments...
Add a comment
Corrections and first-hand experience are the most useful things you can leave. Comments are screened automatically and reviewed by a human; see the moderation policy.