That "AI Compliant" Badge? It May Be Waiting on a Stamp Nobody Told You About
Here's a weird one: a technical standard for AI safety can be completely finished — written, reviewed, voted on, stamped "approved" by the right European committee — and still provide no presumption of conformity under the EU AI Act. Not because the standard is bad. Because it has not yet completed the legal step that lets a company point at it and say "see, we followed the rules."
A finished EU AI safety standard isn't automatically a legal shortcut to "compliant" — it only gains that power after the European Commission formally publishes it in the Official Journal, a step that can lag months or years behind the standard being done.
That's the part almost nobody tells you when they hear the phrase "EU AI Act compliant." It sounds like a finish line. It's actually more like a relay race with an extra, invisible leg that most people don't know exists.
The Three Steps Nobody Talks About
Let's back up. The EU AI Act is Europe's big law for regulating artificial intelligence — things like facial recognition, hiring algorithms, medical AI, all of it. Like most big laws, it doesn't spell out every technical detail itself. Instead, it leans on something called a "harmonised standard" — basically a detailed rulebook, written by engineers and industry experts, that says exactly how a company can prove its AI is safe. Follow a cited standard, and the law presumes you have met the covered requirement unless proven otherwise. That's the whole appeal. It's a shortcut.
But here's where it gets interesting. That shortcut doesn't open the moment the standard is written. It opens in three separate stages, and only the last one actually counts.
Stage one is drafting. A technical group — in this case, a body called CEN-CENELEC JTC 21 — writes the actual standard. Think of this like an architect drawing up blueprints for a building. Lots of expertise goes into it. It goes through rounds of public comment ("enquiry") and formal votes. This article is part of a series — start with Biometric Binding Id Verification Explained.
Stage two is approval. Once the draft survives all that, CEN/CENELEC (Europe's official standards bodies) ratify it as a real, finished European Standard. At this point, the document is stable. It's not changing anymore. If you read it, it looks completely official — headers, version numbers, the whole bureaucratic package.
And this is exactly where people get tripped up, because stage two looks like the finish line. It has all the visual markers of "done." But legally, the standard has not yet gained presumption of conformity.
Stage three is the one that actually matters: citation in the Official Journal of the European Union. This is the EU's own version of a government registry — the place where laws and legal notices become official. Only after the European Commission reviews the standard and formally cites it there does the standard grant what's called a "presumption of conformity" — legal language for "if you followed this, we assume you're compliant unless proven otherwise." Before that citation? According to Modulos, the standard may be real and technically sound, but it does not carry that legal presumption.
Why the Gap Exists — And Why It's Longer Than You'd Guess
You might assume the Commission just rubber-stamps whatever the technical committee hands them. Nope. Once the standard reaches the Commission's desk, officials assess whether it genuinely covers what the AI Act actually requires — not just whether it's technically well-written, but whether it does the specific legal job the law needs done. They can accept it, reject it, or send it back for changes. According to the EU AI Act's own standard-setting overview, the Commission must assess the standard before its reference can be published in the Official Journal.
CEN and CENELEC were reportedly working to deliver a batch of these harmonised standards by the end of 2025. But "delivered" just means stage two — approved, finished, sitting there looking official. It doesn't mean cited. It doesn't mean legally active. A company could theoretically build its entire compliance strategy around a standard that never clears the final hurdle, or clears it a year later than expected. Previously in this series: That Verify Your Age Box 3 Very Different Amounts Of You.
Legal analysts have flagged this exact trap. As WilmerHale's analysis lays out, the presumption of conformity only attaches once the reference is published in the Official Journal — publication is the legal trigger, not the drafting or the ratification.
The Blueprint Nobody Can Pull a Permit With
Picture an architect finishing a full set of blueprints for an apartment building. Every measurement checked. Every code requirement accounted for. The design board even signs off on it. Beautiful. Except the city hasn't published it in the official permit registry yet. Until that happens, a contractor who starts pouring concrete based on those blueprints cannot rely on them as a permit defense if the city later says "actually, we want changes" — or worse, rejects the design outright.
That's the AI standards situation in a sentence. Drafting is the blueprint. Approval is the design board's signature. Citation in the Official Journal is the permit. And a lot of companies are currently pouring concrete on stage-two blueprints, hoping the permit shows up before anyone checks.
What You Just Learned
- 🧠 Finished ≠ legal — A standard can be fully drafted and ratified and still carry no presumption of conformity.
- 🔬 Three separate gates — Drafting, approval, and Official Journal citation are distinct steps, not one continuous process.
- 💡 Even citation isn't a free pass — Regulators can still challenge a company that technically followed a cited standard but missed the law's real intent.
- ⏳ The gap can be long — Citation can lag the finished standard by months or years, leaving a real compliance blind spot in between.
Where the Misconception Comes From
It's easy to see why so many people — and honestly, some companies too — read "compliant with harmonised standards" and assume the box is checked. The word "standard" already sounds official. It has committee names, version numbers, formal European branding. Nothing about it screams "this part doesn't count yet." If you saw a document with that much institutional weight behind it, you'd probably trust it too.
The mistake isn't stupidity. It's that the AI Act splits one word — "compliance" — into a process with an invisible middle step most explainers skip over. According to Adam Leon Smith's analysis, this is precisely why Official Journal citation functions as the true dividing line between a "technically sound European standard" and an actual legal compliance tool — the citation is what transforms the document's status, not its content. Up next: Your Real Id Can Still Be Used To Steal 47 Billion Heres The.
Standards currently under development by CEN-CENELEC JTC 21 will not provide presumption of conformity unless cited in the OJEU, which typically occurs months or even years after publication.
And even after citation, the presumption isn't a blanket shield. It's what lawyers call "rebuttable" — meaning a regulator can still say "you followed the letter of the standard, but not the spirit of the law," and challenge you anyway. Following a cited standard makes your life easier. It doesn't make you bulletproof.
What This Means the Next Time You See "AI Compliant"
This is where it connects to something closer to home: facial recognition tools. Say a school, an airport kiosk, or an HR platform tells you its facial-matching system is "EU AI Act compliant" because it follows an approved technical standard. That claim could be completely honest — and still be premature. The tool might be built against a standard that's finished but not yet cited, meaning it hasn't actually earned the legal presumption it's implying. That's not a lie exactly. It's a truth wearing a costume.
Here at CaraComp, this is exactly the kind of gap we spend our time untangling — because in facial recognition, the difference between "technically built to spec" and "legally proven safe" is often the whole story. A biometric system (a tool that identifies you by your face, voice, or fingerprints — the physical stuff that's uniquely yours) can look complete on a spec sheet and still rest on a document with no presumption of conformity.
"Compliant with EU AI Act standards" should make you ask one question: has this standard actually been cited in the Official Journal, or is the company just pointing at a finished-but-unofficial blueprint? If they can't answer that clearly, the label is decoration, not proof.
So next time an app, a hiring tool, or a face-scanning kiosk flashes "AI compliant" at you like a badge of honor, don't picture a finished checklist. Picture a blueprint sitting on a desk in Brussels, waiting for a stamp that hasn't landed yet — and ask the only question that actually matters: compliant with what, exactly, and has it actually been made official?
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
That Call From Your Kid? Your Ear Fails This Test Worse Than a Coin Flip
A famous voice, willingly donated to researchers, reveals why your ear can't be trusted to catch an AI clone—and the one habit that actually protects you.
privacyThat "Prove You're 18" Pop-Up: One Version Forgets You, One Keeps Your ID Forever
That pop-up asking your age isn't one standard process — it could be a face scan or a full identity handoff. Here's how to tell which one you're agreeing to.
facial-recognitionThat "95% Face Match" Could Be 1 of 500,000 Wrong Guesses
Learn why a facial recognition "match" from comparing two photos is nothing like a "match" pulled from a database of millions — and why that gap matters more than the confidence score itself.
