Articles 40 to 42: standards, common specifications and presumption of conformity
A party applying a harmonised standard whose reference has been published in the Official Journal of the European Union is presumed to be in conformity with the requirements of Section 2 or with the obligations of Chapter V, Sections 2 and 3, to the extent that the standard covers them. As long as no such standard exists, the Commission may adopt common specifications by implementing act, and those carry the same presumption. If you do not apply such a common specification, you must duly justify that you have adopted technical solutions that are at least equivalent. Article 42 adds three narrow presumptions, and they do not all arise in the same way. Paragraph 1 gives the presumption of conformity with Article 10(4) to systems trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used; no publication in the Official Journal is attached to it. Paragraph 2 does carry that condition: the presumption of conformity with the cybersecurity requirements of Article 15 applies to systems certified under a scheme pursuant to Regulation (EU) 2019/881 the references of which have been published in the Official Journal. The paragraph 3 added by Article 1, point (18), of Regulation (EU) 2026/1744 gives that same presumption to systems falling within the scope of Regulation (EU) 2024/2847 that meet the conditions in Article 12(1) thereof. Each of these presumptions is rebuttable and reaches no further than what the standard, the specification or the certification covers.
The final subparagraph of Article 40(2), as added by Article 1, point (17), of Regulation (EU) 2026/1744, provides: the Commission shall request, in accordance with Regulation (EU) No 1025/2012 and without undue delay, the European standardisation organisations to develop standardisation deliverables, including, as appropriate, harmonised standards, to facilitate the joint compliance and presumption of conformity with the requirements or obligations set out in Chapter III, Sections 2 and 3 of this Regulation, and the relevant requirements and obligations laid down in the Union harmonisation legislation listed in Annex I to this Regulation.
Praxikon tracks Articles 40 to 42: standards, common specifications and presumption of conformity under the EU AI Act, checked against the official source on 6 September 2026, citing the source for every statement.
- Status
- Applicable
- Application date
- Not recorded
- Version
- 1.0.0
- Last reviewed
- 6 September 2026
Review status: placed against the official source (6 September 2026). Next check due by 5 March 2027. The check date is the knowledge date of this version; no later recheck has been recorded.
From source to evidence
Why this obligation applies, what it asks of you, and what you show for it.
Applies
Applicable · Not recorded
For whom
- Provider of a GPAI model
- Provider of an AI system
What you do
Record per requirement which standard or specification you rely on, and justify every departure
What you record
Coverage matrix and justification for standards and specifications
Who this is relevant to
When this applies
Provider of a GPAI model
A party that places a general-purpose AI model on the Union market.
Provider of an AI system
A party that develops or has an AI system developed and places it on the market under its own name.
- 1The presumption in Article 40(1) arises only where the references of the harmonised standard have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and it reaches only to the extent that those standards cover those requirements or obligations. The same holds for the cybersecurity certification of Article 42(2), the references of which must likewise have been published in the Official Journal.
- 2The justification duty of Article 41(5) arises only where a common specification has actually been established by implementing act for the requirement concerned and the provider does not apply it. Where no such specification exists, there is nothing to depart from and you demonstrate conformity by the ordinary route.
What the official source establishes
Article 40(1) provides: High-risk AI systems or general-purpose AI models which are in conformity with harmonised standards or parts thereof the references of which have been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012 shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, with the obligations set out in of Chapter V, Sections 2 and 3, of this Regulation, to the extent that those standards cover those requirements or obligations. Paragraph 2 provides: In accordance with Article 10 of Regulation (EU) No 1025/2012, the Commission shall issue, without undue delay, standardisation requests covering all requirements set out in Section 2 of this Chapter and, as applicable, standardisation requests covering obligations set out in Chapter V, Sections 2 and 3, of this Regulation. The standardisation request shall also ask for deliverables on reporting and documentation processes to improve AI systems’ resource performance, such as reducing the high-risk AI system’s consumption of energy and of other resources during its lifecycle, and on the energy-efficient development of general-purpose AI models. When preparing a standardisation request, the Commission shall consult the Board and relevant stakeholders, including the advisory forum. When issuing a standardisation request to European standardisation organisations, the Commission shall specify that standards have to be clear, consistent, including with the standards developed in the various sectors for products covered by the existing Union harmonisation legislation listed in Annex I, and aiming to ensure that high-risk AI systems or general-purpose AI models placed on the market or put into service in the Union meet the relevant requirements or obligations laid down in this Regulation. Paragraph 3 provides: The participants in the standardisation process shall seek to promote investment and innovation in AI, including through increasing legal certainty, as well as the competitiveness and growth of the Union market, to contribute to strengthening global cooperation on standardisation and taking into account existing international standards in the field of AI that are consistent with Union values, fundamental rights and interests, and to enhance multi-stakeholder governance ensuring a balanced representation of interests and the effective participation of all relevant stakeholders in accordance with Articles 5, 6, and 7 of Regulation (EU) No 1025/2012.
Article 41(1) provides: The Commission may adopt, implementing acts establishing common specifications for the requirements set out in Section 2 of this Chapter or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V where the following conditions have been fulfilled: (a) the Commission has requested, pursuant to Article 10(1) of Regulation (EU) No 1025/2012, one or more European standardisation organisations to draft a harmonised standard for the requirements set out in Section 2 of this Chapter, or, as applicable, for the obligations set out in Sections 2 and 3 of Chapter V, and: (i) the request has not been accepted by any of the European standardisation organisations; or (ii) the harmonised standards addressing that request are not delivered within the deadline set in accordance with Article 10(1) of Regulation (EU) No 1025/2012; or (iii) the relevant harmonised standards insufficiently address fundamental rights concerns; or (iv) the harmonised standards do not comply with the request; and (b) no reference to harmonised standards covering the requirements referred to in Section 2 of this Chapter or, as applicable, the obligations referred to in Sections 2 and 3 of Chapter V has been published in the Official Journal of the European Union in accordance with Regulation (EU) No 1025/2012, and no such reference is expected to be published within a reasonable period. When drafting the common specifications, the Commission shall consult the advisory forum referred to in Article 67. Paragraph 2 provides: Before preparing a draft implementing act, the Commission shall inform the committee referred to in Article 22 of Regulation (EU) No 1025/2012 that it considers the conditions laid down in paragraph 1 of this Article to be fulfilled. Paragraph 3 provides: High-risk AI systems or general-purpose AI models which are in conformity with the common specifications referred to in paragraph 1, or parts of those specifications, shall be presumed to be in conformity with the requirements set out in Section 2 of this Chapter or, as applicable, to comply with the obligations referred to in Sections 2 and 3 of Chapter V, to the extent those common specifications cover those requirements or those obligations.
Article 41(4) provides: Where a harmonised standard is adopted by a European standardisation organisation and proposed to the Commission for the publication of its reference in the Official Journal of the European Union, the Commission shall assess the harmonised standard in accordance with Regulation (EU) No 1025/2012. When reference to a harmonised standard is published in the Official Journal of the European Union, the Commission shall repeal the implementing acts referred to in paragraph 1, or parts thereof which cover the same requirements set out in Section 2 of this Chapter or, as applicable, the same obligations set out in Sections 2 and 3 of Chapter V. Paragraph 5 provides: Where providers of high-risk AI systems or general-purpose AI models do not comply with the common specifications referred to in paragraph 1, they shall duly justify that they have adopted technical solutions that meet the requirements referred to in Section 2 of this Chapter or, as applicable, comply with the obligations set out in Sections 2 and 3 of Chapter V to a level at least equivalent thereto. Paragraph 6 provides: Where a Member State considers that a common specification does not entirely meet the requirements set out in Section 2 or, as applicable, comply with obligations set out in Sections 2 and 3 of Chapter V, it shall inform the Commission thereof with a detailed explanation. The Commission shall assess that information and, if appropriate, amend the implementing act establishing the common specification concerned.
Article 42(1) provides: High-risk AI systems that have been trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used shall be presumed to comply with the relevant requirements laid down in Article 10(4). Paragraph 2 provides: High-risk AI systems that have been certified or for which a statement of conformity has been issued under a cybersecurity scheme pursuant to Regulation (EU) 2019/881 and the references of which have been published in the Official Journal of the European Union shall be presumed to comply with the cybersecurity requirements set out in Article 15 of this Regulation in so far as the cybersecurity certificate or statement of conformity or parts thereof cover those requirements.
Our interpretation
The official source remains authoritative. This general interpretation is not legal advice.
The word everything turns on is presumed. A presumption of conformity is not proof of compliance and it is rebuttable: it shifts who has to demonstrate what, and nothing more. If a market surveillance authority shows that your system in fact does not meet a requirement of Section 2, the standard you applied does not stop that. Two limits set out in the text itself come on top. The first is the coverage limit: the presumption operates only in so far as the standard or the specification covers the requirements or obligations concerned. EN 18286 shows exactly what that means, because the coverage statement accompanying that standard expressly excludes Article 17(2) to (4) and Article 72; whatever falls outside the coverage you substantiate yourself. The second is the publication limit: without a reference in the Official Journal of the European Union no presumption arises, however complete the standard may be. That is why all twelve standard objects in data/ai-act/graph/standards.ts carry guidance and not applicable. So anyone hearing a supplier say that his product meets the European standard and is therefore AI Act compliant is hearing two leaps at once: from coverage to completeness, and from standard to legal effect.
Article 41 is often dismissed as an emergency valve that will never be used, and that is the wrong call. The European standards under standardisation request M/613 are not all available yet: the standards layer in data/ai-act/graph/standards.ts shows one completed EN and six deliverables still at drafting or enquiry stage. That is precisely the state described by the conditions of Article 41(1), point (a)(ii), and point (b), and so the common specification route remains practically relevant. For you that means two things. First, an implementing act may appear for a requirement of Section 2 that you did not see coming and that touches your design choices; those acts are adopted under the examination procedure of Article 98(2) and not in consultation with individual providers. Second, there is then a paragraph that asks something of you directly: paragraph 5. If you do not apply the common specification, you must duly justify that your technical solution is at least equivalent. That is the only place in these three Articles where you have to write something yourself, and the text does not say where. In practice that justification belongs in the technical documentation, because that is the file that has to be handed over upon a reasoned request. Article 42 is narrower than it looks and is overrated for that reason. Paragraph 1 touches only Article 10(4) and not the rest of the data governance of Article 10; paragraph 2 touches only the cybersecurity requirements of Article 15 and only where the references of the scheme under Regulation (EU) 2019/881 have been published in the Official Journal. A certificate under a scheme not yet published yields no presumption, and a presumption on Article 15 says nothing about your Article 9, 11, 12, 13 or 14.
What you can do now
Build a coverage matrix per high-risk system and per general-purpose AI model: put every requirement of Section 2 that applies to you in the left column, and next to it which harmonised standard, which common specification or which document of your own covers that requirement. Note per row whether the reference of that standard has been published in the Official Journal of the European Union, because only those rows carry a presumption; the remaining rows call for evidence of your own. For every requirement where a common specification exists that you do not apply, write a justification under Article 41(5): which technical solution you adopted, why it is at least equivalent to what the specification demands, and which test shows it. Include that justification in the technical documentation so that it can travel immediately upon a reasoned request. Set up a standing check on publications in the Official Journal as well: a new reference switches a presumption on, and under Article 41(4) repeals an existing common specification, which can remove the basis under a row of your matrix. If you want to rely on Article 42, record why your training and testing data reflect the geographical, behavioural, contextual or functional setting within which the system is intended to be used, and confine the conclusion to Article 10(4). For the cybersecurity route, first check whether the references of the scheme under Regulation (EU) 2019/881 appear in the Official Journal; without that publication the certificate is a good document with no legal effect under Article 15.
- 01
Record per requirement which standard or specification you rely on, and justify every departure
Keep a coverage matrix of the requirements of Section 2 against the harmonised standards, common specifications and own documents applied, noting per row the publication status in the Official Journal, and write out the Article 41(5) justification for every common specification you do not apply.
What to retain
Coverage matrix and justification for standards and specifications
Per requirement of Section 2: the harmonised standard or common specification applied with its version, the publication status of the reference in the Official Journal, what the standard or specification does and does not cover, and on departure the Article 41(5) justification with the technical solution chosen and the test showing equivalence.
Control and reassessment
Watch on publications in the Official Journal
The control that keeps the coverage matrix current: a fixed check on new references of harmonised standards, on new or amended common specifications, and on the repeal that Article 41(4) prescribes once a standard is published, with a named owner who then updates the matrix.
Public tools
Full text of Articles 40, 41 and 42
The full legal text of the standards and specifications provisions in the public AI Act Explorer.
Conditions and exceptions
- A presumption of conformity is not a finding of compliance. The text says the system shall be presumed to be in conformity, and only in so far as the standard or the specification covers the requirements or obligations concerned. Outside that coverage the burden of proof rests fully on the provider, and a market surveillance authority can rebut the presumption where the system in fact does not meet the requirements.
- Article 41(4) makes a common specification lapse as soon as the standard exists: when reference to a harmonised standard is published in the Official Journal of the European Union, the Commission repeals the implementing acts, or parts thereof, which cover the same requirements or obligations. A file leaning on a repealed specification thereby loses its basis.
Official sources and locators
Digital Omnibus on AI 2026/1744
European Parliament and Council | official-journal-2026-07-24
Source locator: Article 1, points (17) and (18), amending Article 40(2) and Article 42
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 40(1) to (3)
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 41(1) to (3)
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 41(4), (5) and (6)
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 42(1) and (2)
CEN-CENELEC JTC 21: European standards under standardisation request M/613
CEN-CENELEC JTC 21 | work-programme-checked-2026-08-08
Source locator: EN 18286:2026, CEN/CLC/JTC 21 under standardisation request M/613
CEN-CENELEC JTC 21: European standards under standardisation request M/613
CEN-CENELEC JTC 21 | work-programme-checked-2026-08-08
Source locator: prEN 18228 (draft standard), CEN/CLC/JTC 21 under M/613
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 10(4); Article 15; Article 43(1); Chapter III, Section 5, and Article 113, second paragraph
Referring to this object
Citation block
Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.
Reference
Praxikon, "Articles 40 to 42: standards, common specifications and presumption of conformity", praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications@1.0.0, dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0), effective_at 2026-08-02T00:00:00.000Z, known_at 2026-09-06T00:00:00.000Z, sha256 5ed867d4d391f1d4f1bd452fb12e1a85d2b504978e3ac431460b7871eb18c51c, https://www.praxikon.com/en/verplichtingen/article-40-42-standards-and-specifications (https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-40-42-standards-and-specifications&effective_at=2026-08-02&known_at=2026-09-06&lang=en, accessed 2026-09-15)
Short form
praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications@1.0.0 (sha256 5ed867d4)
BibTeX
@misc{praxikon-eu-ai-act-obligation-article-40-42-standards-and-specifications-1-0-0,
author = {{Praxikon}},
title = {Articles 40 to 42: standards, common specifications and presumption of conformity},
year = {2026},
version = {1.0.0},
number = {praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications},
howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
note = {effective_at 2026-08-02T00:00:00.000Z; known_at 2026-09-06T00:00:00.000Z; sha256 5ed867d4d391f1d4f1bd452fb12e1a85d2b504978e3ac431460b7871eb18c51c},
url = {https://www.praxikon.com/en/verplichtingen/article-40-42-standards-and-specifications},
urldate = {2026-09-15},
language = {en}
}CSL JSON
[
{
"id": "praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications@1.0.0",
"type": "dataset",
"title": "Articles 40 to 42: standards, common specifications and presumption of conformity",
"container-title": "AI Act Change & Evidence Graph",
"publisher": "Praxikon",
"version": "1.0.0",
"number": "praxikon:eu:ai-act:obligation:article-40-42-standards-and-specifications",
"URL": "https://www.praxikon.com/en/verplichtingen/article-40-42-standards-and-specifications",
"language": "en",
"issued": {
"date-parts": [
[
2026,
9,
6
]
]
},
"accessed": {
"date-parts": [
[
2026,
9,
15
]
]
},
"note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-08-02T00:00:00.000Z; known_at 2026-09-06T00:00:00.000Z; sha256 5ed867d4d391f1d4f1bd452fb12e1a85d2b504978e3ac431460b7871eb18c51c; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-40-42-standards-and-specifications&effective_at=2026-08-02&known_at=2026-09-06&lang=en; licence https://www.praxikon.com/nl/legal/terms"
}
]How to verify a reference later is set out in the methodology. Terms
Version history
v1.0.0
2 August 2026
Articles 40 to 42: standards, common specifications and presumption of conformity
A party applying a harmonised standard whose reference has been published in the Official Journal of the European Union is presumed to be in conformity with the requirements of Section 2 or with the obligations of Chapter V, Sections 2 and 3, to the extent that the standard covers them. As long as no such standard exists, the Commission may adopt common specifications by implementing act, and those carry the same presumption. If you do not apply such a common specification, you must duly justify that you have adopted technical solutions that are at least equivalent. Article 42 adds three narrow presumptions, and they do not all arise in the same way. Paragraph 1 gives the presumption of conformity with Article 10(4) to systems trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting within which they are intended to be used; no publication in the Official Journal is attached to it. Paragraph 2 does carry that condition: the presumption of conformity with the cybersecurity requirements of Article 15 applies to systems certified under a scheme pursuant to Regulation (EU) 2019/881 the references of which have been published in the Official Journal. The paragraph 3 added by Article 1, point (18), of Regulation (EU) 2026/1744 gives that same presumption to systems falling within the scope of Regulation (EU) 2024/2847 that meet the conditions in Article 12(1) thereof. Each of these presumptions is rebuttable and reaches no further than what the standard, the specification or the certification covers.
Corrections to this obligation
No substantive correction to this object has been recorded.
Open the correction logHelp with implementation
Zahed Ashkara, jurist and freelance AI & Privacy Consultant, supports implementation with your team through Embed AI.
View AI governance at Embed AIFor AI agents and integrations
This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.
