EU AI Act Official Journal Rules: The Legal Gate Explained
Here's a weird one: a technical standard for AI safety can be completely finished — written, reviewed, voted on, stamped "approved" by the right European committee — and still provide no presumption of conformity under the EU AI Act. Not because the standard is bad. Because it has not yet completed the legal step that lets a company point at it and say "see, we followed the rules."
A finished EU AI safety standard isn't automatically a legal shortcut to "compliant" — it only gains that power after the European Commission formally publishes it in the Official Journal, a step that can lag months or years behind the standard being done.
That's the part almost nobody tells you when they hear the phrase "EU AI Act compliant." It sounds like a finish line. It's actually more like a relay race with an extra, invisible leg that most people don't know exists.
The Three Steps of EU AI Act Standards Compliance
Let's back up. The EU AI Act is Europe's big law for regulating artificial intelligence — things like facial recognition, hiring algorithms, medical AI, all of it. Like most big laws, it doesn't spell out every technical detail itself. Instead, it leans on something called a "harmonised standard" — basically a detailed rulebook, written by engineers and industry experts, that says exactly how a company can prove its AI is safe. Follow a cited standard, and the law presumes you have met the covered requirement unless proven otherwise. That's the whole appeal. It's a shortcut.
But here's where it gets interesting. That shortcut doesn't open the moment the standard is written. It opens in three separate stages, and only the last one actually counts.
Stage one is drafting. A technical group — in this case, a body called CEN-CENELEC JTC 21 — writes the actual standard. Think of this like an architect drawing up blueprints for a building. Lots of expertise goes into it. It goes through rounds of public comment ("enquiry") and formal votes. This article is part of a series — start with Biometric Binding Id Verification Explained.
Stage two is approval. Once the draft survives all that, CEN/CENELEC (Europe's official standards bodies) ratify it as a real, finished European Standard. At this point, the document is stable. It's not changing anymore. If you read it, it looks completely official — headers, version numbers, the whole bureaucratic package.
And this is exactly where people get tripped up, because stage two looks like the finish line. It has all the visual markers of "done." But legally, the standard has not yet gained presumption of conformity.
Stage three is the one that actually matters: citation in the Official Journal of the European Union. This is the EU's own version of a government registry — the place where laws and legal notices become official. Only after the European Commission reviews the standard and formally cites it there does the standard grant what's called a "presumption of conformity" — legal language for "if you followed this, we assume you're compliant unless proven otherwise." Before that citation? According to Modulos, the standard may be real and technically sound, but it does not carry that legal presumption.
Why the Official Journal Gap Exists — And Why It's Longer
You might assume the Commission just rubber-stamps whatever the technical committee hands them. Nope. Once the standard reaches the Commission's desk, officials assess whether it genuinely covers what the AI Act actually requires — not just whether it's technically well-written, but whether it does the specific legal job the law needs done. They can accept it, reject it, or send it back for changes. According to the EU AI Act's own standard-setting overview, the Commission must assess the standard before its reference can be published in the Official Journal.
CEN and CENELEC were reportedly working to deliver a batch of these harmonised standards by the end of 2025. But "delivered" just means stage two — approved, finished, sitting there looking official. It doesn't mean cited. It doesn't mean legally active. A company could theoretically build its entire compliance strategy around a standard that never clears the final hurdle, or clears it a year later than expected. Previously in this series: That Verify Your Age Box 3 Very Different Amounts Of You.
Legal analysts have flagged this exact trap. As WilmerHale's analysis lays out, the presumption of conformity only attaches once the reference is published in the Official Journal — publication is the legal trigger, not the drafting or the ratification.
The Blueprint Nobody Can Pull a Permit With
Picture an architect finishing a full set of blueprints for an apartment building. Every measurement checked. Every code requirement accounted for. The design board even signs off on it. Beautiful. Except the city hasn't published it in the official permit registry yet. Until that happens, a contractor who starts pouring concrete based on those blueprints cannot rely on them as a permit defense if the city later says "actually, we want changes" — or worse, rejects the design outright.
That's the AI standards situation in a sentence. Drafting is the blueprint. Approval is the design board's signature. Citation in the Official Journal is the permit. And a lot of companies are currently pouring concrete on stage-two blueprints, hoping the permit shows up before anyone checks.
What You Just Learned
- 🧠 Finished ≠ legal — A standard can be fully drafted and ratified and still carry no presumption of conformity.
- 🔬 Three separate gates — Drafting, approval, and Official Journal citation are distinct steps, not one continuous process.
- 💡 Even citation isn't a free pass — Regulators can still challenge a company that technically followed a cited standard but missed the law's real intent.
- ⏳ The gap can be long — Citation can lag the finished standard by months or years, leaving a real compliance blind spot in between.
Where the Misconception Comes From
It's easy to see why so many people — and honestly, some companies too — read "compliant with harmonised standards" and assume the box is checked. The word "standard" already sounds official. It has committee names, version numbers, formal European branding. Nothing about it screams "this part doesn't count yet." If you saw a document with that much institutional weight behind it, you'd probably trust it too.
The mistake isn't stupidity. It's that the AI Act splits one word — "compliance" — into a process with an invisible middle step most explainers skip over. According to Adam Leon Smith's analysis, this is precisely why Official Journal citation functions as the true dividing line between a "technically sound European standard" and an actual legal compliance tool — the citation is what transforms the document's status, not its content. Up next: Your Real Id Can Still Be Used To Steal 47 Billion Heres The.
Standards currently under development by CEN-CENELEC JTC 21 will not provide presumption of conformity unless cited in the OJEU, which typically occurs months or even years after publication.
And even after citation, the presumption isn't a blanket shield. It's what lawyers call "rebuttable" — meaning a regulator can still say "you followed the letter of the standard, but not the spirit of the law," and challenge you anyway. Following a cited standard makes your life easier. It doesn't make you bulletproof.
What Conformity Proof Actually Requires
This is where it connects to something closer to home: facial recognition tools. Say a school, an airport kiosk, or an HR platform tells you its facial-matching system is "EU AI Act compliant" because it follows an approved technical standard. That claim could be completely honest — and still be premature. The tool might be built against a standard that's finished but not yet cited, meaning it hasn't actually earned the legal presumption it's implying. That's not a lie exactly. It's a truth wearing a costume.
Here at CaraComp, this is exactly the kind of gap we spend our time untangling — because in facial recognition, the difference between "technically built to spec" and "legally proven safe" is often the whole story. A biometric system (a tool that identifies you by your face, voice, or fingerprints — the physical stuff that's uniquely yours) can look complete on a spec sheet and still rest on a document with no presumption of conformity.
"Compliant with EU AI Act standards" should make you ask one question: has this standard actually been cited in the Official Journal, or is the company just pointing at a finished-but-unofficial blueprint? If they can't answer that clearly, the label is decoration, not proof.
So next time an app, a hiring tool, or a face-scanning kiosk flashes "AI compliant" at you like a badge of honor, don't picture a finished checklist. Picture a blueprint sitting on a desk in Brussels, waiting for a stamp that hasn't landed yet — and ask the only question that actually matters: compliant with what, exactly, and has it actually been made official?
Provider Obligations Under the AI Act
Provider obligations are the specific duties that fall on the company building or placing an AI system on the market, as opposed to the company just deploying it. Under the EU AI Act, a provider has to keep technical documentation, register certain high-risk systems, and be ready to show that the ai act requirements were actually met — not just claimed. This matters for the standards gap discussed above, because a provider pointing at an uncited standard is still on the hook for proving conformity some other way if the citation never lands in time.
Risk Management Duties for AI Systems
Risk management under the AI Act isn't a one-time checklist — it's supposed to be a continuous process that runs across the life of the ai system, from design through deployment and monitoring. A provider has to identify foreseeable risks, test for them, and update the system as new risks show up in the real world. For a facial recognition tool, that could mean re-testing accuracy across different lighting or skin tones as new data comes in, not just once before launch.
Human Oversight Requirements Explained
Human oversight means a real person has to be able to understand, monitor, and if necessary override what the ai system is doing — the law does not let a provider just switch on an ai and walk away. For high-risk uses like hiring or biometric identification, this usually means a trained person reviewing flagged decisions before they take effect. The AI Act treats this as a safeguard against the system quietly making a call nobody actually checked.
Conformity Assessment Before Market Entry
Conformity assessment is the formal process a provider goes through to show, on paper, that an ai system meets the act's requirements before it can legally go on the EU market. Depending on the risk category, this can be a self-assessment or it can require an outside notified body to check the work. This is exactly where a cited harmonised standard becomes useful — it gives the provider a template for what "meeting requirements" is supposed to look like, rather than guessing.
Transparency Obligations for AI Providers
Transparency obligations require that people be told, in plain terms, when they are interacting with an ai system rather than a human, and that certain ai-generated content be labeled as such. For a chatbot or an ai-driven customer service tool, this can be as simple as a disclosure line at the start of the conversation. The point is that a person should not have to guess whether an ai is making the decision that affects them.
Risk Classification: Minimal, Limited, High, and No Risk
The AI Act sorts systems into risk tiers, and the obligations above scale up or down depending on which tier an ai system lands in. A minimal or no risk tool, like a spam filter, carries almost none of the heavier requirements, while a high-risk system, like one used in hiring or law enforcement, carries nearly all of them. Knowing which bucket a given ai system falls into is often the first practical step in figuring out what compliance actually requires.
The Role of the AI Office in Enforcement
The AI Office is the EU body set up to help coordinate enforcement and guidance across member states, rather than leaving every question to be answered country by country. It works alongside national regulators on things like reviewing high-risk systems and clarifying open questions about how the rules apply in practice. For companies trying to figure out eu ai act compliance requirements, the AI Office is increasingly the place official guidance is expected to come from.
Governance Structures That Support Compliance
Good AI governance inside a company usually means someone specific owns the compliance file — tracking which systems exist, what risk tier each falls into, and whether documentation is current. Without that kind of internal structure, it's easy for a company to lose track of which ai systems even need a conformity assessment in the first place. Governance is less glamorous than the legal text itself, but it's often the difference between meeting requirements on paper and actually meeting them in practice.
Prohibited Practices the AI Act Rules Out
Prohibited practices are the small list of ai uses the AI Act bans outright, rather than just regulating with paperwork — things like certain kinds of manipulative ai or untargeted scraping of faces to build a biometric database. Unlike high-risk systems, which can go to market once a provider clears documentation and conformity assessment, a prohibited practice cannot be fixed with better paperwork. If an ai system falls into this bucket, no amount of transparency obligations or human oversight brings it back into legal territory — the rules treat it as off-limits from the start.
How Artificial Intelligence Gets Defined Under the Act
Before any of the other rules apply, the AI Act has to settle what actually counts as artificial intelligence in the first place, since not every piece of software with an "ai" label meets the legal definition. The act's definition focuses on systems that infer outputs — predictions, decisions, recommendations — from inputs, rather than just running a fixed set of if-then instructions. This matters practically because a provider cannot be held to ai act requirements for a tool that does not actually meet the act's own definition of an ai system, even if it is marketed as one.
Data Governance Rules for High-Risk AI Systems
Data governance rules require that the data used to train, validate, and test a high-risk ai system be relevant, reasonably complete, and checked for errors that could skew outcomes. For a hiring or lending ai system, this means looking at whether the training data actually represents the population the system will affect, not just whichever dataset was easiest to collect. Weak data governance is one of the most common ways an otherwise well-built ai system ends up producing biased or unreliable results downstream.
Documented Quality Management Systems (QMS) Under the Act
A documented quality management system, or QMS, is the internal paperwork trail a provider keeps to show how it designs, tests, monitors, and updates its high-risk ai systems over time. Regulators use it to check whether a provider's conformity assessment reflects an actual ongoing process rather than a one-time exercise before launch. A gap in the documented quality management system is often the first thing an auditor flags, because it signals the rest of the compliance work may not be as solid as it looks on paper.
Setting Minimal-Risk AI Apart From High-Risk Systems
Deciding where a given ai system sits on the AI Act's risk scale is often the first real compliance decision a provider makes, because it determines almost everything else — whether conformity assessment applies, whether transparency obligations kick in, and how much documentation is required. A minimal risk classification means most of the act's heavier requirements simply do not apply, which is why getting that initial classification right matters so much. Getting it wrong in either direction either creates unnecessary paperwork or, worse, leaves a genuinely high-risk ai system operating without the oversight the law actually requires.
How the European Parliament Shaped the Final Act
The European Parliament was one of the three bodies that negotiated the final text of the AI Act, pushing for stronger protections around biometric surveillance and high-risk ai systems during the trilogue talks with the Council and the European Commission. Some of the provisions on prohibited practices and transparency obligations trace directly back to amendments the European Parliament insisted on before the act was finalized. Understanding that history helps explain why certain sections of the act read more like a compromise than a single clean policy.
Reading the Act Articles That Define Obligations
The act articles that set out provider obligations, risk classification, and conformity assessment are where the practical compliance work actually lives, as opposed to the recitals at the front of the text, which mostly explain intent. A provider trying to figure out what applies to a specific ai system usually ends up cross-referencing several act articles at once, since obligations for a high-risk system are rarely contained in a single place. This is part of why a plain-English act summary, paired with the actual act articles, tends to be more useful in practice than reading either one alone.
Where to Find an Act Summary Before Reading the Full Text
An act summary is useful as a first pass, giving a provider or a curious reader the shape of the law — risk tiers, prohibited practices, provider obligations — before wading into the full legal text. It's not a substitute for the act articles themselves when a real compliance decision is on the line, since a summary necessarily leaves out edge cases and definitions that matter in practice. Treating an act summary as a map rather than the territory is the safest way to use one.
How Act Obligations Differ by Role in the AI Supply Chain
Act obligations don't fall equally on everyone touching an ai system — a provider building the system carries a different set of duties than a deployer just using it in a workplace or a distributor simply reselling it. Knowing which role applies is often the first step in figuring out which act obligations actually attach to a given company, since the same ai system can trigger different duties depending on who is handling it and how. This role-based structure is one reason two companies using the same tool can have very different compliance checklists.
Competent Authorities and Their Enforcement Role
Competent authorities are the national bodies each EU member state designates to enforce the AI Act on the ground, handling things like market surveillance and investigating complaints about a specific ai system. These competent authorities work alongside the AI Office at the EU level, but day-to-day enforcement — inspections, corrective orders, penalties — mostly runs through them rather than through Brussels directly. A provider operating across several member states may end up dealing with more than one set of competent authorities, since each country's authority enforces the same act text within its own borders.
Tracking Act Implementation Across Member States
Act implementation isn't instant across the EU — different provisions of the AI Act come into force on a staggered timeline, and member states have had to stand up their own competent authorities and enforcement structures to match. This staggered act implementation means a provider's compliance deadline can depend on which specific obligation is at issue, not just a single overall date. Watching how act implementation unfolds in practice, rather than just reading the text, is often the only way to know whether a given requirement is actually being enforced yet.
Consulting an Act Database for Cited Standards
An act database that tracks which harmonised standards have actually been cited in the Official Journal is one of the more practical tools a provider can use, since it answers the exact question this article keeps circling back to: has a given standard cleared stage three or not. Without checking an act database or the Official Journal directly, a provider is left trusting a standard's own paperwork, which — as covered above — can look finished without actually being cited yet. This is a small, checkable step that turns a legal question into a factual one.
How Act Regulation Interacts with National Law
Act regulation works as an EU-wide regulation rather than a directive, which means it applies directly in every member state without needing separate national laws to adopt it first. That said, act regulation still leaves room for competent authorities and national rules to fill in enforcement details, so a provider can face slightly different practical requirements depending on where in the EU it operates. Understanding that the core act regulation is uniform, even while enforcement detail varies, helps explain why compliance can look a little different from one member state to the next.
Frequently asked questions
What are the eu ai act compliance requirements for using a harmonised standard?
A harmonised standard only satisfies eu ai act compliance requirements once the European Commission formally cites it in the Official Journal of the European Union. Drafting by the technical committee and ratification by CEN/CENELEC are earlier stages, but neither grants presumption of conformity on their own. Only Official Journal citation legally triggers that presumption.
Is a finished EU AI safety standard automatically legally compliant?
No. A standard can be fully written, reviewed, voted on, and ratified by CEN/CENELEC while still lacking presumption of conformity. That legal status only attaches after the European Commission assesses the standard and formally cites it in the Official Journal, which is a separate and later step than finishing the draft.
How long can the gap be between a finished AI standard and legal compliance status?
The gap between a standard being finished and formally cited in the Official Journal can last months or years. CEN and CENELEC were reportedly working to deliver standards by the end of 2025, but delivery only means approval, not citation, so companies relying on approved-but-uncited standards face a real compliance blind spot.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
UK Digital Identity: 275 Firms Face One New Rulebook
A green checkmark that says "verified" doesn't mean much on its own. Here's what the UK's new digital identity rulebook actually forces companies to prove—and what it teaches you about trusting any identity check.
privacyIllinois BIPA: Court Says a Recorded Voice Is Now a Face Scan
A federal court just ruled that Meta can't dodge a lawsuit over voiceprints — and the reason why teaches something wild about how privacy law treats your voice.
biometricsBiometric Machine: Iowa Medics Get $16,510 Drug Lock
A small Iowa fire district's new fingerprint-locked medication cabinet reveals a surprising truth about biometric machines: they're not built to slow you down, they're built to prove who acted fast.
