When asked who regulates artificial intelligence, most people answer ‘the government’ and point to legislation such as the EU AI Act or national AI strategies such as those of the United Kingdom, France or Singapore. Very few, however, think of technical standards. Laws set out what needs to be achieved: for example, safety, transparency or human oversight. Technical standards flesh out these requirements and describe how they can be implemented in practice. In between lies the quiet, highly organised world of standards development organisations (SDOs), which most people never encounter. Understanding who these organisations are, how they relate to one another, and where AI currently fits into this structure is essential for companies, regulatory bodies and researchers if they wish to have a say in how ‘trustworthy AI’ is actually defined.
Standardisation takes place at three interlinked levels: national, regional and international.
At the national level, participation in standardisation is organised by national standards bodies (NSBs) and national committees (NCs). These organisations represent their respective countries within the International Organisation for Standardisation (ISO) and the International Electrotechnical Commission (IEC). NSBs and NCs are responsible for convening national mirror committees on relevant topics, bringing together experts from industry, academia, government and civil society. These committees develop national positions and contribute to the development of international and regional standards.
At regional level, Europe has the European Committee for Standardisation (CEN) and the European Committee for Electrotechnical Standardisation (CENELEC), both of which are based in Brussels. Their members are the NSBs and NCs from more than 30 European countries, which develop common positions through national mirror committees and delegate experts to the European technical committees and working groups. The resulting standards apply throughout the European Economic Area and, crucially, can be developed as so-called ‘harmonised standards’. These support the implementation of EU legislation and, once their references have been published in the Official Journal of the European Union, can establish a presumption of conformity for products and services with regard to the legal requirements they cover.
At the international level, the ISO and the IEC are active : together, they essentially cover all areas of technology. ISO is an international, non-governmental organisation with 177 national members. It brings together over 50,000 experts and has a collection of more than 26,000 published standards. ISO is coordinated by its Central Secretariat in Geneva. The IEC is also an international, non-governmental organisation based in Geneva, which brings together around 30,000 experts from more than 150 countries to develop international standards for electrical, electronic and related technologies. Neither organisation drafts standards itself; instead, they appoint experts from among their members to develop the standards. Both operate according to the strict principle of ‘one country, one vote’, ensuring that a standard reflects a genuine international consensus rather than the interests of a single market.
Formally, ISO and IEC define a standard as ‘a document drawn up by consensus and approved by a recognised body, which provides rules, guidelines or characteristics for activities or their results, with the aim of achieving an optimal level of order in a specific context’. Consensus means ‘general agreement, characterised by the absence of sustained opposition on significant points’, not unanimity. This distinction is important: consensus-based standards can be advanced more quickly than contract law, whilst still enjoying broad legitimacy.
What do these three levels look like from a national perspective? In Switzerland, participation in international and European standardisation takes place through two organisations: the Swiss Standards Association (SNV), a member of ISO and CEN, and Electrosuisse, a member of IEC and CENELEC.
Interactive infographic
National, European, and international standards bodies work closely together. Through SNV and Electrosuisse, Switzerland is represented at all three levels.
Select one of the three levels to see the organizations, responsibilities, and committees involved.
National standards organizations and national committees represent their countries in ISO and IEC. In national mirror committees, experts from industry, academia, government, and civil society work together to develop common positions.
CEN and CENELEC, both based in Brussels, bring together standards organizations from more than 30 European countries. Their standards apply across the European Economic Area and, when designated as harmonized standards, can support the implementation of EU legislation.
ISO and IEC, both based in Geneva, together cover nearly every area of technology. They do not write standards on their own. Instead, their members bring together experts to develop them. The principle is “one country, one vote.”
Without coordination, the three levels could easily pull in different directions. It is precisely to prevent this that two agreements exist. The Vienna Agreement, signed in 1991 by ISO and CEN, established a framework within which work can be conducted at either European or international level, with the other organisation participating in the process and, where appropriate, adopting the resulting standard. Through parallel development, consultation and coordination, duplication of effort is to be avoided and it is ensured that European and international standards remain aligned. The guiding principle is: ‘One standard, one test, recognised everywhere.’ Three decades later, more than 5,500 documents have been jointly developed under this agreement, and around one in three European standards is now identical to the corresponding ISO standard.
The Frankfurt Agreement, concluded in 2016 between the IEC and CENELEC and building on the earlier Dresden Agreement of 1996, fulfils the same function in the field of electrical engineering. It provides a framework for joint work planning, parallel development and parallel coordination, whereby standards developed by one organisation can, where possible, be adopted by the other. As a result, around 80 per cent of CENELEC standards are now identical to, or based on, the corresponding IEC standards.
For AI, this mechanism is not merely a historical footnote – it is actively shaping the EU AI Act right now. Under Mandate M/613, the European Commission tasked CEN and CENELEC with developing harmonised standards to support the Act. This work is being carried out by their Joint Technical Committee 21 ‘Artificial Intelligence’ (JTC 21). JTC 21 was established in June 2021 and brings together more than 300 experts from 20 countries. Rather than starting from scratch, JTC 21 is deliberately pursuing a dual approach: wherever appropriate, it adopts or adapts existing international work from its international counterpart, ISO/IEC JTC 1/SC 42 ‘Artificial Intelligence’. JTC 21 develops additional Europe-specific standardisation documents only where genuine gaps exist – for example, in the field of AI-specific risk management and cybersecurity.
Although Switzerland is not part of the European Union, the EU AI Act, due to its extraterritorial scope, also affects Swiss companies that place AI systems on the European market. Whilst Switzerland is not involved in the EU’s legislative process, it is fully integrated into the European standardisation system. Through the SNV and Electrosuisse, Swiss experts contribute directly to the standards developed within the framework of CEN and CENELEC, including the work of CEN-CENELEC JTC 21 in support of the AI Act.
Article 40 of the AI Act (Regulation (EU) 2024/1689) states that AI systems which comply with harmonised standards, the references to which have been published in the Official Journal of the European Union (OJEU), benefit from a presumption of conformity with the relevant requirements of the Act. In other words: once the reference to a harmonised standard has been published in the OJEU, organisations can use this as a recognised and widely accepted means of demonstrating compliance with the relevant legal requirements. This is precisely why it matters who is involved in drafting these standards.
AI governance comprises a range of instruments with varying levels of authority and enforceability:
Although each instrument differs significantly from the others in terms of its legal force, each plays a role in how AI systems are developed and deployed.
Standards occupy a unique position within this governance structure. Whilst governments and legislators define the ‘what’ through laws and policy objectives, standards organisations focus on the ‘how’ and translate these objectives into internationally agreed, implementable requirements. Conformity assessment systems then help to verify whether these requirements are met in practice.
This division of labour is not an informal custom, but is enshrined in trade law. Under the WTO Agreement on Technical Barriers to Trade, Member States are required to use relevant international standards as the basis for their technical regulations (Article 2.4) and their conformity assessment procedures (Article 5.4) – unless a particular standard would be ineffective or inappropriate for the policy objective pursued, for example due to fundamental climatic, geographical or technological factors. This is a key reason why AI regulation, including the EU AI Act, relies so heavily on ISO/IEC and CEN/CENELEC standards, rather than incorporating detailed technical requirements directly into the text of the legislation itself: Much of this work has already been carried out as part of international consensus-based processes with greater technical depth.
A standard specifies which requirements must be met and how. Whether a product, system or organisation actually meets these requirements can only be determined through a conformity assessment. Independent testing and certification bodies use tests, inspections and certification to assess whether the requirements of the standard are met.
Through its Committee on Conformity Assessment (CASCO), ISO provides a comprehensive set of standards known as the CASCO Toolbox. These standards set out general principles and requirements for organisations providing conformity assessment services and help to ensure their competence, impartiality and credibility. Most CASCO documents are published jointly by ISO and the IEC. The CASCO Toolbox comprises a broad family of standards on conformity assessment, including the widely used ISO/IEC 17000 series. Whilst CASCO develops guidelines and subsequently publishes these standards, it does not itself carry out any conformity assessment activities.
The IEC has been operating global conformity assessment schemes for decades. Today, it operates four such schemes, each covering a different technological field:
The underlying principle is the same as that of the Vienna and Frankfurt Agreements: test once, recognise everywhere.
AI standardisation is developing in a similar direction. ISO/IEC 42001 defines a certifiable standard for AI management systems, whilst ISO/IEC 42006 sets out requirements for the bodies that assess and certify such management systems. Work is currently continuing on an overarching framework for conformity assessment systems in the AI sector, as well as on the reporting of incidents involving AI systems. In the long term, this could make it possible to independently verify a company’s claim that its AI systems are ‘trustworthy’ or ‘compliant’. Much like the current situation with CE marking or a CB test certificate, compliance could be demonstrated through an objective assessment, rather than merely being claimed through marketing statements.
None of this is abstract. It is precisely this multi-layered, cross-referenced system that enables a principle enshrined in a Brussels regulation to be turned into a checklist that an engineer in Zurich, Belgrade or elsewhere can implement – and which is increasingly subject to independent verification. This is deliberately not a closed loop. Standards are strategic: it is within them that the practical ‘how’ of AI governance is actually decided, often long before the underlying legislation has even been finalised.
Whether you represent a government body responsible for implementing the AI Act or a company required to comply with it: by participating in the development of standards – rather than waiting to receive the final outcome – you are helping to shape rules that reflect your concerns. Your national standards organisation and its AI mirror committee are the gateway to this process.
From 6 to 9 October 2026, the European AI standardisation committee CEN-CENELEC JTC 21 will convene in Winterthur for its second plenary meeting of the year. Several key standards designed to support the EU AI Act are due to be finalised by the end of 2026. The work is therefore entering a crucial phase.
In the run-up to the plenary meeting, SATW and SNV are organising the networking event ‘Trust by Design: Standards for Aligned AI Governance’. The event offers insights into current developments in European and international AI standardisation and provides an opportunity to exchange views with experts directly involved in the development of AI standards.
📅 Monday, 5 October 2026, Mülisaal, Winterthur
🔗 Information and registration
| Role | Title + Name |
|---|---|
| Text by | Boris Inderbitzin, Manuel Kugler, Cindy Parokkil |