The EU AI Act establishes a tiered compliance architecture in which providers of high-risk AI systems must demonstrate conformity before placing their products on the market. The most efficient route to that demonstration is through harmonised standards: European standards developed by CEN, CENELEC, or ETSI at the European Commission's request, whose references are published in the Official Journal of the European Union (OJEU). Conformity with a published harmonised standard creates a legal presumption that the corresponding requirements of the AI Act are met. For fashion AI teams building systems that touch employment screening, biometric categorisation, or critical infrastructure, this mechanism is not optional reading—it is the compliance backbone. The problem is that most of the relevant standards do not yet exist.
Key takeaways
- Conformity with a harmonised standard published in the OJEU creates a legal presumption of conformity with the AI Act requirements that standard covers.
- CEN and CENELEC are the bodies mandated to develop these standards, but the majority of AI-specific harmonised standards remain in draft or have not yet been commissioned.
- Fashion AI systems can fall into high-risk categories depending on how they are used—particularly in recruitment, workforce management, or biometric processing.
- While standards are absent, teams must rely on existing technical specifications, voluntary frameworks, and documented internal governance to build an auditable compliance record.
- The European Commission issued draft guidelines on high-risk classification in 2026, which affect how fashion AI providers should self-assess their systems.
What is a harmonised standard and why does it matter under the AI Act?
A harmonised standard is a European standard developed by a recognised European Standards Organisation—CEN, CENELEC, or ETSI—following a formal standardisation request (mandate) from the European Commission. Its defining legal feature is publication of its reference in the OJEU. That publication triggers the presumption of conformity: a manufacturer or provider who applies a harmonised standard in full is presumed to comply with the legislative requirements that standard covers, without needing to prove conformity by other means.
Under the AI Act, the same logic applies. Providers of high-risk AI systems who follow a published harmonised standard covering, for example, risk management, data governance, or transparency requirements are presumed to have met those obligations. This shifts the evidentiary burden: instead of constructing a bespoke compliance argument from first principles, the provider points to the standard, documents its implementation, and the presumption holds unless a supervisory authority can demonstrate otherwise.
For a fashion technology team, this is significant. The alternative—demonstrating conformity without a harmonised standard—requires assembling evidence across multiple requirements simultaneously, with no single authoritative benchmark to anchor the argument. Auditors, notified bodies, and national market surveillance authorities each bring their own interpretive frameworks. Harmonised standards eliminate that ambiguity, at least for the requirements they cover.
Which AI Act requirements are subject to harmonised standards?
The AI Act's high-risk obligations span several domains: risk management systems, data and data governance, technical documentation, record-keeping, transparency and provision of information to deployers, human oversight measures, accuracy, robustness, and cybersecurity. Harmonised standards can, in principle, cover any or all of these. The Commission's standardisation mandate to CEN-CENELEC—formally issued in 2023—asked for standards addressing the full set of high-risk requirements.
In practice, the standards landscape for AI is still forming. ISO/IEC 42001, the international standard for AI management systems, is already published and widely referenced, but it is not itself a harmonised standard under the AI Act until its reference appears in the OJEU. CEN-CENELEC's work programme is producing European Standards (EN) and Technical Specifications (CEN/CLC TS) aligned with the AI Act's structure, but publication timelines remain uncertain. As of the time of writing, no AI Act-specific harmonised standard has had its reference published in the OJEU.
This creates a structural gap. The legal mechanism exists; the instruments that activate it do not yet.
How does high-risk classification work for fashion AI systems?
Not every AI system a fashion company deploys is high-risk. The AI Act's high-risk categories are defined in Annex III and cover specific use cases—among them: AI used in employment, workers management, and access to self-employment (including CV screening, performance monitoring, and task allocation); biometric categorisation systems; and systems used in the management of critical infrastructure.
In May 2026, the European Commission issued draft guidelines on the classification of high-risk AI systems under the AI Act, providing additional interpretive guidance on when a system falls within these categories and when the self-assessment exception—which allows a provider to conclude that a listed system does not pose a significant risk—applies.
For fashion AI, the relevant pressure points are:
- Recruitment and workforce tools. An AI system that screens job applications, ranks candidates, or monitors worker productivity in a fashion manufacturing or retail context falls squarely within Annex III. This includes tools that score design team applicants or flag attendance patterns in production facilities.
- Biometric processing. Systems that infer personal characteristics—size, body type, age, or emotional state—from images or video can trigger the biometric categorisation provisions, depending on their purpose and deployment context.
- Recommendation and demand forecasting. Pure demand forecasting tools used internally, with no employment or biometric dimension, are unlikely to be high-risk. However, if a forecasting system also drives workforce scheduling decisions, the classification question reopens.
The draft guidelines emphasise that classification depends on the system's actual function and deployment context, not its marketing label. A fashion AI team should map each system it operates or places on the market against the Annex III categories and document that mapping formally.
What should a fashion AI team do while harmonised standards are absent?
The absence of published harmonised standards does not suspend compliance obligations for high-risk systems. Providers must still meet the AI Act's requirements; they simply cannot rely on the presumption mechanism to do so. The practical consequence is that compliance must be demonstrated through alternative means, and those means need to be documented with the same rigour that a future auditor would apply.
Step 1: Identify and document your system's risk classification
Before any technical work, produce a written classification assessment for each AI system you develop or deploy. Reference the Annex III categories, apply the self-assessment exception criteria where relevant, and record your reasoning. The draft Commission guidelines published in 2026 are the most current interpretive resource for this step.
Step 2: Implement the high-risk obligations in parallel with standards development
The AI Act's substantive requirements are already in force for the relevant obligation dates. Build your risk management system, data governance documentation, technical documentation, and human oversight procedures now, using the Act's text as the primary reference. Where international standards such as ISO/IEC 42001 or ISO/IEC 23894 (AI risk management) cover the same ground, implement them and document the mapping to the Act's requirements. These are not harmonised standards, but they provide a defensible technical baseline and are likely to inform the eventual CEN-CENELEC output.
Step 3: Monitor the OJEU and CEN-CENELEC work programme
Harmonised standards, once their references are published in the OJEU, apply prospectively. A provider who has implemented a standard before its OJEU publication is well-positioned: the transition from voluntary compliance to presumption of conformity requires only the publication event, not a new implementation cycle. Assign someone in your compliance function to track the CEN-CENELEC AI standardisation work programme and the OJEU's harmonised standards lists.
Step 4: Engage with the standardisation process
CEN-CENELEC technical committees accept participation from industry. Fashion technology companies have domain-specific knowledge—about garment data structures, supply chain traceability, and biometric processing in fitting contexts—that is underrepresented in the current standardisation drafts. Participation is not purely altruistic: it gives your team early visibility into draft requirements and the opportunity to shape language that will eventually govern your products.
Step 5: Prepare your technical documentation for notified body review
High-risk AI systems in certain categories require conformity assessment by a notified body rather than self-assessment. Even where self-assessment is permitted, the technical documentation must be complete enough to withstand external scrutiny. Structure your documentation now as if a notified body will review it: system description, training data governance records, risk management log, human oversight procedures, accuracy and robustness testing results, and post-market monitoring plan.
The intersection with Digital Product Passport and textile regulation
Fashion AI systems increasingly interact with EU textile regulation beyond the AI Act. The Digital Product Passport (DPP) framework, being developed under the Ecodesign for Sustainable Products Regulation, will require structured data about garment composition, repairability, and supply chain provenance. AI systems that generate or validate DPP data are not automatically high-risk under the AI Act, but they carry their own data quality and transparency obligations.
Where an AI system both generates DPP data and influences employment decisions—for example, a system that allocates production tasks based on predicted output quality—the compliance surface spans both regulatory frameworks. Teams should map these intersections explicitly rather than treating AI Act compliance and DPP compliance as separate workstreams.
Research and advisory firms such as Gartner track enterprise AI governance maturity across industries, and their frameworks for AI risk tiering and documentation standards are useful reference points when building internal governance structures that must satisfy multiple regulatory regimes simultaneously.
What the standards gap means for procurement and vendor due diligence
If you are a fashion brand deploying third-party AI systems rather than building your own, the standards gap affects you as a deployer. Under the AI Act, deployers of high-risk systems carry obligations around human oversight, monitoring, and—in some cases—fundamental rights impact assessments. You cannot discharge those obligations by pointing to a vendor's harmonised standard conformity, because no such standard yet exists.
This means your vendor due diligence process needs to ask different questions in the interim period:
- Has the vendor produced a written classification assessment for the system you are deploying?
- What technical documentation does the vendor maintain, and will they share a summary with you?
- What risk management and data governance procedures does the vendor apply?
- How will the vendor transition its compliance posture when harmonised standards are published?
Vendors who cannot answer these questions coherently represent a compliance risk to your organisation, not just to themselves. Build these questions into your procurement contracts and request that vendors notify you of material changes to their compliance documentation.
Conclusion
The harmonised standards route to AI Act conformity is structurally sound but currently incomplete. The legal mechanism—presumption of conformity triggered by OJEU publication—is clear and well-established in EU product regulation. The instruments that activate it for AI systems are still being written. Fashion AI teams that treat this gap as a reason to defer compliance work will find themselves behind when standards do publish; those that build rigorous documentation, implement international technical standards as proxies, and monitor the CEN-CENELEC pipeline will be positioned to convert that groundwork into formal presumption of conformity with minimal additional effort. The interim period is not a compliance holiday—it is the compliance foundation.
FAQ
What is the presumption of conformity under the EU AI Act? A provider who fully applies a harmonised standard whose reference has been published in the OJEU is legally presumed to comply with the AI Act requirements that standard covers. The presumption can be rebutted by a supervisory authority but shifts the evidentiary burden away from the provider.
Which body develops harmonised standards for the AI Act? CEN and CENELEC are the primary bodies mandated by the European Commission to develop harmonised standards for the AI Act. ETSI may contribute where telecommunications-specific requirements are involved. Standards become harmonised only when their references are published in the Official Journal of the European Union.
Is a fashion demand forecasting AI system high-risk under the AI Act? A pure demand forecasting tool used for inventory planning is unlikely to fall within the Annex III high-risk categories. If the same system also drives workforce scheduling, task allocation, or performance monitoring decisions, the classification changes and a formal assessment is required.
Can ISO/IEC 42001 substitute for a harmonised standard under the AI Act? Not directly. ISO/IEC 42001 is an international standard for AI management systems, not a harmonised standard under the AI Act. Implementing it provides a defensible technical baseline and is likely to map closely to eventual harmonised standards, but it does not trigger the legal presumption of conformity until—and unless—its reference is published in the OJEU.
What obligations do fashion brands have as deployers of third-party AI systems? Deployers of high-risk AI systems must implement appropriate human oversight measures, monitor system performance in their context of use, and in some cases conduct fundamental rights impact assessments. These obligations apply regardless of whether the vendor's system carries harmonised standard conformity.
When will harmonised standards for the AI Act be available? No AI Act-specific harmonised standard had its reference published in the OJEU at the time of writing. CEN-CENELEC's work programme is active, but publication timelines are not fixed. Teams should monitor the OJEU harmonised standards list and the CEN-CENELEC AI standardisation work programme for updates.
Further reading
- Harmonised Standards — European Commission Internal Market
- Draft EU Guidelines on High-Risk AI Classification — Jones Day
