AI Center › Conformity Assessment & CE Marking
Global · The AI Lifecycle — Stage 8 of 14
Conformity Assessment & CE Marking
Stage 8 of 14 in The AI Lifecycle. Before a high-risk AI system may be placed on the market or put into service, Regulation (EU) 2024/1689 requires it to pass a conformity assessment against the Chapter III, Section 2 requirements, be declared conforming, bear the CE marking, and be registered in the EU database.
This stage sets out the conformity-assessment procedures of Article 43 (internal control under Annex VI and notified-body assessment under Annex VII), the EU declaration of conformity (Article 47 and Annex V), CE marking (Article 48), registration (Articles 49 and 71), notified-body certificates (Article 44), and the presumption of conformity from harmonised standards and common specifications (Articles 40 and 41) of Regulation (EU) 2024/1689, with the standardisation status drawn from the European Commission and ISO/IEC 42006:2025 from ISO. Applicability dates follow Article 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 — the Digital Omnibus on AI (procedure 2025/0359(COD)), published in the Official Journal on 24 July 2026 and in force from 27 July 2026.
What does "conformity assessment" mean under the AI Act?
Article 3(20) of Regulation (EU) 2024/1689 defines conformity assessment as the process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled.
Chapter III, Section 2 (Articles 8 to 15) sets the substantive requirements for a high-risk AI system: a risk-management system, data and data governance, technical documentation, record-keeping, transparency and provision of information to deployers, human oversight, and accuracy, robustness and cybersecurity. Conformity assessment is the procedural act by which the provider — and, for one category, a notified body — establishes that those requirements are met before the system reaches the market. Article 16 lists the corresponding provider obligations in sequence: compliance with the Section 2 requirements (point (a)); a quality management system that complies with Article 17 (point (c)); the conformity assessment procedure of Article 43 (point (f)); the EU declaration of conformity of Article 47 (point (g)); affixing the CE marking under Article 48 (point (h)); and the registration duties of Article 49(1) (point (i)). The definition is confined to high-risk AI systems; systems not classified as high-risk are not subject to a conformity assessment obligation, though some carry a separate registration duty under Article 49(2). Point (k) of Article 16 further requires the provider, upon a reasoned request of a national competent authority, to demonstrate the conformity of the system with the Section 2 requirements.
Which conformity-assessment procedure applies to each category of high-risk AI system?
Article 43 routes high-risk systems to one of two procedures — internal control under Annex VI or an assessment involving a notified body under Annex VII — according to the category of system and, for biometrics, whether harmonised standards or common specifications were applied.
For high-risk AI systems listed in point 1 of Annex III (biometrics), Article 43(1) lets the provider choose between the Annex VI internal-control procedure and the Annex VII procedure with notified-body involvement where the provider has applied harmonised standards under Article 40 or common specifications under Article 41. Where such standards do not exist or are not available, where the provider has not applied them or applied only part of a standard, or where a standard was published with a restriction, Article 43(1) requires the Annex VII procedure. For high-risk systems in points 2 to 8 of Annex III — critical infrastructure, education, employment, essential services, law enforcement, migration and asylum, and administration of justice and democratic processes — Article 43(2) requires the internal-control procedure of Annex VI, which does not provide for notified-body involvement. For high-risk systems covered by the Union harmonisation legislation in Section A of Annex I, Article 43(3) requires the sectoral conformity assessment of that legislation, into which the Section 2 requirements are integrated. Where a biometric system is intended for use by law enforcement, immigration or asylum authorities or by Union bodies, Article 43(1) provides that the relevant market surveillance authority acts as the notified body.
How do the two conformity-assessment procedures — Annex VI and Annex VII — differ?
Annex VI is an internal-control procedure the provider performs itself; Annex VII adds a notified body that assesses the quality management system and the technical documentation and issues a certificate.
| Feature | Annex VI — internal control | Annex VII — QMS and technical-documentation assessment |
|---|---|---|
| Notified body | Not involved | Involved; provider may choose any notified body (Art. 43(1)) |
| Procedural basis | Points 2, 3 and 4 of Annex VI | Points 2 to 5 of Annex VII |
| Quality management system | Provider verifies its own QMS against Art. 17 (point 2) | Notified body assesses and approves the QMS against Art. 17 (point 3) |
| Technical documentation | Provider examines the Annex IV documentation for compliance with Section 2 (point 3) | Notified body examines the Annex IV documentation (point 4) |
| Access to data and models | Not applicable | Notified body may access training, validation and testing data (point 4.3) and, on reasoned request, models and parameters (point 4.5) |
| Certificate | None issued | Union technical documentation assessment certificate issued on conformity (point 4.6) |
| Applies to | Annex III points 2–8 (Art. 43(2)); biometrics where standards or common specifications applied and this option is chosen (Art. 43(1)) | Biometrics (Annex III point 1) where required by Art. 43(1) |
What is the quality management system a provider must maintain?
Article 17 requires providers of high-risk AI systems to put in place a documented quality management system ensuring compliance with the Regulation, covering at least the aspects it enumerates in points (a) to (m).
Article 17(1) requires the quality management system to be documented in a systematic and orderly manner in written policies, procedures and instructions, and to include at least: a strategy for regulatory compliance, covering conformity assessment and modification-management procedures (point (a)); design, design-control and design-verification techniques (point (b)); development and quality-assurance techniques (point (c)); examination, test and validation procedures (point (d)); technical specifications and standards applied (point (e)); data-management systems and procedures (point (f)); the risk-management system of Article 9 (point (g)); the post-market monitoring system of Article 72 (point (h)); serious-incident reporting under Article 73 (point (i)); handling of communications with authorities and others (point (j)); record-keeping (point (k)); resource management (point (l)); and an accountability framework (point (m)). Under Annex VI the provider verifies its own quality management system against Article 17; under Annex VII a notified body assesses and approves it. Separately from the Act's regime, ISO/IEC 42006:2025 — "Information technology — Artificial intelligence — Requirements for bodies providing audit and certification of artificial intelligence management systems" (published July 2025, ISO/IEC JTC 1/SC 42, iso.org/standard/42006) — sets requirements for bodies that audit and certify AI management systems established under ISO/IEC 42001; that voluntary certification track is distinct from the notified-body regime of the AI Act.
What are notifying authorities, conformity assessment bodies and notified bodies?
A notifying authority is the national authority that assesses, designates, notifies and monitors conformity assessment bodies (Art. 3(19)); a conformity assessment body performs third-party conformity assessment (Art. 3(21)); once notified under the Act it becomes a notified body (Art. 3(22)).
Article 28 requires each Member State to designate or establish at least one notifying authority responsible for the procedures for the assessment, designation and notification of conformity assessment bodies and their monitoring. A conformity assessment body applies to the notifying authority of its Member State (Article 29), accompanied where available by an accreditation certificate from a national accreditation body attesting that it meets the requirements of Article 31. Article 31 sets the requirements for notified bodies, including independence and competence; Article 30(4) provides that a body may act as a notified body only where no objections are raised by the Commission or other Member States within the periods stated. Under Article 43(1), for biometric systems intended for use by law enforcement, immigration or asylum authorities or by Union bodies, the relevant market surveillance authority acts as the notified body. The institutional framework — Chapter III, Section 4 (Articles 28 to 39) — became applicable on 2 August 2025 under Article 113(b), a year before the general application of the conformity-assessment obligations on providers.
Source: EU AI Act, Arts. 28–31 — Regulation (EU) 2024/1689 ↗
What certificates do notified bodies issue, and how long are they valid?
Under Article 44, certificates issued by notified bodies under Annex VII are valid for the period they indicate, not exceeding five years for AI systems covered by Annex I and four years for those covered by Annex III, and are renewable on re-assessment.
Article 44(1) requires certificates to be drawn up in a language easily understood by the relevant authorities in the notified body's Member State. Article 44(2) caps validity at five years for Annex I systems and four years for Annex III systems; on the provider's request the validity may be extended for further periods of the same maximum length, based on a re-assessment under the applicable procedure, and any supplement remains valid while the certificate it supplements is valid. Under Annex VII, point 4.6, where the system conforms to the Section 2 requirements the notified body issues a Union technical documentation assessment certificate identifying the provider, the conclusions of the examination, any conditions for validity and the data needed to identify the system; where the system does not conform, the notified body refuses the certificate and gives detailed reasons. Article 44(3) requires the notified body, where it finds that a system no longer meets the Section 2 requirements, to suspend, withdraw or restrict the certificate unless the provider takes appropriate corrective action within a deadline set by the body, and provides that an appeal procedure against the notified body's decisions must be available.
How does the presumption of conformity work, and are there harmonised standards yet?
Under Article 40(1) a high-risk AI system conforming to harmonised standards whose references are published in the Official Journal is presumed to conform to the Section 2 requirements they cover; as of 1 July 2026 no such standards had been cited in the Official Journal.
Article 40(1) attaches a presumption of conformity to harmonised standards published in the Official Journal under Regulation (EU) No 1025/2012, to the extent the standard covers the requirement. Article 41 allows the Commission, by implementing act, to establish common specifications where a standardisation request has not been accepted, standards are not delivered on time, they insufficiently address fundamental-rights concerns, or they do not comply with the request, and no reference is published or expected within a reasonable period; Article 41(3) attaches the same presumption to conformity with those common specifications. According to the European Commission's AI Act standardisation page (digital-strategy.ec.europa.eu/en/policies/ai-act-standardisation), no harmonised standard for the AI Act has yet been published in the Official Journal; the first candidate, EN 18286 (a quality management system for AI Act regulatory purposes, developed by CEN-CENELEC JTC 21), entered public enquiry on 30 October 2025 and was approved by CEN and CENELEC in June 2026, which state that the Commission is expected to publish the reference in the Official Journal later in 2026. Approval by the standardisation bodies and citation in the Official Journal are separate events by separate authorities, and only the second engages Article 40(1). Article 42 adds two further presumptions: for data governance where a system is trained and tested on data reflecting its intended geographical, behavioural, contextual or functional setting (Article 42(1)), and for the cybersecurity requirement of Article 15 where the system is certified under a scheme pursuant to Regulation (EU) 2019/881 (Article 42(2)). Because no harmonised standards are yet cited, the Article 40 presumption currently rests on no cited standards.
Source: EU AI Act, Arts. 40–41 — Regulation (EU) 2024/1689 ↗
What is the EU declaration of conformity and what must it contain?
Article 47 requires the provider to draw up a written, machine-readable EU declaration of conformity for each high-risk AI system, stating that it meets the Section 2 requirements and containing the information listed in Annex V.
Under Article 47(1) the declaration is drawn up in machine-readable, physical or electronically signed form, kept at the disposal of national competent authorities for ten years after the system is placed on the market or put into service, and provided on request. Annex V lists the required contents: the AI system's name, type and any reference allowing its identification and traceability; the name and address of the provider or its authorised representative; a statement that the declaration is issued under the sole responsibility of the provider; a statement that the system is in conformity with the Regulation and any other relevant Union law; where personal data is processed, a statement of compliance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680; references to any harmonised standards or other common specification applied; where applicable, the name and identification number of the notified body, a description of the conformity assessment performed and identification of the certificate issued; and the place and date of issue with the signatory's name, function and signature. Under Article 47(3), where the system is subject to other Union harmonisation legislation also requiring a declaration, a single declaration is drawn up covering all applicable Union law. By drawing up the declaration, the provider assumes responsibility for compliance with the Section 2 requirements (Article 47(4)).
Source: EU AI Act, Art. 47 and Annex V — Regulation (EU) 2024/1689 ↗
How is the CE marking affixed to a high-risk AI system?
Article 48 requires the CE marking — governed by the general principles of Article 30 of Regulation (EC) No 765/2008 — to be affixed visibly, legibly and indelibly, with a digital CE marking used for systems provided digitally.
Article 48(1) subjects the CE marking to the general principles of Article 30 of Regulation (EC) No 765/2008. Article 48(2) requires, for high-risk AI systems provided digitally, a digital CE marking, used only if it can be accessed easily via the interface from which the system is accessed or via an easily accessible machine-readable code or other electronic means. Article 48(3) requires the marking to be affixed visibly, legibly and indelibly, or — where that is not possible or not warranted by the nature of the system — to the packaging or the accompanying documentation. Under Article 48(4), where a notified body was involved, the CE marking is followed by that body's identification number, affixed by the body or, under its instructions, by the provider or the provider's authorised representative; the identification number is also indicated in any promotional material stating that the system meets the requirements for CE marking. Article 48(5) provides that where the system is subject to other Union law also providing for the CE marking, the marking indicates conformity with that other law as well. Under Article 3(24), the CE marking is the marking by which a provider indicates that an AI system is in conformity with the Section 2 requirements and other applicable Union harmonisation legislation providing for its affixing.
What registration is required before a high-risk AI system is placed on the market?
Article 49 requires the provider or authorised representative to register itself and the system in the EU database referred to in Article 71 before placing a high-risk system listed in Annex III on the market or putting it into service, with an exception for the critical-infrastructure systems in point 2 of Annex III.
Under Article 49(1), before placing on the market or putting into service a high-risk AI system listed in Annex III — except systems in point 2 (critical infrastructure) — the provider or, where applicable, the authorised representative registers itself and the system in the EU database. Article 49(2) extends registration to systems a provider has concluded are not high-risk under Article 6(3). Article 49(3) requires deployers that are public authorities or Union bodies to register themselves, select the system and register its use. Article 49(4) places registration for certain law-enforcement, migration, asylum and border-control systems (Annex III points 1, 6 and 7) in a secure, non-public section of the database, accessible only to the Commission and the authorities referred to in Article 74(8); systems in point 2 of Annex III are registered at national level (Article 49(5)). Article 71 requires the Commission, in collaboration with the Member States, to set up and maintain the EU database; under Article 71(4) the information registered under Article 49 is, with stated exceptions, accessible and publicly available in a user-friendly, machine-readable manner, and under Article 71(6) the Commission is the controller of the database.
Source: EU AI Act, Arts. 49 and 71 — Regulation (EU) 2024/1689 ↗
When must conformity be reassessed after a system is on the market?
Article 43(4) requires a high-risk AI system that has already undergone conformity assessment to undergo a new conformity assessment where it is substantially modified, regardless of whether the modified system is further distributed or kept in use by the current deployer.
Article 3(23) defines a substantial modification as a change to an AI system after its placing on the market or putting into service that is not foreseen or planned in the initial conformity assessment and that affects the system's compliance with the Section 2 requirements or results in a modification to the intended purpose for which it was assessed. Article 43(4) makes such a modification a trigger for a fresh conformity assessment. For systems that continue to learn after being placed on the market, changes pre-determined by the provider at the initial assessment and documented in the technical documentation referred to in point 2(f) of Annex IV do not constitute a substantial modification. Under Annex VII, point 4.7, where the Annex VII procedure applied, the provider informs the notified body that issued the Union technical documentation assessment certificate of any intended change affecting compliance or intended purpose, and the notified body decides whether a new conformity assessment under Article 43(4) is required or whether the change can be addressed by a supplement to the certificate. The substantial-modification concept and the duties that follow it are addressed at Stage 13 of this series.
From when do the conformity-assessment obligations apply?
Under Article 113 of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, the conformity-assessment, declaration, CE-marking and registration obligations (Articles 43 and 47 to 49) apply from 2 August 2026, while the notifying-authority and notified-body framework in Chapter III, Section 4 has applied since 2 August 2025.
The second paragraph of Article 113 sets 2 August 2026 as the general date of application. Chapters I and II have applied since 2 February 2025, save for the points inserted into Article 5(1) and the new Article 5(1a) and (1b), which apply from 2 December 2026; Chapter III, Section 4 (Articles 28 to 39, on notifying authorities and notified bodies), together with Chapter V, Chapter VII, Chapter XII other than Article 101, and Article 78, has applied since 2 August 2025. Chapter III, Sections 1, 2 and 3 (Articles 6 to 27), other than Article 6(5), apply from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III and from 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I. Chapter III, Section 5 is not among the deferred provisions: the conformity-assessment procedures of Article 43, the EU declaration of conformity of Article 47, the CE marking of Article 48 and the registration duties of Article 49 apply from 2 August 2026, as do the Commission guidelines under Article 6(5). Those deferred dates come from the amending act, the Digital Omnibus on AI (procedure 2025/0359(COD)), adopted as Regulation (EU) 2026/1744, published in the Official Journal of the European Union on 24 July 2026 (OJ L 2026/1744) and in force since 27 July 2026. Its Article 1(40) amends points (a) and (c) of the third paragraph of Article 113 and adds a new point (d); it leaves the second paragraph, and with it the 2 August 2026 general date, unchanged. Article 111(2) sets 2 August 2030 for high-risk systems intended for use by public authorities that were placed on the market or put into service before 2 August 2026.
Source: EU AI Act, Art. 113 — Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 ↗
Terms defined at this stage
- notifying authority
- The national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring (Article 3(19)). Article 28 requires each Member State to designate or establish at least one. ↗
- conformity assessment body
- A body that performs third-party conformity assessment activities, including testing, certification and inspection (Article 3(21)). Once notified in accordance with the Regulation and other relevant Union harmonisation legislation, it becomes a notified body (Article 3(22)). ↗
- common specification
- A set of technical specifications, as defined in Article 2, point (4) of Regulation (EU) No 1025/2012, providing means to comply with certain requirements of the Regulation (Article 3(28)). The Commission may adopt common specifications by implementing act under Article 41 where harmonised standards are absent or inadequate, and conformity with them confers a presumption of conformity (Article 41(3)). ↗
- presumption of conformity
- The effect under Article 40(1) by which a high-risk AI system that conforms to a harmonised standard whose reference is published in the Official Journal of the European Union is presumed to conform to the Chapter III, Section 2 requirements the standard covers; Article 41(3) attaches the same effect to conformity with common specifications. ↗
- quality management system
- The documented system of written policies, procedures and instructions that providers of high-risk AI systems must put in place to ensure compliance with the Regulation, covering at least the thirteen aspects listed in Article 17(1), points (a) to (m), including a regulatory-compliance strategy, data management, the risk-management system, post-market monitoring and an accountability framework. ↗
- internal control (Annex VI procedure)
- The conformity assessment procedure of Annex VI, carried out by the provider without notified-body involvement, comprising verification that the quality management system complies with Article 17, examination of the technical documentation against the Chapter III, Section 2 requirements, and verification that the design, development and post-market monitoring are consistent with that documentation. It is the required procedure for high-risk systems in points 2 to 8 of Annex III (Article 43(2)). ↗
- Union technical documentation assessment certificate
- The certificate a notified body issues under Annex VII, point 4.6, where a high-risk AI system conforms to the Chapter III, Section 2 requirements; it identifies the provider, the conclusions of the examination, any conditions for validity and the data needed to identify the system. Its validity is capped by Article 44(2) at four years for Annex III systems and five years for Annex I systems. ↗
Cite this page
1BusinessWorld AI Center, "Conformity Assessment & CE Marking — The AI Lifecycle." https://1businessworld.com/ai-center/conformity-assessment-and-ce-marking/ Version as of July 26, 2026.
The AI Center is informational only. It is provided by 1BusinessWorld strictly for general informational and educational purposes. Nothing in the AI Center constitutes, or should be construed as, legal, regulatory, compliance, technical, engineering, security, investment, financial, or other professional advice, or a recommendation, endorsement, solicitation, or offer regarding any technology, product, model, provider, framework, or course of action. 1BusinessWorld is not a law firm, regulatory authority, standards body, conformity-assessment or certification body, or investment adviser, and nothing in the AI Center creates any advisory, fiduciary, attorney-client, or other professional relationship with 1BusinessWorld. Although the AI Center references official materials published by legislatures, regulators, standards bodies, research organizations, and other named authorities, 1BusinessWorld makes no representation or warranty, express or implied, as to the accuracy, completeness, timeliness, or fitness for any purpose of any content, and, to the fullest extent permitted by law, disclaims all liability for any loss or damage of any kind arising directly or indirectly from the use of, or reliance on, any information presented. Laws, regulations, standards, technical practices, and AI capabilities change frequently and differ by jurisdiction; readers must verify all information against the current official text or source and consult qualified legal, compliance, technical, and other professional advisors before acting. Any decision relating to the development, deployment, procurement, or governance of AI systems is made solely at the reader's own risk. Last reviewed: July 26, 2026.
