New International Standard for AI Application, Development and Use (ISO/IEC 5339:2024)
- Source
- CMS (law firm)
- URL
- https://cms.law/en/gbr/legal-updates/new-international-standard-for-ai-application-development-and-use-iso-iec-5339-2024
- Type
- legal update
- Retrieved
- 2026-08-17
- License note
- Summary and analysis by On The Ground (OTG). Original article © CMS. This is an original summary, not a reproduction of the source text — see source_url for the complete original.
ISO/IEC 5339:2024 — Guidance on AI Applications: A Practitioner Summary
Original legal update published by CMS (England & Wales), dated 12 June 2024, with contribution acknowledged to Tycho Orton and key contact listed as Dr Sam De Silva. This summary rewords the update's explanation of ISO/IEC 5339 and drops firm-specific promotional content.
What ISO/IEC 5339 is
ISO/IEC 5339:2024 gives stakeholders a shared framework for describing the characteristics and considerations of an "AI application" — defined in the standard, per the article, as AI used with specific functional characteristics that operates in a given stakeholder context to produce an intended result. Its aim is consistent engagement across the AI system life cycle so that development and deployment happen more responsibly and predictably.
The article classifies it as a process standard: ISO 5339 sets out a common approach rather than criteria an organisation is certified against. (The article also outlines a broader five-way taxonomy of standard types — foundational/terminological, interface/architecture, measurement/test-method, product/performance-requirement, and process/management/governance standards — as useful background for readers unfamiliar with how ISO standards are categorised; this taxonomy is the article's own explanatory framing rather than a quotation from ISO 5339 itself.)
Structure: three components
Per the article, the standard covers three things:
AI application context and characteristics — identifying stakeholders (producers, developers, providers, users, customers, regulators, and the community), the life cycle stages an application moves through (model creation, application development, service provision, and AI-augmented decision-making), its functional characteristics (acquiring information, using model output to inform decisions, and improving through use), and its non-functional characteristics (trustworthiness, ethics, societal impact, risk, security, privacy, and explainability). The article also notes the standard points to ISO/IEC 23894 for the risk-management dimension specifically.
An AI application framework built around three perspectives — "make" (producers, developers, and data providers involved in creating the application), "use" (the customers and users applying it to their decisions), and "impact" (the community affected by its deployment, and regulators assessing compliance). The article notes not every stakeholder is involved at every life cycle stage — producers, for example, are described as relevant throughout, while providers and regulators are described as more concentrated around deployment, operation, and monitoring.
Guidance for AI applications (the article associates this with Clause 7) — a set of prompting questions tailored to each stakeholder type. For AI producers, the article lists example questions covering who the customers/users/developers are, what the system and its underlying model/algorithm are, what data trains the model and where it originates, what trustworthiness and risk concerns exist and how they're mitigated, what ethical/legal/privacy considerations apply, and where the system will be built and deployed. The article notes similar question sets exist for data providers, developers, application providers, customers/users, and regulators, and suggests stakeholders can usefully consider each other's questions — e.g., developers reviewing the regulator-facing questions to anticipate compliance concerns.
Relationship to other standards
The article states ISO 5339 complements ISO/IEC 42001 (responsible AI management), ISO/IEC 38507 (governance implications of AI use), and ISO/IEC 23894 (AI risk management) — each addressing a different facet of AI governance rather than duplicating one another.
Scope caveat
The article notes ISO 5339 does not specifically address generative AI, but describes its process, concepts, and framework as technology-agnostic and, in the article's view, applicable to generative AI contexts as well. This is presented in the source as the authors' interpretation rather than an explicit statement within the standard's text, and this summary preserves that distinction.
What this file removes
Removed: CMS's cookie-consent banner text, firm navigation, "sign up for updates" prompts, related-insights teasers, the named partner's contact/bio block, and other law-firm self-promotion. None of this relates to the substance of ISO/IEC 5339.
Verification note
WebFetch of the live source URL succeeded and confirmed the article's title, publish date (12 June 2024), and the acknowledgement of Tycho Orton's contribution, matching the scraped copy. The specific clause numbering (e.g., "Clause 7" for the guidance section) is as stated in the article and was not independently verified against the ISO/IEC 5339 standard text, which is paywalled.