Skip to content
Topic Developing

Conformity Assessment for AI Systems

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Act that warrants dedicated coverage.

33 linked items 32 Laws1 News

Overview

9 sources · Jul 23, 2026

Legal Framework

Conformity assessment is the core compliance gateway under the AI Act for high-risk AI systems before they may be placed on the EU market. Providers of high-risk systems must undergo either an internal control-based assessment (Annex VI) or a third-party conformity assessment involving a notified body, depending on the system's classification. Article 43 establishes the two primary pathways: conformity assessment based on the quality management system and technical documentation review, or conformity assessment supplemented by a product quality assurance system.

Article 46 provides a critical derogation: where a provider has already applied a harmonised standard covering the relevant requirements, or where the system is not otherwise subject to third-party assessment obligations, the provider may opt for internal control. This derogation does not apply where the provider has modified the system in ways that affect its compliance with the AI Act's requirements, or where the system is subject to separate sectoral legislation mandating third-party assessment.

Article 47 requires the provider to draw up and retain an EU declaration of conformity for each high-risk AI system. This written declaration affirms that the system meets the requirements set out in Chapter III of the AI Act. The declaration must identify the provider, the system, the harmonised standards applied, and contain a reference to the technical documentation. It must be translated into an EU language determined by the Member State where the system is made available and retained for ten years after the system is placed on the market.

The technical documentation underpinning the assessment (Article 11 AI Act) must demonstrate compliance with all applicable high-risk requirements, including risk management, data governance, transparency, human oversight, accuracy, and robustness.

Key Developments

No enforcement decisions have yet been issued under the AI Act, as the conformity assessment obligations for high-risk systems apply from 2 August 2026. However, the interaction between AI Act conformity assessment and GDPR accountability obligations is already shaping compliance strategies. The European Data Protection Board has signalled that data protection impact assessments under Article 35 GDPR and AI Act conformity assessments will need to be coordinated, particularly where high-risk AI systems process personal data.

The designation of notified bodies is progressing through Member State notifications under the AI Act, with several bodies seeking designation under the NANDO database framework. Providers should monitor which notified bodies achieve designation for AI-specific competencies, as capacity constraints may create bottlenecks for third-party assessments.

Practical Guidance

  • Map your conformity assessment pathway early: Determine whether your high-risk system qualifies for the Article 46 derogation based on harmonised standard coverage, or whether third-party notified body assessment is mandatory. This determination drives your entire compliance timeline.

  • Prepare technical documentation to Article 11 specifications before initiating assessment: The technical documentation must cover all Chapter III requirements. Incomplete documentation is the most common cause of assessment delays under analogous CE-marking regimes.

  • Establish a quality management system compliant with Article 17: The QMS is the backbone of the conformity assessment. It must cover compliance strategy, technical documentation management, data governance, and post-market monitoring procedures.

  • Draft the EU declaration of conformity (Article 47) only after completing the full assessment: The declaration is a legally binding attestation. Issuing it prematurely exposes the provider to substantial fines under Article 99, up to €15 million or 3% of global turnover.

  • Retain the declaration and technical documentation for ten years: This retention period aligns with the AI Act's post-market monitoring obligations and must be supported by internal records management that survives personnel turnover.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 32
Art. 112(12) Any amendment to this Regulation pursuant to paragraph 10, or relevant delegated or implementing acts, which concerns sectoral Union harmonisation leg… AI Act Art. 3(12) ‘intended purpose’ means the use for which an AI system is intended by the provider, including the specific context and conditions of use, as specifie… AI Act Art. 3(19) ‘notifying authority’ means the national authority responsible for setting up and carrying out the necessary procedures for the assessment, designatio… AI Act Art. 3(20) ‘conformity assessment’ means the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI syste… AI Act rec 125 Recital 125 — High-risk AI systems conformity assessment procedure AI Act Jun 2024 art 46 Derogation from conformity assessment procedure AI Act Jun 2024 rec 78 Recital 78 — conformity assessment cybersecurity high-risk AI AI Act Jun 2024 rec 127 Recital 127 — Mutual recognition of conformity assessment results AI Act Jun 2024 rec 123 Recital 123 — conformity assessment for high-risk AI systems AI Act Jun 2024 rec 124 Recital 124 — conformity assessment integration with existing harmonisation legislation AI Act Jun 2024 rec 71 Recital 71 — high-risk AI technical documentation and logs AI Act Jun 2024 rec 128 Recital 128 — substantial modification triggering new conformity assessment AI Act Jun 2024 art 47 EU declaration of conformity AI Act Jun 2024 art 43 Conformity assessment AI Act Jun 2024 rec 126 Recital 126 — notified body requirements and notification procedure AI Act Jun 2024 art 29 Application of a conformity assessment body for notification AI Act Jun 2024 art 39 Conformity assessment bodies of third countries AI Act Jun 2024 art 11 Technical documentation AI Act Jun 2024 rec 173 Recital 173 — Commission delegated powers to adapt AI rules AI Act Jun 2024 rec 50 Recital 50 — high-risk classification of safety-related AI systems AI Act Jun 2024 rec 81 Recital 81 — provider quality management system AI Act Jun 2024 rec 139 Recital 139 — AI regulatory sandboxes innovation objectives AI Act Jun 2024 rec 77 Recital 77 — cybersecurity compliance equivalence high-risk AI AI Act Jun 2024 rec 51 Recital 51 — high-risk AI classification and product safety AI Act Jun 2024 Show 12 more →
News 1
Gaming Tech Law Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems? Gaming Tech Law Mar 2023