A conformity assessment is how a provider shows that a high-risk AI system meets the EU AI Act's requirements before it goes on the market. This guide explains what it is, the two routes, and what happens afterwards.
What it is
Article 43 of the AI Act requires a conformity assessment for high-risk AI systems before they are placed on the EU market or put into service. It is a structured check that the system meets the high-risk requirements, such as risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness and cybersecurity.
It is the provider's job. Deployers (the organisations that use the system) do not carry it out.
The two routes
- Internal control (Annex VI). The provider checks its own quality management system, technical documentation and the design and monitoring of the system, and records the result. No outside body is involved.
- Assessment with a notified body (Annex VII). An independent organisation, designated by a national authority, reviews the quality management system and the technical documentation, and can test the system.
Which route applies to you
- Most Annex III systems (such as hiring, education, credit and essential services) use internal control.
- Biometric systems in Annex III can use internal control only if the provider has applied the relevant harmonised standards in full. Otherwise a notified body is needed.
- AI built into regulated products (Annex I, such as medical devices or machinery) follows the conformity procedure of that product law, with the AI requirements added.
The rules on exactly when each route applies are detailed, so confirm your case against Article 43 in the official text. Notified bodies are listed in the Commission's NANDO database.
What happens after the assessment
- EU declaration of conformity (Article 47). A written statement that the system meets the requirements.
- CE marking (Article 48). The visible mark that the system conforms.
- Registration in the EU database (Article 49), before the system is placed on the market or put into service.
When you need to do it again
A new assessment is needed when you make a substantial modification to the system. Changes you planned in advance and documented in the technical documentation do not count as substantial. That is why recording planned changes properly matters.
Timing
After the 2026 AI Omnibus, high-risk obligations apply from 2 December 2027 for stand-alone Annex III systems and from 2 August 2028 for AI built into regulated products. Plan to finish the assessment before the system is placed on the market, not by the deadline itself.
What to prepare
- Technical documentation in the Annex IV format
- A quality management system (Article 17)
- A risk management system (Article 9)
- Test and validation records, dated and signed
Not sure whether you are high-risk at all? Start with Is my AI system high-risk? The official text is on EUR-Lex.