Notified Body Responsibilities and Operational Obligations
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed to capture the specific operational obligations, responsibilities, and procedural requirements that notified bodies must fulfill when conducting conformity assessments and maintaining their designation.
Overview
13 sources · Jul 23, 2026Legal Framework
Recital 173 of the AI Act establishes the Commission's delegated authority to amend conformity assessment procedures, technical documentation requirements, and the EU declaration of conformity content. This delegation power under Article 290 TFEU ensures the regulatory framework can adapt as AI technologies evolve. Notified bodies operating under this framework must conduct conformity assessments for high-risk AI systems, verifying that providers have met the substantive requirements set out in the Act's core provisions. Their designation depends on maintaining technical competence, impartiality, and operational independence. Notified bodies must assess quality management systems, review technical documentation, and issue EU-type examination certificates where applicable. They are also obligated to suspend or withdraw certificates where compliance is no longer assured. The Commission's power to modify the conditions under which an AI system is classified as high-risk directly affects the scope of notified body involvement, meaning these entities must monitor regulatory amendments continuously.
Key Developments
The Croatian DPA's enforcement action against a company publishing personal data of sole traders (fine of €40,000) underscores the broader regulatory environment in which notified bodies operate — where data protection failures carry concrete financial consequences. While this decision arose under GDPR rather than the AI Act, it signals the enforcement appetite that supervisory authorities will bring to AI-adjacent compliance failures. The EDPB's guidance on accreditation of certification bodies provides a structural parallel: accreditation standards demand rigorous independence and competence assessments, and notified bodies under the AI Act face analogous scrutiny. The Polish DPA's ongoing activity (UODO, DKN.5131.4.2025, February 2026) indicates continued national-level enforcement pressure on data governance practices that overlap with AI system compliance.
Practical Guidance
- Maintain documented evidence of technical competence for each AI domain in which conformity assessments are performed, updating qualifications as the Commission exercises its delegated powers to modify high-risk classifications under Recital 173.
- Establish internal procedures to monitor delegated acts and implementing acts issued under Article 290 TFEU, ensuring assessment protocols are revised within defined timelines after any amendment to conformity assessment procedures or technical documentation requirements.
- Implement conflict-of-interest controls that prevent any commercial relationship with AI providers from compromising impartiality, with documented reviews at regular intervals.
- Develop a certificate lifecycle management system covering issuance, suspension, withdrawal, and notification to the notifying authority and market surveillance authorities when non-compliance is identified.
- Conduct periodic internal audits of quality management system assessments to verify that providers' post-certification modifications to high-risk AI systems trigger reassessment where required.