Skip to main content

EN 18286 supporting compliance with the AI Act

21.08.2026
Alternate Text

GxSasai/Shutterstock.com

EVS-EN 18286:2026 "Artificial intelligence – Quality management system for EU AI Act regulatory purposes" specifies the requirements and provides guidance for the definition, implementation, and maintenance of a quality management system for organisations that provide AI systems.

It is not specific to any sector but forms part of a broader suite of related standards that are developed to establish a consistent and comprehensive framework for high-risk AI system deployment.

Why this standard matters 

This standard is the first of its kind, being a fundamental step to demonstrate compliance when applying a high-risk AI system. Together with the rest of the standards for high-risk AI, EVS-EN 18286 contributes to building the foundations needed for trustworthy, secure, and responsible AI across Europe.

More specifically, EVS-EN 18286 is important because it is the first harmonised European standard for the AI Act regulatory purposes, focused on the quality management system required for high-risk AI systems. It provides organisations with a concrete framework for governance, life cycle control, documentation and consistency in how AI systems are developed and maintained.

The benefits of using EN 18286

Using this standard will support an organisation in meeting applicable regulatory requirements. A high-risk AI system is an artificial intelligence application that poses significant potential harm to people's health, safety or fundamental human rights. Key examples include AI used in critical infrastructure, hiring and employment and law enforcement.

Standards on high-risk AI, such as EVS-EN 18286, are important because AI system failures or biased decisions can deeply ruin lives, deny essential public or private services and cause physical or societal harm.

EVS-EN 18286 represents a major step towards providing organisations with a practical and structured framework for implementing AI governance and demonstrating conformity with the requirements of the EU AI Act🡭.

In practice, what this means is that companies will have a clearer route to demonstrate conformity with the AI Act, especially Article 17, which sets requirements for high-risk AI providers. It also matters beyond compliance: harmonised standards create legal certainty, help turn regulation into usable engineering practice and support a more common European approach to trustworthy AI.

This is a significant milestone as it is one of the first building blocks in the broader standardisation landscape that will support the AI Act across risk management, cybersecurity, logging and other critical areas.

Source: CEN-CENELEC.