In the fast-evolving world of artificial intelligence, 'trustworthy AI' is no longer a nice-to-have - it is a legal and ethical imperative. The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) places trustworthiness at the centre of high-risk AI compliance through four interlocking requirements in Articles 12 to 15.
These are not abstract ideals; they translate into concrete obligations that providers and deployers must demonstrate. To make compliance practical and harmonised across Europe, CEN/CLC Joint Technical Committee 21 (JTC 21) has developed the prEN 18229 series:
- prEN 18229-1: AI trustworthiness framework - Part 1: Logging, transparency and human oversight
- prEN 18229-2: AI trustworthiness framework - Part 2: Accuracy and robustness
Once cited in the Official Journal of the European Union (expected 2026), adherence to these standards will grant a presumption of conformity with Articles 12-15.
This article explores what trustworthiness really means under the AI Act, how prEN 18229 operationalises it, and why organisations that master these requirements will gain a decisive competitive and regulatory advantage.
Why Trustworthiness Matters: The Four Pillars of the AI Act (Articles 12-15)
The EU AI Act defines trustworthiness through four interdependent pillars that together ensure AI systems are transparent, controllable, verifiable, and resilient.
- Article 12 - Logging: The Evidence Trail
High-risk AI systems must automatically record relevant events in a secure, tamper-proof manner. Logs must capture inputs, outputs, system behaviour, and decisions. - Article 13 - Transparency: Information for Deployers
Providers must supply deployers with clear, accurate information about the system's capabilities, limitations, intended purpose, and foreseeable misuse. - Article 14 - Human Oversight: Keeping Humans in Control
Systems must be designed so natural persons can understand outputs, monitor performance, and intervene effectively (human-in-the-loop, on-the-loop, or in-command). - Article 15 - Robustness, Accuracy & Cybersecurity: Reliable Under Pressure
Systems must maintain stable, predictable, and exact behaviour even under adversarial attacks, data drift, or environmental changes.
prEN 18229: The Harmonised Technical Blueprint for Trustworthiness
prEN 18229-1: Logging, Transparency and Human Oversight
Establishes precise specifications for logging, templates for transparency information, and design patterns for effective human oversight interfaces.
prEN 18229-2: Accuracy and Robustness
Focuses on metrics, testing methods, adversarial training, feature denoising, and integration with cybersecurity controls (prEN 18282).
How prEN 18229 Integrates with RMS (prEN 18228) and QMS (EN 18286)
Trustworthiness is not a standalone workstream. prEN 18229 plugs directly into the two foundational management systems:
- Risk Management System (prEN 18228): Logging data feeds real-time risk monitoring; transparency informs risk communication; oversight and robustness are selected based on risk assessments.
- Quality Management System (EN 18286): Trustworthiness processes become documented QMS procedures with clear roles, change management, and continual improvement.
Practical Benefits and Real-World Implications
- Regulatory certainty and faster market access
- Operational resilience against drift and attacks
- Improved adoption through clear transparency and effective oversight
- Competitive edge: 'EU-trustworthy AI' as a global differentiator
- Liability protection through defensible evidence
Implementation Roadmap
- Map your current state against Articles 12-15 and prEN 18229
- Integrate with RMS and QMS
- Design and document logging, transparency, oversight, and robustness controls
- Test and validate under real-world conditions
- Monitor and improve via post-market surveillance
- Prepare technical documentation for conformity assessment
Ready to build trustworthy AI that meets the highest European standards?
AI Assurance Institute offers targeted training and implementation support on prEN 18229 (Trustworthiness), prEN 18228 (RMS), EN 18286 (QMS), and the full suite of AI Act harmonised standards.
Contact us today to schedule a gap analysis or join one of our upcoming one-day fundamentals courses.
This article is based on the latest public information on the EU AI Act and CEN/CLC JTC 21 standards. Standards remain in the drafting stage and will be updated upon final publication.
© 2026 AI Assurance Institute. All rights reserved.