Conformity Assessment for AI Systems
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Act that warrants dedicated coverage.
Overview
9 sources · Jul 23, 2026Legal Framework
Conformity assessment is the core compliance gateway under the AI Act for high-risk AI systems before they may be placed on the EU market. Providers of high-risk systems must undergo either an internal control-based assessment (Annex VI) or a third-party conformity assessment involving a notified body, depending on the system's classification. Article 43 establishes the two primary pathways: conformity assessment based on the quality management system and technical documentation review, or conformity assessment supplemented by a product quality assurance system.
Article 46 provides a critical derogation: where a provider has already applied a harmonised standard covering the relevant requirements, or where the system is not otherwise subject to third-party assessment obligations, the provider may opt for internal control. This derogation does not apply where the provider has modified the system in ways that affect its compliance with the AI Act's requirements, or where the system is subject to separate sectoral legislation mandating third-party assessment.
Article 47 requires the provider to draw up and retain an EU declaration of conformity for each high-risk AI system. This written declaration affirms that the system meets the requirements set out in Chapter III of the AI Act. The declaration must identify the provider, the system, the harmonised standards applied, and contain a reference to the technical documentation. It must be translated into an EU language determined by the Member State where the system is made available and retained for ten years after the system is placed on the market.
The technical documentation underpinning the assessment (Article 11 AI Act) must demonstrate compliance with all applicable high-risk requirements, including risk management, data governance, transparency, human oversight, accuracy, and robustness.
Key Developments
No enforcement decisions have yet been issued under the AI Act, as the conformity assessment obligations for high-risk systems apply from 2 August 2026. However, the interaction between AI Act conformity assessment and GDPR accountability obligations is already shaping compliance strategies. The European Data Protection Board has signalled that data protection impact assessments under Article 35 GDPR and AI Act conformity assessments will need to be coordinated, particularly where high-risk AI systems process personal data.
The designation of notified bodies is progressing through Member State notifications under the AI Act, with several bodies seeking designation under the NANDO database framework. Providers should monitor which notified bodies achieve designation for AI-specific competencies, as capacity constraints may create bottlenecks for third-party assessments.
Practical Guidance
Map your conformity assessment pathway early: Determine whether your high-risk system qualifies for the Article 46 derogation based on harmonised standard coverage, or whether third-party notified body assessment is mandatory. This determination drives your entire compliance timeline.
Prepare technical documentation to Article 11 specifications before initiating assessment: The technical documentation must cover all Chapter III requirements. Incomplete documentation is the most common cause of assessment delays under analogous CE-marking regimes.
Establish a quality management system compliant with Article 17: The QMS is the backbone of the conformity assessment. It must cover compliance strategy, technical documentation management, data governance, and post-market monitoring procedures.
Draft the EU declaration of conformity (Article 47) only after completing the full assessment: The declaration is a legally binding attestation. Issuing it prematurely exposes the provider to substantial fines under Article 99, up to €15 million or 3% of global turnover.
Retain the declaration and technical documentation for ten years: This retention period aligns with the AI Act's post-market monitoring obligations and must be supported by internal records management that survives personnel turnover.