AI Assurance Institute Logo AI Assurance Institute

Trustworthy AI Under the EU AI Act
How Articles 12-15 and prEN 18229 (Parts 1 & 2) Build Real Confidence in High-Risk Systems

March 2026 - Data Protection Schemes

In the fast-evolving world of artificial intelligence, 'trustworthy AI' is no longer a nice-to-have - it is a legal and ethical imperative. The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) places trustworthiness at the centre of high-risk AI compliance through four interlocking requirements in Articles 12 to 15.

These are not abstract ideals; they translate into concrete obligations that providers and deployers must demonstrate. To make compliance practical and harmonised across Europe, CEN/CLC Joint Technical Committee 21 (JTC 21) has developed the prEN 18229 series:

Once cited in the Official Journal of the European Union (expected 2026), adherence to these standards will grant a presumption of conformity with Articles 12-15.

This article explores what trustworthiness really means under the AI Act, how prEN 18229 operationalises it, and why organisations that master these requirements will gain a decisive competitive and regulatory advantage.

Why Trustworthiness Matters: The Four Pillars of the AI Act (Articles 12-15)

The EU AI Act defines trustworthiness through four interdependent pillars that together ensure AI systems are transparent, controllable, verifiable, and resilient.

  1. Article 12 - Logging: The Evidence Trail
    High-risk AI systems must automatically record relevant events in a secure, tamper-proof manner. Logs must capture inputs, outputs, system behaviour, and decisions.
  2. Article 13 - Transparency: Information for Deployers
    Providers must supply deployers with clear, accurate information about the system's capabilities, limitations, intended purpose, and foreseeable misuse.
  3. Article 14 - Human Oversight: Keeping Humans in Control
    Systems must be designed so natural persons can understand outputs, monitor performance, and intervene effectively (human-in-the-loop, on-the-loop, or in-command).
  4. Article 15 - Robustness, Accuracy & Cybersecurity: Reliable Under Pressure
    Systems must maintain stable, predictable, and exact behaviour even under adversarial attacks, data drift, or environmental changes.

prEN 18229: The Harmonised Technical Blueprint for Trustworthiness

prEN 18229-1: Logging, Transparency and Human Oversight
Establishes precise specifications for logging, templates for transparency information, and design patterns for effective human oversight interfaces.

prEN 18229-2: Accuracy and Robustness
Focuses on metrics, testing methods, adversarial training, feature denoising, and integration with cybersecurity controls (prEN 18282).

How prEN 18229 Integrates with RMS (prEN 18228) and QMS (EN 18286)

Trustworthiness is not a standalone workstream. prEN 18229 plugs directly into the two foundational management systems:

Practical Benefits and Real-World Implications

Implementation Roadmap

  1. Map your current state against Articles 12-15 and prEN 18229
  2. Integrate with RMS and QMS
  3. Design and document logging, transparency, oversight, and robustness controls
  4. Test and validate under real-world conditions
  5. Monitor and improve via post-market surveillance
  6. Prepare technical documentation for conformity assessment

Ready to build trustworthy AI that meets the highest European standards?

AI Assurance Institute offers targeted training and implementation support on prEN 18229 (Trustworthiness), prEN 18228 (RMS), EN 18286 (QMS), and the full suite of AI Act harmonised standards.

Contact us today to schedule a gap analysis or join one of our upcoming one-day fundamentals courses.

This article is based on the latest public information on the EU AI Act and CEN/CLC JTC 21 standards. Standards remain in the drafting stage and will be updated upon final publication.

© 2026 AI Assurance Institute. All rights reserved.