1 · Concept overview
Established The strongest available evidence that technical standards govern is that when the standards are late, the law moves. The European Union’s Artificial Intelligence Act put its high-risk obligations into statute and then delegated their operative content to harmonised standards that private European standards bodies had not yet written. The standards slipped. In 2026 the Union amended its own flagship statute rather than enforce it against an absent compliance route: Regulation (EU) 2026/1744 entered into force on 27 July 2026, moving the Annex III high-risk obligations from August 2026 to December 2027 and the Annex I product-embedded obligations to August 2028. Frontier A legislature deferring to a standards committee’s work rate is the mechanism of this brief, stated once and in public.
Established The mechanism is not metaphorical and it has a legal name. Under the European New Approach, legislation states essential requirements and a harmonised standard cited in the Official Journal confers a presumption of conformity on anyone who follows it. The Court of Justice held in 2016 that such a standard forms part of European Union law and falls within the Court’s interpretive jurisdiction, and in March 2024 its Grand Chamber held that harmonised standards must therefore be publicly accessible, overriding the standards bodies’ copyright. In the United States the same seam runs through the National Technology Transfer and Advancement Act of 1995 and Circular A-119, which direct federal agencies to adopt private consensus standards, thousands of which are incorporated by reference into the Code of Federal Regulations.
Frontier The commission that prompted this brief named ISO Strategy 2030 as its starting point, and it should be read as what it is. It is a normative agenda published by an interested party about its own future importance. It asserts that standards serve the public good; it is not evidence that any particular governance mechanism works, and nothing in it measures an outcome. This brief cites it as a statement of ambition and looks elsewhere for evidence.
Established Scope, because three sibling briefs hold neighbouring ground and none owns this question. Global Cooperation Models measures treaty regimes and finds one with instrumented success; standards are the non-treaty instrument that sits underneath those regimes. Future Legal Systems owns computation entering law; this brief owns the older and larger phenomenon of private technical documents becoming law. Innovation Ecosystems ranks innovation policy by evidence quality, and standards policy would rank near the bottom of that ranking on its own terms. The joint question — how definitions, interoperability rules, certification and participation rules shape technology before any legislature acts — is what follows.
Established A note on sourcing. This brief was commissioned in September 2026 from the Institute’s research base. Reading-list entries without links are cited from the bibliographic record rather than re-fetched, and claims are dated no later than early 2026 unless carried by a linked source.
2 · Current scientific position
Established Start with the landscape, because the word “standard” covers at least four institutions with incompatible constitutions. The International Organization for Standardization and the International Electrotechnical Commission vote by country through national member bodies, one country one vote. The Third Generation Partnership Project, which specifies mobile networks, is a partnership of regional organisations in which companies negotiate and the unit of agreement is corporate. The Institute of Electrical and Electronics Engineers admits individuals and entities. The Internet Engineering Task Force has no membership at all. Frontier These are four different answers to who is represented, and they produce four different capture patterns; treating them as one sector is the commonest analytical error in the literature.
Established The Internet body is the only one that has written down its decision rule and admitted its fragility. RFC 7282 defines rough consensus as the state in which every issue has been addressed but not necessarily accommodated, holds that the absence of sustained disagreement matters more than the presence of agreement, and states plainly that the model is not self-enforcing. Frontier That is doctrine rather than outcome evidence, and no standards body anywhere publishes an evaluation of whether its procedure produces better standards than an alternative would.
Established The definitional layer governs hardest and attracts the least scrutiny. Whether methane is counted over a hundred-year or a twenty-year warming horizon changes national emissions inventories by a large factor without changing a molecule of gas. Whether a company’s purchased electricity is accounted market-based or location-based decides whether renewable energy certificates count towards its target. Established These are measurement definitions written in technical committees, and they redistribute obligations between states and firms more decisively than most statutes do. A definition is a policy instrument that is not debated as one.
Established Interoperability standards create markets, and the cleanest case is mobile telephony. European administrations and operators converged on a single digital cellular specification in the late 1980s and built a continental market before any directive compelled it, while the United States left the choice to licensees and got incompatible systems competing for a decade. Frontier The causal weight of that choice is genuinely contested: Europe’s early equipment lead did not survive into the platform era, so the standard explains a market and not an industry’s long-run position. It remains the strongest natural experiment the field has.
Established A single national agency now sets global cryptography, which is the most concentrated instance of standards power in existence. The United States National Institute of Standards and Technology ran a multi-year public competition for post-quantum algorithms and approved the resulting federal information processing standards in 2024. Those algorithms are what the world will migrate to, because the alternative is no interoperable migration at all. Frontier The process was open, adversarial and technically excellent, and it was still one government’s process; Post-Quantum Migration owns the migration timetable that follows from it.
Established Conformity assessment is where standards actually bite, and it fails on capacity rather than on content. The European medical devices regime moved from directives to a regulation and required almost every product to be re-certified by designated notified bodies; the certification supply did not exist, products were withdrawn from the European market, and the Union extended its own transition deadlines by legislation in 2023 to avoid shortages. Established That is the same failure shape as the artificial intelligence deadline slip four years later: the substantive rule was written, the assessment infrastructure was not, and the deadline moved. Frontier The Cyber Resilience Act now places a very large population of connected products into the same machinery, and no published analysis has established that assessment capacity exists for it either.
Established Standard-essential patents are the mechanism by which standardisation converts into revenue, and the declaration system is known to be inaccurate. Firms self-declare patents as essential to a standard when they commit to license on fair, reasonable and non-discriminatory terms; independent essentiality checks repeatedly find that a minority of declared patents are truly essential. Established Courts have taken the governance role by default: a European court framework for injunctions, an English court setting a global licence rate, and a German court reading the same commitments more favourably to patent holders. Frontier The European Commission proposed in April 2023 to govern this directly with a register, essentiality checks and an aggregate royalty mechanism, and withdrew the proposal in 2025. The only attempt to regulate the regulators failed within two years.
Established The geopolitical story is real and is routinely told with a document that does not exist. There is no published Chinese plan called China Standards 2035; the phrase originates in a research project and in Western commentary. The actual instrument is a national standardisation development outline issued in 2021 by the State Council and the Party centre, which sets targets for international standards participation and for converting domestic standards into international ones. Frontier The measurable fact underneath the rhetoric is a sustained rise in Chinese secretariats and leadership positions in international technical committees, from a low base, alongside proposals in the telecommunications union that were considered and not adopted.
Established The responses have been institutional rather than technical. The Union published a standardisation strategy in 2022 and amended its standardisation regulation so that decisions on harmonised standards are taken by national delegations rather than by any participant, an explicit move to exclude non-European influence from the part of the system that carries legal effect. The United States published a national standards strategy for critical and emerging technology in 2023 and has since stood up dedicated artificial-intelligence standards capacity, including an agent-standards initiative announced in February 2026. Frontier Both are statements of intent whose effects are not yet measurable.
Frontier Meanwhile the fastest-moving standards of the decade are being set outside the standards system entirely. Memory interfaces are fixed by a trade consortium; the interface by which language models call external tools was published by a vendor and is versioned by date rather than by ballot; and the authentication of autonomous agents is being drafted in the Internet body as an individual submission. Frontier Whether agentic infrastructure ends up governed by a treaty-adjacent standards organisation, a consortium, or a company repository is undecided, and Agentic Autonomy and Control owns the control question that sits on top of it.
3 · Frontier questions
Frontier Can standardisation carry a general-purpose technology at all? Every successful conformity regime tests a product against a fixed specification: a pressure vessel, a plug, a radio. A general-purpose model has no fixed function, and the artificial-intelligence rulebook currently indexes systemic risk to a compute threshold because no validated capability measurement exists to index it to instead. Frontier That substitution is the single most consequential open question in technical governance, and it is a measurement problem before it is a policy one.
Frontier Does free access change who participates? The 2024 access ruling in Europe is a natural experiment with a clean before and after: harmonised standards that were sold are now to be available, and the field has decades of complaint that paywalls exclude small firms, academics and civil society. Whether access changes downloads, compliance, or committee composition is measurable and, so far as this brief can establish, unmeasured.
Frontier Is a standard that nobody can be sued over a standard? Voluntary consensus documents acquire legal force through citation, incorporation or certification, and each route has different reviewability. A harmonised standard is reviewable as Union law; a standard incorporated by reference into a United States regulation is reviewable as agency action; a consortium specification adopted by every vendor is reviewable by nobody. The fastest-growing category is the third.
Speculative Do standards actually improve outcomes, or select good firms? The management-system literature — quality, environmental, and now artificial-intelligence management standards — finds effects that are small, heterogeneous and heavily confounded by self-selection. Certification is a signal whose informational content depends on the auditor, and auditor quality is itself unstandardised.
4 · Technological bottlenecks
Established Committee throughput is a hard constraint and nobody plans around it. A harmonised standard takes years from standardisation request to citation in the Official Journal, and the volume of expert time available is finite and donated by employers. Legislation can be drafted faster than the standards it depends on, and the artificial-intelligence timetable is the proof.
Established Assessment capacity is the second constraint and it is physical. Notified bodies, laboratories and auditors are people with accreditations; their number cannot be doubled by regulation. Every expansion of conformity assessment scope without a matching expansion of assessor supply has produced the same outcome: bottleneck, market withdrawal, deadline extension.
Frontier Participation is priced, and the price is the governance. Membership fees, travel to international meetings and the staff time to read and comment on hundreds of pages per ballot cycle are all affordable to large firms and to nobody else. European consumer and trade-union representation in standardisation is publicly subsidised precisely because it would otherwise not exist, and that subsidy covers a small fraction of active technical committees.
Established The text is often paywalled, which is a constraint on compliance as well as on scrutiny. A firm subject to a regulation may need to buy a set of documents costing thousands to learn what the law requires of it. The Court of Justice resolved this for harmonised standards in 2024 and it remains the ordinary condition for standards incorporated into law elsewhere.
Frontier Measurement is the constraint for anything at the frontier. There is no agreed instrument for the capability or the risk of a general-purpose model, no agreed benchmark for the reliability of an autonomous agent, and no reference material for either. Standards bodies can write process requirements without a measurement, and process requirements are exactly what they have written.
5 · Research dependencies
Established Everything here depends on metrology, which is the part of the system that works. The international system of units, the mutual recognition arrangement between national measurement institutes, and the traceability chain that connects a factory instrument to a primary realisation are the quiet precondition for every conformity claim ever made. That infrastructure is over a century old, is genuinely multilateral, and is the best counterexample to the pessimism in the rest of this brief.
Established It depends on trade law. The World Trade Organization agreement on technical barriers to trade obliges members to base regulations on international standards where they exist, which is what converts a Geneva committee output into an instrument with global reach. Future Trade Systems owns the trade architecture; the point here is that the obligation runs from the treaty to the standard, and it is the treaty that makes the standard matter.
Frontier It depends on a measurement science that nobody owns. Evaluation of general-purpose systems is currently produced by the firms being evaluated, by academic groups without stable funding, and by new government institutes with small budgets. Until an evaluation is reproducible across laboratories, a conformity claim about an artificial-intelligence system is a claim about paperwork.
Established It depends on courts willing to look inside. The European access and interpretation rulings exist because litigants brought them, and the American incorporation-by-reference fight was carried by a single nonprofit publisher against trade associations. Judicial review of technical governance is presently a function of who is willing to litigate.
6 · Required experiments
Frontier The decisive experiment is already running and has a date: whether European harmonised standards for high-risk artificial intelligence exist and are cited in time for the December 2027 obligations, or the deadline moves a second time. This is the cleanest test technical governance has ever been given. A legislature has committed in statute to obligations whose content only a private standards committee can supply, has already once amended the statute rather than enforce it without that content, and has published a new date. If the standards arrive and the date holds, delegated standardisation can carry frontier technology. If the date moves again, it cannot, and the Union will have demonstrated that on its own most important technology file. Frontier No new institution is required to run this experiment and no one can stop it.
Frontier The second experiment is the access ruling. Free availability of harmonised standards from 2024 onwards permits a straightforward before-and-after study of who reads and who participates. The counterfactual is unusually clean because the change was judicial, abrupt, and applied to one category of document and not to its neighbours.
Speculative The third is a comparison nobody has run. The same technical problem is now being addressed simultaneously by a national institute, an Internet body working group and a vendor specification in the agent-authentication space. Tracking which text is implemented, by whom and how fast would be the first controlled comparison of standardisation venues ever conducted, and the material is public.
Frontier The natural experiment already completed is the medical device regulation. A jurisdiction expanded conformity assessment scope without expanding assessor supply and measured the result in withdrawn products and extended deadlines. That dataset exists, and it predicts the artificial-intelligence outcome better than any theory of standardisation does.
7 · Engineering requirements
Established A standard is an engineering artefact with a versioning problem. Physical-product standards assume a stable specification and a slow revision cycle; software and model standards face artefacts that change weekly. The vendor protocol governing model-to-tool calls is versioned by publication date, which is an honest admission that the ballot cycle is the wrong clock.
Frontier Machine-readable standards are the obvious fix and are barely deployed. If a requirement can be expressed as a testable assertion rather than as prose, conformity assessment can be partly automated and the assessor bottleneck partly relieved. Pilot work exists in several sectors; no major regulatory regime has adopted it as the primary form of a requirement.
Established Reference implementations and test suites decide whether a standard is real. The bodies whose standards interoperate in practice ship conformance suites and plugfests; the bodies whose standards are paper requirements do not. This distinction predicts implementation quality better than the formality of the process does.
Established Profiles and options are where interoperability goes to die. A standard with many optional features produces conforming implementations that do not work together, which is why the durable interoperability successes tend to be the ones with narrow mandatory cores.
8 · Adjacent technologies
Established Governance of artificial intelligence is the live application. AI Governance owns the substantive regulatory debate; this brief owns the delivery mechanism that debate depends on, which is why the 2026 postponement belongs here rather than there. Agentic Autonomy and Control owns the authorisation problem whose standardisation is being contested in three venues at once.
Established Network and compute infrastructure are standards artefacts end to end. Next-Generation Networks owns the mobile specification lineage; Compute Concentration owns the consequences of memory and interconnect standards set by consortia; Post-Quantum Migration owns the migration that a single agency’s algorithm choice initiated.
Frontier Provenance and identity are the next standards battlegrounds. Content Authenticity Infrastructure covers the credential formats whose adoption will be decided by browser and platform implementers rather than by ballots, which is the third reviewability category above.
Established The institutional literature sits next door. Distributed Governance carries the evidence on non-hierarchical decision procedures and their drift towards oligarchy, which is the general form of the capture worry here. Innovation History supplies the patent-measurement caution that applies directly to declared standard-essential patents.
9 · Institutional requirements
Established The accountability gap is specific and nameable. A body that writes an instrument with legal effect is not subject to freedom-of-information law, administrative procedure, impact assessment, or judicial review of its drafting. European litigation has closed the access half of that gap for harmonised standards and left the procedural half untouched. There is no route by which an affected party can challenge the content of a technical committee’s decision before it acquires legal force.
Frontier The fix that would matter most is boring and cheap. Publicly funded seats for non-industry experts on the committees whose outputs will be cited in law, at a scale matching the number of such committees rather than a token share, is the only proposal in circulation that addresses composition rather than transparency. It is unglamorous, costs a rounding error against the regulated sectors, and has never been implemented at scale.
Established Standards bodies are funded by selling the documents they write, and that business model is now in conflict with their legal role. Once a document is law, charging for it is untenable, and the 2024 ruling says so. No replacement funding model for the European bodies has been agreed, which makes the access victory an unfunded mandate.
Frontier Venue choice is now a strategic decision made by firms. A company that prefers speed and control publishes a specification; one that prefers legitimacy takes it to an international body; one that prefers a defensible intellectual-property position takes it to a body with a favourable licensing policy. Speculative Nothing constrains that choice, and the observable trend in frontier computing is towards the venues with the least external accountability.
10 · Ethical & societal considerations
Established Rule-making without representation is the ethical core of the problem. The people bound by a technical standard — workers using a machine, patients with an implant, users of a model — are not present when it is written, and the procedural protections that exist for legislation exist here only where a court has imposed them.
Frontier Standards export regulatory preferences to states that had no vote. A manufacturer serving a large market builds to that market’s standard everywhere, so a European or American requirement becomes a global requirement without any other jurisdiction consenting. This is usually described approvingly when the requirement is a safety one and critically when it is a trade barrier; it is the same mechanism in both cases.
Established Certification can launder responsibility. A certificate transfers the appearance of assurance from the manufacturer to an auditor who inspected documents, and the failure cases — devices, emissions test cycles, financial audits — share a structure in which everyone was compliant and the outcome was bad. Compliance is not safety, and conformity regimes systematically blur the two.
Speculative The frontier version is worse because the measurement is missing. A management-system certificate for artificial intelligence attests that a process exists, not that a system is safe, and a market that treats the two as equivalent will have built an assurance industry on an unvalidated proxy.
11 · Civilizational implications
Established Standards are the most durable technical institutions humans have built, and their durability is underrated. Container dimensions, screw threads, units, character encodings and network protocols have outlasted the states and companies that produced them, and they coordinate more behaviour per page than any body of legislation. A civilization’s technical standards are a better record of what it actually required than its laws are.
Frontier The fragmentation scenario is the one worth watching. If the major blocs certify to incompatible requirements for the same technologies, the cost is not principally trade friction but the loss of a shared technical vocabulary, and the assurance that a measurement made in one place means the same in another. The metrology layer has so far held while the regulatory layer diverged, and nothing guarantees it continues to.
Speculative The long-run question is whether machine-verifiable requirements displace prose ones. If conformity can be demonstrated by executing a test rather than by an auditor reading a file, the assessor bottleneck disappears and so does much of the certification industry. That would be the largest structural change in technical governance since the New Approach, and nothing currently in force points at it.
12 · Timelines
These horizons track dated legal instruments and committee deliverables rather than technology, because in this field the dates are the evidence:
- 10 yr: Frontier The December 2027 high-risk date either holds against delivered harmonised standards or moves again, and that single outcome is the field’s decisive result. Frontier The Cyber Resilience Act meets the same assessor-capacity constraint that the medical device regulation already demonstrated. Speculative A funded participation mechanism for non-industry experts is cheap, obvious and has no sponsor.
- 25 yr: Speculative Either a validated measurement of model capability exists and conformity assessment for artificial intelligence becomes real, or certification remains a process attestation and the assurance industry is built on a proxy. Speculative Bloc-level certification divergence becomes structural, with mutual recognition surviving in metrology and not in requirements.
- 50 yr: Speculative Machine-verifiable requirements displace prose requirements in at least one major regime, or the assessor bottleneck permanently caps how much technology can be regulated at all. Speculative The venue question for computing infrastructure resolves towards consortia and vendors rather than towards treaty-adjacent bodies.
- 100 / 250+ yr: Handwave Claims that global technical governance converges on a single legitimate standards constitution assume away the fact that the four existing constitutions disagree about who is represented, and that disagreement is the whole subject.
13 · Technology tree & dependencies
- Depends on Global Cooperation Models for the treaty architecture that gives international standards their global reach, and Future Trade Systems for the trade obligations that convert a committee output into a market requirement. AI Governance supplies the substantive rules whose delivery mechanism is examined here. No research result on this map blocks standards governance; its blockers are institutional, and that is the finding.
- Requires (not on this map) Six constraints, five of them decisions and one a result. Free public access to standards incorporated into law was ordered for European harmonised standards in 2024 and is still the exception globally; it is also an unfunded mandate until the bodies that sell documents are funded another way. A participation subsidy for non-industry experts on technical committees is the only proposal that addresses composition rather than transparency, and it exists at token scale. An independent essentiality check for declared standard-essential patents would replace self-declaration with measurement, and the attempt to mandate one was withdrawn in 2025. Notified body capacity matched to the scope of conformity assessment is an industrial-capacity question that no regulation can legislate into being, and its absence has already moved two European deadlines. An aggregate royalty determination mechanism for standardised technologies is the market instrument that would end the litigation-by-jurisdiction regime, and no jurisdiction now proposes one. A validated measurement of general-purpose model capability and risk is the scientific result nobody is producing, and without it every artificial-intelligence conformity claim describes a process rather than a property.
- Enables Enforceable frontier-technology regulation, assurance that means something to a buyer, and mutual recognition across blocs. No typed enabling edge is claimed, because each of those waits on a constraint above rather than on a result produced here.
- Adjacent Future Legal Systems, Innovation Ecosystems, Distributed Governance, Next-Generation Networks, Post-Quantum Migration, Compute Concentration, Content Authenticity Infrastructure, Innovation History; and off the map, metrology, competition law and trade law.
14 · Common misconceptions & speculative claims
Handwave “China Standards 2035 is a published national plan.” No such document has been published. The phrase comes from a research project and from Western analysis of it; the real instrument is a 2021 national standardisation development outline with participation targets. The underlying trend in committee leadership is real and is routinely evidenced by citing a plan that does not exist, which is a bad habit whatever one concludes.
Established “Standards are voluntary.” A harmonised standard cited in the Official Journal confers a presumption of conformity and has been held to form part of Union law; a standard incorporated by reference into a United States regulation is enforceable as that regulation. The formal freedom to demonstrate conformity another way is, in practice, the freedom to fund your own test programme and argue with an inspector.
Frontier “Whoever writes the standard wins the market.” The mobile case supports a weaker claim: a coordinated standard created a continental market and an equipment lead that did not survive into the platform era. Standards allocate positions within a market they help create; they do not determine who captures the value a generation later.
Established “Declared standard-essential patents measure contribution.” Declarations are self-made, unaudited, and over-inclusive by design because declaring is cheap and failing to declare risks the licensing commitment. Independent essentiality checks find a minority genuinely essential, so any ranking built on declaration counts is measuring declaration behaviour.
Frontier “ISO Strategy 2030 shows the system is working.” It is a normative agenda by an interested party about its own importance, and it contains goals rather than measured outcomes. The evidence that standards govern is elsewhere: in court judgments, in incorporation by reference, and in a legislature moving its own deadline because a committee was late.
Speculative “Open standards means free standards.” Openness usually refers to the process, not the text. Several of the most important standards in the world are sold, and until 2024 that included documents with direct legal effect in the European Union. The two properties are independent and are conflated constantly.
Handwave “Certification means the product is safe.” Certification means an assessor found documentary evidence of conformity with a specification at a point in time. The canonical failures — implants, emissions test cycles, audited accounts — were all compliant. Treating a certificate as a safety claim is the single most expensive category error in this field.
Speculative “Artificial intelligence can be standardised like machinery.” Machinery conformity rests on a fixed function and a validated test. General-purpose models have neither, which is why the rulebook currently indexes systemic risk to training compute rather than to capability. That is a placeholder, is acknowledged as one, and is the reason the decisive experiment in this brief is about a deadline rather than about a technology.