EU AI Act conformity assessment
The check a provider runs on a high-risk system before it goes to market. For most Annex III systems it is done in-house; for some it needs a notified body.
Conformity assessment is how the provider of a high-risk AI system demonstrates it meets the Act's requirements before market. Most Annex III systems use internal control under Annex VI; some use a notified body under Annex VII.
This is a high-risk obligation, so it only reaches you once a system is classified as high-risk and you are within scope. Settle scope first (Article 2) and classification next: the high-risk and Annex III guide covers both. We assess readiness and do not carry out, certify or notify any conformity assessment; this page explains the process, it is not part of it.
What is conformity assessment?
It is the process by which the provider of a high-risk AI system checks that the system meets the Act's high-risk requirements, and records the evidence, before it is placed on the market or put into service (Article 43). It ends in an EU declaration of conformity and, where applicable, CE marking, with registration in the EU database (Article 47, Article 48 and Article 49).
It is a provider-facing product-safety step. A readiness self-assessment, like the tools on this site, helps you see whether you are ready to begin, but it is not the conformity assessment itself and produces no declaration or mark.
Who has to do one?
The provider of the high-risk system. The obligation follows the provider role, so the first question is which role you hold for the system in question (Article 3).
Watch Article 25: a deployer that substantially modifies a high-risk system, or puts its own name on one, becomes a provider and inherits the conformity-assessment obligation with the rest of the provider set. That is the most common way a UK organisation that thought of itself only as a user finds itself carrying provider duties.
Internal control or a notified body?
The default for stand-alone high-risk systems is the internal-control procedure in Annex VI, where the provider carries out and documents the assessment itself. This covers most of the Annex III areas.
A narrower set uses the notified-body procedure in Annex VII, where an independent notified body is involved: this applies to certain biometrics systems under Annex III point 1, in the conditions the Act sets. Which procedure a system takes is set by its category, so confirm the classification before assuming internal control applies.
What changed with the deferral?
The timetable moved, not the procedures. Conformity assessment sits among the high-risk obligations deferred to 2 December 2027 for Annex III stand-alone systems and 2 August 2028 for Annex I product-embedded systems under Regulation (EU) 2026/1744. Deferred, not cancelled: the procedures themselves are unchanged.
The gap is preparation time. Because the classification test and the procedures are settled, a provider can map which systems will need an Annex VI or Annex VII route well before the date. The timeline has the dates, downloadable as a one-page PDF.
What does a deployer check instead?
A deployer that stays a deployer does not run a conformity assessment. Its obligations run to using the system in line with the provider's instructions, human oversight, monitoring and keeping the relevant records, and telling the provider or authorities about serious incidents or risks. The line to watch is Article 25, because crossing it turns those deployer checks into the full provider set.
If you are not sure which role you hold for a given system, the EU AI Act check works through role and classification and points you to the duties that follow.