RSS Amplifier

AI regulation, standards and reality · May 4, 2026

ISO/IEC 25059 gets a rewrite: AI quality models expand beyond the product

0
Sign in to vote or save

This page did not load. You can still read it on the original site — the toolbar below keeps your place in the directory.

The SQuaRE quality model for AI systems revision completes enquiry

The second edition of ISO/IEC 25059 — the SQuaRE quality model for AI systems — has just finished its three-month Draft International Standard (DIS) public enquiry, with voting closing on 12 March 2026. This is the stage at which the text is circulated to all ISO member bodies, who in turn open it for national stakeholder comment before casting a vote. Approval requires a two-thirds majority of P-members of the committee, with no more than one quarter of all votes negative. If approved without substantive technical changes, the standard proceeds to publication; if technical changes are introduced, a Final Draft International Standard (FDIS) ballot is triggered.

Substantively, the revision is more than a tidy-up. It expands the scope from a single product quality model to three models, introduces environmental sustainability as a first-class concern, and realigns the document to sit atop the restructured SQuaRE 25010/25019/25011 stack published in 2023.

AI regulation, standards and reality is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Below, I walk through where 25059 came from, what the first edition did, and what has changed in the DIS.

How we got here: an extension to 25010

ISO/IEC 25010 is the backbone of the SQuaRE (Systems and software Quality Requirements and Evaluation) series. It sets out a general product quality model — functional suitability, performance efficiency, usability, reliability, security, maintainability, and so on — and a corresponding quality-in-use model, against which software and systems can be specified, measured, and evaluated. It is the lingua franca that software engineering has used for roughly two decades to talk about what “quality” means beyond “does the thing work.”

The problem is that conventional software quality models were not designed for systems that replace human decision-making, adapt during operation, produce probabilistic outputs, or depend fundamentally on the quality of training data.

That is the slot ISO/IEC 25059:2023 was created to fill. It is formally a SQuaRE Extension Division standard — part of the ISO/IEC 25050–25099 range reserved for application-specific extensions — and it does not replace 25010. Rather, it adds and modifies sub-characteristics where AI-specific behaviour demands them, and inherits everything else from the parent model. The first edition was published in 2023 by ISO/IEC JTC 1/SC 42, the subcommittee responsible for artificial intelligence standardisation.

What the 2023 first edition did

The 2023 edition modified the 25010 product quality model by adding four new sub-characteristics and modifying one:

  • User controllability (new, under usability) — the degree to which a user can appropriately intervene in an AI system’s functioning in a timely manner.

  • Functional adaptability (new, under functional suitability) — the ability of the system to adapt to a changing dynamic environment, subsuming continuous learning but not requiring it.

  • Functional correctness (modified) — retained from 25010 but with a note explicitly acknowledging that AI systems, particularly probabilistic ML, do not usually provide functional correctness in all observed circumstances.

  • Robustness (new, under reliability) — the ability to maintain functional correctness under unseen, biased, adversarial, or invalid inputs, external interference, and varying environmental conditions.

  • Transparency (new, under usability and also under satisfaction in the quality-in-use model) — the degree to which appropriate information about the AI system is communicated to relevant stakeholders.

  • Intervenability — closely related to controllability, but framed from the operator’s perspective and oriented toward preventing harm or hazard, rather than ordinary user interaction.

On the quality-in-use side, the 2023 edition added societal and ethical risk mitigation as a new sub-characteristic of freedom from risk, reflecting the societal and ethical concerns about AI.

It is important to realise that 25059 isn’t a standard that has requirements or processes in. You can’t comply with it. It just defines a quality model. However, it has become crucial for AI standards in both ISO/IEC and CEN-CENELEC. People don’t talk about performance and accuracy in AI standards anymore; they talk about more specific terms like functional correctness.

That’s the baseline. Now, to what has changed.

What the DIS changes

The Foreword of the DIS lists the main technical changes explicitly:

  • Alignment with the revised ISO/IEC 25010:2023.

  • Alignment with the revised ISO/IEC 25019:2023 (the new home of the quality-in-use model).

  • Addition of an AI service quality model based on ISO/IEC TS 25011:2017.

  • Addition of environmental sustainability as a sub-characteristic of performance efficiency in the product quality model.

Each of these deserves a closer look.

Structural realignment with the SQuaRE 2023 rewrite

Between the first edition of 25059 and the DIS, SQuaRE itself was restructured. ISO/IEC 25010 was revised in 2023 and no longer includes the quality-in-use model, which was moved to a new standalone standard, ISO/IEC 25019:2023. The DIS follows suit: Clause 5 now references 25010:2023 for the product quality model, and Clause 6 references 25019:2023 for the quality-in-use model. The normative references list has been updated accordingly, and the 2011 editions of the base standards no longer appear.

This has knock-on effects throughout. The product quality model table in the DIS is substantially larger than the 2023 diagram, because 25010:2023 itself introduced more sub-characteristics. Things like: authenticity, resistance, recoverability, user engagement, inclusivity, self-descriptiveness, and a full safety characteristic with sub-characteristics including operational constraint, risk identification, fail-safe, hazard warning, and safe integration. 25059 inherits all of these.

The quality-in-use model has also been relabelled. In the 2023 edition, the top-level characteristic was “freedom from risk”; in the DIS, aligned with 25019:2023, it is “risk mitigation,” with sub-characteristics including economic, environmental, societal and ethical, health, and human life risk mitigation.

The new AI service quality model

This is the biggest substantive addition. The DIS introduces an entirely new Clause 7 covering service quality, based on ISO/IEC TS 25011:2017. The rationale is straightforward: users and organisations increasingly consume AI as a service rather than as a shrink-wrapped product, and the quality concerns around a service — tangibility, responsiveness, service reliability, professionalism, courtesy — are not the same as those around a product.

The AI service quality model adds three AI-specific elements:

  • Traceability (modified sub-characteristic of security) — proper logging and record-keeping of models, datasets, requests, and outcomes, with a pointer to the forthcoming ISO/IEC TS 24970 on AI system logging.

  • Service adaptability (modified characteristic) — the degree to which a service can be adapted based on functions, responsibility, employee skills, communication style, or available instruments.

  • Customizability (modified sub-characteristic of service adaptability) — the degree to which the AI service can be customised at the request of users.

For organisations offering AI-as-a-service, this is the first time SQuaRE has given them a quality vocabulary that is not just pulled sideways from product quality.

Environmental sustainability

Clause 5.8 of the DIS is entirely new. Environmental sustainability appears as a sub-characteristic of performance efficiency in the product quality model, and environmental risk mitigation appears as a sub-characteristic of risk mitigation in the quality-in-use model. The definitions draw on ISO 14001 and ISO 17889-1, introducing terminology around the sustainability aspects, environmental impact, life cycle assessment, economic sustainability, and social sustainability.

The Clause itself is relatively modest in what it describes (environmental sustainability of AI is described as an emerging discipline) but it points to a reasonably comprehensive set of other standards that practitioners can reach for: ISO/IEC TR 20226 on environmental sustainability aspects of AI systems, ISO/IEC 21031 on software carbon intensity, ISO 14040 on life cycle assessment, ISO 14064-1 on greenhouse gas emissions, IEEE 1922.2, ITU-T L.1480, and ISO 59020 on circular economy. The worked example in the text is worth reading: a designer uses ISO/IEC TR 20226 to specify software carbon-intensity requirements, a developer implements the measurement using ISO/IEC 21031, and the deploying organisation consumes the metric output in its greenhouse gas emissions reporting.

The significance here is less what the clause says in isolation and more that environmental concerns are now a first-class quality property of an AI system, on equal footing with correctness, robustness and transparency.

Refinements to existing sub-characteristics

Several of the existing additions have been tidied up:

  • User controllability has moved from being a sub-characteristic of usability to being a sub-characteristic of interaction capability, reflecting the 25010:2023 restructuring. The text now references a “controller” as an authorised human or external agent performing a control — a definition borrowed from ISO/IEC/IEEE 24765:2017 — and introduces the concepts of control points and engagement of control. Cross-references have been updated to ISO/IEC TS 8200, the new controllability standard.

  • Intervenability has been promoted from a sub-characteristic of usability to a sub-characteristic of the new safety characteristic — a more natural home given that its purpose is explicitly to prevent harm or hazard.

  • Transparency now references ISO/IEC 12792 (the AI transparency taxonomy, published in 2025) and ISO/IEC TS 6254 (on the explainability and interpretability of ML models), giving practitioners a concrete reference for the underlying taxonomy.

  • Robustness is now tied to the ISO/IEC TS 22440 series on functional safety and AI systems (parts 1–3), replacing the reference to the older TR 5469.

Updated and expanded bibliography

The bibliography grows substantially in the DIS, reflecting the maturation of the AI standards ecosystem since 2023. Notable additions include references to ISO/IEC TS 25058:2024 (quality evaluation of AI systems), ISO/IEC TS 8200 (controllability), ISO/IEC 12792 (transparency taxonomy), ISO/IEC TS 12791 (treatment of unwanted bias), ISO/IEC TR 20226 (environmental sustainability aspects), ISO/IEC 21031 (software carbon intensity), ISO/IEC TS 22443 (societal concerns and ethical considerations, replacing the reference to TR 24368 as the primary source), and the ISO/IEC 42119 series for AI testing, which supersedes the references to ISO/IEC TR 29119-11:2020 in the main text.

What this means in practice

For anyone using 25059 as a reference for AI quality specification — whether that’s in regulated contexts, internal quality programmes, or procurement — three things are worth noting.

First, the second edition will be substantially larger in scope. Anyone specifying against the first edition has essentially been working with the product quality model plus two quality-in-use additions. The DIS brings a full-service quality model and a serious environmental sustainability layer into the picture.

Second, the alignment with 25010:2023 means the inherited characteristics are richer. Safety is now a full top-level characteristic rather than being folded into reliability or freedom from risk. Authenticity, resistance, and recoverability are now named security sub-characteristics. User engagement and inclusivity are now sub-characteristics of interaction capability. All of these flow into 25059 by reference.

Third, the DIS has now completed the public enquiry. Under ISO/IEC procedures, that means member bodies have cast their votes based on national stakeholder comments. If the text is approved without substantive technical changes, it proceeds to publication; if technical changes are introduced, an FDIS ballot will be triggered. Either way, the 2023 edition is on its way out, and the shape of the successor is now largely set.

Why do I need to buy this standard?

National standards bodies probably won’t like me saying this, but you probably don’t. Unless you work directly with quality models and specify requirements for AI systems. In some ways, this is a standard for standards developers, it provides a consistent model that is then reused in testing, evaluation and conformity assessment related standards. More on those standards soon....

AI regulation, standards and reality is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.

Read on adamleonsmith.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.