Providers Fill the AI Standard-Setting Vacuum Globally
Public standards bodies missed their August 2025 deadline to publish the harmonized technical standards the EU AI Act relies on, according to a Just Security analysis published June 30, 2026, prompting the European Commission to propose staggering parts of the Act's application into 2027 and 2028. An official EU Council press release confirms Annex III high-risk AI requirements are now deferred to December 2027. In the interim, Just Security reports, AI providers are defining their own interpretations of requirements such as accuracy, fairness, robustness, and human oversight, relying on sectoral guidance or internal processes rather than finalized public standards. For practitioners, that raises compliance risk and increases the cost of demonstrating safety and fairness, since teams must document their own definitions and tests without a shared external benchmark.
For compliance, assurance, and evaluation teams, the current moment is one where vendor-created definitions and tests will materially shape what "compliant" AI looks like in the short term. That raises the importance of rigorous, reproducible documentation for metrics, test suites, and challenge cases, and it raises the stakes for independent auditability.
What happened
According to Just Security, the harmonized technical standards the EU AI Act expects standards bodies to publish were not delivered by their August 2025 deadline. Just Security reports that the European Commission proposed delaying parts of the Act's application into 2027 and 2028 because of that delay. An official EU Council press release from May 7, 2026 confirms enforcement of Annex III high-risk AI requirements is deferred to December 2027, and law firm analysis (Travers Smith) reports Annex I embedded products are deferred to August 2028, both due to standards not being ready by the original August 2, 2026 date. Just Security's article states that, in the interim, providers are developing their own definitions of what satisfying legal requirements such as accuracy, fairness, robustness, and human oversight entails, supplemented at most by sectoral guidance from non-AI regulators.
Industry context
The gap between legal requirements and operational definitions is a recurring pattern when policy specifies high-level outcomes but delegates technical detail to standards bodies. Practitioners face comparable frictions in other regulated domains where technical committees lag. The Just Security piece highlights a structural disconnect between the technical risk-framing used by engineers and the rights-and-process framing used by legal regulators, creating room for divergent operational interpretations.
For practitioners
Engineering and compliance teams should assume increased responsibility for defensible metrics and testing protocols. Where public standards are absent, internally consistent evidence - versioned test suites, benchmark distributions, provenance for training/validation data, and documented human-in-the-loop processes - will be the primary artifacts that auditors and sector regulators examine. The absence of harmonized standards also elevates the role of third-party testing and sector-specific guidance during audits.
What to watch
- •Publications from standards bodies for any interim technical specifications.
- •Sectoral regulator guidance that may establish de facto norms.
- •Third-party audit frameworks and major providers' whitepapers that could become de facto standards if widely adopted.
- •Whether the European Commission's staggered timeline (2027, 2028) holds or slips further, since that governs how long provider-defined norms persist.
Editorial analysis
The pattern here is not unique to the EU: whenever binding law outruns the technical standards meant to operationalize it, the entities being regulated end up writing the interim definitions. For AI specifically, that means the providers with the most resources to produce polished self-assessments have outsized influence over what "compliant" comes to mean in practice, at least until harmonized standards or strong third-party audit norms catch up.
Key Points
- 1Standards bodies missed their August 2025 deadline for EU AI Act technical standards, delaying Annex III enforcement to December 2027.
- 2In the gap, AI providers are self-defining compliance criteria for accuracy, fairness, robustness, and human oversight.
- 3Teams should prioritize versioned test suites and documented evidence now, since these will be what auditors examine absent shared standards.
Scoring Rationale
The EU AI Act Annex III deferral to December 2027 creates an 18-month window where provider-defined tests and metrics will shape compliance, directly affecting practitioner decisions on evaluation, documentation, and procurement. Well-corroborated by an official EU Council decision and independent legal analysis alongside the Just Security piece, though the story is more consequential for compliance specialists than for a broad practitioner audience, keeping it in the solid-to-notable range.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

