Guidelines  ·  2026-08-28

CEN-CENELEC prEN 18282 (EU AI Act harmonised cybersecurity standard for high-risk AI systems) completes public enquiry

GuidelinesHigh impactGlobal
prEN 18282, the CEN-CENELEC draft European standard developed explicitly under the European Commission's AI Act standardisation request to cover cybersecurity of high-risk AI systems (data poisoning, model poisoning, adversarial examples, confidentiality attacks), completed its public enquiry stage, receiving 1,817 comments from national standards bodies plus additional contributions from the OWASP AI Exchange. This closes the enquiry phase and moves the standard into comment resolution ahead of a targeted Q1 2027 publication; requirements for high-risk systems would apply from 2 December 2027 (2 August 2028 for regulated products/components). Unlike ISO/IEC 27090, prEN 18282 is normative/certifiable and, if cited in the Official Journal of the EU, would provide presumption of conformity with the AI Act's cybersecurity requirements.
prEN 18282 is the standard most directly tied to EU AI Act legal compliance for high-risk AI system cybersecurity — closing of its public enquiry with a very high comment volume (1,817) signals it is entering its decisive drafting phase and is the closest thing to a binding AI-security control catalogue for EU high-risk AI providers.
High-risk AI system providers under the EU AI Act should begin tracking prEN 18282's comment-resolution process and align internal security control evidence (testing, risk justification) with its outcome-based approach ahead of the 2027-2028 compliance deadlines; do not wait for final publication to start remediation.
Rob van der Veer (CEN/CENELEC JTC21/WG5 co-editor) — LinkedIn announcement of prEN 18282 public enquiry completionCEN-CENELEC JTC 21 Blog
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →