# Conformity Body Notification — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/conformity-assessment-body-notification
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because the content specifically addresses the application and notification procedures for conformity assessment bodies under the AI Act, which is a distinct regulatory mechanism not adequately covered by existing topics.

## Overview

## Legal Framework

Conformity body notification under the AI Act is governed primarily by Articles 29 and 30, which establish the procedural mechanism through which conformity assessment bodies obtain official status to evaluate high-risk AI systems before market placement. Article 29 sets out the application requirements: a conformity assessment body must submit an application to the notifying authority of the Member State in which it is established, demonstrating compliance with the requirements laid down in Articles 31 through 36. These requirements cover independence, competence, staff qualifications, impartiality, and the body's internal organisation and quality management system.

Article 30 governs the notification procedure itself. Once the notifying authority verifies that the applicant body meets the applicable requirements, the Member State notifies the European Commission and the other Member States. The notification must include details of the conformity assessment activities, the AI system categories covered, relevant harmonisation standards applied, and any national accreditation certificate issued. Where a notification is based on national accreditation, presumptions of competence apply. Where accreditation is not used, the notifying authority must provide the Commission with documentary evidence demonstrating the body's competence and arrangements for regular monitoring.

Article 85 complements this framework by granting any natural or legal person the right to lodge complaints with the relevant market surveillance authority where they consider that AI Act provisions have been infringed, linking the notification regime to downstream enforcement under Regulation (EU) 2019/1020.

## Key Developments

The AI Act's conformity body notification regime draws directly on the established New Legislative Framework model used across EU product safety law, meaning that existing jurisprudence and Commission implementing decisions under that framework provide interpretive guidance. The Court of Justice has repeatedly affirmed that notified bodies operate within a system of shared competence between national authorities and EU institutions, and that notification decisions must be reasoned and subject to judicial review under national law.

A critical structural feature is the distinction between accreditation-based and non-accreditation-based notifications. Where accreditation is used, the notifying authority's discretion is significantly constrained, as accreditation certificates issued under Regulation (EC) 765/2008 carry binding evidentiary weight. This creates a practical threshold: bodies seeking notification without prior accreditation face a substantially heavier documentary burden and greater scrutiny of their competence demonstrating.

The notification is not self-executing. The Commission and Member States may raise objections, particularly where concerns exist about the body's independence or technical capacity. The standing of notified bodies is also subject to periodic reassessment, and notifications can be restricted, suspended, or withdrawn where competence conditions are no longer met.

## Practical Guidance

- Verify accreditation status before submitting an Article 29 application. Bodies holding valid accreditation under Regulation (EC) 765/2008 benefit from a presumption of competence that materially reduces the notification timeline and documentary burden under Article 30.
- Prepare a comprehensive conformity assessment scope definition. The notification must specify the categories of AI systems and conformity assessment modules the body intends to cover, and subsequent expansion requires a new or amended notification.
- Document the quality management system against Articles 33 and 34 requirements before application. Notifying authorities will scrutinise internal procedures, conflict-of-interest safeguards, and staff competence records as part of the initial assessment.
- Establish procedures for ongoing compliance monitoring. Notifying authorities are required to conduct regular surveillance of notified bodies, and deficiencies identified during monitoring can trigger restriction or withdrawal of notification status.
- Map complaint exposure under Article 85. Since market surveillance authorities must handle complaints about AI Act infringements, notified bodies should implement internal mechanisms to address complaints that may be escalated to these authorities, including documentation of assessment decisions and rationale.

## Legislation (full text of key provisions)

### Application of a conformity assessment body for notification

*Source: AI Act, aiact-art-29-en, 2024-06-12 — https://overview.legal/posts/92458*

### Right to lodge a complaint with a market surveillance authority

*Source: AI Act, aiact-art-85-en, 2024-06-12 — https://overview.legal/posts/93389*

Without prejudice to other administrative or judicial remedies, any natural or legal person having grounds to consider that there has been an infringement of the provisions of this Regulation may submit complaints to the relevant market surveillance authority.In accordance with Regulation (EU) 2019/1020, such complaints shall be taken into account for the purpose of conducting market surveillance activities, and shall be handled in line with the dedicated procedures established therefor by the market surveillance authorities.

### Notification procedure

*Source: AI Act, aiact-art-30-en, 2024-06-12 — https://overview.legal/posts/92470*

### Presumption of conformity with requirements relating to notified bodies

*Source: AI Act, aiact-art-32-en, 2024-06-12 — https://overview.legal/posts/92508*

Where a conformity assessment body demonstrates its conformity with the criteria laid down in the relevant harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, it shall be presumed to comply with the requirements set out in Article 31 in so far as the applicable harmonised standards cover those requirements.

### Recital 126 — notified body requirements and notification procedure

*Source: AI Act, aiact-rec-126-en, 2024-06-12 — https://overview.legal/posts/93934*

In order to carry out third-party conformity assessments when so required, notified bodies should be notified under this Regulation by the national competent authorities, provided that they comply with a set of requirements, in particular on independence, competence, absence of conflicts of interests and suitable cybersecurity requirements. Notification of those bodies should be sent by national competent authorities to the Commission and the other Member States by means of the electronic notification tool developed and managed by the Commission pursuant to Article R23 of Annex I to Decision No 768/2008/EC.

### Recital 50 — high-risk classification of safety-related AI systems

*Source: AI Act, aiact-rec-50-en, 2024-06-12 — https://overview.legal/posts/93782*

As regards AI systems that are safety components of products, or which are themselves products, falling within the scope of certain Union harmonisation legislation listed in an annex to this Regulation, it is appropriate to classify them as high-risk under this Regulation if the product concerned undergoes the conformity assessment procedure with a third-party conformity assessment body pursuant to that relevant Union harmonisation legislation. In particular, such products are machinery, toys, lifts, equipment and protective systems intended for use in potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft equipment, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, automotive and aviation.

### Recital 156 — market surveillance and compliance enforcement framework

*Source: AI Act, aiact-rec-156-en, 2024-06-12 — https://overview.legal/posts/93994*

In order to ensure an appropriate and effective enforcement of the requirements and obligations set out by this Regulation, which is Union harmonisation legislation, the system of market surveillance and compliance of products established by Regulation (EU) 2019/1020 should apply in its entirety. Market surveillance authorities designated pursuant to this Regulation should have all enforcement powers laid down in this Regulation and in Regulation (EU) 2019/1020 and should exercise their powers and carry out their duties independently, impartially and without bias. Although the majority of AI systems are not subject to specific requirements and obligations under this Regulation, market surveillance authorities may take measures in relation to all AI systems when they present a risk in accordance with this Regulation. Due to the specific nature of Union institutions, agencies and bodies falling within the scope of this Regulation, it is appropriate to designate the European Data Protection Supervisor as a competent market surveillance authority for them. This should be without prejudice to the designation of national competent authorities by the Member States. Market surveillance activities should not affect the ability of the supervised entities to carry out their tasks independently, when such independence is required by Union law.

### Recital 159 — biometric AI surveillance authority powers

*Source: AI Act, aiact-rec-159-en, 2024-06-12 — https://overview.legal/posts/94000*

Each market surveillance authority for high-risk AI systems in the area of biometrics, as listed in an annex to this Regulation insofar as those systems are used for the purposes of law enforcement, migration, asylum and border control management, or the administration of justice and democratic processes, should have effective investigative and corrective powers, including at least the power to obtain access to all personal data that are being processed and to all information necessary for the performance of its tasks. The market surveillance authorities should be able to exercise their powers by acting with complete independence. Any limitations of their access to sensitive operational data under this Regulation should be without prejudice to the powers conferred to them by Directive (EU) 2016/680. No exclusion on disclosing data to national data protection authorities under this Regulation should affect the current or future powers of those authorities beyond the scope of this Regulation.

### Recital 161 — Union and national supervision responsibilities for general-purpose AI

*Source: AI Act, aiact-rec-161-en, 2024-06-12 — https://overview.legal/posts/94004*

It is necessary to clarify the responsibilities and competences at Union and national level as regards AI systems that are built on general-purpose AI models. To avoid overlapping competences, where an AI system is based on a general-purpose AI model and the model and system are provided by the same provider, the supervision should take place at Union level through the AI Office, which should have the powers of a market surveillance authority within the meaning of Regulation (EU) 2019/1020 for this purpose. In all other cases, national market surveillance authorities remain responsible for the supervision of AI systems. However, for general-purpose AI systems that can be used directly by deployers for at least one purpose that is classified as high-risk, market surveillance authorities should cooperate with the AI Office to carry out evaluations of compliance and inform the Board and other market surveillance authorities accordingly. Furthermore, market surveillance authorities should be able to request assistance from the AI Office where the market surveillance authority is unable to conclude an investigation on a high-risk AI system because of its inability to access certain information related to the general-purpose AI model on which the high-risk AI system is built. In such cases, the procedure regarding mutual assistance in cross-border cases in Chapter VI of Regulation (EU) 2019/1020 should apply mutatis mutandis.

### Recital 170 — complaint rights for AI regulation infringement

*Source: AI Act, aiact-rec-170-en, 2024-06-12 — https://overview.legal/posts/94022*

Union and national law already provide effective remedies to natural and legal persons whose rights and freedoms are adversely affected by the use of AI systems. Without prejudice to those remedies, any natural or legal person that has grounds to consider that there has been an infringement of this Regulation should be entitled to lodge a complaint to the relevant market surveillance authority.

## Related topics

- **Notified Bodies for AI Systems** — https://overview.legal/topics/notified-bodies-ai
  This topic is needed to comprehensively cover the role, responsibilities, and obligations of notified bodies in the AI Act conformity assessment framework, incl
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Post-Market Monitoring for AI Systems** — https://overview.legal/topics/post-market-monitoring-ai
  Risk management systems require ongoing post-market monitoring to identify and respond to risks that emerge during real-world deployment. This is a distinct and
- **Market Surveillance and Control of AI Systems** — https://overview.legal/topics/market-surveillance-control-ai
  This new topic is needed to comprehensively cover the specific procedures, mechanisms, and authorities involved in market surveillance and control of AI systems
- **AI Incident Notification** — https://overview.legal/topics/serious-incident-notification-ai
  The AI Act establishes specific procedures for notifying authorities about serious incidents and anomalies in high-risk AI systems, which requires dedicated cov

---
Generated by overview.legal · https://overview.legal/topics/conformity-assessment-body-notification · 2026-08-22
