AI Conformity Declaration
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.The EU declaration of conformity is a specific, mandatory compliance document under the AI Act that deserves its own dedicated topic to cover its requirements, content, format, maintenance, and availability obligations for AI system providers.
Overview
10 sources · Sep 8, 2026Legal Framework
The EU declaration of conformity is a mandatory compliance document under the AI Act, required before a high-risk AI system may be placed on the market or put into service. The primary obligation arises under Article 16(g), which lists the declaration among the core obligations of providers of high-risk AI systems. Providers must complete the relevant conformity assessment under Article 43 and then draw up the declaration in accordance with Article 47.
The declaration forms part of a broader documentary chain. Under Article 18(1)(e), the provider must retain the EU declaration of conformity for ten years after the system has been placed on the market or put into service, making it available to national competent authorities throughout that period. This retention obligation runs parallel to the keeping of technical documentation and quality management system records.
"draw up an EU declaration of conformity in accordance with Article 47"
— AI Act Art. 16(g)
The declaration also serves as a checkpoint for downstream actors. Importers, under Article 23(1)(c), must verify that the high-risk AI system is accompanied by the EU declaration of conformity before placing it on the market. Authorised representatives of non-EU providers bear a verification and custodial duty: under Article 22(3)(a), they must confirm that the declaration has been drawn up and that an appropriate conformity assessment was carried out, and under Article 22(3)(b) they must retain a copy for the same ten-year period.
Key Developments
No court or enforcement authority has yet ruled specifically on the content or sufficiency of an AI Act EU declaration of conformity, as the Act's application dates for high-risk systems have not yet arrived. However, the EDPB has already signalled the declaration's relevance to data protection supervision. In Opinion 28/2024, the Board noted that the AI Act requires providers of high-risk systems to draw up the declaration and observed its substantive content:
"such declaration contains a statement that the relevant AI system comp"
— EDPB Opinion 28/2024 §97
This indicates that data protection authorities will look to the declaration as evidence of compliance not only with AI Act requirements but potentially as a factor in assessing GDPR conformity where personal data is processed. The interplay between the declaration's attestation of AI Act compliance and separate GDPR accountability obligations is an area where supervisory authorities are positioning themselves early.
Status of the Debate
This topic is an emerging debate. The AI Act's obligations regarding the EU declaration of conformity are codified and clear in their basic requirements, but the practical content, format, and interaction with other regulatory regimes—particularly the GDPR—remain untested. No court has interpreted Article 47's requirements, and no enforcement decision has assessed the adequacy of a declaration. The debate is currently driven by scholarship and regulatory guidance ahead of the Act's application deadlines. What would resolve the open questions is either implementing acts specifying the declaration's template under Article 47, or the first enforcement actions by market surveillance authorities examining whether a provider's declaration substantively meets the statutory standard.
Practical Guidance
- Draw up the declaration before market placement. Article 16(g) requires the EU declaration of conformity to be completed after the conformity assessment under Article 43 but before the system is placed on the market or put into service—sequence matters.
- Retain for ten years. Under Article 18(1)(e), keep the declaration accessible to national competent authorities for a decade after market placement; ensure your records management system tracks this deadline.
- Brief your authorised representative and importers. Non-EU providers must empower authorised representatives under Article 22(3) to verify and retain the declaration, and importers must confirm under Article 23(1)(c) that the system is accompanied by it before market entry.
- Align declaration content with GDPR accountability. Given the EDPB's attention to the declaration's compliance statement, ensure the declaration's assertions are consistent with your GDPR documentation, particularly where the high-risk system processes personal data.
Nothing of this type on this topic.