AI is moving fast. See how Whisperly helps you get control back and reduce risk.See how →
    AI Governance 21 min read

    EU AI Act Conformity Assessment: What Providers Must Do Before August 2026

    EU AI Act conformity assessment: which systems need a notified body, what Annex VI and VII require, and the steps providers must complete before August 2026.

    Jelena Djukanovic
    Jelena Djukanovic| Attorney at Law, Whisperly
    Published: · Last reviewed: · Reviewed by: Tamara Zavisic, AI Governance Consultant
    EU AI Act conformity assessment: which systems need a notified body, what Annex VI and VII require, and steps providers must complete before August 2026.

    Most organisations working to comply with the EU AI Act are focused on classification: determining whether their systems qualify as high-risk under the Act's classification rules. That question matters. But it is the second question that trips people up in practice. Almost every time.

    Once you have established that a system is high-risk, what exactly must you do before it can be placed on the market or put into service?

    The answer is a conformity assessment, and the EU AI Act is more specific about what that involves than most compliance programmes have internalised.

    Fines of up to 35 million EUR or 7% of global annual turnover

    EU AI Act, Article 99, applicable from 2 August 2025 for prohibited practice infringements, with the full enforcement framework for high-risk systems operative from 2 August 2026

    The full compliance framework for high-risk AI systems applies from 2 August 2026. For AI embedded in regulated products under Annex I (medical devices, machinery, vehicles), the deadline extends to 2 August 2027. Note that the Digital Omnibus proposes changes to both dates; see our EU AI Act timeline for the latest schedule. By either date, providers must have completed the conformity assessment, issued the EU declaration of conformity, affixed the CE marking, and registered the system in the EU database. None of those steps can happen without the assessment being done first.

    This article explains the EU AI Act conformity assessment procedure in procedural terms: which route applies to which system, what each route requires, and what follows a successful assessment. For a broader overview of the regulation, see our EU AI Act summary. For the full compliance guide, see our EU AI Act compliance guide. For guidance on governance obligations, see our EU AI Act guidebook.

    What Is a Conformity Assessment Under the EU AI Act?

    TL;DRA conformity assessment is the mandatory verification process that providers of high-risk AI systems must complete before placing a system on the EU market. It confirms compliance with all requirements in Chapter 2 of the EU AI Act, covering risk management, data governance, transparency, human oversight, accuracy, and cybersecurity. No high-risk system may carry CE marking without it.

    TL;DRA conformity assessment under the EU AI Act is the formal procedure a provider must complete before placing a high-risk AI system on the market or putting it into service. It verifies that the system meets the following requirements of the Act: risk management, data governance, technical documentation, logging, transparency, human oversight, and accuracy. It is governed by Article 43 of the EU AI Act and carried out via either internal self-assessment (Annex VI) or third-party assessment by a notified body (Annex VII).

    Before a high-risk AI system can legally enter the EU market, the provider must prove it works as intended and meets the Act's requirements. That proof process is the conformity assessment.

    Those requirements cover eight areas:

    • risk management (Article 9),
    • data and data governance (Article 10),
    • technical documentation (Article 11),
    • record-keeping and logging (Article 12),
    • transparency toward deployers (Article 13),
    • human oversight (Article 14), and
    • accuracy, robustness and cybersecurity (Article 15).

    The conformity assessment is not a one-time audit. It is the foundational accountability mechanism the Act builds everything else on. The EU declaration of conformity, CE marking, and database registration all flow from a completed assessment. Without it, a high-risk system cannot legally be placed on the EU market.

    Conformity assessment is a provider obligation. Deployers do not conduct conformity assessments. Their obligation is to verify that the provider has done so: to check for the CE marking, obtain a copy of the technical documentation upon request, and confirm the system is registered in the EU database. That distinction matters for organisations that deploy third-party AI: their conformity due diligence is a separate process from the conformity assessment itself. For guidance on the deployer side, see our supplier due diligence checklist.

    Which Route Applies to Your System: Internal or Third-Party?

    TL;DRMost high-risk AI systems follow the internal assessment route under Annex VI, where the provider self-certifies through its own quality management system. Third-party assessment by a notified body under Annex VII is required only for biometric identification systems and a narrow set of critical infrastructure applications listed in Annex III, point 1. The substantive compliance requirements are identical under both routes.

    TL;DRThe EU AI Act offers two conformity assessment routes. Most high-risk systems listed in Annex III use internal self-assessment under Annex VI, with no notified body required. Third-party assessment under Annex VII is mandatory for systems involving real-time or post remote biometric identification, and for any provider who cannot fully apply harmonised standards. For high-risk AI embedded in regulated products under Annex I, the relevant sectoral legislation determines the procedure.

    Article 43 creates three distinct tracks depending on the type of high-risk AI system involved. Getting the track wrong is a substantive compliance error, not a procedural one.

    Track 1: Annex III Systems (Most High-Risk AI) - Internal Assessment

    High-risk AI systems listed in points 2 to 8 of Annex III, covering biometric categorisation, critical infrastructure management, education, employment, access to essential services, law enforcement, migration and asylum management, and administration of justice, follow the internal conformity assessment procedure under Annex VI. No notified body is involved. The provider verifies compliance with all Chapter 2 requirements through its own quality management system and technical documentation review.

    The exception within this track is significant: if the provider has not applied, or has only partially applied, harmonised standards covering the relevant requirements, the provider must escalate to the Annex VII third-party route. Harmonised standards under Article 40 are the Act's primary tool for enabling the presumption of conformity. Where they do not yet exist, or where the provider deviates from them, the internal route is not available.

    The harmonised standards gap: a practical problem in 2026

    As of March 2026, harmonised standards specifically designed for the EU AI Act are still in development. CEN-CENELEC JTC 21 is the responsible standards body, but comprehensive standards covering Articles 9 through 15 are not yet finalised. Providers relying on the internal assessment route should document which existing standards (ISO/IEC 27001, relevant sector standards) they are applying and which requirements those standards cover, and which they do not. For guidance on implementing ISO 42001 as a governance framework alongside your AI Act obligations, see our ISO 42001 guidebook. Any gap between an existing standard and an AI Act requirement must be addressed through the provider's own documented procedures.

    This is, in practice, where most organisations will find themselves in 2026: not non-compliant by intent, but under-documented by default.

    Track 2: Annex I Systems - Sectoral Legislation Governs

    For high-risk AI systems that are safety components of products regulated under Section A of Annex I, which includes medical devices under the MDR, in vitro diagnostic devices under the IVDR, machinery under the Machinery Regulation, and vehicles under automotive safety legislation, the provider must follow the conformity assessment procedure set out in that sectoral legislation. The AI Act requirements in Articles 8 to 15 are incorporated into that existing procedure. Notified bodies already designated under the MDR or Machinery Regulation are authorised to assess compliance with the AI Act requirements as part of the same assessment.

    This means a medical device manufacturer whose product incorporates a high-risk AI system does not run a separate AI Act conformity assessment alongside the MDR assessment. The MDR procedure is expanded to include AI Act requirements. In practice, this requires early engagement with the notified body to confirm that their scope of designation covers AI Act obligations.

    Track 3: Mandatory Third-Party Assessment for Biometric Identification Systems

    Remote biometric identification systems, specifically AI systems listed under point 1 of Annex III, require third-party assessment by a notified body regardless of whether harmonised standards are applied. This is the only category in Annex III for which third-party involvement is mandatory as a baseline requirement. The provider selects any accredited notified body, except where the system is intended for use by law enforcement, immigration, or asylum authorities. In that case, the relevant market surveillance authority acts as the notified body. One practical difficulty: as of early 2026, the pool of formally designated notified bodies under the EU AI Act remains very small. Providers planning to follow the Annex VII route should begin identification and engagement well in advance of their compliance deadline.

    System TypeAssessment Route
    Annex III, points 2-8 (employment, education, essential services, etc.)Internal assessment (Annex VI). No notified body.
    Annex III, points 2-8, where harmonised standards are not fully appliedThird-party assessment (Annex VII). Notified body required.
    Annex III, point 1: remote biometric identificationThird-party assessment (Annex VII). Notified body required.
    Annex I products (MDR, Machinery Regulation, etc.)Sectoral legislation procedure, expanded to include AI Act requirements.
    Law enforcement / immigration use, any route requiring notified bodyMarket surveillance authority acts as notified body.
    EU AI Act conformity assessment routes Annex VI vs Annex VII - Whisperlywhisperly.ai/eu-ai-act-conformity-assessmentThree tracks. One determines your route.Getting it wrong is a substantive error.SYSTEM TYPEROUTENOTIFIED BODY?Annex III pts 2-8 (employment, education etc)Annex VI internalNoAnnex III pts 2-8, harmonised standards not fully appliedAnnex VII third-partyRequiredAnnex III pt 1 (biometric ID)Annex VII third-partyRequiredAnnex I products (MDR, machinery etc)Sectoral legislationPer sectorLaw enforcement / immigrationMarket surveillance authorityAuthority acts as bodyDeadline: 2 August 2026 for most high-risk systems

    What the Internal Conformity Assessment (Annex VI) Requires

    TL;DRUnder Annex VI, the provider must operate a documented quality management system covering the full AI lifecycle, compile technical documentation per Annex IV, and verify compliance with every requirement in Articles 8 to 15. The provider then signs an EU declaration of conformity and affixes the CE mark. No external auditor is involved, but the documentation must withstand regulatory scrutiny.

    TL;DRInternal conformity assessment under Annex VI is a self-assessment process. The provider verifies that its quality management system meets Article 17, reviews technical documentation for compliance with all Chapter 2 requirements, and confirms that design, development, and post-market monitoring are consistent with that documentation. No external audit is required, but the documentation must be complete and auditable by market surveillance authorities on request.

    Three steps. They run in sequence, not in parallel. A provider cannot credibly document post-market monitoring plans without first having a compliant QMS and accurate technical documentation to build from.

    1. 1.Verify QMS compliance with Article 17. Article 17 requires a quality management system covering 11 areas: the overall AI governance strategy, policies and procedures for regulatory compliance, human oversight mechanisms, data management, risk management system documentation, technical documentation maintenance, post-market monitoring, incident reporting, corrective action procedures, communication with third parties, and record-keeping. The QMS must be documented, implemented, and capable of being demonstrated to competent authorities on request.
    1. 1.Review technical documentation against Annex IV. Technical documentation must cover the system's intended purpose, the design logic, training data specifications and governance procedures, validation and testing results, risk management measures, human oversight mechanisms, cybersecurity measures, and any substantial modifications planned post-deployment. The documentation standard under Annex IV is extensive. A 15-page technical summary is not sufficient. Providers routinely underestimate the depth required.
    1. 1.Confirm consistency of design, development, and post-market monitoring. The internal assessment concludes with the provider verifying that what the system actually does, and how it will be monitored after deployment, matches what the technical documentation says. This is the step most likely to reveal gaps: systems that have evolved during development but whose documentation has not kept pace. The gap between what a system does and what its documentation says it does is one of the most common substantive compliance problems in regulated technology generally. AI systems are not different in this respect.

    A critical point that Article 43 does not make explicit but that the Annex VI procedure implies: the internal assessment must be documented and retained. The EU declaration of conformity must be kept for 10 years after the system is placed on the market (Article 47). Market surveillance authorities can request demonstration of compliance at any time during that period. An internal assessment that was genuine at the time but is not documented is not an assessment the Act will recognise.

    What the Third-Party Conformity Assessment (Annex VII) Requires

    TL;DRAnnex VII assessment requires a notified body to audit both the quality management system and the technical documentation. The notified body issues a certificate valid for up to five years, subject to periodic surveillance. Providers must notify the body of any material change, and the body can suspend or withdraw the certificate if compliance lapses. This route is mandatory for biometric identification systems.

    The third-party route adds an external layer that the internal route deliberately avoids. Two parallel tracks run simultaneously: the notified body assesses the QMS and the technical documentation independently.

    QMS assessment

    The provider submits an application to a notified body containing: the list of all AI systems covered by the QMS, technical documentation for each, the QMS documentation itself, and a description of procedures for keeping the QMS adequate. The notified body audits the QMS against the Article 17 requirements and, where compliant, issues an approval. Any subsequent changes to the QMS must be reported to the notified body, which decides whether a new assessment is required or whether the change can be confirmed through a supplement.

    Technical documentation assessment

    Separately, the notified body reviews the technical documentation for the specific AI system seeking certification. It examines the documentation against the Chapter 2 requirements and may request additional information or testing. Where the technical documentation demonstrates compliance, the notified body issues an EU Technical Documentation Certificate under Article 44. This certificate is valid for four years and may be renewed for a further four years. If the notified body finds the system no longer meets requirements, it suspends or withdraws the certificate unless the provider takes corrective action within the prescribed period.

    Choosing a notified body

    Providers may select any notified body designated for AI systems. As of early 2026, the number of bodies formally designated under the EU AI Act remains limited. This is a practical constraint that should inform planning timelines: providers expecting to follow the Annex VII route should identify and engage potential notified bodies early, rather than treating notification as a late-stage step. Waiting until the documentation is complete before contacting a notified body has resulted in delays in analogous CE marking processes under the MDR.

    TL;DRThird-party assessment under Annex VII involves a notified body auditing both the quality management system and the technical documentation. The provider submits an application with the full QMS documentation, technical documentation for all AI systems covered, and a description of QMS maintenance procedures. Upon successful assessment, the notified body issues an EU Technical Documentation Certificate, valid for four years and renewable. Any significant changes to the QMS must be notified to the body.

    Substantial Modification: When a New Assessment Is Required

    TL;DRAny change that affects compliance with the Act's requirements or alters the system's intended purpose triggers a fresh conformity assessment. This applies even without redistribution. Continuous learning updates that were pre-approved and documented during the initial assessment are excluded. Deployers who modify a system beyond its original scope become the new provider and inherit all provider obligations.

    Article 43(4) is one of the most practically significant provisions in the conformity assessment framework. It states that a high-risk AI system already assessed must undergo a new conformity assessment whenever a substantial modification occurs. That obligation applies even if the modified system remains with the same deployer and is never redistributed.

    What constitutes a substantial modification is not always obvious. The Act does not provide an exhaustive definition, but the operative question is whether the change affects compliance with the Chapter 2 requirements or changes the system's intended purpose. A change to the training data governance process affecting Article 10 compliance, a modification to the human oversight mechanism required under Article 14, or an expansion of the system's intended use to a new sector: each of these would trigger a new assessment.

    That ambiguity is deliberate, and arguably unavoidable: a fixed list would quickly become obsolete as AI systems evolve. But it creates real uncertainty for providers trying to determine whether a model update triggers a full reassessment or falls within the scope of their existing documentation.

    For data governance obligations that run alongside the AI Act, the EDPB guidelines on AI models and personal data provide the most directly applicable regulatory guidance on how Article 10 requirements interact with the GDPR.

    There is an important carve-out for AI systems that continue to learn after deployment. If the learning behaviour, its scope, and its potential effects on compliance were documented in the original technical documentation and pre-approved as part of the initial assessment, those changes do not constitute a substantial modification. This is a strong argument for providers of continuously learning systems to invest in thorough upfront documentation: the scope of what is covered by the initial assessment.

    SME-specific provision

    The EU AI Act includes a specific provision at Article 43 protecting the interests of small and medium-sized enterprises. Fees charged by notified bodies for third-party conformity assessments must be set proportionate to the SME's size and market share. Providers that qualify as SMEs under EU Recommendation 2003/361/EC should confirm this with their notified body at the point of engagement.

    TL;DRA high-risk AI system that undergoes a substantial modification must complete a new conformity assessment, regardless of whether it was already assessed. A substantial modification is any change that affects compliance with the AI Act requirements, or any change to the system's intended purpose. Continuous learning updates that were documented and pre-approved at the time of the initial assessment do not constitute substantial modifications.

    Practical example

    A provider completes an Annex VI assessment in January 2026 for an AI system used in employment screening. In March, the engineering team updates the model to improve accuracy on a new demographic dataset. The update was not documented in the original technical documentation.

    Because the update changes the data governance arrangements underpinning Article 10 compliance, and because it was not pre-approved in the initial assessment, it constitutes a substantial modification. A new conformity assessment is required before the updated system can continue in service.

    After the Assessment: Declaration of Conformity, CE Marking, and Registration

    TL;DRThree steps follow a successful assessment: the provider signs an EU declaration of conformity under Article 47, affixes the CE mark under Article 48, and registers the system in the EU database under Article 49. The declaration must be kept for ten years and made available to authorities on request. Registration must occur before the system is placed on the market.

    TL;DRA completed conformity assessment triggers three sequential obligations: the provider draws up an EU declaration of conformity under Article 47, affixes CE marking under Article 48, and registers the system in the EU database under Article 49. The declaration must be retained for 10 years. These steps are prerequisites for legal market placement; the assessment alone is not sufficient.

    Completing the assessment is not the finish line. Three further steps are required before the system can legally be placed on the market.

    Step 1: EU Declaration of Conformity (Article 47)

    The provider must draw up a written EU declaration of conformity for each high-risk AI system. The declaration must be machine-readable, and can be physical or electronically signed. It identifies the system, confirms it meets the Chapter 2 requirements, and contains the information specified in Annex V. The declaration must be translated into a language understandable by the national competent authorities of each Member State where the system is placed on the market.

    The provider must keep the declaration available for national competent authorities for 10 years after the system is placed on the market or put into service. Where a high-risk AI system is also subject to other EU harmonisation legislation requiring a declaration of conformity (for example, the MDR), a single declaration covering all applicable legislation may be drawn up.

    Step 2: CE Marking (Article 48)

    CE marking must be affixed to the high-risk AI system before it is placed on the market. Where affixing to the system itself is not possible (as is often the case for software-only systems), the marking may appear on packaging or accompanying documentation. For systems provided digitally, a digital CE marking must be easily accessible from the interface through which the system is accessed.

    Where third-party assessment under Annex VII was conducted, the CE marking must be followed by the identification number of the notified body. That number is affixed either by the notified body directly or, under its instructions, by the provider. The number must also appear in any promotional material claiming CE marking compliance.

    Step 3: Registration in the EU Database (Article 49)

    Before placing a high-risk AI system on the market, providers must register it in the EU database established under Article 71. The information to be submitted is set out in Annex VIII. The EU database is publicly accessible for systems in Annex III (other than law enforcement) and is intended to enable deployers, users, and supervisory authorities to identify and verify systems.

    Providers who have determined that a system listed in Annex III is not high-risk under Article 6(3) must also register that determination in the EU database before placing the system on the market, under the separate registration obligation in Article 49(2). This is the mechanism through which the Commission's market surveillance function can challenge classification decisions.

    The registration obligation is also a transparency mechanism. Providers who self-assess their systems as non-high-risk are not operating in a grey zone after registration: they are making a documented, publicly visible claim that competent authorities can scrutinise.

    Post-Market Monitoring: The Assessment Does Not End at Deployment

    TL;DRConformity assessment is not a one-off exercise. Providers must operate a post-market monitoring system proportionate to the AI technology and the system's risk profile. Serious incidents or malfunctions must be reported to market surveillance authorities. For third-party assessed systems, the notified body conducts periodic surveillance and can withdraw certification if compliance deteriorates.

    TL;DRConformity does not stop at market placement. Article 72 requires providers to operate a post-market monitoring system proportionate to the risk level of the system throughout its lifecycle. The system must collect and analyse data on performance, incidents, and near-misses. Serious incidents must be reported to national market surveillance authorities under Article 73. Post-market monitoring findings that indicate non-compliance trigger corrective action obligations under Article 20.

    The assessment tells you the system was compliant when it launched. It says nothing about what happens six months later. Post-market monitoring is the mechanism that closes that gap, and the Act treats it as a continuous obligation, not an optional review.

    Under Article 72, the post-market monitoring system must be documented in the technical documentation and must include, at minimum: a plan for collecting and analysing data on system performance in real operating conditions, procedures for identifying and reporting serious incidents, and a process for implementing corrective actions. The scope of monitoring must be proportionate to the nature and risk level of the system.

    This is technically straightforward to describe and operationally difficult to implement. Providers of high-risk AI systems need data pipelines from deployment environments back into their compliance function. A system deployed by a third-party organisation under Article 26 obligations creates a dependency: the deployer must cooperate with the provider's post-market monitoring requirements, and the provider must specify what data is needed and through what mechanism in the instructions for use.

    Findings from post-market monitoring that indicate the system no longer meets Chapter 2 requirements are not a compliance failure that can be absorbed quietly. They trigger the corrective action obligations under Article 20, which may include withdrawing the system from the market and notifying competent authorities. Providers must establish, before deployment, what the trigger conditions for corrective action are and who has internal authority to initiate withdrawal.

    How Whisperly Supports EU AI Act Conformity Assessment

    Conformity assessment is not a one-time project. It requires systematic documentation, a functioning quality management system, ongoing monitoring, and a chain of evidence that can withstand scrutiny from national competent authorities for up to 10 years after deployment. For organisations managing multiple AI systems across different risk tiers, building that infrastructure manually is not viable.

    Whisperly's AI governance platform provides a structured environment for documenting conformity assessment procedures, maintaining technical documentation, tracking QMS compliance, and managing post-market monitoring obligations. For organisations deploying third-party AI systems and managing the corresponding vendor due diligence, the vendor assessment capability provides a framework for verifying that providers have completed the required assessments before a system enters your environment.

    If you are working through your EU AI Act conformity assessment obligations, schedule a demo to see how Whisperly maps your AI systems to their applicable assessment requirements and generates the documentation structure you need.

    The enforcement framework is new and national market surveillance authorities are still building capacity. That does not make the obligations advisory. It means the window for getting compliance infrastructure in place, before enforcement activity scales, is narrower than it appears.

    How Whisperly supports EU AI Act conformity assessment - Whisperlywhisperly.aiConformity assessment is not a one-time project.Whisperly keeps the evidence current.WITHOUT WHISPERLYWITH WHISPERLYQMS documented in spreadsheetsStructured QMS built and maintainedTechnical docs assembled per auditAuto-generated, versioned, currentSubstantial modification missedChange triggers reassessment alertPost-market monitoring manualMonitoring pipeline configured10-year declaration storage ad hocAudit-ready evidence retained alwaysThe enforcement window is narrower than it looks.AI-powered. Human-reviewed.

    FAQ: EU AI Act Conformity Assessment

    What is the difference between an internal conformity assessment and a third-party assessment under the EU AI Act?

    Internal conformity assessment under Annex VI is a self-assessment: the provider verifies compliance with all Chapter 2 requirements through its own quality management system and technical documentation, without external audit. Third-party assessment under Annex VII involves a notified body auditing both the QMS and technical documentation and issuing a certificate. Both routes require the same substantive compliance with Articles 8 to 15; the difference is in who verifies it. Internal assessment is available to most Annex III systems where harmonised standards are fully applied. Third-party assessment is mandatory for biometric identification systems and where harmonised standards are not fully applied.

    When must a high-risk AI system undergo a new conformity assessment?

    A new conformity assessment is required whenever the system undergoes a substantial modification: any change that affects compliance with the Act's requirements or alters the system's intended purpose. This applies even if the system remains with the same deployer and is not redistributed. Continuous learning updates that were documented and pre-approved at the time of the initial assessment are explicitly excluded from the substantial modification definition.

    Does a deployer need to conduct a conformity assessment?

    No. Conformity assessment is a provider obligation. Deployers of high-risk AI systems must verify that the provider has completed the assessment: by checking CE marking, requesting technical documentation, and confirming registration in the EU database. They do not conduct the assessment themselves. Deployers do have their own obligations under Article 26, including implementing appropriate human oversight, monitoring for unintended use, and notifying the provider of incidents.

    What happens if a notified body refuses to certify a high-risk AI system?

    Under Article 45, a provider may appeal against a notified body's determination. If the notified body withdraws or suspends a certificate after initial certification, the provider has an opportunity to take corrective action within a timeframe specified by the notified body. If corrective action is not taken, the certificate is withdrawn and the provider must cease placing the system on the market. The Act also provides a derogation under Article 46 for exceptional circumstances involving public security, life and health, environmental protection, or critical infrastructure: in these cases a system may be put into service before the assessment is complete, subject to regulatory approval.

    Which AI systems are exempt from conformity assessment?

    Conformity assessment applies only to high-risk AI systems as classified under Article 6. AI systems that fall outside the high-risk classification have no conformity assessment obligation, though they may be subject to transparency obligations under Article 50. Providers who assess that an Annex III system does not pose a significant risk of harm under Article 6(3) may treat it as non-high-risk, but must document that assessment and register it in the EU database. Open-source AI systems released under qualifying licences are also subject to certain exemptions. General-purpose AI models have separate obligations under Articles 53 to 55, which are distinct from the conformity assessment framework applicable to high-risk systems.

    EU AI Actconformity assessmenthigh-risk AIAnnex VIAnnex VIICE markingcompliance

    Questions & Answers

    What is the difference between an internal conformity assessment and a third-party assessment under the EU AI Act?+

    Internal conformity assessment under Annex VI is a self-assessment: the provider verifies compliance with all Chapter 2 requirements through its own quality management system and technical documentation, without external audit. Third-party assessment under Annex VII involves a notified body auditing both the QMS and technical documentation and issuing a certificate. Both routes require the same substantive compliance with Articles 8 to 15; the difference is in who verifies it.

    When must a high-risk AI system undergo a new conformity assessment?+

    A new conformity assessment is required whenever the system undergoes a substantial modification: any change that affects compliance with the Act's requirements or alters the system's intended purpose. This applies even if the system remains with the same deployer and is not redistributed. Continuous learning updates that were documented and pre-approved at the time of the initial assessment are explicitly excluded. See our full guide on high-risk AI systems for more detail.

    Does a deployer need to conduct a conformity assessment?+

    No. Conformity assessment is a provider obligation. Deployers of high-risk AI systems must verify that the provider has completed the assessment: by checking CE marking, requesting technical documentation, and confirming registration in the EU database. They do not conduct the assessment themselves.

    What happens if a notified body refuses to certify a high-risk AI system?+

    Under Article 45, a provider may appeal against a notified body's determination. If corrective action is not taken, the certificate is withdrawn and the provider must cease placing the system on the market. The Act also provides a derogation under Article 46 for exceptional circumstances. Read the full EU AI Act summary for broader context.

    Which AI systems are exempt from conformity assessment?+

    Conformity assessment applies only to high-risk AI systems as classified under Article 6. AI systems outside the high-risk classification have no conformity assessment obligation, though they may be subject to transparency obligations under Article 50. Open-source AI systems released under qualifying licences are also subject to certain exemptions.

    Jelena Djukanovic

    Written by

    Jelena Djukanovic

    Attorney at Law, Whisperly

    Reviewed by: Tamara Zavisic, AI Governance Consultant

    Share
    Get Started

    Ready to make compliance
    feel effortless?

    Join 100+ companies automating GRC with Whisperly. Get audit-ready in weeks, not months.

    Stay ahead of compliance changes

    Practical compliance tips, delivered to your inbox every two weeks.