# Conformity Assessment Procedures and Methodologies — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/conformity-assessment-procedures-ai
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed to specifically address the procedural and methodological aspects of conformity assessment for AI systems, including step-by-step procedures, assessment phases, documentation requirements, and reporting mechanisms that are distinct from the general conformity assessment concept.

## Overview

## Legal Framework

Conformity assessment procedures under the AI Act are governed primarily by Articles 40 through 47, which establish the methodological and procedural requirements for demonstrating that high-risk AI systems comply with the regulation's substantive obligations. Article 43 sets out the available conformity assessment pathways, distinguishing between internal control mechanisms (Annex VI) and third-party assessment involving notified bodies (Annex VII), depending on the AI system's classification and intended purpose. Article 46 provides a derogation mechanism, permitting Member States to authorise the placing on the market of high-risk AI systems without having undergone the conformity assessment procedure, provided this is justified on grounds of public security, protection of life, or the protection of health and the environment, and subject to strict conditions and Union-level notification.

Recital 50 clarifies the classification logic for AI systems that serve as safety components of products, or are themselves products, falling within the scope of listed Union harmonisation legislation. Where the underlying product undergoes a third-party conformity assessment under that harmonisation legislation, the AI system is classified as high-risk under the AI Act, triggering the corresponding assessment obligations. This ensures that AI components embedded in regulated products such as machinery, lifts, toys, and equipment for explosive atmospheres are subject to the same scrutiny as the products they are integrated into.

## Key Developments

The interplay between the AI Act's conformity assessment regime and existing Union harmonisation legislation represents the most significant practical development. The AI Act does not operate in isolation; where an AI system is a safety component of a product already subject to third-party conformity assessment under directives such as the Machinery Directive or the Lifts Directive, the AI-specific assessment must be integrated into the existing procedure rather than conducted as a parallel process. This avoids duplication while ensuring AI-specific risks are captured.

The derogation under Article 46 has not yet been tested in practice, but its design mirrors emergency authorisation provisions in other sectoral product safety legislation. The requirement to notify the Commission and other Member States, combined with the obligation to provide reasons and specify the scope and duration of the derogation, establishes a transparency mechanism that limits unilateral state discretion. Practitioners should expect the Commission to scrutinise derogations closely, particularly where they appear to circumvent third-party assessment obligations under Annex VII.

## Practical Guidance

- **Map the conformity assessment pathway early**: Determine whether the AI system falls under Annex VI (internal control) or Annex VII (notified body involvement) based on the system's classification and whether it is a safety component of a product subject to listed harmonisation legislation under Recital 50.

- **Integrate with existing product assessments**: Where the AI system is embedded in a product already undergoing third-party conformity assessment under Union harmonisation legislation, coordinate the AI-specific assessment within that existing procedure to avoid parallel or conflicting obligations.

- **Prepare technical documentation before initiating assessment**: Annex IV documentation requirements must be satisfied before any conformity assessment module can be applied, regardless of whether the pathway is internal or third-party.

- **Monitor derogation conditions closely**: If relying on Article 46, ensure the public security or health justification is documented with specificity, notify the Commission and Member States with full reasoning, and set a defined duration — open-ended derogations are unlikely to withstand scrutiny.

- **Establish a post-market monitoring infrastructure**: Conformity assessment is not a one-time event; Article 72 requires ongoing monitoring, and the assessment methodology must account for how the provider will detect and respond to emerging risks throughout the system's lifecycle.

## Legislation (full text of key provisions)

### Derogation from conformity assessment procedure

*Source: AI Act, aiact-art-46-en, 2024-06-12 — https://overview.legal/posts/92688*

### Recital 125 — High-risk AI systems conformity assessment procedure

*Source: AI Act, aiact-rec-125-en, 2024-06-12 — https://overview.legal/posts/93932*

Given the complexity of high-risk AI systems and the risks that are associated with them, it is important to develop an adequate conformity assessment procedure for high-risk AI systems involving notified bodies, so-called third party conformity assessment. However, given the current experience of professional pre-market certifiers in the field of product safety and the different nature of risks involved, it is appropriate to limit, at least in an initial phase of application of this Regulation, the scope of application of third-party conformity assessment for high-risk AI systems other than those related to products. Therefore, the conformity assessment of such systems should be carried out as a general rule by the provider under its own responsibility, with the only exception of AI systems intended to be used for biometrics.

### Recital 78 — conformity assessment cybersecurity high-risk AI

*Source: AI Act, aiact-rec-78-en, 2024-06-12 — https://overview.legal/posts/93838*

The conformity assessment procedure provided by this Regulation should apply in relation to the essential cybersecurity requirements of a product with digital elements covered by a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and classified as a high-risk AI system under this Regulation. However, this rule should not result in reducing the necessary level of assurance for critical products with digital elements covered by a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements. Therefore, by way of derogation from this rule, high-risk AI systems that fall within the scope of this Regulation and are also qualified as important and critical products with digital elements pursuant to a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements and to which the conformity assessment procedure based on internal control set out in an annex to this Regulation applies, are subject to the conformity assessment provisions of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements insofar as the essential cybersecurity requirements of that regulation are concerned. In this case, for all the other aspects covered by this Regulation the respective provisions on conformity assessment based on internal control set out in an annex to this Regulation should apply. Building on the knowledge and expertise of ENISA on the cybersecurity policy and tasks assigned to ENISA under the Regulation (EU) 2019/881 of the European Parliament and of the Council (37), the Commission should cooperate with ENISA on issues related to cybersecurity of AI systems.

### Recital 139 — AI regulatory sandboxes innovation objectives

*Source: AI Act, aiact-rec-139-en, 2024-06-12 — https://overview.legal/posts/93960*

The objectives of the AI regulatory sandboxes should be to foster AI innovation by establishing a controlled experimentation and testing environment in the development and pre-marketing phase with a view to ensuring compliance of the innovative AI systems with this Regulation and other relevant Union and national law. Moreover, the AI regulatory sandboxes should aim to enhance legal certainty for innovators and the competent authorities’ oversight and understanding of the opportunities, emerging risks and the impacts of AI use, to facilitate regulatory learning for authorities and undertakings, including with a view to future adaptions of the legal framework, to support cooperation and the sharing of best practices with the authorities involved in the AI regulatory sandbox, and to accelerate access to markets, including by removing barriers for SMEs, including start-ups. AI regulatory sandboxes should be widely available throughout the Union, and particular attention should be given to their accessibility for SMEs, including start-ups. The participation in the AI regulatory sandbox should focus on issues that raise legal uncertainty for providers and prospective providers to innovate, experiment with AI in the Union and contribute to evidence-based regulatory learning. The supervision of the AI systems in the AI regulatory sandbox should therefore cover their development, training, testing and validation before the systems are placed on the market or put into service, as well as the notion and occurrence of substantial modification that may require a new conformity assessment procedure. Any significant risks identified during the development and testing of such AI systems should result in adequate mitigation and, failing that, in the suspension of the development and testing process. Where appropriate, national competent authorities establishing AI regulatory sandboxes should cooperate with other relevant authorities, including those supervising the protection of fundamental rights, and could allow for the involvement of other actors within the AI ecosystem such as national or European standardisation organisations, notified bodies, testing and experimentation facilities, research and experimentation labs, European Digital Innovation Hubs and relevant stakeholder and civil society organisations. To ensure uniform implementation across the Union and economies of scale, it is appropriate to establish common rules for the AI regulatory sandboxes’ implementation and a framework for cooperation between the relevant authorities involved in the supervision of the sandboxes. AI regulatory sandboxes established under this Regulation should be without prejudice to other law allowing for the establishment of other sandboxes aiming to ensure compliance with law other than this Regulation. Where appropriate, relevant competent authorities in charge of those other regulatory sandboxes should consider the benefits of using those sandboxes also for the purpose of ensuring compliance of AI systems with this Regulation. Upon agreement between the national competent authorities and the participants in the AI regulatory sandbox, testing in real world conditions may also be operated and supervised in the framework of the AI regulatory sandbox.

### Recital 173 — Commission delegated powers to adapt AI rules

*Source: AI Act, aiact-rec-173-en, 2024-06-12 — https://overview.legal/posts/94028*

In order to ensure that the regulatory framework can be adapted where necessary, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission to amend the conditions under which an AI system is not to be considered to be high-risk, the list of high-risk AI systems, the provisions regarding technical documentation, the content of the EU declaration of conformity the provisions regarding the conformity assessment procedures, the provisions establishing the high-risk AI systems to which the conformity assessment procedure based on assessment of the quality management system and assessment of the technical documentation should apply, the threshold, benchmarks and indicators, including by supplementing those benchmarks and indicators, in the rules for the classification of general-purpose AI models with systemic risk, the criteria for the designation of general-purpose AI models with systemic risk, the technical documentation for providers of general-purpose AI models and the transparency information for providers of general-purpose AI models. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (55). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

### Recital 50 — high-risk classification of safety-related AI systems

*Source: AI Act, aiact-rec-50-en, 2024-06-12 — https://overview.legal/posts/93782*

As regards AI systems that are safety components of products, or which are themselves products, falling within the scope of certain Union harmonisation legislation listed in an annex to this Regulation, it is appropriate to classify them as high-risk under this Regulation if the product concerned undergoes the conformity assessment procedure with a third-party conformity assessment body pursuant to that relevant Union harmonisation legislation. In particular, such products are machinery, toys, lifts, equipment and protective systems intended for use in potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft equipment, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, automotive and aviation.

### Recital 81 — provider quality management system

*Source: AI Act, aiact-rec-81-en, 2024-06-12 — https://overview.legal/posts/93844*

The provider should establish a sound quality management system, ensure the accomplishment of the required conformity assessment procedure, draw up the relevant documentation and establish a robust post-market monitoring system. Providers of high-risk AI systems that are subject to obligations regarding quality management systems under relevant sectoral Union law should have the possibility to include the elements of the quality management system provided for in this Regulation as part of the existing quality management system provided for in that other sectoral Union law. The complementarity between this Regulation and existing sectoral Union law should also be taken into account in future standardisation activities or guidance adopted by the Commission. Public authorities which put into service high-risk AI systems for their own use may adopt and implement the rules for the quality management system as part of the quality management system adopted at a national or regional level, as appropriate, taking into account the specificities of the sector and the competences and organisation of the public authority concerned.

### Recital 126 — notified body requirements and notification procedure

*Source: AI Act, aiact-rec-126-en, 2024-06-12 — https://overview.legal/posts/93934*

In order to carry out third-party conformity assessments when so required, notified bodies should be notified under this Regulation by the national competent authorities, provided that they comply with a set of requirements, in particular on independence, competence, absence of conflicts of interests and suitable cybersecurity requirements. Notification of those bodies should be sent by national competent authorities to the Commission and the other Member States by means of the electronic notification tool developed and managed by the Commission pursuant to Article R23 of Annex I to Decision No 768/2008/EC.

## Recent developments

### Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

*Source: Gaming Tech Law, 2023-03-29 — https://overview.legal/posts/6223 — original: https://www.gamingtechlaw.com/2023/03/draft-ai-act-general-purpose-artificial-intelligence/#entry-4244*

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act…

## Related topics

- **Notified Body Assessment Procedures** — https://overview.legal/topics/notified-body-assessment-procedures
  The content extensively covers the operational procedures and methodologies that notified bodies must follow when conducting conformity assessments, which deser
- **AI Act Procedures** — https://overview.legal/topics/ai-act-procedural-framework
  The 'Procedure' section of the AI Act establishes the overarching procedural framework and mechanisms for implementing and enforcing the regulation. This topic 
- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **High-Risk AI Classification** — https://overview.legal/topics/high-risk-ai-classification
  The content specifically addresses classification rules for high-risk AI systems under the AI Act, which is a distinct regulatory concept requiring its own dedi

---
Generated by overview.legal · https://overview.legal/topics/conformity-assessment-procedures-ai · 2026-08-22
