The EU AI Act conformity assessment is the procedure a provider of a high-risk AI system has to complete before placing it on the EU market: prove the system meets the requirements in Chapter III Section 2, draw up an EU declaration of conformity, affix the CE marking and register the system in the EU database.
For most Annex III systems it is a self-assessment under Annex VI; for biometric systems without fully applied harmonised standards, and for AI embedded in products already regulated under Annex I, a notified body is involved. The obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products, after the July 2026 Digital Omnibus moved both dates.
This guide sets out which route applies to which system, what each route requires, what the declaration, CE marking and registration steps involve, when a re-assessment is triggered, and how harmonised standards change the work.

Which EU AI Act conformity assessment route applies
Article 43 assigns the EU AI Act conformity assessment route by where the system sits in the high-risk classification:
| High-risk system | Route | Notified body? | Basis |
|---|---|---|---|
| Annex III point 1 — biometrics (remote identification, categorisation, emotion recognition) — where harmonised standards or common specifications are applied in full | Provider’s choice: Annex VI internal control, or Annex VII assessment of the QMS and technical documentation | Optional | Art 43(1)(a)–(b) |
| Annex III point 1 — biometrics — where harmonised standards do not exist or are not fully applied | Annex VII | Yes | Art 43(1), second subparagraph |
| Annex III points 2–8 — critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes | Annex VI internal control | No | Art 43(2) |
| Annex I section A — AI as a safety component of, or itself, a product under listed Union harmonisation law (machinery, medical devices, toys, lifts, radio equipment and others) | The sectoral product’s own conformity assessment, with the AI Act requirements folded in | As the sectoral law requires | Art 43(3) |
The Omnibus replaced Article 43(3) to let notified bodies already designated under sectoral legislation assess AI Act conformity, provided their compliance with the relevant Article 31 requirements was verified when they were notified; such bodies must apply for designation under the Act’s own Section 4 by 28 January 2028. Where a product is covered both by Annex I law and by Annex III, the sectoral procedure applies.
Article 43(5) and (6) let the Commission amend the annexes for technical progress and, on evidence that internal control is inadequate, move Annex III points 2–8 to the Annex VII route. That is a delegated act that has not been used; as the law stands, most high-risk providers self-assess.
EU AI Act conformity assessment route 1: internal control under Annex VI
Internal control means the provider performs the EU AI Act conformity assessment itself, verifying its own compliance, without a notified body, and takes responsibility for the result in the declaration. Annex VI requires the provider to:
- Verify that the established quality management system complies with Article 17.
- Examine the technical documentation to assess the system’s compliance with the Section 2 requirements — risk management (Art 9), data governance (Art 10), technical documentation (Art 11), record-keeping (Art 12), transparency (Art 13), human oversight (Art 14), and accuracy, robustness and cybersecurity (Art 15).
- Verify that the design and development process and the post-market monitoring system (Art 72) are consistent with the technical documentation.
It is a documentation-heavy exercise. The technical file under Annex IV has to exist and be complete before step 2 can be performed honestly; our guide to the EU AI Act documentation requirements lists what goes in it. The Omnibus introduced a simplified technical documentation form for SMEs and small mid-caps under Article 11.
EU AI Act conformity assessment route 2: notified body assessment under Annex VII
Annex VII is a third-party EU AI Act conformity assessment of two things: the provider’s quality management system, and the technical documentation of the specific system. The notified body audits the QMS, reviews the technical file, may request tests or access to training and testing data, and — if satisfied — issues an EU technical documentation assessment certificate.
Article 44 limits certificate validity to five years for Annex I systems and four years for Annex III systems, renewable on re-assessment, and lets the notified body suspend, restrict or withdraw a certificate where the system no longer meets the requirements, subject to an appeal procedure.
Notified bodies are designated by Member States under Chapter III Section 4 and listed by the Commission. In September 2026 the pool is still forming; providers on the Annex VII route should engage a candidate body early, because the same lead-time problem that affects ISO/IEC 42001 certification applies here.
After the EU AI Act conformity assessment: declaration, CE marking, registration
EU declaration of conformity (Article 47)
A written, machine-readable declaration for each high-risk system, containing the information in Annex V, translated for the authorities of each Member State where the system is placed on the market, kept for ten years after placing on the market or putting into service, and kept up to date. Where other Union harmonisation law also requires a declaration, one combined document covers all. By drawing it up, the provider assumes responsibility for compliance with Section 2.
CE marking (Article 48)
The visible sign that the assessment has been done — affixed visibly, legibly and indelibly, or digitally for systems provided only digitally, with the notified body’s identification number where one was involved.
Registration (Article 49)
Before placing an Annex III high-risk system on the market, the provider registers itself and the system in the EU database under Article 71. Providers who conclude a system listed in Annex III is not high-risk under the Article 6(3) exemption register that conclusion too. Deployers that are public authorities register their use. Critical-infrastructure systems under Annex III point 2 register at national level instead.
When the EU AI Act conformity assessment has to be repeated
Article 43(4) requires a new assessment whenever a high-risk system is substantially modified — a change that affects compliance with Section 2 or alters the intended purpose — whether or not the modified system is to be distributed further.
The exception matters for machine-learning systems: changes that continue to learn after placing on the market, where the change was pre-determined by the provider at the initial assessment and is part of the technical documentation, are not substantial modifications. In practice this means the technical file should describe the intended learning envelope, because a change outside it restarts the procedure. Systems already on the market before the application date are covered by the Article 111 transitional rules, which reach them only on significant change in design.
How harmonised standards change the work
Article 40 changes the EU AI Act conformity assessment by giving a presumption of conformity with the Section 2 requirements to systems that comply with harmonised standards published in the Official Journal, to the extent those standards cover the requirements; Article 41 provides for Commission common specifications where standards are absent or inadequate. Two consequences for the assessment:
- For biometric systems, applying the harmonised standards in full is what unlocks the choice between Annex VI and Annex VII.
- For every high-risk provider, a standards-based technical file is a shorter argument: “we applied EN standard X” replaces a bespoke demonstration for each requirement it covers.
Until the harmonised standards are cited in the Official Journal, providers demonstrate compliance directly, and management-system standards such as ISO/IEC 42001 are the practical scaffolding for the Article 17 QMS — see ISO 42001 vs the EU AI Act.
An EU AI Act conformity assessment sequence for providers
- Classify each system against Annex I, Annex III and Article 6(3); record the reasoning.
- Establish the Article 17 quality management system, or extend an existing one.
- Build the Annex IV technical documentation as part of development, not after it.
- Test against the declared metrics for accuracy, robustness and cybersecurity; document data governance and bias examination.
- Run the Annex VI verification, or engage a notified body for Annex VII.
- Draw up the Annex V declaration, affix the CE marking, register in the EU database.
- Operate post-market monitoring; track changes against the substantial-modification test.
Costs for each step are in our guide to EU AI Act compliance cost; the equivalent product-law procedure under the Cyber Resilience Act is covered in CRA conformity assessment.
Frequently asked questions
Does every high-risk AI system need a notified body?
No. Annex III points 2–8 use internal control under Annex VI. A notified body is required for biometric systems without fully applied harmonised standards and, through sectoral law, for Annex I products; it is optional for biometric systems that apply the standards.
When does the EU AI Act conformity assessment become mandatory?
From 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products, following Regulation (EU) 2026/1744. Both dates were moved from August 2026 and August 2027 respectively.
How long is a notified body certificate valid?
Up to five years for Annex I systems and four years for Annex III systems under Article 44, renewable after re-assessment.
Can we self-certify and still use the CE marking?
Yes. Internal control under Annex VI ends in the provider’s own EU declaration of conformity and CE marking, without a notified body number.
Does a model update trigger a new assessment?
Only if it is a substantial modification — affecting Section 2 compliance or changing the intended purpose. Continuous-learning changes pre-determined in the technical documentation do not.
Where this leaves you
Work out the route first — for most Annex III providers it is Annex VI internal control — then treat the EU AI Act conformity assessment as the last step of a documentation pipeline rather than a project of its own. Build the QMS and the technical file so that step 2 of Annex VI is a review, not a reconstruction; describe the learning envelope so updates stay inside it; and if you are on the Annex VII route, engage a notified body now rather than in 2027.
References
- Article 43 — Conformity assessment — the consolidated text including the Omnibus replacement of paragraph 3.
- Article 44 — Certificates — validity periods and suspension or withdrawal.
- Regulation (EU) 2026/1744 — Digital Omnibus on AI — the amending regulation that moved the application dates.
More on AI governance
- The EU AI Act conformity assessment — you are here
- The EU AI Act explained
- EU AI Act risk categories
- EU AI Act documentation requirements
- EU AI Act compliance cost
The conformity assessment procedure, Annex IV technical documentation template, EU declaration of conformity template, CE marking and registration procedures and the Article 17 QMS procedure are in the EU AI Act Toolkit (60 templates), or start with the free templates.