Skip to content

Conformity assessment

Conformity assessment is the procedure by which a high-risk AI system is checked against the EU AI Act's requirements before it is placed on the market, either by the provider itself under internal control or by a notified body, depending on the system. It ends in a declaration of conformity and CE marking, and it is what compliance actually means.

Compliance is a finding that follows an assessment, not a statement a supplier makes about itself.

Why it matters when the plan changes

The word compliant is used loosely long before any assessment has happened. Conformity assessment is the point at which the loose usage meets a defined procedure, a documented result and a legal declaration a provider is accountable for. A system only enters this procedure once it meets the Article 6 conditions that make it high risk; until then, a provider has requirements it is working toward, which is a different and honest statement.

The tension is that for most Annex III systems the route is self-assessment under internal control. That is faster and cheaper than a notified body and it places the judgement with the party most interested in the answer. The obligations themselves start applying only from the date in the Act's implementation timeline, giving providers a defined period to build the documentation and oversight the assessment will check. A provider that documents its self-assessment thoroughly and invites scrutiny of it is doing what the procedure asks; one that treats it as a formality is not.

In practice

A tender asks whether the supplier's system has undergone conformity assessment. One supplier answers yes, meaning its legal team has read the Act. Another answers that the obligations apply from a stated date, that documentation and oversight are being built against them, and that a declaration will be made only when the assessment is complete. The second answer is the one that survives the follow-up.

Evidence

What it cannot tell you

Conformity assessment confirms that a system met the Act's requirements at a point in time, under the classification and route applicable then. It says nothing about performance in use, does not certify accuracy or fairness in outcome, and does not survive a substantial modification without reassessment. A declaration is a legal status, not a guarantee of ongoing behaviour.

Questions

For most Annex III systems, classified as high risk under Article 6 of the European Union Artificial Intelligence Act, the provider assesses its own system through internal control against the requirements. Certain systems, including some biometric ones, require a notified body instead. The applicable route depends on classification and the harmonised standards used.

That the system meets the applicable requirements, in an EU declaration of conformity the provider signs and is legally accountable for, followed by CE marking and registration in the EU database. Annex III obligations begin applying from 2 December 2027, and a declaration made before assessment is complete has no legal standing.

Once before market placement, and again whenever the system is substantially modified. A provider that retrains a model, changes its intended purpose or alters how outputs are produced may need to reassess. Ongoing monitoring after placement is a separate and continuing duty.

It is the starting point, and the deployer still carries its own duties on use, oversight and informing affected people. A deployer should ask to see the declaration and the documentation behind it, and should notice when a supplier cannot produce either.

What has been built, what it is being built against, which obligations would apply, and that a declaration will follow assessment. That answer is accurate and it survives scrutiny. A yes that means something weaker is the answer that later becomes a problem for both parties.