← Back to all articles
Insights

EU AI Act Conformity Assessment and CE Marking: A Plain-English Guide for High-Risk AI Providers

Editorial cover for a guide on EU AI Act conformity assessment and CE marking for high-risk AI. Theme: product certification, compliance checkpoint, technical documentation. Motifs like a CE mark, checklist/stamp of approval, EU stars, a workflow/gateway, technical blueprint. Professional, clean, authoritative; minimal text.

Classification was step one. Concluding that your AI system is high-risk under the EU AI Act is a significant milestone - but it is not compliance. It is the starting gun. What follows is a structured gauntlet: a conformity assessment, a technical documentation file, a written declaration, a CE marking, and a public database registration - all of which must be completed before you place the system on the Union market or put it into service. This guide explains each step in plain English.

Not yet sure whether your system is high-risk? Start with our classification guide first, then come back here.


The No-Assessment, No-Market Rule (Article 43)

Article 43 of the EU AI Act prohibits placing a high-risk AI system on the Union market - or putting it into service - without a completed conformity assessment. This is not a soft obligation. There is no grace period for "we were working on it." The assessment must be done, documented, and signed off before the system ships.

The rule applies to providers - the entities that develop the system and place it on the market under their own name or trademark. If you are a deployer using a third-party high-risk system, your obligations are different (and lighter), but you should verify that your provider has completed their assessment before you go live.


Which Route Do You Take? Annex VI vs. Annex VII

Article 43 establishes two conformity assessment routes. The choice is not entirely yours to make - it is determined by your system's category and whether harmonised standards exist and have been applied in full.

Route 1 - Internal Control (Annex VI): Self-Assessment

For high-risk AI systems listed in points 2 to 8 of Annex III - covering biometric categorisation, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and administration of justice - providers must follow the internal conformity assessment procedure under Annex VI, which does not involve a notified body.

Under Annex VI, you verify compliance with all Chapter III, Section 2 requirements through your own quality management system and technical documentation review. No external auditor signs off. The catch: if the provider has not applied, or has only partially applied, harmonised standards covering the relevant requirements, the provider must escalate to the Annex VII third-party route.

Route 2 - Third-Party Assessment (Annex VII): Notified Body Required

Annex III point 1 biometric identification systems must use the third-party route under Annex VII, as must any high-risk system where the provider cannot establish full conformity through harmonised standards or common specifications. Under Annex VII, an accredited notified body reviews your quality management system and/or technical documentation. The third-party EU technical documentation assessment certificate issued under Annex VII is valid for up to five years. The provider must notify the notified body of any substantial modification during that period.

For Annex I systems (AI embedded in regulated products such as medical devices or machinery), the relevant sectoral conformity assessment procedure applies, with notified bodies ensuring AI-specific requirements are also met.

The Harmonised Standards Gap - A Practical Problem Right Now

The internal-control route depends on harmonised standards existing and being applied in full. On 30 October 2025, prEN 18286 - the Quality Management System standard for EU AI Act regulatory purposes - became the first harmonised AI standard to enter public enquiry. CEN-CENELEC harmonised standards are tracking to Q4 2026 delivery after the October 2025 acceleration measures. Until standards are formally published and cited in the Official Journal of the EU, providers cannot rely on them to unlock the presumption of conformity. If no relevant harmonised standard is cited when you need to assess, you either use common specifications (if adopted by the Commission) or escalate to Annex VII.


The Annex IV Technical File: What You Must Document

Both routes require the same underlying evidence bundle: the technical documentation specified in Article 11 and Annex IV. This documentation must be prepared before the system is placed on the market and kept up to date throughout the system's lifecycle. It is not a one-off submission - it is a living file that travels with the system from development through post-market monitoring.

Annex IV organises the required content into approximately ten categories:

# Category What it covers
1 General description Intended purpose, version, hardware/software dependencies, human-oversight model
2 Design & development Design specifications, development methodology, tools used
3 System architecture & compute Architecture diagrams, computational resource requirements
4 Data & data governance Training, validation, and test datasets: provenance, representativeness, bias mitigation
5 Human oversight measures How operators can intervene, override, or shut down the system
6 Lifecycle & resource use Expected operational lifetime, maintenance procedures, resource consumption
7 Risk management system Article 9 risk register: identification, evaluation, mitigation, residual risk acceptance
8 Lifecycle changes Version history, change-control records, post-market modifications
9 Harmonised standards applied List of standards applied and, where not fully applied, the alternative means used
10 EU declaration of conformity Copy of the Article 47 declaration (see below)

The post-market monitoring plan (Article 72) must also be part of the technical documentation. Treat the Annex IV file as your primary audit artefact - it is what a notified body or national market surveillance authority will ask to see first.

warning Warning

Common mistake: treating Annex IV as a one-time deliverable. The file must reflect the current state of the system at all times. If your risk register, training data, or architecture changes, the file must be updated. A static Word document filed at launch and never touched again is a compliance liability, not an asset.


The EU Declaration of Conformity (Article 47)

Once the conformity assessment is complete, the provider must draw up a written EU declaration of conformity. Under Article 47, the provider must draw up the EU declaration of conformity and keep it for 10 years after the system is placed on the market or put into service. The declaration states that the system meets all applicable requirements of Chapter III, Section 2, and it is the provider's own responsibility - not the notified body's.

The declaration must identify the system, the provider, the applicable requirements, the harmonised standards or common specifications applied, and (where relevant) the notified body and certificate number. A copy of the declaration must be included in the Annex IV technical file and submitted as part of the EU database registration.


CE Marking Mechanics (Article 48)

After the declaration is drawn up, the CE marking can be affixed. The rules are straightforward but worth stating precisely:

  • The CE marking must be affixed visibly, legibly, and indelibly to the high-risk AI system. Where that is not possible or not warranted on account of the nature of the system, it must be affixed to the packaging or accompanying documentation.
  • For high-risk AI systems provided digitally, a digital CE marking must be used, accessible via the interface from which the system is accessed or via an easily accessible machine-readable code or other electronic means.
  • Where a notified body was involved in the conformity assessment, the CE marking must be followed by the notified body's identification number, affixed by the body itself or under its instructions. That number must also appear in any promotional material that mentions CE marking compliance.
  • If the system is also subject to other Union law requiring CE marking (e.g., the Medical Devices Regulation), a single CE marking covers both, but must indicate compliance with all applicable laws.

For most software-delivered AI systems, the practical implementation is a digital CE marking accessible from the product's about screen, documentation portal, or a machine-readable code in the system's metadata.


EU Database Registration (Article 49 / Article 71)

Registration in the EU public database is a separate step that must happen before market placement - not after. Before placing on the market or putting into service a high-risk AI system listed in Annex III (with the exception of systems in point 2, which register at national level), the provider must register themselves and their system in the EU database referred to in Article 71.

The database is publicly accessible for most Annex III systems, serving both transparency and market surveillance purposes. Providers must keep entries current and update them for substantial modifications. Note that systems used in law enforcement, migration, asylum, and border control register in a secure, non-public section accessible only to the Commission and designated national authorities.

lightbulb Tip

Free tools on AI Act Navigator:

  • High-Risk Obligations Guide — maps every Article 9–15 obligation to practical compliance steps for providers and deployers, including the full Article 17 QMS requirements that underpin both conformity routes.
  • The AI Act Brief newsletter — weekly updates on standards progress, guidance publications, and deadline changes, including Omnibus developments.

Post-Market Monitoring and Re-Assessment on Substantial Change

Conformity is not a one-time event. Under Article 72, providers must establish a post-market monitoring system that actively and systematically collects, documents, and analyses relevant data on the performance of high-risk AI systems throughout their lifetime, allowing the provider to evaluate continuous compliance. The monitoring plan must be part of the Annex IV technical file from day one.

Two triggers can require a fresh conformity assessment:

  1. Substantial modification. Article 43(4) requires a new conformity assessment whenever a high-risk AI system is substantially modified, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer. A substantial modification is any change that affects compliance with the Act's requirements or alters the system's intended purpose.
  2. Continuous-learning systems. For high-risk AI systems that continue to learn after being placed on the market, changes that were predetermined by the provider at the time of the initial conformity assessment and are documented in the Annex IV technical file do not constitute a substantial modification. Everything else does.

The practical implication: version-control your model, your policy configuration, and your data governance setup. Without clear versioning, you cannot demonstrate which state was in effect on a given date - and your technical file will diverge from operational reality.


Deadlines and the Digital Omnibus Caveat

Here is where things are genuinely unsettled as of June 2026, and you deserve a straight answer.

Current binding law: Under the AI Act as enacted, high-risk obligations for stand-alone Annex III systems were set to apply from 2 August 2026, and for Annex I (regulated-product) systems from 2 August 2027.

The Omnibus provisional deal: On 7 May 2026, the Council of the EU and the European Parliament reached a provisional political agreement on the Digital Omnibus on AI, deferring stand-alone Annex III high-risk obligations to 2 December 2027 and Annex I high-risk obligations to 2 August 2028. The provisional agreement must still be formally endorsed and adopted by the co-legislators before it becomes law; formal adoption and publication in the Official Journal are expected before 2 August 2026.

What this means for you: The Omnibus is not yet law as of this writing. Plan against the new dates as your working baseline - but do not stop preparation. The delay is intended to provide businesses with additional time to achieve compliance, while underscoring the expectation that implementation efforts should already be underway. Building a compliant risk-management system, producing the Annex IV technical file, setting up post-market monitoring, and running the conformity assessment typically takes 9-12 months of focused work. If you need a notified body, providers planning to place systems on the Union market should already be in the notified-body queue, as late entries will not receive certificates before the applicable deadline.


Your 9-12 Month Preparation Checklist

The sequence below reflects the logical dependency order. Steps 1-4 are prerequisites for the conformity assessment itself; steps 5-8 follow from it.

1
Stand up your Article 9 risk management system

Identify, evaluate, and mitigate risks across the AI system lifecycle. This is the foundation of your Annex IV file and must be maintained continuously — not completed once at launch. Align with prEN 18286 (the draft QMS standard) even before it is formally cited in the Official Journal.

2
Build the Annex IV technical documentation file

Assemble all ten categories: general description, design specs, architecture, data governance, human oversight, lifecycle plan, risk management records, change history, standards applied, and the declaration of conformity. Treat it as a living document from day one.

3
Establish your Article 17 quality management system

The QMS must cover design, development, verification, change control, and post-market monitoring as a documented system. If you already have ISO 9001 or ISO/IEC 42001 in place, map your existing controls to the AI Act's Article 17 requirements rather than building from scratch.

4
Determine your conformity assessment route

Use the decision tree above. If you need Annex VII (notified body), engage one now — queue times are a real constraint. If you qualify for Annex VI, conduct the internal assessment against your completed technical file and QMS.

5
Draw up the EU declaration of conformity (Article 47)

Once the assessment is complete, prepare the written declaration. Keep it for 10 years. Include a copy in your Annex IV file. This is the provider's own statement of responsibility — it cannot be delegated to a notified body.

6
Affix the CE marking (Article 48)

Apply the CE marking visibly, legibly, and indelibly — or digitally, if the system is software-delivered. If a notified body was involved, add their identification number immediately after the CE mark.

7
Register in the EU database (Article 49 / Article 71)

Complete registration before market placement. Prepare your Annex VIII data fields in advance. Integrate the registration ID into your internal product records and update the entry for any substantial modifications.

8
Activate post-market monitoring (Article 72)

Your monitoring plan should already be in the Annex IV file. Now operationalise it: set up data collection from deployers, define serious-incident reporting thresholds under Article 73, and schedule periodic reviews of the technical file against live system performance.


A Note on What This Guide Is Not

This is a plain-English orientation to the conformity assessment and CE marking process under the EU AI Act. It is not legal advice, and it does not substitute for qualified legal or regulatory counsel. The AI Act is a complex regulation, its supporting standards are still being finalised, and the Digital Omnibus amendments are not yet formally adopted. Always verify your obligations against the official text of Regulation (EU) 2024/1689 and the latest guidance from the EU AI Office.

For the official text and supporting documents, see artificialintelligenceact.eu and the EU AI Office.