Docply Browse kits
AI Act

AI Act Conformity Assessment: Which Route Applies to You

By Alessandro Stella · · 15 min read

AI Act conformity assessment: three routes under Article 43, decided by system category, not by choice

“Conformity assessment” gets talked about as if it’s one process with a fixed shape — write the technical documentation, get it checked, get a certificate. Article 43 of the EU AI Act actually sets out three distinct routes, and which one applies to your system is decided by category, almost never by preference. Most guidance also still reports the pre-Omnibus deadlines, which passed their usefulness on 27 July 2026.

This article covers the three routes, what a notified body actually examines when one is involved, what changed when the Digital Omnibus amended Article 43 itself — not just the dates around it — and what happens after a positive assessment.

The three routes, decided by category

Your system isRouteWho decides conformity
Annex III, point 1 (biometric identification/categorisation)Conditional — see belowYou, or a notified body, depending on standards used
Annex III, points 2–8 (employment, education, credit, law enforcement, migration, justice, critical infrastructure, and the rest)Internal control, Annex VIYou, self-assessed
Annex I (safety component of a product already regulated — medical devices, machinery, aviation, and similar)The sectoral procedure that already applies to the productUsually a notified body already in that sector, now also checking AI Act requirements

Nobody picks a route because it’s cheaper or faster. The category your system falls into under Article 6 — covered in what applies to you under the AI Act — determines the route before conformity assessment planning starts.

Annex III, points 2 to 8: internal control, no notified body

This is the default for most standalone high-risk AI systems — recruitment tools, credit scoring, exam proctoring, most law enforcement and migration applications outside biometrics. Article 43(2) is unambiguous: providers follow the internal control procedure in Annex VI, “which does not provide for the involvement of a notified body.”

Internal control doesn’t mean informal. The provider must have a quality management system compliant with Article 17, draw up the technical documentation required by Article 11 and Annex IV, verify that both the system and the documentation meet the Chapter III Section 2 requirements, and then draw up the EU declaration of conformity and affix the CE marking on that basis — all without a third party reviewing any of it before the system goes to market. The check is real; it’s just performed and signed by the provider, not verified externally before launch. Market surveillance authorities can still examine it afterward, which is where a self-assessment that cut corners gets found.

Annex III, point 1: the conditional route

Biometric identification and categorisation systems get a genuinely different structure, and it hinges on one fact: did you apply the relevant harmonised standards (Article 40) or common specifications (Article 41) in full?

If you applied them in full, Article 43(1) gives you a choice: internal control (Annex VI) or the notified body route (Annex VII). Your call.

If you didn’t — no harmonised standard exists yet and no common specification is available, you applied only part of a standard, a common specification existed but you didn’t use it, or a standard was published with a restriction covering the part you’re relying on — the choice disappears. Article 43(1) requires Annex VII, notified body involvement, full stop.

Given how much of the AI Act’s harmonised standards landscape is still being finalised as of 2026, a biometric system provider today is more likely to be in the second situation than the first, even without intending to be.

Which conformity assessment route applies: Annex III point 1 conditional logic based on harmonised standards

What a notified body actually checks under Annex VII

Two separate assessments, not one: the provider’s quality management system, and the specific system’s technical documentation.

The technical documentation assessment is the more concrete of the two, and Annex VII sets out what it involves in some detail. The provider applies with the name and address of the business, a written declaration that the same application hasn’t been lodged with any other notified body, and the technical documentation itself. The notified body examines it — and where relevant, is granted access to the training, validation and testing datasets used, including via API where appropriate. If the notified body isn’t satisfied with the provider’s own testing, it can require further evidence, further tests, or run tests itself. In an extreme case, after other reasonable means of verification have been exhausted, the notified body can request access to the trained model and its parameters, subject to intellectual property and trade secret protections.

That last provision is the one most providers don’t expect: a notified body’s access isn’t capped at documents. It can, in specific circumstances, extend to the model itself.

The quality management system assessment is the other half, and it works the way QMS assessments do under other EU product law — the notified body reviews the provider’s documented processes for design, development, testing, deployment and post-market monitoring, not just the technical file for one system. Passing it once doesn’t mean skipping it for the next system: a provider with an approved QMS still submits each individual high-risk system’s technical documentation for its own assessment, covered by that already-approved QMS rather than starting governance review from zero each time.

Certificates have a shelf life. Under Annex VII, a Union technical documentation assessment certificate cannot exceed five years’ validity. Notified bodies can suspend or withdraw a certificate if the system stops complying, and providers whose certificate is refused, restricted, suspended or withdrawn find out through the same notification chain that keeps notifying authorities and other notified bodies informed — Article 45 requires notified bodies to report exactly these events. A five-year certificate is not a five-year exemption from scrutiny; it’s the outer bound before reassessment is mandatory regardless of what else has or hasn’t changed.

Annex VII notified body assessment: technical documentation review plus quality management system assessment, certificate capped at five years

Annex I: when your AI is a safety component

If your AI system is a safety component of a product already covered by EU harmonisation legislation — the Medical Devices Regulation, the Machinery Regulation, civil aviation rules, and similar — Article 43(3) doesn’t create a parallel AI Act assessment. It routes you through the conformity assessment procedure that product already has to go through, with the AI Act’s Chapter III Section 2 requirements folded in as part of that same assessment.

The Digital Omnibus amended this paragraph directly, not just the deadline around it. The current text adds an explicit requirement that assessment of the quality management system under Article 17 must also be undertaken as part of that sectoral assessment, alongside specific points of Annex VII (points 3, 4.3, 4.4, 4.5, the fifth paragraph of 4.6). Practically: a medical device manufacturer whose notified body was already assessing the device under the Medical Devices Regulation now has an explicit obligation to also assess the AI-specific QMS requirements within that same review, rather than treating the AI Act’s requirements as a documentation add-on checked separately.

Where the sectoral legislation lets the manufacturer opt out of third-party assessment entirely (some frameworks allow this for lower-risk product categories, provided harmonised standards were applied), that opt-out is only available if the manufacturer has also applied the harmonised standards or common specifications covering the AI Act’s own requirements — the sectoral opt-out doesn’t automatically carry the AI-specific obligations with it.

Annex I conformity assessment: routed through existing sectoral legislation with Article 17 QMS assessment added by the Digital Omnibus

The Digital Omnibus moved the finish line, not the routes

Regulation (EU) 2026/1744 entered into force on 27 July 2026 and deferred the application dates for high-risk obligations — the routes above are unchanged, but the date from which they bite moved.

CategoryDeferred to
Annex III standalone high-risk systems2 December 2027
Annex I embedded high-risk systems2 August 2028

What actually moved and what didn’t covers the full picture — critically, Article 50 transparency obligations were not deferred and have applied since 2 August 2026, a date already behind us. Conformity assessment readiness and transparency-obligation readiness are two different clocks; conflating them is the most common planning error the deferral has produced.

The deferral doesn’t mean the classification stops applying. A system that’s high-risk under Annex III is high-risk today — what moved is when Chapter III’s substantive obligations, including the conformity assessment requirement itself, become enforceable against it.

After a positive assessment: three more steps

Passing conformity assessment isn’t the finish line, it’s the gate to three further obligations.

EU declaration of conformity (Article 47). The provider draws this up stating the system meets the Chapter III Section 2 requirements, keeps it for the period set by the Regulation, and provides a copy to authorities on request.

CE marking (Article 48). Affixed visibly, legibly and indelibly, following the general principles governing CE marking under EU product law. Where a notified body was involved, its identification number accompanies the marking.

Registration (Articles 49 and 71). Before placing the system on the market, providers of Annex III high-risk systems register in the EU database — the Council and Parliament specifically rejected a Commission proposal to drop this requirement during the Omnibus negotiations, so the registration duty survived intact, with the information required around it streamlined instead.

Skipping straight from “assessment passed” to “shipped” without these three is a documentation gap a market surveillance authority finds immediately, because they’re checking for exactly these artefacts, not re-running your assessment.

Substantial modification resets the clock

Article 43(4) is direct: a high-risk AI system that’s already been through conformity assessment needs a new assessment if it undergoes a substantial modification — regardless of whether the modified version is redistributed or just continues in use by the deployer who already has it.

One exception, relevant to systems that keep learning post-deployment: changes that were pre-determined by the provider at the time of the original assessment, and documented in the technical documentation under Annex IV point 2(f), don’t count as substantial modifications. The boundary is whether the change was anticipated and documented in advance, not whether the model’s behaviour changed at all.

For deployers, this is also where role can shift: modifying a system substantially enough can move an organisation from deployer to provider for that system, with the full provider obligation set — including conformity assessment — attaching as a result.

A worked example: three systems, three routes

Concrete beats abstract here, so three systems through the decision.

A CV-screening tool for a mid-size employer. Annex III point 4 (employment) — one of points 2 to 8. Route: internal control, Annex VI, no notified body, regardless of what standards exist or how the provider built it. The provider’s own QMS, technical documentation and self-declared conformity carry the whole weight, checked afterward only if a market surveillance authority looks.

A remote facial-recognition access-control system for a stadium operator. Annex III point 1 (biometric identification). Route: conditional. If the provider fully applied the relevant harmonised standards, it chooses between Annex VI and Annex VII. If — as is common in 2026, with several relevant standards still in development — the standards landscape isn’t fully settled and full application isn’t achievable, Annex VII is mandatory: notified body, technical documentation assessment, potentially QMS assessment, a certificate with a five-year cap.

An AI-assisted diagnostic feature inside a certified medical device. Annex I, via the Medical Devices Regulation. Route: whatever conformity assessment procedure the device already follows under the MDR, now also covering the Chapter III Section 2 AI Act requirements and, since the Omnibus, an explicit Article 17 QMS assessment within that same review. No separate AI Act certificate; one assessment, wider scope.

Same regulation, three genuinely different processes, decided entirely by what each system is and does — not by which route the provider would prefer.

Three example AI systems mapped to their conformity assessment routes: internal control, conditional notified body, and sectoral integration

Common mistakes

Assuming ISO 42001 certification discharges this. It doesn’t. ISO 42001 builds most of the operational machinery — risk process, impact assessment, technical documentation habits — but conformity is assessed against the AI Act itself, not against a voluntary standard, however well the two align in practice.

Treating the Annex III point 1 conditional logic as a genuine free choice. It’s conditional on harmonised standards being available and fully applied. Assuming you have the choice, then discovering mid-process that the relevant standard doesn’t exist yet, is a planning failure that shows up late and expensively.

For Annex I systems, treating the AI Act requirements as a bolt-on documentation exercise. Since the Omnibus, the Article 17 QMS assessment is explicitly part of the same sectoral review — a notified body already auditing your medical device QMS is now also checking the AI-specific piece within that visit, not receiving a separate binder afterward.

Forgetting registration because “the assessment is what matters.” Registration is a distinct, mandatory step that survived the Omnibus’s simplification push specifically because the co-legislators pushed back on removing it. Build it into the release plan, not as an afterthought once the system already ships.

Not distinguishing which deadline applies. Annex III and Annex I now have different application dates sixteen months apart. A single “AI Act compliance date” on a project plan is already wrong for one of the two categories.

FAQ

Do I get to choose between internal control and a notified body? Almost never. For Annex III points 2–8, internal control is mandatory. For Annex III point 1 (biometric systems), you have a genuine choice only if you’ve fully applied the relevant harmonised standards or common specifications — otherwise notified body assessment is mandatory. For Annex I systems, the sectoral legislation’s own procedure decides.

Does the Digital Omnibus change which route applies to my system? No. It deferred the application dates and added the explicit Article 17 QMS assessment requirement for Annex I systems, but it didn’t change which of the three routes a given system category follows.

What happens if we can’t find a notified body accredited for our system type? This is a real capacity constraint as of 2026 — the pool of bodies accredited for AI Act assessments, particularly for Annex III point 1 biometric systems, is still small relative to demand. Engaging early, rather than at the point you need the certificate, is the practical mitigation; there’s no regulatory workaround for capacity shortage.

Can a notified body really access our trained model? In narrow circumstances, yes — Annex VII permits it after other reasonable verification means have been exhausted and on a reasoned request, subject to intellectual property and trade secret protections. It’s not a routine step of every assessment, but it is a real possibility, not a theoretical one.

Do we need to redo conformity assessment for every model update? Only for substantial modifications. Changes pre-determined at the time of the original assessment and documented in the technical documentation aren’t substantial modifications, which is specifically meant to accommodate systems that continue learning post-deployment without triggering reassessment on every update.

Is the 2 December 2027 / 2 August 2028 split final, or could it move again? It’s enacted law as of 27 July 2026, not a proposal — but the Digital Omnibus itself demonstrates the EU is willing to amend the Act’s timeline when implementation infrastructure lags. Treat the dates as the current binding reference, and watch for further amendments the way you’d watch any other area of live legislation.

How long is a conformity assessment certificate valid? Up to five years under Annex VII, whichever comes first between that cap and any earlier suspension or withdrawal if the notified body finds the system no longer compliant. Internal-control self-assessments under Annex VI don’t issue a certificate in the same sense, but the underlying conformity has to be maintained continuously, not just at the point of the original assessment.

Who pays for a notified body assessment, and roughly what does it cost? The provider does, directly to the notified body it selects — there’s no EU-subsidised route. Costs vary by notified body, system complexity and how much testing the body ends up requiring beyond the provider’s own; unlike ISO certification audit fees, there’s no equivalent published day-rate table yet, since the market is still young and capacity-constrained as of 2026.


Sources

Regulation (EU) 2024/1689 (the AI Act) and Regulation (EU) 2026/1744 (the Digital Omnibus on AI) are both in force and publicly available via the European Commission’s AI Act Service Desk and EUR-Lex; this article describes their requirements without reproducing their text. Article 43’s amended text and the deferred application dates are taken directly from the enacted Digital Omnibus regulation, not from summaries.


Where to go from here

The AI Act Compliance Suite contains the technical documentation, risk management file and post-market monitoring plan structured by role — provider, deployer, GPAI model provider — so the conformity assessment route you land on has the underlying documents already organised rather than assembled from scratch. €590 excl. VAT.

For the classification question that decides which route applies before any of this starts, AI Act compliance: what applies to you covers the four risk tiers and the roles. For the corrected 2026 timeline in full, what actually moved after the Digital Omnibus is the piece to read next.