IT Brief India - Technology news for CIOs & IT decision-makers
India
BSI sets AI quality standard for EU high-risk systems

BSI sets AI quality standard for EU high-risk systems

Mon, 27th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

BSI has published a standard for quality management systems under the EU AI Act, aimed at organisations placing high-risk AI systems on the EU market.

Known as BS EN 18286:2026, the framework gives companies a route to show compliance with the bloc's rules for high-risk AI systems. It is intended to fill a gap in the legislation, which requires providers to maintain a documented quality management system but does not set out a detailed standard for doing so.

The move comes as businesses face growing scrutiny over how they develop, document and oversee AI systems in regulated settings. Under the EU AI Act, providers of high-risk AI tools must maintain controls covering areas such as lifecycle governance, risk management, validation and technical documentation.

The standard can be used by any organisation placing on the market, or putting into service, high-risk AI systems covered by the EU rules. It is designed to help companies manage risk, improve traceability and embed human oversight in AI systems, while giving them presumption of conformity with the Act.

Regulatory gap

The European Commission issued a standardisation request to support implementation of the AI Act's quality management provisions. BS EN 18286:2026 was developed in response.

The issue is significant because the EU AI Act is the first broad, cross-sector AI regulatory framework adopted by a major economy. Companies selling into Europe are now under pressure to turn legal obligations into internal processes that can withstand conformity assessment.

The standard also aligns with BS ISO/IEC 42001, which focuses more broadly on the management and governance of AI systems across organisations. BSI distinguishes the two by noting that the newer standard is specifically focused on quality management system requirements for high-risk AI systems under the EU regime.

In practice, organisations using the new framework would be expected to formalise governance structures, document processes more consistently, and set out how human oversight is built into decision-making and monitoring. The aim is to create a clearer audit trail for systems that fall into the EU's higher-risk categories.

Governance challenge

The publication also highlights a wider gap between enthusiasm for AI and the controls around it. BSI research found that 65% of business leaders believe AI has delivered tangible benefits to their organisations, while only 24% have an AI governance programme in place.

That mismatch has become more significant as regulators move from broad principles to operational requirements. For many companies, the challenge is no longer whether to adopt AI, but whether they can show systems are documented, tested and overseen in line with legal expectations.

Sectors most affected are likely to include those where AI can influence safety, rights or access to essential services. The press material cited healthcare and autonomous vehicles as examples of areas where businesses want to deploy AI while also meeting stricter regulatory tests.

The standard was developed by experts led by BSI in the UK, together with participants from other national standards bodies in the EU. The group included AI providers and deployers, conformity assessment and certification bodies, regulators, public authorities, academics, civil society representatives, lawyers, and infrastructure and technology suppliers.

That breadth reflects the complexity of the EU AI Act, which spans industries and combines product compliance, governance and risk management requirements. It also underlines how standard-setting is being used as a practical tool to translate legislation into processes organisations can apply.

For BSI, the publication forms part of a broader push around AI governance and assurance. The organisation, which serves as the UK's national standards body, has been involved in developing and adopting standards intended to create common approaches across markets and sectors.

David Cuckow, Director of Digital, Knowledge Solutions, BSI, said: "Organisations are moving quickly to harness the opportunities presented by AI, including healthcare and autonomous vehicles. However, success in the European market and beyond depends on meeting robust regulatory requirements. Before AI systems can be placed on the market or used in the EU, they must comply with the EU AI Act.

"This standard provides organizations with a clear, practical framework to demonstrate compliance, while strengthening their approach to risk management, traceability and human oversight. Ultimately, building trust in AI starts with strong governance, and this standard represents an important step in enabling organizations to deliver responsible, transparent and trustworthy AI."