TL;DR: EU AI Act Conformity Assessment: What It Is and Who Must Do It, a practical compliance guide for enterprise and HR teams in 2026.
Conformity assessment under the EU AI Act is the formal process by which an organization confirms that a high-risk AI system meets the requirements of the regulation before placing it on the EU market or putting it into service. With Annex III high-risk obligations set to apply from December 2, 2027 (roughly two months away), any provider that skips this step for a system in production will be operating without authorization in the EU market, which exposes it to fines of up to 15 million euros or 3 percent of global annual turnover under Article 99 for high-risk provider violations, whichever is higher. The 35 million euro / 7 percent ceiling in Article 99(3) is reserved for breaches of the Article 5 prohibited-practice ban.
This article explains what conformity assessment actually involves, who must do it, which path applies to which type of system, and what the resulting documentation must contain.
Which AI systems require conformity assessment
The EU AI Act uses a tiered risk classification. Prohibited systems under Article 5 are banned outright. GPAI models have their own obligations under Title III. Limited-risk systems have transparency obligations but no conformity assessment requirement. Minimal-risk systems have no mandatory obligations. Only high-risk systems require conformity assessment.
High-risk AI systems are defined in Article 6 and Annex III of the Regulation (EU) 2024/1689. There are two categories.
The first category covers AI systems that are safety components of products already regulated under Union harmonization legislation listed in Annex I. These include medical devices, machinery, aviation, and automotive systems. If an AI system is a safety component of such a product, it must go through the conformity assessment procedure for that product, which typically requires the AI system to be addressed as part of the product's existing assessment.
The second category, and the one that applies to most companies building or deploying standalone AI products, is Annex III. That annex lists eight domains:
Biometrics: remote biometric identification systems, biometric categorization systems, and emotion recognition systems.
Critical infrastructure: AI used to manage or operate critical digital infrastructure, road traffic, and the supply of water, gas, heating, or electricity.
Education and vocational training: AI used to determine access to educational institutions, assess students, or monitor students during exams.
Employment and workers management: AI used for recruitment, selection, promotion, task allocation, monitoring, and performance evaluation. The recruitment use case covers resume screening tools and interview scoring tools.
Access to essential private services and public services and benefits: AI used by banks or insurers to evaluate creditworthiness, AI used to determine eligibility for public benefits, and AI used to assess health risks.
Law enforcement: AI used for risk assessments, polygraph testing, crime analytics, and profiling individuals.
Migration, asylum, and border control: AI used to assess risks posed by people seeking entry, to verify documents, and to process applications.
Administration of justice and democratic processes: AI used to assist courts and to influence elections.
If your system falls into any of these categories and you place it on the EU market or put it into service in the EU, you must complete conformity assessment before deployment.
The two conformity assessment paths
Article 43 of the EU AI Act defines two conformity assessment procedures.
The first is internal control, often called self-assessment. This applies to the majority of high-risk AI systems under Annex III. The provider conducts its own assessment using the requirements in Chapters 2 and 3 of Title III, documents the results, draws up an EU Declaration of Conformity, and affixes the CE marking.
The second is third-party assessment by a notified body. This is mandatory for two categories of systems: AI systems intended for use in real-time remote biometric identification of natural persons in public spaces, and AI systems listed in Annex III point 1(a) where the provider has not applied harmonized standards or common specifications that cover all applicable requirements. In practice, real-time facial recognition in public spaces is the primary use case that requires a notified body.
For most companies building AI tools for employment, credit, or education, self-assessment is the applicable path. The remainder of this article focuses on self-assessment, because that is what affects the largest number of organizations.
What self-assessment requires
Self-assessment under Article 43(1) requires the provider to demonstrate conformity with all requirements in Articles 8 through 15. Those requirements fall into five areas.
Technical documentation under Article 11. The provider must draw up technical documentation before the system is placed on the market. This documentation must be kept up to date throughout the system's lifecycle. Annex IV specifies what the documentation must contain: a general description of the system and its intended purpose, a description of the system's development process including training methodology and data provenance, details of the monitoring and logging system, validation and testing procedures used, risk management documentation, instructions for use for deployers, and any changes made after initial assessment. There is no standard page count, but for a system of moderate complexity, 40 to 80 pages of substantive technical documentation is a typical range.
Quality management system under Article 17. The provider must establish, document, and implement a quality management system that covers the AI system's entire lifecycle. This QMS must include a strategy for regulatory compliance, techniques for AI system design, testing procedures, quality control and quality assurance measures, resource management procedures, an accountability framework, a post-market monitoring plan, and a record-keeping process. ISO 42001, the AI management system standard published in December 2023, provides a useful reference structure for building a compliant QMS.
Logging system under Article 12. High-risk AI systems must have logging capabilities that enable automatic recording of events throughout their operation. Logs must enable post-hoc verification of the system's operation and, at minimum, record the period of each use, the reference database against which input data was checked (for biometric systems), and input data that led to the system's output. For most non-biometric systems, the logging requirement means preserving input-output pairs, timestamps, and the version of the model in use at the time of each decision.
Human oversight under Article 14. High-risk AI systems must be designed to be effectively overseen by humans. The system must have tools or interfaces that allow human overseers to understand the system's capabilities and limitations, to monitor its operation, to intervene when the system produces an erroneous output, and to override or halt the system. The provider must make instructions for use available to deployers explaining how to exercise this oversight. A deployer that never uses the override capability is not protected. The system must be designed so that oversight is practically feasible, not just theoretically possible.
Accuracy, robustness, and cybersecurity under Article 15. High-risk AI systems must achieve an appropriate level of accuracy as specified in their technical documentation, and their level of accuracy must be declared to deployers. The system must be resilient to errors, faults, and inconsistencies. For systems used in consequential decisions, performance must be tested across demographic groups where disparate accuracy could cause discriminatory outcomes. Cybersecurity requirements apply to systems that could be manipulated through adversarial examples or data poisoning.
The EU Declaration of Conformity
Once the provider has completed its self-assessment and is satisfied that the system meets all applicable requirements, it draws up an EU Declaration of Conformity under Article 47. This is a formal legal document, not a summary memo. It must contain the following elements:
The provider's name, registered trade name, and registered address. The name of any authorized representative established in the EU (required for non-EU providers under Article 22). The AI system's name, type, and version number. A statement that the Declaration of Conformity is issued under the sole responsibility of the provider. A statement that the AI system is in conformity with the EU AI Act. References to any harmonized standards or technical specifications applied. The place and date of issue. The name and signature of the person authorized to sign on behalf of the provider.
The Declaration of Conformity must be kept for 10 years after the AI system is placed on the market, under Article 18. For providers that operate SaaS AI products with ongoing deployments, the 10-year clock does not start until the last version of the system is withdrawn from the market.
After the Declaration of Conformity is drawn up, the provider affixes the CE marking to the AI system or its documentation before placing it on the EU market, in accordance with Article 48. The CE marking signals to market surveillance authorities and deployers that the system has passed conformity assessment.
When you must redo the assessment
Conformity assessment is not a one-time event. Under Article 43(4), if the provider makes a substantial modification to the high-risk AI system after its initial conformity assessment, it must undertake a new conformity assessment for the modified system. A new CE marking and a new Declaration of Conformity are required before the modified system is placed on the market.
Post-market monitoring under Article 72 also requires providers to actively collect and review data about how the system performs in practice after deployment. If post-market monitoring reveals that the system no longer meets the accuracy, robustness, or safety requirements in its technical documentation, the provider must take corrective action. Depending on the severity, this may require suspending the system, issuing corrective instructions to deployers, notifying the relevant national competent authority, or conducting a new assessment.
The AI regulation deadline calendar 2026 provides a timeline of when each requirement took or takes effect, which is useful for planning assessment timelines in relation to product launch schedules.
Role of notified bodies for mandatory third-party assessment
Notified bodies are organizations officially designated by EU member states to conduct third-party conformity assessments for specific regulated products. For AI Act purposes, the Commission designated the first notified bodies in early 2026, and the list is maintained by NANDO (New Approach Notified and Designated Organisations), the official EU database.
For providers that require third-party assessment, including those building real-time remote biometric identification systems for public-space use, the process involves selecting a notified body that is designated for AI Act assessments, submitting the technical documentation and QMS to the body for review, undergoing an audit of the QMS, and receiving a conformity certificate. The notified body issues the certificate, and the provider then draws up the Declaration of Conformity referencing the certificate.
Notified bodies are authorized to request additional testing, to require changes to the system before issuing a certificate, and to withdraw certificates if a previously certified system is substantially modified without re-assessment. Their certificates are recognized across all EU member states, so a provider does not need separate assessments for France, Germany, and Italy.
Fees for notified body assessment vary widely by body and system complexity. For a moderately complex biometric system, costs in the range of 50,000 to 150,000 euros are a reasonable planning estimate. Timeline from initial engagement to certificate issuance is typically 6 to 12 months, depending on documentation readiness and notified body scheduling.
Practical steps for compliance teams
The path from a gap to a completed self-assessment has five practical stages.
Confirm scope. Audit your AI system inventory against Annex III to determine which systems are high-risk. Systems built on third-party foundation models may still be high-risk if you are the deployer making consequential decisions, or the provider if you built a product on top of the model. The EU AI Act compliance guide for small teams covers scope-determination in more depth.
Assign ownership. Each high-risk system needs a named technical documentation owner, a QMS owner, and an oversight owner. Without named individuals, documentation accumulates errors and gaps.
Draft technical documentation. Use Annex IV as the table of contents. Write each section in enough detail that an auditor who has never seen your system could understand how it works, how it was trained, what data was used, how it was tested, and what its accuracy limitations are. Version-control the documentation so that the version active at any given deployment date can be reconstructed.
Complete the QMS. Map your existing software development lifecycle to Article 17 requirements. Identify gaps and fill them. Common gaps include absence of a post-market monitoring plan, absence of a formal accuracy validation procedure, and absence of a documented corrective action process.
Sign the Declaration of Conformity. This is the formal act that completes the conformity assessment. The signatory should be a person with legal authority to bind the company, and the document should be reviewed by legal counsel before signing.
For a parallel view of how GPAI providers are handling their obligations, which technically applied from August 2, 2025 and are already in effect, the EU AI Act GPAI compliance checklist August 2026 provides a useful cross-reference. Note that GPAI providers have different obligations from high-risk AI system providers under Annex III. Some organizations have products in both categories and must satisfy both sets of requirements independently.
The conformity assessment process rewards organizations that build documentation habits early. A team that documents its training data provenance, testing methodology, and risk management decisions as part of its normal development workflow will find the Annex IV technical documentation requirements manageable. A team that tries to reconstruct this documentation retroactively from code repositories and meeting notes will find the process significantly more time-consuming.
Related Reading
-
Human-in-the-Loop AI: What EU AI Act Article 14 Actually Requires
-
EU AI Act high-risk classification draft guidelines May 2026
-
EU AI Act SME support and regulatory sandboxes: what small businesses
-
EU AI Act national competent authorities: who enforces in each EU memb
-
EU AI Act post-market monitoring: what Article 72 requires for high-ri
-
Vietnam's 46 High-Risk AI Systems: Who Must Comply by August 2026
-
EU AI Act enforcement starts August 2, 2026: what it means and what to
-
EU AI Act GPAI Codes of Conduct: What They Require and How to Use Them
-
EU AI Act Article 13 transparency: what deployers must tell users of h
-
AI Model Cards in 2026: What Regulators Now Expect and How to Write One
-
EU AI Act High-Risk AI Systems: Annex III Checklist for Employers and Ve
-
EU AI Act Article 9 risk management system: step-by-step implementation
-
EU AI Act compliance checklist 2026: 35 items for providers and deployers
