# AI Conformity Declaration — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/eu-declaration-of-conformity-ai
> Sources are cited per item. Verify against the official texts before relying on them.

The EU declaration of conformity is a specific, mandatory compliance document under the AI Act that deserves its own dedicated topic to cover its requirements, content, format, maintenance, and availability obligations for AI system providers.

## Overview

## Legal Framework

Article 47 of the AI Act establishes the EU declaration of conformity as a mandatory, standalone compliance instrument that providers of high-risk AI systems must draw up before placing a system on the market or putting it into service. The declaration constitutes a formal attestation that the AI system satisfies the requirements set out in Chapter III of the AI Act, which encompasses risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, and robustness.

The declaration must be issued for each individual high-risk AI system and must contain the information specified in Annex V. It must be translated into an EU official language determined by the Member State where the system is made available. Providers must retain the declaration for ten years following the system's placement on the market — a retention period that aligns with the product safety regime under the Union harmonisation legislation framework.

Recital 77 clarifies an important interaction with the forthcoming Cyber Resilience Act: high-risk AI systems falling within the scope of that regulation may demonstrate compliance with the AI Act's cybersecurity requirements by fulfilling the essential cybersecurity requirements established under the Cyber Resilience Act. This creates a convergence point where a single conformity assessment can satisfy overlapping obligations.

## Key Developments

The declaration of conformity mechanism draws directly from established practice under the New Legislative Framework for product safety in the EU. The Court of Justice has consistently reinforced the principle that compliance documentation serves not merely an administrative function but constitutes a substantive guarantee that enables effective market surveillance and enforcement — as reflected in the broader jurisprudence on independent supervisory oversight and the effectiveness of regulatory obligations.

The integration of the declaration requirement into the AI Act signals that high-risk AI systems are treated as products subject to the full weight of EU conformity assessment architecture. National market surveillance authorities, designated under Article 71, will rely on these declarations as a primary verification tool. The ten-year retention period exceeds typical GDPR documentation timelines and reflects the product-liability orientation of the regime.

## Practical Guidance

- **Draft a separate declaration per system**: Article 47 requires an individual EU declaration of conformity for each high-risk AI system placed on the market or put into service — a blanket declaration covering a product portfolio will not satisfy the requirement.

- **Verify Chapter III completeness before signing**: The declaration attests to compliance with all Chapter III requirements, meaning providers must confirm that risk management systems, data governance measures, technical documentation, logging capabilities, transparency provisions, human oversight mechanisms, and accuracy/robustness standards are all in place and documented.

- **Align with Annex V content specifications**: The declaration must contain the specific elements listed in Annex V, including provider identification, system description, references to harmonised standards applied or common specifications used, and the identity of any notified body involved in conformity assessment.

- **Leverage Cyber Resilience Act convergence**: Where the AI system falls within the Cyber Resilience Act's scope, structure cybersecurity conformity assessments to satisfy both instruments simultaneously, as contemplated by Recital 77.

- **Establish a ten-year retention and update protocol**: Maintain the declaration for ten years post-placement on the market, and implement internal procedures to review and update the declaration when substantial modifications to the system trigger new conformity assessment obligations under Article 43.

## Legislation (full text of key provisions)

### EU declaration of conformity

*Source: AI Act, aiact-art-47-en, 2024-06-12 — https://overview.legal/posts/92704*

### Recital 77 — cybersecurity compliance equivalence high-risk AI

*Source: AI Act, aiact-rec-77-en, 2024-06-12 — https://overview.legal/posts/93836*

Without prejudice to the requirements related to robustness and accuracy set out in this Regulation, high-risk AI systems which fall within the scope of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, in accordance with that regulation may demonstrate compliance with the cybersecurity requirements of this Regulation by fulfilling the essential cybersecurity requirements set out in that regulation. When high-risk AI systems fulfil the essential requirements of a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, they should be deemed compliant with the cybersecurity requirements set out in this Regulation in so far as the achievement of those requirements is demonstrated in the EU declaration of conformity or parts thereof issued under that regulation. To that end, the assessment of the cybersecurity risks, associated to a product with digital elements classified as high-risk AI system according to this Regulation, carried out under a regulation of the European Parliament and of the Council on horizontal cybersecurity requirements for products with digital elements, should consider risks to the cyber resilience of an AI system as regards attempts by unauthorised third parties to alter its use, behaviour or performance, including AI specific vulnerabilities such as data poisoning or adversarial attacks, as well as, as relevant, risks to fundamental rights as required by this Regulation.

### Recital 173 — Commission delegated powers to adapt AI rules

*Source: AI Act, aiact-rec-173-en, 2024-06-12 — https://overview.legal/posts/94028*

In order to ensure that the regulatory framework can be adapted where necessary, the power to adopt acts in accordance with Article 290 TFEU should be delegated to the Commission to amend the conditions under which an AI system is not to be considered to be high-risk, the list of high-risk AI systems, the provisions regarding technical documentation, the content of the EU declaration of conformity the provisions regarding the conformity assessment procedures, the provisions establishing the high-risk AI systems to which the conformity assessment procedure based on assessment of the quality management system and assessment of the technical documentation should apply, the threshold, benchmarks and indicators, including by supplementing those benchmarks and indicators, in the rules for the classification of general-purpose AI models with systemic risk, the criteria for the designation of general-purpose AI models with systemic risk, the technical documentation for providers of general-purpose AI models and the transparency information for providers of general-purpose AI models. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making (55). In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States’ experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.

## Guidance

### Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models

*Source: EDPB, opinion-282024-on-certain-data-protection-aspects-related-to-en, 2024-12-18 — https://overview.legal/posts/125697 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-282024-on-certain-data-protection-aspects-related-to_en*

Adopted 1 Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models Adopted on 17 December 2024 Adopted 2 Executive summary AI technologies create many opportunities and benefits across a wide range of sectors and social activities. By protecting the fundamental right to data protection, GDPR supports these opportunities and promotes other EU fundamental rights, including the right to freedom of thought, expression and information,…

### Fundamentals of Secure AI Systems with Personal Data (Training module)

*Source: EDPB, spe-training-on-ai-and-data-protection-technical-en, 2025-06-17 — https://overview.legal/posts/50901 — original: https://edpb.europa.eu/system/files/2025-06/spe-training-on-ai-and-data-protection-technical_en.pdf*

SPE document "Training curriculum on AI and data protection Fundamentals of Secure AI Systems with Personal Data" door Dr.

## Recent developments

### Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

*Source: Gaming Tech Law, 2023-03-29 — https://overview.legal/posts/6223 — original: https://www.gamingtechlaw.com/2023/03/draft-ai-act-general-purpose-artificial-intelligence/#entry-4244*

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act…

### The EU’s home affairs chief wants to read your private messages

*Source: European Digital Rights, 2023-03-29 — https://overview.legal/posts/6224 — original: https://edri.org/our-work/the-eus-home-affairs-chief-wants-to-read-your-private-messages/#entry-4245*

> 
					The CSA Regulation, proposed by European Commissioner Ylva Johansson, could undermine the trust we have in secure and confidential processes like sending work emails, communicating with our doctors, and even governments protecting intelligence.

### De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen.

*Source: Datatilsynet, 2022-09-21 — https://overview.legal/posts/51817*

De Deense Autoriteit voor Persoonsgegevens heeft onderzoek gedaan naar het instrument Google Analytics en de bijbehorende instellingen, evenals de voorwaarden waaronder het instrument wordt aangeboden. Op basis van dit onderzoek concludeert de Deense Autoriteit voor Persoonsgegevens dat het instrument, zonder aanvullende maatregelen, niet op een wettelijke manier kan worden gebruikt. Wettelijk gebruik vereist de implementatie van aanvullende maatregelen, naast de instellingen die door Google worden aangeboden.

### Gezamenlijk document van de AEPD en de EDPS: 10 misverstanden over machine learning.

*Source: EDPS, 2022-09-19 — https://overview.legal/posts/51818*

De Europese Unie heeft kunstmatige intelligentie (AI) aangemerkt als een van de meest relevante technologieën van de 21e eeuw en benadrukt 1 het belang ervan in de strategie voor de digitale transformatie van de EU. AI heeft een breed scala aan toepassingen en kan bijdragen aan uiteenlopende gebieden, zoals het behandelen van chronische ziekten, het bestrijden van klimaatverandering of het anticiperen op cyberbeveiligingsrisico's.

### Europol wordt gevraagd om persoonlijke gegevens over te dragen aan een Nederlandse activist.

*Source: Fair Trials, 2022-09-15 — https://overview.legal/posts/51821*

De Europese Toezichthouder op de Bescherming van Persoonsgegevens heeft Europol opgedragen om persoonlijke gegevens over te dragen aan de Nederlandse activist Frank van der Linde. Dit besluit is het resultaat van een onderzoek van twee jaar naar de manier waarop Europol de persoonlijke gegevens van Van der Linde bewaart en verwerkt.

## Related topics

- **Conformity Assessment for AI Systems** — https://overview.legal/topics/conformity-assessment-ai
  Provider obligations typically include conformity assessment procedures and documentation requirements, which is a specific compliance mechanism under the AI Ac
- **Provider Obligations for AI Systems** — https://overview.legal/topics/provider-obligations-ai
  The content specifically addresses obligations imposed on providers of high-risk AI systems, which is a distinct and important category of requirements that des
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons

---
Generated by overview.legal · https://overview.legal/topics/eu-declaration-of-conformity-ai · 2026-08-22
