EN 18286

The first European standard published to support the EU AI Act. It exists, you can buy it, and it does not yet give anyone a presumption of conformity.

EN 18286 is the European standard for a quality management system for EU AI Act regulatory purposes. CEN-CENELEC ratified it on 12 July 2026. Because its reference has not yet appeared in the Official Journal, conformity with it does not yet carry the presumption of conformity that Article 40 provides.

Published, not yet cited

Two things happened this summer that get reported as one, and the difference between them decides whether the standard is worth anything to you legally yet.

What it is

EN 18286 is titled Artificial intelligence. Quality management system for EU AI Act regulatory purposes. It was developed by CEN-CENELEC's technical committee JTC 21, and it is built around the quality management system the Act requires of providers of high-risk AI systems at Article 17.

CEN-CENELEC ratified it on 12 July 2026, describing it as the first European standard developed to support the implementation of the EU AI Act (CEN-CENELEC on the publication of EN 18286). BSI has published it in the UK as BS EN 18286:2026 (BSI on BS EN 18286:2026).

Published is not the same as cited

This is the distinction the reporting tends to lose, and it is the whole of the practical position.

Publishing a European standard is something CEN-CENELEC and the national bodies do. Citing one in the Official Journal of the EU is something the European Commission does, separately and afterwards. Only the second turns a standard into a harmonised standard for legal purposes: Article 40 gives a presumption of conformity to systems that conform to harmonised standards whose references have been published in the Official Journal.

EN 18286's reference has not been published there. CEN-CENELEC's own note says the Commission is expected to publish it later in 2026 (CEN-CENELEC on the publication of EN 18286). Until that happens, an organisation conforming to the standard is well prepared, and cannot point at Article 40 and claim anything from it.

Why you may see a 2027 date attached to it

European standards carry two dates and they are easy to mix up. The date of ratification is when CEN-CENELEC approved the text, which for EN 18286 was 12 July 2026. A later date, usually around six months afterwards, is the deadline by which every national standards body has to publish an identical national standard and withdraw any conflicting ones.

That second date is an administrative deadline for the national bodies, not a sign that the standard is still pending. BSI met it within a fortnight. If you see a 2027 date next to EN 18286, that is what it refers to, and it says nothing about whether the standard exists or when the Official Journal citation might come.

How it sits next to ISO 42001

They do different jobs and neither replaces the other. ISO/IEC 42001 is an international management system standard for governing AI across an organisation, and an accredited body can certify you against it (ISO/IEC 42001:2023). EN 18286 is European, and it is written around a specific legal requirement in a specific regulation.

CEN-CENELEC's own framing is that EN 18286 complements other standards and technical specifications covering areas such as risk management, data governance, transparency, cybersecurity, accuracy and post-market monitoring (CEN-CENELEC on the publication of EN 18286). That is worth taking at face value: it is the quality management layer, not a whole governance system.

None of this changes the position on certification. The EU AI Office determined in May 2024 that ISO 42001 is not fully aligned with the Act and is not part of its harmonisation process (Cloud Security Alliance research note on prEN 18286), so an ISO 42001 certificate remains useful evidence of good governance and not a route to compliance. The standard-versus-Act guide works through that in full.

What is coming, and what to do now

EN 18286 is the first and so far the only European standard published in support of the Act. Further standards covering other obligations under it are in development at JTC 21.

For most organisations there is nothing urgent here. If you provide a high-risk AI system, or expect to, the standard is now readable and is the clearest available statement of what the Act's quality management duty is taken to mean in practice, which makes it useful for preparation whatever the Official Journal does next. If you are a deployer rather than a provider, this one is not aimed at you, and the risk assessment guide covers which duties are.

The thing to watch for is the citation, not another publication announcement. When the reference appears in the Official Journal, the legal position changes and this page changes with it.

Common questions

Has EN 18286 been published?
Yes. CEN-CENELEC ratified it on 12 July 2026, the first European standard published to support the EU AI Act, and BSI has issued it in the UK as BS EN 18286:2026.
Does conforming to EN 18286 make you compliant with the EU AI Act?
Not yet, and not by itself. A harmonised standard gives a presumption of conformity only once its reference has been published in the Official Journal of the EU, and EN 18286 has not been cited there. The Commission is expected to publish the reference later in 2026.
Does EN 18286 replace ISO 42001?
No. They are built for different jobs. ISO 42001 is an international management system standard for governing AI across an organisation, and it is certifiable. EN 18286 is a European standard written around the quality management system the EU AI Act requires of providers of high-risk systems. CEN-CENELEC describes it as complementing other standards rather than replacing them.