What are Essential Requirements?
Essential requirements in European product safety law are fundamental safety and performance criteria that products must meet before being placed on the EU market. These requirements are deliberately written in broad, outcome-focused language rather than prescriptive technical details.
Essential requirements are set out in EU directives and regulations (such as the AI Act, the Machinery Directive, Medical Device Regulation, or Construction Products Regulation). They typically address:
Safety of persons, animals, and property - preventing harm from mechanical, electrical, chemical, or other hazards
Health protection - ensuring products don't pose unacceptable health risks
Environmental protection - minimising environmental impact
Consumer protection - ensuring products perform as intended
For example, the Machinery Directive requires that machinery be "designed and constructed so that it is fitted for its function, and can be operated, adjusted and maintained without putting persons at risk."
The Role of Harmonised Standards
Harmonised standards are detailed technical specifications developed by European standardisation bodies (CEN, CENELEC, ETSI) that provide specific methods for meeting essential requirements. When a product complies with relevant harmonised standards, there's a "presumption of conformity" with the corresponding essential requirements.
Benefits of This Two-Tier Approach
Flexibility and innovation: Essential requirements don't lock manufacturers into specific technologies or methods. Companies can innovate and find new ways to meet safety objectives without waiting for legislation to catch up.
Technical expertise: In theory, standards are developed by technical experts who understand the practical challenges and latest technological developments in specific sectors, rather than by legislators who may lack specialised knowledge.
International trade: Harmonised standards often align with or reference international standards (ISO, IEC), facilitating global trade and avoiding technical barriers.
Proportionate regulation: The system allows for different approaches based on risk levels and product types, while maintaining consistent safety outcomes across the EU.
Rapid updates: Standards can be revised more quickly than legislation to reflect technological advances, new safety knowledge, or market developments.
Legal certainty: While essential requirements might seem vague, harmonised standards provide clear, testable criteria that manufacturers, testing bodies, and market surveillance authorities can all understand and apply consistently.
This approach reflects the EU's "New Legislative Framework," which balances mandatory safety outcomes with flexible means of achieving them, promoting both safety and innovation in the single market.
Essential requirements in the EU’s AI Act
The EU AI Act follows the familiar European regulatory pattern of setting broad "essential requirements" while leaving technical implementation details to harmonised standards. These can be found in Chapter III, Section 2 of the Act.
For high-risk AI systems, these essential requirements focus on fundamental outcomes: accuracy and robustness of performance, transparency and provision of information to users, human oversight capabilities, and cybersecurity measures. The Act requires that these systems be "sufficiently accurate, robust and cybersecure" and perform "consistently for their intended purpose" - deliberately avoiding prescriptive technical specifications about how these outcomes should be achieved.
This approach mirrors the structure found in EU product safety legislation, ranging from machinery to medical devices; however, the AI Act's essential requirements present unique challenges. Unlike physical products, where safety parameters are well-established, AI systems necessitate new approaches to defining and measuring concepts such as "accuracy" and "robustness" across diverse tasks and contexts. As highlighted in the current standards development delays, reaching consensus on how to technically implement these broad requirements has proven particularly complex.
The harmonised standards being developed by CEN-CENELEC JTC 21 must translate abstract concepts, such as "appropriate transparency," into concrete, measurable criteria that can be consistently applied across different AI applications, from credit scoring algorithms to autonomous vehicles. Without these standards, companies face the challenging task of independently demonstrating compliance with requirements that, while legally binding, remain deliberately broad in their technical interpretation.
This, in turn, explains why some are calling for some kind of delay to the AI Act while the technical standards are developed. See: Is AI harder than cement?

