Blog

EU AI Act Conformity Assessment for Deployed AI Tools

Navigate conformity assessment paths for high-risk AI tools: internal control, notified body involvement, technical documentation, and post-market monitoring.

EU AI Act conformity assessment paths for high-risk AI tools internal control notified body technical documentation
EU AI Act conformity assessment determines whether high-risk AI tools can carry CE marking, enter the EU database, and operate with defensible post-market monitoring.

Organizations deploying AI tools in the European Union face a compliance cliff as high-risk system obligations phase in through 2027 and 2028. Conformity assessment is the gate between development and lawful market placement. When auditors, notified bodies, or national authorities ask how you proved compliance, vague assurances about vendor SOC reports fail. You need documented paths, technical files, and monitoring hooks aligned to Regulation (EU) 2024/1689 and subsequent Digital Omnibus amendments.

EU AI Act conformity assessment is the procedure providers and deployers follow to verify that a high-risk AI system meets Chapter III Section 2 requirements before CE marking, EU declaration of conformity, and Article 49 database registration. This guide covers compliance owners evaluating AI transcription tools in hiring workflows, AI chatbot systems in essential services, and embedded vendor AI features your teams configure. The goal is a decision tree you can operationalize, not legal theory alone.

Which AI Tools Trigger Conformity Assessment

Conformity assessment applies to high-risk AI systems under Annex III use cases and Annex I product safety integrations, not to every chatbot or productivity assistant your employees adopt. A marketing copy generator processing public website text typically falls outside high-risk scope. An AI tool scoring job applicants, evaluating creditworthiness, or triaging emergency calls likely triggers full assessment obligations. Map each deployed tool to Annex III categories before selecting assessment modules.

Annex III area Example AI tools Assessment trigger
Point 1: Biometrics Facial recognition access, voice ID for banking Annex VI or VII depending on standards application
Points 2 to 8 HR screening, credit scoring, education assessment Annex VI internal control without notified body
Annex I products Medical devices, machinery with embedded AI Sectoral legislation plus AI Act requirements
Limited risk General-purpose chatbots with transparency duties No conformity assessment; transparency obligations only

Provider vs Deployer Roles

Providers who place high-risk AI on the market conduct conformity assessment before CE marking; deployers who substantially modify a system or use it outside the provider's intended purpose may inherit provider obligations. When your team fine-tunes a foundation model on proprietary hiring data and deploys it for candidate ranking, you may be a provider under Article 25 even if the base model came from a GPAI vendor. Legal counsel should map roles per system in your AI inventory register.

Decision Tree Starting Point

Start every assessment with three questions: Is the system high-risk under Annex III or Annex I? Are you the provider or deployer with provider duties? Which harmonised standards or common specifications apply? Answers route you to Annex VI internal control, Annex VII notified body involvement, or sectoral conformity procedures. Document the decision tree outcome in your technical file before procurement signatures on new high-risk tools.

Module A Internal Control vs Notified Body Paths

Article 43 routes Annex III points 2 through 8 to Annex VI internal control without notified body involvement, while Annex III point 1 biometrics may require Annex VII assessment when harmonised standards are absent, incomplete, or restricted. This distinction matters for budget planning and timeline. Internal control still demands rigorous self-certification, not informal checklists.

Procedure Annex reference Notified body Typical use case
Internal control Annex VI Not required Annex III points 2 to 8 high-risk systems
QMS plus technical doc assessment Annex VII Required Biometrics when standards gap exists
Provider choice Article 43(1) Optional Annex VI or VII Point 1 when full standards applied

Annex VI Internal Control Steps

Annex VI requires the provider to verify QMS compliance under Article 17, examine Annex IV technical documentation, confirm system conformity with Section 2 requirements, and establish post-market monitoring before issuing the EU declaration of conformity. Each step produces evidence artifacts auditors sample. Self-assessment without independent review invites gaps that market surveillance authorities later expose.

Annex VII Notified Body Involvement

When Annex VII applies, the notified body examines your QMS and technical documentation, issues a Union technical documentation assessment certificate if compliant, or refuses with reasoned findings including training data quality deficiencies. Certificate refusal on data grounds may require model retraining before reapplication. Budget six to twelve months for first-time notified body engagement in regulated sectors.

Technical Documentation Minimum Contents

Annex IV technical documentation must describe the system's intended purpose, design specifications, development process, monitoring capabilities, human oversight measures, and risk management outcomes in sufficient detail for authorities to assess compliance. Vendor marketing PDFs rarely satisfy Annex IV. Procurement should require machine-readable technical files or model cards mapped to Annex IV sections before high-risk deployment.

  1. General system description, intended purpose, and provider identity.
  2. Detailed design specifications including computational resources and third-party components.
  3. Data governance: training, validation, and testing datasets with provenance.
  4. Risk management system documentation per Article 9.
  5. Human oversight design per Article 14, including override procedures.
  6. Accuracy, robustness, and cybersecurity measures per Articles 15 and 16.
  7. Changes and version history with impact assessments.

Documentation Checklist for Deployers

Deployers must maintain logs per Article 26, including automatic recording for certain high-risk systems, and ensure provider technical documentation is accessible for the system's lifetime plus ten years. Link documentation to your GRC repository with version control. When vendors update models, trigger re-review against the documentation delta and reassess conformity impact.

GPAI Downstream Documentation

When your high-risk system builds on a general-purpose AI model, Annex IV must cover your modifications, fine-tuning data, RAG corpora, and integration architecture separately from the GPAI provider's base documentation. GPAI providers owe transparency obligations under Chapter V, but deployers who become providers through substantial modification own the full technical file for the modified system.

Quality Management System Hooks

Article 17 requires providers of high-risk AI to implement a QMS covering design control, data management, risk management, post-market monitoring, incident reporting, and documentation updates. Most enterprises already operate ISO 9001 or sectoral QMS frameworks. The task is mapping AI Act Article 17 clauses to existing procedures rather than building parallel bureaucracy.

Article 17 element Existing QMS hook AI-specific addition
Design and development Software development lifecycle Model versioning, eval gates, bias testing
Data management Data governance policies Training data quality metrics, lineage
Risk management Enterprise risk register Article 9 AI risk management system
Post-market monitoring Product quality surveillance Performance drift, incident triggers

Integrating With ISO 42001

ISO/IEC 42001 AI management system certification provides a structured overlay that many organizations use to demonstrate Article 17 QMS maturity to notified bodies and enterprise customers. Alignment is not automatic equivalence, but auditors increasingly accept ISO 42001 evidence as supporting Annex VI self-assessment when gap analysis documents map controls explicitly.

Post-Market Monitoring and Serious Incident Links

Article 72 mandates post-market monitoring plans that track AI system performance in real-world deployment, while Article 73 requires reporting serious incidents to market surveillance authorities within prescribed timelines. Your monitoring plan must connect observability data from production AI chatbot and AI transcription deployments to escalation procedures legal and compliance teams can execute.

  • Define performance metrics and drift thresholds tied to risk management documentation.
  • Establish user feedback channels that feed monitoring dashboards.
  • Map serious incident criteria: death, serious harm, fundamental rights violations, systemic failures.
  • Document reporting timelines and authority contact points per member state of deployment.
  • Link incident response to model rollback, human oversight escalation, and customer notification.

Monitoring for SaaS Embedded AI

When high-risk capability comes from a SaaS vendor's embedded AI feature, your post-market monitoring plan must cover vendor change notifications, your configuration choices, and downstream harm signals you can observe. Contract clauses should require vendor incident disclosure and model change alerts within defined windows. You cannot outsource Article 72 accountability entirely.

Frequently Asked Questions

How does conformity assessment work when we fine-tune a GPAI model?

If your modifications make you a provider under Article 25, you conduct conformity assessment on the modified high-risk system and maintain a complete Annex IV technical file covering your changes. The GPAI provider's obligations under Chapter V do not replace your provider duties for the deployed high-risk use case. Document the division of responsibilities in vendor contracts and internal registers.

Do legacy AI systems deployed before 2026 need conformity assessment?

Systems already on the market before applicable deadlines may qualify for transitional provisions, but any substantial modification after the deadline triggers full conformity obligations for the modified system. Inventory legacy deployments now, classify risk tier, and plan remediation before Annex III enforcement dates. The Digital Omnibus adjusted some timelines; verify current dates with legal counsel.

What are the current EU AI Act conformity assessment deadlines?

High-risk AI systems under Annex III face application from 2 August 2027 under current Digital Omnibus amendments, with Annex I product-integrated systems following 2 August 2028. Prohibited practices and GPAI obligations already apply on earlier staggered dates. Build assessment programs now; twelve-month lead times are realistic for first high-risk deployments with notified body involvement.

We are deployers only. Do we skip conformity assessment?

Deployers of third-party high-risk AI must verify provider conformity, maintain usage logs, conduct fundamental rights impact assessments where required, and comply with Article 26 deployer obligations. You do not conduct provider conformity assessment unless you become a provider through modification. Due diligence on provider CE marking and EU declaration remains mandatory.

Cross-Functional Assessment Team

Conformity assessment requires a cross-functional team spanning legal, quality, engineering, privacy, and product ownership, with documented RACI for each Annex IV section and Article 17 QMS element. Siloed assessments where engineering writes technical documentation without legal review of intended purpose statements produce files that fail notified body examination. Convene a monthly conformity working group until CE marking is complete, then quarterly for post-market evidence review.

Evidence Repository Structure

Store conformity evidence in a version-controlled repository with immutable audit trails: risk management reports, test logs, human oversight procedures, cybersecurity assessments, and declaration of conformity drafts. Link repository entries to your AI inventory register system IDs. Auditors sample three systems across risk tiers quarterly to validate evidence completeness before external assessment.

Implementation Roadmap

Month one: classify all AI tools against Annex III; month two through three: gap-assess technical documentation and QMS hooks; month four through six: execute Annex VI self-assessment or engage notified body; ongoing: post-market monitoring with quarterly evidence review. Conformity assessment succeeds when classification is documented, assessment modules are selected with legal sign-off, Annex IV files are complete, QMS integrates AI-specific controls, and monitoring links to serious incident reporting before CE marking and database registration.

Defensible Conformity, Lawful Deployment

EU AI Act conformity assessment is not a one-time checkbox before launch. It is an ongoing program connecting classification decisions, technical documentation, quality management, and post-market monitoring into evidence regulators and enterprise customers can verify. Organizations that begin assessment planning eighteen months before enforcement deadlines avoid the compressed timelines and notified body queue delays that penalize late starters. Start with your highest-risk deployed tools and expand coverage systematically.

Related blogs

  • AI Clinical Trial Patient Matching at Scale

    AI Clinical Trial Patient Matching at Scale

    Research-backed explainer on clinical trial matching ai: what works today, limits, and workflows, without tool listicles.

  • What a Simulated Fly Brain Teaches AI Architects

    What a Simulated Fly Brain Teaches AI Architects

    The complete male fruit fly connectome is being simulated in games and AI experiments. What 166,000 neurons reveal about scaling agent architectures.

  • AI Perfume Formulation: How Models Suggest Accords Without Replacing Noses

    AI Perfume Formulation: How Models Suggest Accords Without Replacing Noses

    Generative models propose molecule combinations matching briefs like rain on concrete. Niche for indie perfumers and R&D labs.

  • Phased vs Big-Bang AI Tool Rollouts: Choosing a Strategy

    Phased vs Big-Bang AI Tool Rollouts: Choosing a Strategy

    Compare phased pilots and organization-wide launches for AI tools. Decision criteria by risk tier and team size.

  • Reclaiming Unused AI Tool Seats: Process and Policy

    Reclaiming Unused AI Tool Seats: Process and Policy

    Idle seats waste budget. A fair process to identify, notify, and reassign licenses without surprise lockouts.

  • What Is Structured Output in LLMs? JSON, Schemas, and Reliability

    What Is Structured Output in LLMs? JSON, Schemas, and Reliability

    Structured output forces models to return JSON or schema-valid data. Learn when it works, when it fails, and how tools implement it.

Didn't find tool you were looking for?

Be as detailed as possible for better results