EU AI Act conformity assessment

The check a provider runs on a high-risk system before it goes to market. For most Annex III systems it is done in-house; for some it needs a notified body.

Conformity assessment is how the provider of a high-risk AI system demonstrates it meets the Act's requirements before market. Most Annex III systems use internal control under Annex VI; some use a notified body under Annex VII.

This is a high-risk obligation, so it only reaches you once a system is classified as high-risk and you are within scope. Settle scope first (Article 2) and classification next: the high-risk and Annex III guide covers both. We assess readiness and do not carry out, certify or notify any conformity assessment; this page explains the process, it is not part of it.

What is conformity assessment?

It is the process by which the provider of a high-risk AI system checks that the system meets the Act's high-risk requirements, and records the evidence, before it is placed on the market or put into service (Article 43). It ends in an EU declaration of conformity and, where applicable, CE marking, with registration in the EU database (Article 47, Article 48 and Article 49).

It is a provider-facing product-safety step. A readiness self-assessment, like the tools on this site, helps you see whether you are ready to begin, but it is not the conformity assessment itself and produces no declaration or mark.

Who has to do one?

The provider of the high-risk system. The obligation follows the provider role, so the first question is which role you hold for the system in question (Article 3).

Watch Article 25: a deployer that substantially modifies a high-risk system, or puts its own name on one, becomes a provider and inherits the conformity-assessment obligation with the rest of the provider set. That is the most common way a UK organisation that thought of itself only as a user finds itself carrying provider duties.

Internal control or a notified body?

The default for stand-alone high-risk systems is the internal-control procedure in Annex VI, where the provider carries out and documents the assessment itself. This covers most of the Annex III areas.

A narrower set uses the notified-body procedure in Annex VII, where an independent notified body is involved: this applies to certain biometrics systems under Annex III point 1, in the conditions the Act sets. Which procedure a system takes is set by its category, so confirm the classification before assuming internal control applies.

What changed with the deferral?

The timetable moved, not the procedures. Conformity assessment sits among the high-risk obligations deferred to 2 December 2027 for Annex III stand-alone systems and 2 August 2028 for Annex I product-embedded systems under Regulation (EU) 2026/1744. Deferred, not cancelled: the procedures themselves are unchanged.

The gap is preparation time. Because the classification test and the procedures are settled, a provider can map which systems will need an Annex VI or Annex VII route well before the date. The timeline has the dates, downloadable as a one-page PDF.

What does a deployer check instead?

A deployer that stays a deployer does not run a conformity assessment. Its obligations run to using the system in line with the provider's instructions, human oversight, monitoring and keeping the relevant records, and telling the provider or authorities about serious incidents or risks. The line to watch is Article 25, because crossing it turns those deployer checks into the full provider set.

If you are not sure which role you hold for a given system, the EU AI Act check works through role and classification and points you to the duties that follow.

Common questions

What is conformity assessment under the EU AI Act?
It is the process by which the provider of a high-risk AI system checks and demonstrates that the system meets the Act's high-risk requirements before it is placed on the market or put into service. Most Annex III systems use an internal-control procedure under Annex VI; some, such as certain biometrics under Annex III point 1, use a notified-body procedure under Annex VII.
Who has to do a conformity assessment?
The provider of a high-risk AI system. A deployer that substantially modifies a high-risk system, or places it on the market under its own name, becomes a provider under Article 25 and takes on that obligation. Deployers who do not become providers have their own separate checks rather than a conformity assessment.
What changed with the deferral?
The obligations were deferred, not removed. High-risk duties, conformity assessment among them, apply from 2 December 2027 for Annex III stand-alone systems and 2 August 2028 for Annex I product-embedded systems under Regulation (EU) 2026/1744. The procedures themselves are unchanged.