What matters in AI.

Subscribe

Learn / AI governance

Definition · AI governance

Conformity assessment

Conformity assessment, under the EU AI Act, is the process of demonstrating whether a high-risk AI system meets the Act's requirements for high-risk systems. For most such systems, the provider must complete it before placing the system on the market or putting it into service, through internal control, a notified body, or an EU product law's procedure.

Last reviewed

Key points

  • Conformity assessment is how a provider shows a high-risk AI system meets the EU AI Act's requirements before it reaches the market. AI in Section B products, such as cars and aircraft, is outside it.
  • The Act sets two procedures: internal control by the provider itself (Annex VI), or assessment by an independent notified body (Annex VII).
  • Most Annex III systems use internal control. Biometric systems can too, but only if the provider fully applied harmonised standards or common specifications; otherwise a notified body is needed, in full or in part.
  • AI in products such as medical devices or toys goes through the product law's own conformity assessment, extended to the AI Act's requirements.
  • The duty applies from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Systems already on sale by then need one only after a significant design change.

How it works

Article 43 of the Act sets out two procedures for a high-risk AI system.

Internal control (Annex VI). The provider checks itself: its quality management system, its technical documentation against the high-risk requirements, and that development and post-market monitoring match that documentation.

Notified body assessment (Annex VII). An independent notified body examines the quality management system and technical documentation. It can run its own tests, see the training and testing data and, as a last resort, the trained model. If the system passes, it issues a certificate and audits the provider periodically.

Either way, the provider then signs an EU declaration of conformity and affixes the CE marking (Articles 47 and 48).

Which procedure applies

Article 43 mostly fixes the route:

System Procedure
Annex III points 2 to 8, such as employment, education and credit scoring Internal control
Annex III point 1: biometrics Provider’s choice if it fully applied harmonised standards or common specifications; otherwise a notified body
AI in products under Section A of Annex I, such as medical devices, toys and lifts, including any that are also Annex III uses The product law’s own procedure, extended to the AI Act’s requirements

Harmonised standards are technical standards the EU lists in its Official Journal. Common specifications are ones the Commission sets where those fall short.

Why it matters

Conformity assessment is the usual check before a high-risk AI system reaches the EU market. Its requirements include Article 15’s accuracy, robustness and cybersecurity rules.

For most Annex III systems, including hiring and credit-scoring tools, no one outside the provider checks the system before release. Article 43(6) lets the Commission change that by delegated act.

In practice

When it applies. The duty does not apply yet. The Digital Omnibus on AI set it to apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. A high-risk system already on the market before those dates is caught only if its design changes significantly afterwards. Systems for public authorities must comply by 2 August 2030 regardless (Article 111(2)).

Products under Section B of Annex I, such as cars and aircraft, are outside Article 43 altogether: only a handful of the Act’s articles apply to AI in them (Article 2(2)).

Products under Section A of Annex I. The product law’s procedure covers the AI Act’s requirements too. Since the Digital Omnibus on AI replaced Article 43(3) in July 2026, it also covers the provider’s quality management system. Being high-risk under Article 6(1) does not by itself force a third-party route the product law would not require. But a manufacturer can use a product law’s option to skip the third party only if it has also applied harmonised standards or common specifications covering all the AI Act’s high-risk requirements.

Notified bodies under those product laws can assess the AI requirements if their notification already checked them against the Act’s independence and competence rules (Article 31(4), (5), (10) and (11)). They must apply for designation under the AI Act by 28 January 2028.

Biometric systems. A standard can be published with a restriction. A provider relying on it needs a notified body only for the restricted part. For systems put into service by law enforcement, immigration or asylum authorities, or by EU institutions, the market surveillance authority acts as the notified body.

Certificates. A notified body’s certificate lasts at most five years for Annex I systems and four for Annex III, renewable after re-assessment (Article 44).

Changes after release. A substantial modification means a new assessment, whether the system is sold on or stays with its current deployer (Article 43(4)). For a system that keeps learning, changes the provider planned and documented at the first assessment do not count.

Cybersecurity. A high-risk AI system that meets the conditions in Article 12(1) of the Cyber Resilience Act is deemed to meet Article 15’s cybersecurity requirements (Article 42(3)).

Emergencies. For exceptional reasons such as public security, a market surveillance authority can authorise a specific high-risk system in its country for a limited period while the assessment is completed (Article 46). It may do so only if it concludes the system meets the high-risk requirements. For Section A products, only the product law’s own derogations apply.

Questions and answers

What is a conformity assessment under the EU AI Act?

The process of demonstrating whether a high-risk AI system meets the requirements in Chapter III, Section 2 of the EU AI Act, such as risk management, data governance, human oversight, and accuracy, robustness and cybersecurity. Article 16(f) requires the provider to complete it before placing the system on the market or putting it into service.

Does every high-risk AI system need a notified body?

No. Systems in points 2 to 8 of Annex III, such as those used in employment, education or credit scoring, use internal control, which involves no notified body, unless they are also part of a product covered by Section A of Annex I. Biometric systems in point 1 of Annex III need a notified body unless the provider fully applied harmonised standards or common specifications. AI in products covered by Section A of Annex I follows the product law's own procedure.

When does a high-risk AI system need a new conformity assessment?

After a substantial modification, whether or not the modified system is sold on or stays with the current deployer (Article 43(4)). For a system that keeps learning after release, changes the provider planned and documented at the first assessment do not count as a substantial modification.

Sources

  1. Regulation (EU) 2024/1689 (EU AI Act), Articles 3(20) to 3(22), 16, 40 and 41, and Annex I Section BEuropean Union, 12 Jul 2024
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Article 1 point 19 and recital 18European Union, 24 Jul 2026