This dissertation examines the role of technical standards in the implementation of the EU AI Act and questions a central assumption behind the Act’s regulatory design, i.e., that harmonised standards can translate high-level legal requirements for trustworthy AI into concrete technical specifications. Rather than treating standardisation mainly as a question of institutional legitimacy, the thesis asks whether standards can perform the regulatory work assigned to them. Its main contribution is to show that, in the field of AI, this task is limited not only by the procedures of private standard-setting, but by the nature of the requirements that standards are expected to specify. The thesis argues that several core obligations in the AI Act are value-laden. Requirements concerning acceptable risk (art. 9 AI Act), appropriate accuracy (art. 15 AI Act), and commensurate human oversight (art. 14 AI Act) cannot be reduced to technical thresholds without first resolving normative questions. These terms do not merely describe measurable properties of AI systems. They require judgments about which risks should be tolerated, which trade-offs are defensible, and whose interests should prevail in contexts of uncertainty. To make this argument, the dissertation brings legal analysis of EU standardisation into dialogue with metaethics, especially the literature on thick ethical concepts. This interdisciplinary move allows the thesis to identify the problem, often obscured in discussions of AI governance, that some of the apparent technical questions raised by the AI Act are also ethical and political questions. This reframes the debate on harmonised standards. The difficulty is not simply that standards are developed by bodies whose democratic credentials may be contested. Even a procedurally improved standardisation system would struggle to produce determinate answers to requirements whose meaning depends on context, evidence, and value judgment. Standards can support compliance by organising technical knowledge, setting common methods, and stabilising expectations. They can also provide useful tools for risk management, testing, documentation, and conformity assessment. What they cannot do, at least not without concealing the issue, is settle the normative content of requirements such as acceptability, appropriateness, and proportionality. The thesis then shows how this limitation affects the operationalisation of the AI Act. When standards do not resolve the Act’s open-textured requirements, the burden of judgment shifts to providers, notified bodies, and competent authorities. Compliance is therefore not a purely technical exercise. It becomes a site where contested decisions are made, often under the appearance of neutral verification. This creates risks of inconsistency, opacity, and weak accountability, especially where conformity assessment treats normative questions as if they had already been answered by technical specifications. The dissertation’s constructive contribution is to propose a different understanding of the role of standards. Instead of expecting them to deliver final substantive answers, the thesis argues that standards should help structure justification. It puts forward the idea of an AI Act Compliance Case, i.e., a documented and auditable account of how providers identify risks, evaluate evidence, consider alternatives, and justify the choices through which they claim compliance. On this view, standards remain important, but their role is procedural rather than substantial. They should support reasoned, transparent, and reviewable compliance, rather than create the false impression that value-laden regulatory problems have purely technical solutions.

Artificial Intelligence Standardisation for AI Regulation. A study on the role and limitations of harmonised standards in the context of the European Union legislation on AI / Tartaro, A.. - (2026 Jul 21).

Artificial Intelligence Standardisation for AI Regulation. A study on the role and limitations of harmonised standards in the context of the European Union legislation on AI

TARTARO, Alessio
2026-07-21

Abstract

This dissertation examines the role of technical standards in the implementation of the EU AI Act and questions a central assumption behind the Act’s regulatory design, i.e., that harmonised standards can translate high-level legal requirements for trustworthy AI into concrete technical specifications. Rather than treating standardisation mainly as a question of institutional legitimacy, the thesis asks whether standards can perform the regulatory work assigned to them. Its main contribution is to show that, in the field of AI, this task is limited not only by the procedures of private standard-setting, but by the nature of the requirements that standards are expected to specify. The thesis argues that several core obligations in the AI Act are value-laden. Requirements concerning acceptable risk (art. 9 AI Act), appropriate accuracy (art. 15 AI Act), and commensurate human oversight (art. 14 AI Act) cannot be reduced to technical thresholds without first resolving normative questions. These terms do not merely describe measurable properties of AI systems. They require judgments about which risks should be tolerated, which trade-offs are defensible, and whose interests should prevail in contexts of uncertainty. To make this argument, the dissertation brings legal analysis of EU standardisation into dialogue with metaethics, especially the literature on thick ethical concepts. This interdisciplinary move allows the thesis to identify the problem, often obscured in discussions of AI governance, that some of the apparent technical questions raised by the AI Act are also ethical and political questions. This reframes the debate on harmonised standards. The difficulty is not simply that standards are developed by bodies whose democratic credentials may be contested. Even a procedurally improved standardisation system would struggle to produce determinate answers to requirements whose meaning depends on context, evidence, and value judgment. Standards can support compliance by organising technical knowledge, setting common methods, and stabilising expectations. They can also provide useful tools for risk management, testing, documentation, and conformity assessment. What they cannot do, at least not without concealing the issue, is settle the normative content of requirements such as acceptability, appropriateness, and proportionality. The thesis then shows how this limitation affects the operationalisation of the AI Act. When standards do not resolve the Act’s open-textured requirements, the burden of judgment shifts to providers, notified bodies, and competent authorities. Compliance is therefore not a purely technical exercise. It becomes a site where contested decisions are made, often under the appearance of neutral verification. This creates risks of inconsistency, opacity, and weak accountability, especially where conformity assessment treats normative questions as if they had already been answered by technical specifications. The dissertation’s constructive contribution is to propose a different understanding of the role of standards. Instead of expecting them to deliver final substantive answers, the thesis argues that standards should help structure justification. It puts forward the idea of an AI Act Compliance Case, i.e., a documented and auditable account of how providers identify risks, evaluate evidence, consider alternatives, and justify the choices through which they claim compliance. On this view, standards remain important, but their role is procedural rather than substantial. They should support reasoned, transparent, and reviewable compliance, rather than create the false impression that value-laden regulatory problems have purely technical solutions.
21-lug-2026
Artificial Intelligence Standardisation for AI Regulation. A study on the role and limitations of harmonised standards in the context of the European Union legislation on AI / Tartaro, A.. - (2026 Jul 21).
File in questo prodotto:
File Dimensione Formato  
tartaro_tesi_final.pdf

accesso aperto

Descrizione: Artificial Intelligence Standardisation for AI Regulation. A study on the role and limitations of harmonised standards in the context of the European Union legislation on AI
Tipologia: Tesi di dottorato
Dimensione 3.16 MB
Formato Adobe PDF
3.16 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11388/389789
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact