This document specifies the requirements and provides guidance for the definition, implementation and maintenance of a quality management system for organizations that provide AI systems.
This document is intended to support the organization in meeting applicable regulatory requirements. It is primarily intended for organizations placing on the market or putting into service high-risk AI systems and is not specific to any particular sector.

  • Standard
    51 pages
    English language
    e-Library read for
    1 day

This document specifies the requirements and provides guidance for the definition, implementation and maintenance of a quality management system for organizations that provide AI systems.
This document is intended to support the organization in meeting applicable regulatory requirements. It is primarily intended for organizations placing on the market or putting into service high-risk AI systems and is not specific to any particular sector.

  • Standard
    51 pages
    English language
    e-Library read for
    1 day

This document provides terminology, concepts, requirements, and guidance for humanoversight of AI systems. It is primarily intended for organizations placing on the market or putting into service AI systems and is not specific to any particular sector;

  • Draft
    29 pages
    English language
    e-Library read for
    1 day

This document describes a taxonomy of the AI tasks related to computer vision. It includes AI tasks pertaining to either the analysis or generation of images and videos.

  • Draft
    30 pages
    English language
    e-Library read for
    1 day

This document provides terminology, concepts, requirements, and guidance for logging of AI systems.
It is primarily intended for organizations placing on the market or putting into service AI systems and is not specific to any particular sector.

  • Draft
    21 pages
    English language
    e-Library read for
    1 day

This document specifies requirements and provides guidance for risk management of AI systems. It specifies terminology, principles and a process for risk management.
The process described in this document intends to assist providers of AI systems to identify the hazards associated with the AI systems, to estimate and evaluate the associated risks, to control these risks, and to monitor the effectiveness of the controls. The process described in this document applies to risks to health, safety and fundamental rights associated with an AI system. The process described in this document is applied throughout the life cycle of the AI system.
This document requires providers to establish objective criteria for risk acceptability but does not specify acceptable risk levels.
This document is intended for use by organizations providing AI systems, regardless of their size, nature or location. This document is not intended for managing risk faced by organizations. This document is intended to support the organization in meeting applicable regulatory requirements.

  • Draft
    71 pages
    English language
    e-Library read for
    1 day

This document specifies the evaluation of computer vision systems, in the sense of measuring the quality of a system’s results to
assess its functional suitability. It provides a definition of evaluation methods for those systems, together with guidance on how to
select, implement and interpret those evaluation methods. This document covers quantitative metrics as well as other evaluation
methods. It includes requirements on the implementation of the described metrics, and further requirements on the technical
resources involved in the evaluation process.

  • Draft
    56 pages
    English language
    e-Library read for
    1 day

This document describes common capabilities, requirements and a supporting information model for logging of events in AI systems.
This document is designed to be used with a risk management system.

  • Draft
    26 pages
    English language
    e-Library read for
    1 day

This document addresses organizational and technical solutions aimed at ensuring the cybersecurity of high-risk AI systems over the life cycle, appropriate to the relevant circumstances and the risks. The technical solutions to address AI-specific vulnerabilities include, where appropriate, measures to prevent, detect, respond to, resolve and control for attacks trying to manipulate the training dataset (data poisoning), or pre-trained components used in training (model poisoning), inputs designed to cause the model to make a mistake (adversarial examples or model evasion), confidentiality attacks or model flaws. This document provides objective criteria to enable decisions on whether a given technical or organizational solution adequately achieves a given vulnerability-related goal.

  • Draft
    55 pages
    English language
    e-Library read for
    1 day

This document provides terminology, concepts, requirements, and guidance for humanoversight of AI systems. It is primarily intended for organizations placing on the market or putting into service AI systems and is not specific to any particular sector;

  • Draft
    29 pages
    English language
    e-Library read for
    1 day

This document provides terminology, concepts, requirements, and guidance for logging of AI systems.
It is primarily intended for organizations placing on the market or putting into service AI systems and is not specific to any particular sector.

  • Draft
    21 pages
    English language
    e-Library read for
    1 day

This document addresses organizational and technical solutions aimed at ensuring the cybersecurity of high-risk AI systems over the life cycle, appropriate to the relevant circumstances and the risks. The technical solutions to address AI-specific vulnerabilities include, where appropriate, measures to prevent, detect, respond to, resolve and control for attacks trying to manipulate the training dataset (data poisoning), or pre-trained components used in training (model poisoning), inputs designed to cause the model to make a mistake (adversarial examples or model evasion), confidentiality attacks or model flaws. This document provides objective criteria to enable decisions on whether a given technical or organizational solution adequately achieves a given vulnerability-related goal.

  • Draft
    55 pages
    English language
    e-Library read for
    1 day

This document specifies requirements and provides guidance for risk management of AI systems. It specifies terminology, principles and a process for risk management.
The process described in this document intends to assist providers of AI systems to identify the hazards associated with the AI systems, to estimate and evaluate the associated risks, to control these risks, and to monitor the effectiveness of the controls. The process described in this document applies to risks to health, safety and fundamental rights associated with an AI system. The process described in this document is applied throughout the life cycle of the AI system.
This document requires providers to establish objective criteria for risk acceptability but does not specify acceptable risk levels.
This document is intended for use by organizations providing AI systems, regardless of their size, nature or location. This document is not intended for managing risk faced by organizations. This document is intended to support the organization in meeting applicable regulatory requirements.

  • Draft
    71 pages
    English language
    e-Library read for
    1 day

This document describes a taxonomy of the AI tasks related to computer vision. It includes AI tasks pertaining to either the analysis or generation of images and videos.

  • Draft
    30 pages
    English language
    e-Library read for
    1 day

This document specifies the evaluation of computer vision systems, in the sense of measuring the quality of a system’s results to
assess its functional suitability. It provides a definition of evaluation methods for those systems, together with guidance on how to
select, implement and interpret those evaluation methods. This document covers quantitative metrics as well as other evaluation
methods. It includes requirements on the implementation of the described metrics, and further requirements on the technical
resources involved in the evaluation process.

  • Draft
    56 pages
    English language
    e-Library read for
    1 day

This document describes common capabilities, requirements and a supporting information model for logging of events in AI systems.
This document is designed to be used with a risk management system.

  • Draft
    26 pages
    English language
    e-Library read for
    1 day

Frequently Asked Questions

An EU Regulation is a binding legislative act that must be applied in its entirety across the European Union. Unlike directives, regulations do not need to be transposed into national law and are directly applicable in all member states. Regulations are used when uniform application across all EU countries is essential.

Regulation 2024/1689 covers "EU AI Act". There are 16 standards associated with this regulation.

Harmonized standards under 2024/1689 are European standards (ENs) developed by CEN, CENELEC, or ETSI in response to a mandate from the European Commission. When these standards are cited in the Official Journal of the European Union, products manufactured in conformity with them benefit from a presumption of conformity with the essential requirements of 2024/1689, facilitating CE marking and free movement within the European Economic Area.