Conformity Body Notification
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because the content specifically addresses the application and notification procedures for conformity assessment bodies under the AI Act, which is a distinct regulatory mechanism not adequately covered by existing topics.
Overview
9 sources · Sep 8, 2026Legal Framework
The AI Act establishes a conformity assessment regime for high-risk AI systems in which notified bodies — conformity assessment bodies designated by national authorities — certify provider compliance before market placement. Several provisions define the obligations that connect providers, authorised representatives, and notified bodies within this framework.
Article 20 imposes corrective-action and information duties on providers when a high-risk AI system is found non-compliant. Where a system presents a risk within the meaning of Article 79(1), the provider must investigate and notify both the competent market surveillance authority and the notified body that certified the system:
"the notified body that issued a certificate for that high-risk AI system in accordance with Article 44, in particular, of the nature of the non-compliance and of any relevant corrective action taken"
— AI Act Art. 20(2)
Article 22 governs authorised representatives appointed by third-country providers before market placement. Among the mandated tasks, the representative must verify that conformity assessment procedures were properly completed:
"verify that the EU declaration of conformity referred to in Article 47 and the technical documentation referred to in Article 11 have been drawn up and that an appropriate conformity assessment procedure has been carried out by the provider"
— AI Act Art. 22(3)(a)
The definitions in Article 3 frame the relevant actors: the provider as the entity placing the system on the market under its own name, the authorised representative as the Union-established mandatary, and the importer as the entity introducing third-country systems into the Union market.
Key Developments
The AI Act entered into force in August 2024 with phased application dates. No case law, DPA enforcement decisions, or regulatory guidance specifically addressing conformity body notification has yet emerged. The textual requirements are defined — providers must report non-conformities to the issuing notified body alongside market surveillance authorities — but the operational mechanics of how notified bodies receive, process, and act on such notifications remain untested. The dual-reporting structure under Article 20(2), linking notified body certificates under Article 44 to post-market obligations, will likely become a focal point once the first notified bodies are designated and initial enforcement actions materialise.
Status of the Debate
This topic is developing: no dominant doctrinal pattern has emerged. The AI Act's conformity assessment framework draws on established New Legislative Framework precedents, but the specific application to AI systems has not been tested through enforcement or judicial review. Key open questions include the threshold for "appropriate" corrective actions triggering notified body involvement, the scope of the notified body's duty to respond to reported non-conformities, and the interplay between notified body certificates and market surveillance authority powers under Article 79. These questions will likely be resolved through the first Commission implementing acts designating notified bodies and through initial national enforcement actions.
Practical Guidance
Establish dual-notification protocols: Article 20(2) requires providers to inform both the competent market surveillance authority and the notified body that issued the certificate under Article 44 when a high-risk system presents a risk. Build internal escalation procedures that trigger both notification streams without delay.
Verify conformity assessment completion through authorised representatives: Under Article 22(3)(a), third-country providers' authorised representatives must confirm that an appropriate conformity assessment procedure was carried out. Ensure mandates explicitly authorise this verification and that documentation is retained for the 10-year period specified in Article 22(3)(b).
Maintain records linking certificates to notified bodies: Article 20(2) ties reporting obligations to certificates issued "in accordance with Article 44." Track which notified body issued which certificate, including scope and validity, to ensure accurate notification when non-conformities arise.
Map the conformity assessment pathway before market placement: Providers of high-risk AI systems must complete the appropriate conformity assessment procedure before placing systems on the Union market. Identify early whether the assessment requires notified body involvement and secure the necessary certifications before deployment.
Nothing of this type on this topic.