What happened
prEN 18282, the CEN-CENELEC draft European standard developed explicitly under the European Commission's AI Act standardisation request to cover cybersecurity of high-risk AI systems (data poisoning, model poisoning, adversarial examples, confidentiality attacks), completed its public enquiry stage, receiving 1,817 comments from national standards bodies plus additional contributions from the OWASP AI Exchange. This closes the enquiry phase and moves the standard into comment resolution ahead of a targeted Q1 2027 publication; requirements for high-risk systems would apply from 2 December 2027 (2 August 2028 for regulated products/components). Unlike ISO/IEC 27090, prEN 18282 is normative/certifiable and, if cited in the Official Journal of the EU, would provide presumption of conformity with the AI Act's cybersecurity requirements.
Why it matters
prEN 18282 is the standard most directly tied to EU AI Act legal compliance for high-risk AI system cybersecurity — closing of its public enquiry with a very high comment volume (1,817) signals it is entering its decisive drafting phase and is the closest thing to a binding AI-security control catalogue for EU high-risk AI providers.
Action needed
High-risk AI system providers under the EU AI Act should begin tracking prEN 18282's comment-resolution process and align internal security control evidence (testing, risk justification) with its outcome-based approach ahead of the 2027-2028 compliance deadlines; do not wait for final publication to start remediation.