Standards for trustworthy AI in the European Union: technical rationale, structural challenges, and an implementation path
This white paper outlines a layered, lifecycle-oriented framework for EU AI standardization under the AI Act, arguing that despite unique technical challenges like stochastic behavior and data dependencies, harmonized standards combining horizontal process obligations with sectoral profiles are essential for translating legal requirements into auditable engineering practices and enabling scalable conformity assessment.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The Big Picture: Turning Rules into Recipes
Imagine the European Union (EU) has passed a strict law called the AI Act. This law says, "AI must be safe, fair, and trustworthy." But laws are like broad instructions: "Drive safely." They don't tell you how to drive safely (e.g., "keep two car lengths behind the car in front").
This paper argues that technical standards are the missing "driving manuals." They turn the vague legal rule ("be safe") into a specific, checkable recipe ("test the brakes every 5,000 miles").
If an AI company follows these specific recipes (standards), the EU gives them a "Presumption of Conformity." Think of this like a Golden Seal of Approval. Instead of the company having to prove to a judge, "Trust me, my car is safe," they can just say, "I followed the official recipe, and the recipe says my car is safe." The burden of proof shifts from the company to the standard itself.
The Problem: AI is a "Shifty" Ingredient
The paper explains why writing these recipes for AI is incredibly hard, much harder than for a toaster or a car.
AI is Stochastic (It's a Coin Flip):
- The Analogy: Imagine baking a cake. If you follow the exact same recipe with the same ingredients, you get the same cake. But AI is more like a magic trick. Even if you use the exact same ingredients and instructions, the "cake" (the output) might look slightly different every time you bake it.
- The Challenge: How do you write a rule that says "the cake must be perfect" when the cake naturally changes a little bit every time? The paper suggests we stop looking for "perfect copies" and start measuring "stability." We need to agree on how much the cake is allowed to change before it's considered unsafe.
The Data is a Mystery Box:
- The Analogy: An AI is like a student studying for a test. If the student studies from a textbook written by someone else (third-party data) that has missing pages or bad facts, the student will fail.
- The Challenge: AI companies often don't own all the data their AI learns from. The paper says we can't demand they control every single grain of sand in the data ocean. Instead, we need a risk-based approach: If the AI is doing something dangerous (like diagnosing a disease), we need to know exactly where the data came from. If it's doing something low-risk (like recommending a movie), we can be more relaxed.
The "Moving Target" Problem:
- The Analogy: A car is built once and sold. An AI is like a video game character that gets updated every week with new skills and new weaknesses.
- The Challenge: You can't just test an AI once when it's launched. It needs to be tested continuously as it learns and changes. The paper suggests we need a system of continuous logging (like a flight recorder) to see what the AI is doing in real-time, not just a report from the day it was born.
The Solution: The "Layer Cake" Approach
The paper argues that we can't write one single rulebook that fits every AI. A chatbot for a coffee shop has different needs than an AI that controls a nuclear plant.
- The Bottom Layer (Horizontal Standards): This is the skeleton. It applies to all AI. It says things like: "You must have a risk management plan," "You must keep logs," and "You must document your data." It's the common language everyone speaks.
- The Top Layer (Sectoral Profiles): This is the flesh. It adds specific rules for specific jobs.
- Example: The "skeleton" says "test for errors." The "medical profile" says "For heart surgery AI, errors must be less than 0.1%." The "entertainment profile" says "For a movie recommender, errors up to 5% are fine."
Why this matters: If we tried to write one rule for everyone, it would either be too vague to be useful or too strict for simple apps. By stacking the layers, we get a common foundation with specific rules for specific dangers.
How It Actually Works: The "Assurance Case"
The paper proposes a new way for companies to prove they are safe. Instead of just saying "We are safe," they must build an Assurance Case.
- The Analogy: Think of this like a detective's case file.
- The Claim: "This AI is safe."
- The Evidence: A stack of documents. "Here is the test where we tried to trick the AI, and here is the log showing it didn't break. Here is the data we used, and here is the plan for what we do if it starts acting weird."
- The Inspector: A third-party auditor looks at the case file. They don't need to guess; they just check if the evidence matches the "recipe" (the standard).
The Bottom Line
The paper concludes that while AI is messy, unpredictable, and hard to pin down, we must have these technical standards. Without them, the law is just a slogan.
- Without Standards: Every company invents its own way to prove safety. It's chaotic, expensive, and impossible to compare.
- With Standards: Everyone uses the same measuring tape. Companies build "quality systems" to follow the rules. Auditors check the "case files." Authorities can enforce the law based on clear logs.
It won't guarantee that AI is perfect (because AI is complex), but it creates a system where AI behavior is governable and accountable. That is the true definition of "trustworthy" in this context.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.