EU AI Act conformity assessment: Requirements and process guide for April 2026

Your team might assume every high-risk AI system needs an external auditor to pass EU AI Act conformity assessment, but Article 43 actually reserves third-party certification for biometric systems and cases where harmonized standards don't exist yet. Most enterprise AI systems covering employment, credit, public services, and critical infrastructure qualify for the internal control procedure, where you self-assess, compile technical documentation, and register directly in the EU database. Knowing which path you're on early determines whether you're scheduling notified body reviews or building internal QMS records to support your declaration of conformity.
TLDR:
- High-risk AI systems under the EU AI Act require conformity assessment by August 2, 2026.
- Most Annex III systems use self-assessment; biometric systems require notified body review.
- Technical documentation must cover risk management, data governance, and test evidence.
- Substantial modifications trigger full reassessment; continuous monitoring is mandatory post-deployment.
- Openlayer automates EU AI Act evidence capture with 100+ tests and audit-ready compliance mapping.
Understanding EU AI Act conformity assessment
Conformity assessment is the formal process that proves your AI system meets the EU AI Act's requirements before it reaches the market. For high-risk AI systems, this process covers everything from risk management and data governance to transparency and human oversight. The goal is a structured way to verify that your system was built responsibly and will behave predictably once deployed. The EU AI Act lays out two distinct paths for this assessment, and which one applies to you depends on the type of AI system you're deploying. Getting that determination right is where most organizations stumble first.
Which AI systems require conformity assessment under the EU AI Act
Not every AI system goes through conformity assessment. The EU AI Act reserves that requirement for systems classified as high-risk, and classification comes down to two categories.
The first covers AI systems embedded in products regulated under existing EU safety laws listed in Annex I, such as medical devices, aviation equipment, and industrial machinery. If your AI is a safety component of one of those products, it is automatically high-risk.
The second category is Annex III, which lists specific use cases regardless of what product they are embedded in:
- Biometric identification and categorization of individuals, covering both remote and real-time systems used in public or private contexts.
- AI used in critical infrastructure like energy grids or water systems, where failure or bias in outputs carries public safety consequences.
- Education and vocational training access decisions, including systems that gate admissions or assess student performance.
- Employment screening, hiring, and performance evaluation tools that affect a person's livelihood.
- Access to public services including credit scoring and social benefits determinations.
- Law enforcement use cases, including risk assessments, predictive policing tools, and evidence evaluation.
- Migration, asylum, and border control management systems.
- Administration of justice and democratic processes.
In practice, this sweeps in a wide range of enterprise systems. A credit decisioning model at a bank, a hiring filter at an insurer, a patient triage tool in a hospital, or a fraud detection system in utilities could all qualify. There are narrow exceptions for systems used solely for procedural tasks or where human review fully overrides outputs before any decision takes effect. Regulators interpret those exclusions conservatively. The EU AI Act regulatory framework provides the full classification criteria directly from the European Commission.
Two conformity assessment procedures: internal control vs. third-party assessment

Article 43 of the EU AI Act draws a clear line between two procedures, and where your system falls determines how much external scrutiny you face.
Most Annex III high-risk systems, those in points 2 through 8 covering areas like employment, credit, and critical infrastructure, follow the internal control procedure defined in Annex VI. Under this path, you self-assess compliance, compile technical documentation, and register the system in the EU database before deployment. No external auditor is required.
The third-party route applies in two situations: biometric identification systems listed under Annex III point 1, and any high-risk system where no harmonized EU standard exists covering the relevant requirements. In those cases, you must engage a notified body, an accredited conformity assessment organization recognized by a member state, to independently audit and certify your system under Annex VII.
The VDE assessment of high-risk AI conformity notes that most providers are surprised to find they qualify for self-assessment, since the third-party route gets most of the attention.
Knowing which path applies early saves real time. The two procedures share documentation requirements but differ sharply in timeline, cost, and control. The table below looks at the dimensions and how they can be assessed using internal controls or third-party assessment.
| Dimension | Internal Control (Annex VI) | Third-Party Assessment (Annex VII) |
|---|---|---|
| Applicable Systems | Most Annex III high-risk systems: employment screening, credit decisions, critical infrastructure, education access, public services (points 2-8) | Biometric identification systems (Annex III point 1) and any high-risk AI system where harmonized EU standards do not yet exist |
| Assessment Authority | Self-assessment by the AI system provider with no external auditor required | Independent audit and certification by an accredited notified body recognized by an EU member state |
| Process Duration | Weeks to months depending on documentation readiness and internal QMS maturity | Several months to over a year, including notified body scheduling, QMS review, technical documentation audit, and potential live testing requirements |
| Core Requirements | Verify QMS meets Article 17, confirm Annex IV technical documentation completeness, align post-market monitoring design | Notified body reviews QMS against Article 17, audits technical documentation, may request additional evidence or live testing, issues EU technical documentation assessment certificate |
| Certification Validity | Valid until substantial modification occurs; continuous monitoring and reassessment required for material changes | EU technical documentation assessment certificate valid for four years, after which full reassessment by notified body is mandatory |
| Cost Structure | Internal resource allocation for QMS development, documentation compilation, testing infrastructure, and ongoing monitoring | Notified body fees for initial assessment and four-year recertification, plus all internal costs for QMS and documentation preparation |
| Control and Flexibility | Provider maintains full control over assessment timeline, interpretation of requirements, and documentation approach within regulatory bounds | Notified body determines assessment scope, evidence sufficiency, and certification readiness; provider has limited control over timeline and interpretation |
Internal control conformity assessment: the self-assessment pathway
The Annex VI self-assessment pathway gives providers direct control over the conformity process, but it sets real obligations in return. Three steps define it:
- Step 1: quality management system review
- Step 2: technical documentation check
- Step 3: post-market monitoring alignment
Once all three steps are satisfied, you compile the documentation, register the system in the EU database, sign the declaration of conformity, and affix CE marking. No notified body reviews your work unless you request one.
Step 1: Quality management system review
You verify that your QMS meets Article 17 requirements. That covers documented procedures for risk management, data governance, testing, version control, and post-market monitoring. The system must be in place before deployment, not assembled retroactively.
Step 2: Technical documentation check
You confirm that all documentation required under Annex IV is complete and accurate. This includes system architecture, training data descriptions, performance metrics, known limitations, and test results. Incomplete documentation is the most common failure point in self-assessments.
Step 3: Post-market monitoring alignment
You verify that your system's design supports ongoing monitoring obligations. The architecture must allow for performance tracking, incident logging, and feedback loops back to the risk management process.
Third-party conformity assessment: working with notified bodies
Third-party assessment under Annex VII applies when the stakes are highest or when harmonized standards haven't caught up yet. Biometric identification systems, law enforcement applications, and any high-risk system operating outside a recognized harmonized standard all require an accredited notified body to independently audit both your QMS and your technical documentation.
The process runs in two stages. First, the notified body reviews your QMS against Article 17 requirements. Second, it audits your technical documentation and may request live testing or additional evidence. A passing result yields an EU technical documentation assessment certificate valid for four years, after which reassessment is required.
Harmonized standards under the EU AI Act are still being developed, so more systems may temporarily fall into third-party territory until those standards are finalized. Notified bodies are also not uniformly available across member states, and demand is expected to spike as deadlines approach. Starting that engagement early matters more here than in self-assessment.
Core requirements assessed during conformity evaluation
Whether you self-assess or engage a notified body, the same core requirements are on the table:
- Risk management covering identification, analysis, and mitigation of reasonably foreseeable risks across the full system lifecycle
- Data governance practices including training data quality, bias checks, and relevance to intended use
- Technical documentation completeness per Annex IV
- Logging and traceability to support post-market review
- Transparency obligations so users understand AI involvement in decisions
- Human oversight measures built into the system design
- Accuracy, robustness, and cybersecurity controls backed by test evidence
Technical documentation requirements for conformity assessment
Article 11 requires technical documentation to exist before conformity assessment begins, not after. Annex IV defines exactly what goes in it. This documentation must cover:
- General system description including intended purpose, deployment context, and the categories of persons it affects
- Design specifications covering system architecture, algorithmic logic, and key development decisions
- Training data provenance: sources, selection criteria, labeling methodology, and bias mitigation steps
- Performance validation results including test datasets, evaluation metrics, known failure modes, and accuracy thresholds across relevant subgroups
- Risk management records showing identified risks and corresponding controls
- Post-market monitoring plan describing how performance will be tracked once deployed
Gaps in any of these areas will stall your self-assessment or fail a notified body review. Regulators want to see that results were recorded, analyzed, and fed back into the risk process. Evidence of continuous evaluation carries more weight than a single pre-deployment snapshot.
Quality management system obligations for high-risk AI providers
Article 17 requires every high-risk AI provider to maintain a documented quality management system before deployment. The QMS must cover:
- A compliance strategy documenting how regulatory requirements map to your system's design and deployment context
- Design and development controls including version history, change procedures, and test protocols
- Data governance procedures covering data sourcing, labeling, and bias review
- Testing and validation records tied directly to your risk register
- Post-market monitoring commitments with defined feedback loops back into risk management
- Incident reporting procedures and corrective action workflows
The QMS is a living document. Regulators expect it to evolve with the system. If you modify a model, the QMS should reflect it. If a monitoring alert fires, the QMS should show how you responded. Both self-assessment and notified body reviews will check whether the system was actually followed, instead of merely documented.
EU declaration of conformity and CE marking process
Passing conformity assessment, whether through self-assessment or a notified body, does not complete your compliance obligation. Three final steps close the loop:
- Declaration of conformity
- CE marking
- EU database registration
Once those three steps are complete, you must retain all underlying technical documentation and QMS records for ten years from market placement. Regulators can request that evidence at any point within that window, so the records need to stay accurate and accessible, ready for review on demand.
EU declaration of conformity
Article 47 requires you to draft a declaration confirming that your high-risk AI system meets all applicable EU AI Act requirements. The document must identify the provider, the system, the conformity assessment procedure followed, any notified body involved, and a statement of compliance. One declaration can cover multiple systems where applicable.
CE marking
Article 48 requires the CE mark to appear visibly on the system or its packaging before EU market placement. Where that is not physically practical, it goes on documentation accompanying the system. Affixing it without completing the underlying conformity process is a violation.
EU database registration
Article 49 requires registration in the EU database before deployment. You submit system identifiers, provider contact details, intended use, and the conformity assessment path taken.
Substantial modifications and reassessment requirements
Not every change to a high-risk AI system triggers reassessment. Article 83 draws a line between routine updates and substantial modifications, and misreading that boundary creates real compliance exposure.
A substantial modification is any change affecting the system's intended purpose, its risk level, or its conformity with applicable requirements. Retraining on new data that changes performance characteristics, expanding to a new use case, or altering core algorithmic logic all qualify. Each triggers a full reassessment from the start.
Pre-determined learning adaptations are treated differently. If your initial technical documentation described how the system would continue learning post-deployment, those adaptations generally do not constitute a substantial modification, provided behavior stays within documented bounds. If it was not captured during the initial assessment, regulators will not treat it as pre-determined.
Change management and conformity assessment must connect directly. Every model update, prompt revision, or scope change should be tested against a defined threshold before release.
August 2026 compliance timeline and transition deadlines
The EU AI Act's phased rollout means different deadlines apply depending on your system type. For most high-risk AI systems falling under Annex III, the hard deadline is August 2, 2026. By that date, conformity assessment must be complete, technical documentation finalized, CE marking affixed, and your system registered in the EU database. High-risk systems embedded in regulated products covered by Annex I receive an extended transition period until August 2, 2027, giving manufacturers more runway to align with existing product safety certification timelines.
One deadline that often gets missed: general-purpose AI models with systemic risk face their own obligations, with some requirements taking effect as early as mid-2025. These are separate from the high-risk conformity assessment process but can affect providers whose models power downstream high-risk EU AI Act compliance requirements applications.
August 2026 sounds distant until you account for the actual work involved. QMS documentation, bias audits, test evidence compilation, and notified body scheduling each take months. Teams starting in early 2026 will likely miss it.
Accelerating conformity assessment with continuous testing and monitoring

Conformity assessment is not a one-time audit you survive and forget. Post-market monitoring under Article 72 requires ongoing evidence that your system continues to perform as assessed.
Openlayer's evaluation infrastructure generates that evidence continuously. Over 100 automated tests across bias, toxicity, hallucinations, and PII leakage map directly to the behavioral requirements assessed during conformity. CI/CD integration means every model update is tested before release, so your technical documentation reflects actual system behavior, not a pre-deployment snapshot. The governance layer automatically maps projects to EU AI Act requirements, capturing audit-ready evidence as a byproduct of normal operations. Whether you're on the self-assessment path or working with a notified body, the records regulators want already exist.
Final thoughts on preparing for conformity assessment deadlines
The path to AI conformity assessment starts long before August 2026. Whether you're following internal control procedures or engaging a notified body, your technical documentation needs to describe actual system behavior across bias, accuracy, robustness, and transparency. Post-market monitoring isn't optional, regulators expect ongoing evidence that your system continues performing as assessed. The organizations that build testing and governance into their development process will have conformity evidence as a byproduct, not a scramble. If you need to automate that evidence pipeline, talk to our team.
FAQ
What is the difference between internal control and third-party conformity assessment?
Internal control under Annex VI allows you to self-assess compliance for most high-risk AI systems (Annex III points 2-8), while third-party assessment under Annex VII requires an accredited notified body to audit biometric systems and any high-risk AI lacking harmonized standards.
How long does technical documentation need to be retained after deployment?
You must retain all technical documentation and quality management system records for ten years from market placement, and regulators can request access to this evidence at any point during that period.
Does retraining my model on new data trigger a new conformity assessment?
Yes, if the retraining changes performance characteristics, alters the system's risk level, or affects conformity with EU AI Act requirements; unless the learning adaptation was pre-documented in your initial technical documentation and behavior stays within those bounds.
When should I start preparing for the August 2026 deadline?
Start now. Quality management system documentation, bias audits, test evidence compilation, and notified body scheduling each take months; teams beginning in early 2026 will likely miss the deadline.
Can I use the same declaration of conformity for multiple AI systems?
Yes, Article 47 allows one EU declaration of conformity to cover multiple systems where applicable, provided each system is properly identified and follows the same conformity assessment procedure.





