[Wecken Sie das Interesse Ihrer Leser mit einem passenden Zitat aus dem Dokument, oder November 2025 # 17 Weizenbaum Institute Harmonised Standards and Conformity Assessments in the AI Act: Strengthening Independent and Participatory Oversight
\1 Harmonised Standards and Conformity Assessments in the AI Act ABOUT THE AUTHORS Bettina Berendt \\ Technische Universität Berlin \\ KU Leuven \\ Weizenbaum Institute Vasilios Danos\\ TÜV Informationstechnik GmbH David Hartmann \\ Technische Universität Berlin\\ Weizenbaum Institute Fabian Langer \\TÜV Informationstechnik GmbH Tina Lassiter \\ University of Texas at Austin, USA (former Fellow, Weizenbaum Institute) Julia Maria Mönig \\ Universität Bonn Charlotte Mysegades\\ Weizenbaum Institute Michael Puntschuh \\Beyond AI Collective, Germany Herbert Zech \\ Humboldt-Universität zu Berlin \\ Weizenbaum Institute Authors listed in alphabetical order. If you have any questions about this position paper, please contact Charlotte Mysegades. Contact:
[email protected] ABOUT THIS PAPER The position paper “Harmonised Standards and Conformity Assessments in the AI Act: Strengthening Independent and Participatory Oversight” was developed following the Weizenbaum Forum “An Ecosystem for AI Accountability? Between Evaluation, Audit and Certification” and reflects the Institute’s ongoing interdisciplinary research on technological evaluation and governance of AI systems. In addition to its research-based objectives, this paper serves as a complementary contribution to the Weizenbaum Institute’s official statement1 on the draft bill for the national implementation of the EU Artificial Intelligence Act (AIA) issued by the Federal Ministry for Digital Transformation and Government Modernisation (BMDS).2 It thereby underscores its interdisciplinary expertise in shaping responsible AI regulation. 1 Weizenbaum-Institut, Stellungnahme zum Referentenentwurf eines Gesetzes zur Durchführung der VO (EU) 2024, 1689. 2 Entwurf eines Gesetzes zur Durchführung der Verordnung (EU) 2024/1689 des Europäischen Parlaments und des Rates vom 13. Juni 2024 zur Festlegung harmonisierter Vorschriften für künstliche Intelligenz und zur Änderung der Verordnungen (EG) Nr. 300/2008 (Gesetz zur Durchführung der KI-Verordnung).
\2 Harmonised Standards and Conformity Assessments in the AI Act Weizenbaum Policy Paper Harmonised Standards and Conformity Assessments in the AI Act: Strengthening Independent and Participatory Oversight Weizenbaum Institute Abstract Adopted by the European Union in 2024, the Artificial Intelligence Act (AIA) constitutes a landmark framework for the regulation of AI systems within the EU’s internal market. While recognising its significance for fostering accountability and trustworthy AI, this position paper focuses on two central mechanisms for its effective implementation: (1) technical standardisation and (2) conformity assessments. It argues that, in their current formulation, both mechanisms risk an excessive reliance on private governance, thereby constraining democratic oversight and the effective protection of fundamental rights. The AIA implements its legal obligations through technical standardisation under Article 40, delegating detailed requirements to the European standardisation organisations. Compliance with these harmonised standards creates a presumption of conformity, giving companies strong incentives to follow them. Although the AIA introduces broader stakeholder consultation via the AI Board and Advisory Forum, participation remains non-binding, allowing large corporations to dominate standard-setting and raising concerns about democratic legitimacy and fundamental rights protection. Under Article 43, conformity assessments verify whether high-risk AI systems meet AIA requirements before market entry. Most rely on internal self-assessment; external control is only required in very limited cases. While this reduces administrative burdens, it also risks weakening oversight, transparency, and protection of fundamental rights.
\3 Harmonised Standards and Conformity Assessments in the AI Act Contents 1 Introduction 4 1.1 Identifying the Accountability Gap in the AI Act 4 1.2 Current Standardisation Practice and Its Limitations 5 1.3 The Role and Inadequacy of Conformity Assessments 8 2 Recommendations for Democratic AI Accountability 10 Recommendation 1: Mandatory Independent Audits by Third Parties 10 Recommendation 2: Participatory Audits and Inclusion of Affected Communities 11 Recommendation 3: Periodic Re-Auditing and Life-cycle Monitoring 13 Recommendation 4: Enforcing Rights and Redress Mechanisms 14 Recommendation 5: Strengthening Civil Society and Academic Representation in European Standardisation Processes 15 3 Towards Independent and Participatory Oversight 16 4 Conclusion 16
\4 Harmonised Standards and Conformity Assessments in the AI Act 1 Introduction As a horizontal regulatory framework, the AIA establishes obligations for providers, deployers, importers, and distributors of AI systems, with a particular focus on those AI-systems classified as “high-risk”. Although we acknowledge the important legislative progress achieved with the AIA, we also identify shortcomings regarding its enforceability, democratic oversight and legitimacy, and capacity to ensure effective protection of fundamental rights. This position paper focuses specifically on two critical areas of the AIA that are key to its effective implementation: the role of technical standardisation and conformity assessments. These two mechanisms define both the substance of the AIA requirements and the manner in which compliance is verified. However, in their current form, both are characterized by inadequate transparency and democratic control. In Section 1 we identify the legal architecture and the deficiencies of both the technical standardisation (1.2) and the conformity assessments (1.3) under the AIA, demonstrating a structural deficit in democratic oversight. Based on these analyses, the Weizenbaum Institute identifies five recommendations to ensure that the AIA’s implementation achieves its trustworthiness and accountability goals to ensure and enforce continued compliance as AI systems, respectively, their functionalities can change, e.g. due to system updates or varying operational environments. Section 2 presents five concrete recommendations to address these gaps through: (2.1) mandatory third-party audits, (2.2) participatory oversight mechanisms, (2.3.) periodic re-auditing, (2.4) accessible redress mechanisms, and (2.5) participatory standardisation. We conclude with a short summary. 1.1 Identifying the Accountability Gap in the AI Act In what follows, we highlight the legal architecture, current practice, and the deficiencies in creating oversight, one of four accountability goals3, especially focusing on standardisation and conformity assessment procedures. We argue that these mechanisms reveal structural deficiencies in the Act: the risk of privatising accountability and the lack of third-party-audit mechanisms under the AIA, resulting in an imbalance in the distribution of democratic oversight. 3 Claudio Novelli, Mariarosaria Taddeo, and Luciano Floridi. “Accountability in artificial intelligence: What it is and how it works”. In: Ai & Society 39.4 (2024), pp. 1871–1882.
\5 Harmonised Standards and Conformity Assessments in the AI Act 1.2 Current Standardisation Practice and Its Limitations Legal Framework: Harmonised Standards as Quasi-Normative Technical Standardisation (Art. 40 AIA) The AI Act is based on the New Legislative Framework (NLF), which relies on co-regulation to concretise legal obligations into technical standards. Instead of specifying technical details in legislation, the AIA defines essential requirements and leaves the task of concretisation to the European standardisation organisations CEN and CENELEC through their joint committee, JTC21, in cooperation with national bodies such as DIN and DKE in Germany. Therefore, the AIA delegates much of the substantive definitions to harmonised technical standards developed by private standardisation bodies.4 Harmonised standards provide legal certainty. Once adopted by the Commission, compliance with these standards creates a presumption of conformity with the AIA. As Ebers5 explains it, companies can, in theory, develop their own technical solutions; the administrative difficulties and additional costs involved usually lead them to follow standards. Recognising these effects, the European Court of Justice (ECJ) has ruled that harmonised standards form “part of EU law” and must be developed and published in accordance with the rule of law.6 Although harmonised standards are relatively unknown in digital law, they are a well-established tool in product safety law. Harmonised standards translate the AIA’s general legal requirements into detailed technical procedures, ensuring consistency and flexibility across sectors. However, harmonised standards do not have any legal status, as European standardisation organizations are not democratically legitimate.7 Despite of that, technical standards will create considerable incentives for compliance in practice. The source of their incentive effect lies in the presumption of conformity regulated in Article 40(1) of the AIA, according to which compliance with the legal requirements is presumed in favour of those subject to the standard if and to the extent that they adhere to the standards laid down in the harmonised standards when designing and controlling a highrisk AI system.8 The awarding of standardisation mandates is governed in accordance with Art. 40(2) subpara. 1 sentence 1 AIA in conjunction with Art. 10 Regulation (EU) 1025/20129 in its basic features by the requirements known from product safety law, but is supplemented 4 Sandra Wachter. “Limitations and Loopholes in the EU AI Act and AI Liability Directives: What This Means for the European Union, the United States, and beyond Special Issue: Yale Information Society Project Digital Public Sphere Series”. In: Yale Journal of Law and Technology 26.3 (2024), pp. 671–718. (Visited on 08/06/2025). 5 Ebers, Martin: When Guidance Becomes Overreach: How the forthcoming Code of Practice Threatens to Undermine the EU’s AI Act, VerfBlog, 2025/4/08, https://verfassungsblog.de/when-guidance-becomes-overreach-gpaicodeofpractice-aiact/. 6 Ibid. 7 Ibid. 8 Gerdemann: Harmonisierte Normen und ihre Bedeutung für die Zukunft der KI (MMR 2024, 614). 9 Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council Text with EEA relevance.
\6 Harmonised Standards and Conformity Assessments in the AI Act and specified in Art. 40(2) of the AIA. The additional procedural requirements of the AIA consistently reflect the need for more democratic legitimacy because the regulation of high-risk AI systems is very relevant to fundamental rights entails compared to traditional product safety law. Thus, before issuing a standardisation mandate, the European Artificial Intelligence Board (the ‘Board’) pursuant to Art. 64 AIA must be consulted with the delegated representatives of the Member States, and the Advisory Forum established pursuant to Art. 67 AIA. Art. 67(2) AIA states that the membership of the advisory forum shall represent a balanced selection of stakeholders, including industry, start-ups, SMEs, civil society and academia. The membership of the advisory forum shall be balanced with regard to commercial and non-commercial interests and, within the category of commercial interests, with regard to SMEs and other undertakings.10 Article 40(3) of the AIA also sets out various substantive objectives for the development of harmonised standards. It rules that the participants in the standardisation process shall seek to promote investment and innovation in AI, through increasing legal certainty, as well as the competitiveness and growth of the Union market, to contribute to strengthening global cooperation on standardisation and taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and to enhance multi-stakeholder governance ensuring a balanced representation of interests and the effective participation of all relevant stakeholders in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012. In these Articles the representation of interests and the effective multi-stakeholder governance is nonetheless no binding prerequisite of the standardisation process. Art. 5 states that national standardisation bodies shall encourage and facilitate the access for all stakeholders. Whereas this might have worked for the standardisation process in regards to product safety law, the regulation of high-risk AI systems is due to its fast development and socio-technical consequences in need of a broader and mandatory inclusion of stakeholder participation. In May 2023, the EU Commission issued the mandate to develop the harmonised standards in accordance with Article 10 of the Regulation (EU) No 1025/2012.11 With the standardisation mandate, the Commission pursued the goal of preparing the necessary technical environment for the implementation of the AI Regulation as early as possible. However, the fact that the AIA was not yet in force at that time also meant that the Commission was not required to comply with the participatory procedural rules set out in Article 40(2) and (3) when issuing the standardisation mandate. But even if these rules had already been in force at the time of the standardisation mandate, their wording remains non-binding. This is because Article 40(3) stipulates that “the participants in the standardisation process shall seek (...) taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and to enhance multi-stakeholder governance ensuring a balanced representation of interests and the effective participation of all relevant stakeholders 10 Gerdemann: Harmonisierte Normen und ihre Bedeutung für die Zukunft der KI (MMR 2024, 614). 11 C(2023)3215 – Standardisation request M/593, COMMISSION IMPLEMENTING DECISION of 22.5.2023 on a standardisation request to the European Committee for Standardisation and the European Committee for Electrotechnical Standardisation in support of Union policy on artificial intelligence
\7 Harmonised Standards and Conformity Assessments in the AI Act in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012.” CEN and CENELEC were obliged to ensure that the outcome of standardisation is consistent with EU law, in particular with the fundamental rights and values of the European Union, the public interest and data protection, and that there is appropriate stakeholder participation, including SMEs, consumer organisations and trade unions.12 In practice, however Gerdemann13 argues, the picture already familiar from product safety law is emerging in the relevant committees, whereby primarily resource-rich international companies are actively involved in the technically challenging standardisation process. Standards are developed in processes that suffer from significant transparency and accountability limitations. Civil society organisations and academic experts are generally underrepresented and often only hold observer status, thus lack meaningful participation rights, and governance remains largely dominated by big industrial stakeholders.14 These standards effectively define how compliance with the AIA’s essential requirements is operationalised. As the European Commission states itself, the AIA sets result-oriented requirements and obligations but leaves the concrete technical solutions and operationalisation to industry-driven standards and codes of practice that are flexible to be adapted to different use cases and to enable new technological solutions.15 While this approach allows for flexibility and technological adaptability, it also raises concerns regarding democratic legitimacy, transparency, and regulatory sufficiency. Wachter notes that the lack of participatory parity undermines the democratic legitimacy of these standards, which acquire quasi-normative status under EU law, even though they are developed outside public law processes.16 Providers may also choose alternative technical specifications under Article 43(1)(2) AIA, but doing so creates greater legal uncertainty for the developers and providers and requires additional justification. Given that these standards profoundly shape the interpretation of fundamental rights obligations this privatised norm-setting process raises constitutional and democratic concerns. From a legal perspective, delegating effective norm creation to private actors with insufficient public oversight may infringe principles of legality, proportionality, and democratic legitimacy. Ebers underlines that this form of delegated legislation through harmonised standards is problematic, primarily because of the lack of democratic legitimacy. Standardisation requires a series of legal and ethical decisions to be made, which necessitate a democratic discourse involving the whole of society, in which stakeholders should be adequately involved. European standardisation involves the delegation of legislative powers to private organisations. To Ebers this is problematic due to the lack of participation rights for the 12 See Article 2 and recitals 5, 8(1) and (2), 14(2), 14(4) and 15(2), 15(1) of the Implementing Decision. 13 Gerdemann: Harmonisierte Normen und ihre Bedeutung für die Zukunft der KI (MMR 2024, 614). In German. 14 Wachter, “Limitations and Loopholes in the EU AI Act and AI Liability Directives”. 15 European Commission. Artificial Intelligence – Questions and Answers. https://ec. europa.eu/commission/presscorner/detail/en/qanda_21_1683. Published 1 August 2024, accessed 3 November 2025. url: https://ec.europa.eu/commission/presscorner/ detail/en/qanda_21_1683. 16 Wachter, “Limitations and Loopholes in the EU AI Act and AI Liability Directives”.
\8 Harmonised Standards and Conformity Assessments in the AI Act Council and Parliament, the limited influence of relevant interest groups and insufficient judicial control (no validity check of harmonised standards by the ECJ).17 Neither the European Parliament nor the Member States can veto the harmonised standards commissioned by the European Commission. Even the Commission has only limited influence. Veale and Zuiderveen Borgesius18 therefore state: “Consequently, standardisation is arguably where the real rulemaking in the AI Act will occur.”15 This concern has not only been underlined by academia but also by civil society. The European consumer protection organisations, ANEC and BEUC, also emphasise that the current EU standardisation system lacks democratic legitimacy and adequate inclusion of public interest stakeholders. In its 2023 position paper, the ANEC and BEUC both highlight that “the standardisation process is currently dominated by industrial actors and suffers from a lack of transparency, accessibility and effective representation of civil society, SMEs and consumer interests”19. Particularly in areas such as artificial intelligence, where technical standards effectively operationalise legal norms, this imbalance can lead to a systemic underrepresentation of fundamental rights considerations and public accountability. 1.3 The Role and Inadequacy of Conformity Assessments Article 43 AIA requires that the majority of high-risk AI systems undergo conformity assessments through internal checks conducted by the providers themselves. While this approach aims to reduce administrative burden, this reliance on self-certification contradicts basic principles of independent oversight, particularly in light of the systemic risks posed by not only high-risk AI systems, but AI systems in general, in critical domains such as education, employment, migration policy, jurisdiction and law enforcement. Conformity assessments verify whether high-risk AI systems comply with the AIA’s obligations before market entry.20 In most cases, these checks are conducted internally by providers, while third-party evaluation and continuous monitoring are required only in limited sectors. The conformity assessment procedure to be applied depends on the type of highrisk AI system. The conformity assessment of high-risk AI systems listed in Annex I of the AIA is carried out in accordance with Art. 43(3) AIA, in accordance with the legal acts from the New Legislative Framework specified therein. These regularly provide for third-party 17 Ebers; Martin/ Streitbörger; Chiara; Die Regulierung von Hochrisiko-KI-Systemen in der KI-Verordnung; RDI 9/2024; 393 (398). 18 Michael Veale and Frederik Zuiderveen Borgesius. “Demystifying the Draft EU Artificial Intelligence Act”. In: Computer Law Review International 22.4 (2021), pp. 97–112. url: https://ssrn.com/abstract=3896852. 19 ANEC and BEUC. For a ‘Standardisation Governance Act’: Recommendations to adapt Regulation (EU) 1025/2012. Tech. rep. Position paper; accessed via https://www.beuc. eu / sites / default / files / publications / BEUC - X - 2024 - 001 _ For _ a _ standardisation _ governance_act.pdf on 24 July 2025. ANEC – The European consumer voice in standardisation; BEUC – The European Consumer Organisation, 2024. 20 Markus Fuderer. “Doppelte Konformitätsbewertung bei KI-basierten Medizinprodukten”. In: (2022). in German, pp. 121–126.
\15 Harmonised Standards and Conformity Assessments in the AI Act Recommendation 5: Strengthening Civil Society and Academic Representation in European Standardisation Processes The Weizenbaum Institute recommends a reform of the EU standardisation process to ensure that normative standards reflect the plurality of European fundamental rights, including consumer protection, non-discrimination and social and ecological fairness. This must include structural funding for civil society participation, clearer legislation that mandates inclusiveness, and a rebalancing of influence within standardisation bodies, because there are insufficient opportunities for interest groups to participate in the development of harmonised standards, as shown above. In practice, European interest groups have only limited rights of participation. They have no voting rights, but can only request access to documents, submit suggestions and proposals, and provide comments and technical opinions. European interest groups can only appeal against decisions made by standardisation organisations under very narrow conditions. In addition, there are a number of practical obstacles that make it difficult for interest groups to participate. Civil rights associations, trade unions and environmental and consumer associations usually have no experience or technical expertise in the field of European standardisation. They may not even be represented at the EU level.39 Despite their technical sophistication, existing standards exhibit several critical limitations: Many of the current standardisation processes show structural weaknesses that limit their ability to ensure accountable and rights-based AI governance. First, they tend to lack contextual sensitivity. Standards often focus narrowly on technical system behaviour without considering the socio-technical settings in which AI systems are deployed, such as criminal justice, welfare, or education. Second, fundamental rights are insufficiently integrated. Core rights such as non-discrimination, fair trial, and access to information are often only indirectly referenced or embedded in fragmented ways. Third, most standards follow a static audit logic that concentrates on one-time, pre-deployment assessments rather than continuous, adaptive evaluations as systems evolve in practice. To rectify this imbalance, we recommend the German Federal Government to: Promote the institutionalisation and funding of academia and civil society representation on the EU Level within the standardisation processes, for example by improving access and exploring options for stronger procedural roles. 39 Ebers: Standardisierung Künstlicher Intelligenz und KI-Verordnungsvorschlag RDi 2021, 588., In German.
\16 Harmonised Standards and Conformity Assessments in the AI Act 3 Towards Independent and Participatory Oversight Building on these analyses, the Weizenbaum Institute identifies five recommendations to ensure that the AIA’s implementation achieves its goals of trustworthiness and accountability: 1. Third-party audits for high-risk AI systems where internal conformity assessment is insufficient, complemented by transparent publication of audit outcomes. 2. Participatory oversight mechanisms that integrate perspectives of affected communities and civil society organisations into system evaluation and fundamental rights impact assessments. 3. Periodic re-auditing and lifecycle monitoring to ensure continued compliance as AI systems change through retraining, as well as implementation and deployment changes. 4. Accessible complaint and redress mechanisms supported by public funding and collective action tools to enable effective enforcement of individual and group rights. 5. Promote the institutionalisation and funding of academia and civil society representation on the EU Level within the standardisation processes, for example by improving access and exploring options for stronger procedural roles. 4 Conclusion The German Federal Government has a critical responsibility to advocate at the European level, particularly within the Council of the European Union, for the European Commission to adopt a delegated act under the AI Act that establishes binding requirements for external third-party audits in high-risk AI areas, as internal controls and assessments are often insufficient, and risks of conflict of interest are high. Moreover, it should ensure that the implementation of the AIA aligns with constitutional principles of legality, transparency, accountability, and participation. This includes not only faithfully transposing the AIA into national law, where possible, but also leveraging available discretion to enhance protections, build inclusive institutions, and promote democratic oversight.
\17 Harmonised Standards and Conformity Assessments in the AI Act Imprint Weizenbaum Institute Harmonised Standards and Conformity Assessments in the AI Act: Strengthening Independent and Participatory Oversight Weizenbaum Policy Paper # 17 Berlin, November 2025 ISSN 2940-8490 \ DOI 10.34669/WI.PP/17 LICENSE: This Paper is licensed under Creative Commons Attribution 4.0 (CC BY 4.0). Weizenbaum-Institut e.V. Hardenbergstraße 32 \ 10623 Berlin \ Tel.: +49 30 700141-001
[email protected] \ www.weizenbaum-institut.de ABOUT THE WEIZENBAUM INSTITUTE The Weizenbaum Institute is a joint project funded by the German Federal Ministry of Research, Technology and Space (BMFTR) and the State of Berlin. It conducts interdisciplinary and basic research on the digital transformation of society and provides evidenceand value-based options for action in order to shape digitalization in a sustainable, self-determined and responsible manner.