Harmonised standard
A harmonised standard is a technical standard developed on the basis of a Union standardisation request, whose application creates a presumption of conformity: a provider that follows it is presumed to meet the corresponding requirement. As of mid-2026, harmonised standards covering the AI Act's high-risk requirements had not yet been finalised, so the presumption of conformity is not currently available.
The rules are set out in Articles 40 and 41. The absence of a harmonised standard does not remove the obligation — the requirements of Articles 9–15 remain fully binding even without a standard — it only makes proof harder: the burden of proof falls back on the provider, who must demonstrate in the technical documentation that it independently meets the requirement level set by the Regulation. The delay stems from the standardisation request (M/593) running behind schedule: the delivery deadline was pushed from 30 April 2025 to 31 August 2025, and the standards were still not ready by then. ISO/IEC 42001 and ISO 31000 can provide a useful framework for internal processes, but neither is a harmonised standard within the meaning of the AI Act, so neither on its own creates a presumption of conformity.
Until a harmonised standard exists, a company must demonstrate compliance on its own — it is worth recording decisions and the chosen metrics in writing, since the burden of proof rests entirely with the provider.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- Conformity assessmentConformity assessment is the procedure by which a provider demonstrates that a high-risk AI system meets the requirements laid down in Section 2 of Chapter III of the Regulation — risk management, data governance, documentation, human oversight, and the rest. For systems falling under points 2–8 of Annex III, internal control suffices; involvement of a notified body is typically mandatory only for biometric systems.
- Notified bodyA notified body is an independent third party designated by a Member State to take part in the conformity assessment of certain high-risk AI systems. For systems falling under points 2–8 of Annex III — HR, education, creditworthiness assessment, essential services — internal control always suffices; a notified body is practically relevant only for biometric systems, and even there it is mandatory only in the absence of a harmonised standard.
- Risk management systemThe risk management system is a continuous, documented, testing-based process spanning the entire lifecycle of a high-risk AI system, which identifies, evaluates and mitigates the risks the system poses to the health, safety and fundamental rights of third persons. It does not manage organisational risk — it protects a different interest than ISO 31000 or ISO/IEC 42001, and neither creates a presumption of conformity, since neither is a harmonised standard.
Related questions in the knowledge base (Hungarian)
- Hogyan bizonyítható a megfelelés, ha nincsenek harmonizált AI-szabványok?A kötelezettségek harmonizált szabvány nélkül is teljes mértékben kötelezőek. A 40. cikk szerinti megfelelőségi vélelem hiánya nem magát a kötelezettséget érinti, hanem a bizonyítás módját: a bizonyítási teher a szolgáltatóra száll vissza, akinek a műszaki dokumentációban kell igazolnia, hogy eléri a 9–15. cikk követelményszintjét.
- Miért csúsztak el a magas kockázatú AI-kötelezettségek határidői?A közvetlen ok a harmonizált szabványok elmaradása: az M/593 szabványosítási kérelem szállítási határidejét 2025. április 30-ról 2025. augusztus 31-re tolták, és a szabványok akkor sem készültek el. A halasztás azonban a hatályos szövegben feltétlen — nem függ attól, megjelennek-e időben a szabványok.
- Kötelező-e tanúsított minőségirányítási rendszer, és elég-e az ISO/IEC 42001?Tanúsított rendszer nem kötelező: a 17. cikk dokumentált minőségirányítási rendszert követel, nem akkreditált tanúsítványt. Az ISO/IEC 42001 hasznos váz, de nem harmonizált szabvány, így a 40. cikk szerinti megfelelőségi vélelmet nem keletkezteti, és önmagában nem fedi le a 17. cikk (1) valamennyi pontját.