Key takeaways
- A conformity assessment is the procedure that proves a high-risk AI system meets the requirements of Chapter III, Section 2 of the EU AI Act before it reaches the market.
- Article 43 sets out two conformity assessment routes: internal control under Annex VI, or assessment of your quality management system and technical documentation by a notified body under Annex VII.
- Only Annex III point 1, biometrics, can be routed to a notified body. Everything in Annex III points 2 to 8 self-assesses.
- The Digital Omnibus moved the deadline for standalone high-risk systems to 2 December 2027, and to 2 August 2028 for AI embedded in regulated products.
- No harmonised standard has been cited in the Official Journal and no notified body has been designated, so nobody can currently claim presumption of conformity.

What a conformity assessment actually is
Conformity assessment is not an AI invention. It is the mechanism the European single market has used for decades to answer one question: does this thing meet the rules that apply to it? The European Commission treats it as a building block of the free movement of goods, and the IEC describes it as the set of activities that demonstrate specified requirements have been fulfilled.
The activities are familiar to anyone who has certified a product: testing, inspection, audit, validation and verification, and certification. Above them sits accreditation, which is the check that the body doing the testing or the certifying is itself competent. The ANSI National Accreditation Board groups them along the same lines.
The second axis is who performs the work. A first-party assessment is the supplier checking its own product and issuing a declaration. A second-party assessment is the buyer checking it. A third-party assessment is an independent body checking it. Most EU product legislation mixes the three, reserving independent involvement for the categories where the consequences of being wrong are severe.
An AI system breaks the pattern in one respect. There is no physical sample to put on a bench. A conformity assessment of software that learns cannot inspect a finished object, so it inspects the process and the record instead: how the system was designed, what data trained it, how it was tested, which risks were identified and what was done about them, and how a person can intervene. That is why the AI Act version of the procedure reads more like a management system audit than a product test, and why it rewards organisations that already run structured AI compliance programmes.
Do you need one at all? The Article 6 gate
Before choosing a conformity assessment route, establish whether the obligation applies. Plenty of teams assume they are in scope and start assembling a file they do not owe. Others assume they are out of scope and never document the reasoning, which is itself a breach.
Annex I embedded products versus Annex III standalone systems
Article 6 creates two doors into high-risk status. Article 6(1) covers AI that is a safety component of, or is itself, a product already governed by the Union harmonisation legislation listed in Annex I, such as medical devices, machinery, lifts or toys, where that legislation already requires third-party assessment. Article 6(2) plus Annex III covers eight standalone areas including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and the administration of justice.
The distinction matters commercially. If you are in the Annex I world, Article 43(3) folds the AI requirements into the conformity assessment procedure your sector already runs. You do not gain a second conformity assessment, you gain new content inside an existing one. If you are in the Annex III world, the AI Act procedure is the whole procedure.
The Article 6(3) derogation and the profiling carve-out
Article 6(3) is the escape hatch, and it is narrower than most summaries suggest. An Annex III system is not high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, provided it meets at least one of four conditions: it performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations from prior patterns without replacing or influencing the human assessment absent proper review; or it performs a preparatory task to an assessment relevant to an Annex III use case.
One rule overrides all four. A system that performs profiling of natural persons is always high-risk, however narrow or preparatory the task looks. Teams building candidate-ranking or customer-scoring features regularly misread this, which is why the rules on AI in recruitment trip so many vendors.
The derogation is also not free. A provider claiming it must document that assessment before the system is placed on the market or put into service, and register the system. In practice you produce a compliance artefact either way. The only question is whether it is a full technical file or a reasoned exemption memo.
The two conformity assessment routes under Article 43
Article 43 is short, and almost every practical question about conformity assessment under the AI Act is answered in its first four paragraphs.
Annex VI: internal control
Internal control is self-assessment. The provider verifies that its quality management system complies with Article 17, examines the technical documentation against the Chapter III, Section 2 requirements, and confirms that the design and post-market monitoring arrangements are consistent with that documentation. No external party is involved. The provider then draws up the declaration, affixes the marking and registers the system.
Internal control is not a lighter conformity assessment. It is the same standard, read by fewer people.
Annex VII: quality management system plus technical documentation
Annex VII brings in a notified body across five sections. The body assesses whether the quality management system satisfies Article 17 and whether it remains adequate and efficient in operation. It then reviews the technical documentation against Section 2, and it can go further: it may demand additional evidence, carry out its own tests, require access to the training, validation and testing datasets, and on a reasoned request obtain access to the trained models themselves.
Approval is not a one-off event. The body runs periodic surveillance audits, and a provider must notify it of intended changes so the body can decide whether a change needs supplementary certification or a full reassessment.
Who actually gets a choice
This is the part that is most often stated imprecisely. Article 43(1) applies only to Annex III point 1, biometric systems. Those providers may choose between Annex VI and Annex VII where they have applied harmonised standards or common specifications. Where such standards do not exist, have been applied only in part, or the provider has not applied available common specifications, the Annex VII route becomes mandatory.
Article 43(2) covers Annex III points 2 to 8, and it is unambiguous: those providers follow the internal control procedure in Annex VI, without notified body involvement. If your system does credit scoring, exam grading, CV screening or emergency triage, no independent body will sign it off. You sign it off.
Two qualifications are worth carrying. First, where a high-risk system is intended to be put into service by law enforcement, immigration or asylum authorities, or by Union institutions, the market surveillance authority acts as the notified body. Second, Article 43(6) lets the Commission extend the Annex VII route to Annex III points 2 to 8 by delegated act, weighing the effectiveness of internal control against the available capacity of notified bodies. Today’s self-assessment is not guaranteed to stay a self-assessment.
The evidence a conformity assessment inspects
Whichever route applies, the reading list is the same. A conformity assessment consumes the artefacts that Chapter III, Section 2 requires you to maintain anyway.
- Article 9, a risk management system running across the full lifecycle, with identified risks, adopted measures and residual risk judgements. This is where a disciplined AI risk management practice pays for itself.
- Article 10, data and data governance: the provenance, relevance, representativeness and examination for bias of training, validation and testing datasets.
- Article 11 and Annex IV, the technical documentation, drawn up before the system is placed on the market and kept current. It is the single largest deliverable and the one that takes longest to assemble, which is why AI system documentation deserves its own workstream.
- Article 12, automatic recording of events over the system’s lifetime.
- Article 13, transparency and instructions for use that let a deployer interpret and use the output.
- Article 14, human oversight designed into the system, which is a different obligation from the operational choice between human in the loop and human on the loop.
- Article 15, accuracy, robustness and cybersecurity, with declared metrics.
- Article 17, the quality management system that ties all of the above into documented policies, procedures and responsibilities.
Read that list back and a pattern emerges. Nothing in it can be produced retrospectively in the weeks before an assessment. Data governance evidence has to be captured while the data is being assembled. Risk decisions have to be recorded when they are taken. A conformity assessment does not create compliance, it photographs it.
What you sign at the end
Three formal acts close the conformity assessment, and each has its own article.
Article 47 requires an EU declaration of conformity, drawn up for each high-risk system, kept for ten years after the system is placed on the market or put into service, and provided to national competent authorities on request. By signing it, the provider assumes responsibility for compliance.
Article 48 governs the CE marking, which follows the general principles in Article 30 of Regulation (EC) No 765/2008. It must be affixed visibly, legibly and indelibly, or where the nature of the system makes that impractical, to the packaging or accompanying documentation. For systems provided digitally, a digital CE marking is used only where it can be reached easily through the interface or through an accessible machine-readable code. Where a notified body was involved, its identification number follows the marking, which is the visible trace of which conformity assessment route you took.
Article 49 and Annex VIII require registration in the EU database before the system is placed on the market, including for providers who concluded under Article 6(3) that their Annex III system is not high-risk. Registration is a public act, so it is worth treating the entry as external communication rather than a form.
The infrastructure that does not exist yet
Here is the part the ranking explainers omit, and it changes what a sensible plan looks like.
The Annex VII conformity assessment route depends on notified bodies. As of reporting in spring 2026, no body had yet been designated for AI Act conformity assessment, with designation processes running in several Member States and the Commission’s NANDO database being extended to cover AI notifications. Capacity, when it arrives, will be finite and shared across the whole Union.
The Annex VI conformity assessment route depends, for its practical workability, on harmonised standards. The Commission mandated CEN and CENELEC in May 2023 and amended the request in June 2025 to match the final text. The standardisation work missed its August 2025 target, and as of mid-2026 none of the JTC 21 deliverables had been cited in the Official Journal, which is the step that confers presumption of conformity. CEN and CENELEC responded with an exceptional package of measures allowing direct publication after a positive Enquiry vote in order to reach availability around the end of 2026. The standard-setting overview tracks the state of play, and the Commission’s own AI Act FAQ acknowledges the timing pressure.
Put the two together and the bind is visible. Article 43(1) pushes biometric providers toward a notified body precisely when harmonised standards are not applied, and not applying them is currently the only option available. Meanwhile every Annex III provider in points 2 to 8 must self-assess against the bare legal text rather than against a standard that translates it into testable criteria.
The reasonable response is not to wait. Build the Annex IV file now, run the Annex VI conformity assessment as a dry run against Section 2 and record where the gaps are, track Official Journal citations so you can claim presumption the moment it is available, and if you are in the biometrics category, open conversations with candidate bodies early. Mapping your controls to ISO/IEC 42001 alongside the AI Act is the most efficient available proxy while the harmonised standards are pending.
When you have to do it again
A conformity assessment is not permanent. Article 43(4) requires a new conformity assessment whenever a high-risk system undergoes a substantial modification, and it applies whether or not the modified system is distributed further or continues to be used by the current deployer.
The carve-out in the same paragraph is the one worth designing around. Changes that the provider has predetermined and documented in the technical documentation at the time of the initial assessment do not count as substantial modifications, including for systems that continue to learn after being placed on the market. That single sentence is the legal basis on which a continuously updated model stays compliant between assessments. It also means the change envelope should be written into the file deliberately and generously at the outset, because anything outside it triggers a full repeat.
Under Annex VII the notified body performs periodic conformity assessment audits and must be told about intended changes to the approved quality management system or to the specifications of the system, and the body decides whether supplementary certification suffices or a fresh assessment is required. That is why ongoing compliance monitoring matters more than a single push toward a launch date.
The new timeline and the next twelve months
Every competitor article on this topic still cites 2 August 2026. That date is no longer correct.
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was endorsed by the European Parliament on 16 June 2026 by 423 votes to 57 with 174 abstentions, received final Council approval on 29 June 2026, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the original deadline. Standalone Annex III high-risk obligations now apply from 2 December 2027, a sixteen-month deferral. AI embedded in Annex I products moves to 2 August 2028. Prohibited practices, in force since 2 February 2025, and the general-purpose AI obligations are unchanged. The full picture sits in our EU AI Act operators guide and the broader 2026 AI laws overview.
A deferral of sixteen months sounds generous until you sequence the work. Classify under Article 6 and write the reasoning down. Stand up the Article 17 quality management system, since it is assessed under both routes. Assemble Annex IV, which is measured in quarters rather than weeks for a system of any complexity. Run a gap assessment against Section 2 requirement by requirement. Decide your conformity assessment route, and if it is Annex VII, secure a body. Only then prepare the declaration, the marking and the registration entry. Teams that treat the new date as relief rather than as a schedule will meet it with an incomplete file, and an incomplete file is what a conformity assessment is designed to expose.
FAQ
What is the meaning of conformity assessment?
Conformity assessment is the process of demonstrating that a product, service, system, process or person meets the requirements of a specified standard or regulation. It covers testing, inspection, audit, validation and verification, and certification, and it can be performed by the supplier itself, by the buyer, or by an independent third party. Accreditation sits above it as the mechanism confirming that the assessing body is competent.
What are AI conformity assessments?
Under the EU AI Act, a conformity assessment is the procedure a provider must complete before placing a high-risk AI system on the market, demonstrating that it satisfies the requirements in Chapter III, Section 2. Unlike a physical product test it examines documentation and process: risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and the quality management system.
Do I need a notified body for my high-risk AI system?
Probably not. Under Article 43(2), high-risk systems falling under Annex III points 2 to 8 follow internal control under Annex VI without any notified body. Only Annex III point 1 biometric systems can require one, and then mainly where harmonised standards or common specifications have not been fully applied. Systems covered by Annex I product legislation follow that sector’s existing procedure instead.
What is the difference between Annex VI and Annex VII?
Annex VI is internal control: the provider verifies its own quality management system and technical documentation against the requirements and signs the declaration. Annex VII adds an independent notified body that assesses the quality management system, reviews the technical documentation, can request further evidence, tests, datasets and even the trained models, and then conducts periodic surveillance audits.
Does a conformity assessment expire?
The AI Act does not attach a fixed expiry to the assessment itself, but it is not a permanent state either. Under Annex VII the notified body performs periodic audits and must be told about intended changes, and under Article 43(4) any substantial modification triggers a new assessment. The declaration of conformity must be kept for ten years.
What happens if I retrain or update the model?
It depends on whether the change was foreseen. Article 43(4) treats changes that the provider predetermined and documented in the technical documentation at the time of the initial assessment as falling outside the definition of substantial modification, which is what allows systems that keep learning to remain compliant. Changes beyond that documented envelope are substantial modifications and require a new conformity assessment.
Conclusion
The sixteen-month deferral changed the deadline, not the work. Conformity assessment under the AI Act is a reading exercise performed on a file you must already hold, and the file is the deliverable. Providers in Annex III points 2 to 8 will sign their own declarations with no external body to catch a weak risk register or a thin data governance record, which makes internal rigour the entire control. Providers in biometrics face a third-party conformity assessment ecosystem that is still being built, and early queue position will matter. In both cases the work that determines the outcome happens now, in how deliberately the evidence is captured, not in December 2027. If you want a structured starting point, our AI governance framework maps these obligations to the controls that produce the evidence.