Notified Bodies for AI Systems
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This topic is needed to comprehensively cover the role, responsibilities, and obligations of notified bodies in the AI Act conformity assessment framework, including their designation, accreditation, and operational requirements.
Overview
9 sources · Jul 23, 2026Legal Framework
The AI Act establishes a conformity assessment framework for high-risk AI systems in which notified bodies serve as the critical independent evaluators. Article 31 sets out the overarching requirements that conformity assessment bodies must meet to be designated as notified bodies, covering organizational and operational competence, independence, impartiality, and confidentiality. Article 32 provides the mechanism for demonstrating compliance: where a conformity assessment body shows it meets the criteria laid down in relevant harmonized standards referenced in the Official Journal of the European Union, it benefits from a presumption of conformity with Article 31 requirements, to the extent those standards cover the applicable requirements. Article 37 addresses challenges to the competence of notified bodies, creating an accountability layer that allows Member States and the Commission to scrutinize whether a notified body continues to meet the threshold for designation.
The rationale is structural: high-risk AI systems — those used in biometric identification, critical infrastructure, education, employment, essential services, and law enforcement — cannot be placed on the market without rigorous third-party verification where no harmonized standards-based self-assessment is available. Notified bodies function as the gatekeepers of that verification, ensuring that providers' technical documentation, quality management systems, and post-market monitoring plans satisfy the substantive requirements of Chapter III of the AI Act.
Key Developments
The AI Act's notified body framework draws on established patterns from the New Legislative Approach used across EU product safety law, meaning that the designation, accreditation, and peer-evaluation processes mirror those already applied under regimes such as the Medical Devices Regulation and Machinery Regulation. The European Cooperation for Accreditation operates the peer evaluation mechanism, and bodies must successfully complete this process before being listed in the NANDO database.
Article 37's challenge mechanism reflects lessons from the medical devices sector, where concerns about notified body competence — particularly regarding inconsistent evaluation depth across Member States — prompted strengthened oversight. Under the AI Act, the Commission and other Member States can challenge a notified body's competence, triggering a review that may result in suspension or withdrawal of designation. This creates a dynamic accountability structure rather than a one-time accreditation.
The presumption of conformity under Article 32 operates identically to parallel provisions in other CE-marking legislation: harmonized standards developed by CEN, CENELEC, and ETSI under standardization requests from the Commission translate the abstract Article 31 requirements into technical specifications. Until such standards are finalized and published, notified bodies must assess compliance directly against Article 31 criteria, increasing the evidentiary burden on both the body and the provider seeking assessment.
Practical Guidance
Verify accreditation scope before engagement: Providers of high-risk AI systems must confirm that a notified body's designation explicitly covers the conformity assessment procedure applicable to their system, as notified bodies are designated only for specific AI system categories and assessment modules.
Monitor harmonized standard development: Track CEN/CENELEC/ETSI standardization mandates for AI. Once harmonized standards are referenced in the Official Journal, alignment with them triggers the Article 32 presumption of conformity, streamlining the assessment process for both the body and the provider.
Prepare for direct Article 31 assessment: Until harmonized standards are published, ensure your technical documentation and quality management system can be evaluated directly against Article 31 competence and operational requirements, as notified bodies cannot rely on the presumption mechanism.
Document independence and impartiality safeguards: Notified bodies must maintain structural separation from the providers they assess. Providers should avoid any commercial relationships that could compromise the body's impartiality, as this is grounds for challenge under Article 37 and potential withdrawal of the resulting certificate.
Anticipate competence challenges: If a notified body's competence is challenged under Article 37, certificates issued may come under scrutiny. Providers should maintain comprehensive assessment records to demonstrate the thoroughness of the conformity assessment process independently of the specific notified body involved.