Suggested region and language based on your location

    Your current region and language

    Framework that sets out route for compliance with EU AI Act launches

    23 July 2026 – A framework designed to help organizations demonstrate the compliance of high-risk AI systems with key EU legislation has been published by UK national standards body, BSI.

    The standard, Quality management system (QMS) for EU AI Act regulatory purposes (BS EN 18286:2026), can help any organization to manage risk, ensure traceability and embed human oversight within AI systems, whilst providing presumption of conformity with the EU AI Act; the world’s first comprehensive cross-sector AI regulatory framework adopted by a major economy. This is important because the Act (Regulation [EU] 2024/1689), mandates that providers of high-risk AI systems must have a documented quality management system (QMS) covering areas such as lifecycle governance, risk management, documentation and validation.

    The Act itself doesn’t define a detailed QMS standard, so the European Commission formally issued a Standardisation Request to help organizations implement and operationalise the QMS requirements. BS EN 18286:2026 was developed in response, to help organizations prepare for conformity assessment, reduce their legal uncertainty, and strengthen industry and societal trust in AI systems.

    The framework, which can be used by any company that is placing on the market, or putting into service, high-risk AI systems under the EU AI Act, supports the development of clear, structured governance. It also aligns with BS ISO/IEC 42001, the first international standard for managing AI systems. Whilst ISO/IEC 42001 provides a framework for managing and governing AI responsibly across an organization, focusing on good AI governance practices, BS EN 18286:2026 focuses specifically on the QMS requirements for high-risk AI systems under the EU AI Act to help them meet obligations. It promotes more consistent AI lifecycle management, strengthens accountability, enhances risk controls, and encourages robust documentation practices, contributing to improved organizational readiness and supporting Europe’s evolving regulatory landscape.

    The introduction of the EU AI Act has driven an increased focus on the need for a thorough understanding of the risks associated with AI, alongside good governance. BSI research has found that, although 65% of business leaders believe AI has delivered tangible benefits to their organizations, only 24% have an AI governance program in place.

    David Cuckow, Director of Digital, Knowledge Solutions, BSI said: “Organizations are moving quickly to harness the opportunities presented by AI, including healthcare and autonomous vehicles. However, success in the European market and beyond depends on meeting robust regulatory requirements. Before AI systems can be placed on the market or used in the EU, they must comply with the EU AI Act.

    “This standard provides organizations with a clear, practical framework to demonstrate compliance, while strengthening their approach to risk management, traceability and human oversight. Ultimately, building trust in AI starts with strong governance, and this standard represents an important step in enabling organizations to deliver responsible, transparent and trustworthy AI.”

    The development of this standard was led by UK BSI experts and those from across other notable National Standards Bodies within the EU. Organizations included leading AI providers and deployers, conformity assessment and certification bodies, regulators and public authorities, academia and research, civil society and human rights representation, the legal industry, and infrastructure and enabling technology providers. 

    For more information on the standard, please click here.