RSS Amplifier

AI regulation, standards and reality · May 7, 2026

prEN 18228 heads to Enquiry: the product-safety answer to AI risk management

0
Sign in to vote or save

This page did not load. You can still read it on the original site — the toolbar below keeps your place in the directory.

The draft harmonised standard on AI risk management has reached the CEN Enquiry stage. Here’s what practitioners should notice about how it defines risk, what counts as a risk control, and what to do

The CEN-CENELEC JTC 21 working group has now released prEN 18228 — “AI Risk Management” — for public Enquiry. This is the draft harmonised standard intended to provide a presumption of conformity with Article 9 of the EU AI Act, which requires providers of high-risk AI systems to establish, implement, document and maintain a risk management system across the life cycle.

This is also the first horizontal AI risk management standard, anywhere, drafted with a product safety focus.

The Enquiry draft has evolved considerably from earlier working drafts. Three features of the current text deserve particular attention, because each represents a deliberate choice by the drafters with practical consequences for any provider trying to implement a compliant risk management system.

These are:

  1. Risk is defined in line with product safety traditions, but extended to fundamental rights.

  2. Internal policies are not risk controls.

  3. Risk is not always quantifiable.

Read more

Read on adamleonsmith.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.