Organizations deploying AI tools in the European Union face a compliance cliff as high-risk system obligations phase in through 2027 and 2028. Conformity assessment is the gate between development and lawful market placement. When auditors, notified bodies, or national authorities ask how you proved compliance, vague assurances about vendor SOC reports fail. You need documented paths, technical files, and monitoring hooks aligned to Regulation (EU) 2024/1689 and subsequent Digital Omnibus amendments.
EU AI Act conformity assessment is the procedure providers and deployers follow to verify that a high-risk AI system meets Chapter III Section 2 requirements before CE marking, EU declaration of conformity, and Article 49 database registration. This guide covers compliance owners evaluating AI transcription tools in hiring workflows, AI chatbot systems in essential services, and embedded vendor AI features your teams configure. The goal is a decision tree you can operationalize, not legal theory alone.
Which AI Tools Trigger Conformity Assessment
Conformity assessment applies to high-risk AI systems under Annex III use cases and Annex I product safety integrations, not to every chatbot or productivity assistant your employees adopt. A marketing copy generator processing public website text typically falls outside high-risk scope. An AI tool scoring job applicants, evaluating creditworthiness, or triaging emergency calls likely triggers full assessment obligations. Map each deployed tool to Annex III categories before selecting assessment modules.
| Annex III area | Example AI tools | Assessment trigger |
|---|---|---|
| Point 1: Biometrics | Facial recognition access, voice ID for banking | Annex VI or VII depending on standards application |
| Points 2 to 8 | HR screening, credit scoring, education assessment | Annex VI internal control without notified body |
| Annex I products | Medical devices, machinery with embedded AI | Sectoral legislation plus AI Act requirements |
| Limited risk | General-purpose chatbots with transparency duties | No conformity assessment; transparency obligations only |
Provider vs Deployer Roles
Providers who place high-risk AI on the market conduct conformity assessment before CE marking; deployers who substantially modify a system or use it outside the provider's intended purpose may inherit provider obligations. When your team fine-tunes a foundation model on proprietary hiring data and deploys it for candidate ranking, you may be a provider under Article 25 even if the base model came from a GPAI vendor. Legal counsel should map roles per system in your AI inventory register.
Decision Tree Starting Point
Start every assessment with three questions: Is the system high-risk under Annex III or Annex I? Are you the provider or deployer with provider duties? Which harmonised standards or common specifications apply? Answers route you to Annex VI internal control, Annex VII notified body involvement, or sectoral conformity procedures. Document the decision tree outcome in your technical file before procurement signatures on new high-risk tools.
Module A Internal Control vs Notified Body Paths
Article 43 routes Annex III points 2 through 8 to Annex VI internal control without notified body involvement, while Annex III point 1 biometrics may require Annex VII assessment when harmonised standards are absent, incomplete, or restricted. This distinction matters for budget planning and timeline. Internal control still demands rigorous self-certification, not informal checklists.
| Procedure | Annex reference | Notified body | Typical use case |
|---|---|---|---|
| Internal control | Annex VI | Not required | Annex III points 2 to 8 high-risk systems |
| QMS plus technical doc assessment | Annex VII | Required | Biometrics when standards gap exists |
| Provider choice | Article 43(1) | Optional Annex VI or VII | Point 1 when full standards applied |
Annex VI Internal Control Steps
Annex VI requires the provider to verify QMS compliance under Article 17, examine Annex IV technical documentation, confirm system conformity with Section 2 requirements, and establish post-market monitoring before issuing the EU declaration of conformity. Each step produces evidence artifacts auditors sample. Self-assessment without independent review invites gaps that market surveillance authorities later expose.
Annex VII Notified Body Involvement
When Annex VII applies, the notified body examines your QMS and technical documentation, issues a Union technical documentation assessment certificate if compliant, or refuses with reasoned findings including training data quality deficiencies. Certificate refusal on data grounds may require model retraining before reapplication. Budget six to twelve months for first-time notified body engagement in regulated sectors.
Technical Documentation Minimum Contents
Annex IV technical documentation must describe the system's intended purpose, design specifications, development process, monitoring capabilities, human oversight measures, and risk management outcomes in sufficient detail for authorities to assess compliance. Vendor marketing PDFs rarely satisfy Annex IV. Procurement should require machine-readable technical files or model cards mapped to Annex IV sections before high-risk deployment.
- General system description, intended purpose, and provider identity.
- Detailed design specifications including computational resources and third-party components.
- Data governance: training, validation, and testing datasets with provenance.
- Risk management system documentation per Article 9.
- Human oversight design per Article 14, including override procedures.
- Accuracy, robustness, and cybersecurity measures per Articles 15 and 16.
- Changes and version history with impact assessments.
Documentation Checklist for Deployers
Deployers must maintain logs per Article 26, including automatic recording for certain high-risk systems, and ensure provider technical documentation is accessible for the system's lifetime plus ten years. Link documentation to your GRC repository with version control. When vendors update models, trigger re-review against the documentation delta and reassess conformity impact.
GPAI Downstream Documentation
When your high-risk system builds on a general-purpose AI model, Annex IV must cover your modifications, fine-tuning data, RAG corpora, and integration architecture separately from the GPAI provider's base documentation. GPAI providers owe transparency obligations under Chapter V, but deployers who become providers through substantial modification own the full technical file for the modified system.
Quality Management System Hooks
Article 17 requires providers of high-risk AI to implement a QMS covering design control, data management, risk management, post-market monitoring, incident reporting, and documentation updates. Most enterprises already operate ISO 9001 or sectoral QMS frameworks. The task is mapping AI Act Article 17 clauses to existing procedures rather than building parallel bureaucracy.
| Article 17 element | Existing QMS hook | AI-specific addition |
|---|---|---|
| Design and development | Software development lifecycle | Model versioning, eval gates, bias testing |
| Data management | Data governance policies | Training data quality metrics, lineage |
| Risk management | Enterprise risk register | Article 9 AI risk management system |
| Post-market monitoring | Product quality surveillance | Performance drift, incident triggers |
Integrating With ISO 42001
ISO/IEC 42001 AI management system certification provides a structured overlay that many organizations use to demonstrate Article 17 QMS maturity to notified bodies and enterprise customers. Alignment is not automatic equivalence, but auditors increasingly accept ISO 42001 evidence as supporting Annex VI self-assessment when gap analysis documents map controls explicitly.
Post-Market Monitoring and Serious Incident Links
Article 72 mandates post-market monitoring plans that track AI system performance in real-world deployment, while Article 73 requires reporting serious incidents to market surveillance authorities within prescribed timelines. Your monitoring plan must connect observability data from production AI chatbot and AI transcription deployments to escalation procedures legal and compliance teams can execute.
- Define performance metrics and drift thresholds tied to risk management documentation.
- Establish user feedback channels that feed monitoring dashboards.
- Map serious incident criteria: death, serious harm, fundamental rights violations, systemic failures.
- Document reporting timelines and authority contact points per member state of deployment.
- Link incident response to model rollback, human oversight escalation, and customer notification.
Monitoring for SaaS Embedded AI
When high-risk capability comes from a SaaS vendor's embedded AI feature, your post-market monitoring plan must cover vendor change notifications, your configuration choices, and downstream harm signals you can observe. Contract clauses should require vendor incident disclosure and model change alerts within defined windows. You cannot outsource Article 72 accountability entirely.
Frequently Asked Questions
How does conformity assessment work when we fine-tune a GPAI model?
If your modifications make you a provider under Article 25, you conduct conformity assessment on the modified high-risk system and maintain a complete Annex IV technical file covering your changes. The GPAI provider's obligations under Chapter V do not replace your provider duties for the deployed high-risk use case. Document the division of responsibilities in vendor contracts and internal registers.
Do legacy AI systems deployed before 2026 need conformity assessment?
Systems already on the market before applicable deadlines may qualify for transitional provisions, but any substantial modification after the deadline triggers full conformity obligations for the modified system. Inventory legacy deployments now, classify risk tier, and plan remediation before Annex III enforcement dates. The Digital Omnibus adjusted some timelines; verify current dates with legal counsel.
What are the current EU AI Act conformity assessment deadlines?
High-risk AI systems under Annex III face application from 2 August 2027 under current Digital Omnibus amendments, with Annex I product-integrated systems following 2 August 2028. Prohibited practices and GPAI obligations already apply on earlier staggered dates. Build assessment programs now; twelve-month lead times are realistic for first high-risk deployments with notified body involvement.
We are deployers only. Do we skip conformity assessment?
Deployers of third-party high-risk AI must verify provider conformity, maintain usage logs, conduct fundamental rights impact assessments where required, and comply with Article 26 deployer obligations. You do not conduct provider conformity assessment unless you become a provider through modification. Due diligence on provider CE marking and EU declaration remains mandatory.
Cross-Functional Assessment Team
Conformity assessment requires a cross-functional team spanning legal, quality, engineering, privacy, and product ownership, with documented RACI for each Annex IV section and Article 17 QMS element. Siloed assessments where engineering writes technical documentation without legal review of intended purpose statements produce files that fail notified body examination. Convene a monthly conformity working group until CE marking is complete, then quarterly for post-market evidence review.
Evidence Repository Structure
Store conformity evidence in a version-controlled repository with immutable audit trails: risk management reports, test logs, human oversight procedures, cybersecurity assessments, and declaration of conformity drafts. Link repository entries to your AI inventory register system IDs. Auditors sample three systems across risk tiers quarterly to validate evidence completeness before external assessment.
Implementation Roadmap
Month one: classify all AI tools against Annex III; month two through three: gap-assess technical documentation and QMS hooks; month four through six: execute Annex VI self-assessment or engage notified body; ongoing: post-market monitoring with quarterly evidence review. Conformity assessment succeeds when classification is documented, assessment modules are selected with legal sign-off, Annex IV files are complete, QMS integrates AI-specific controls, and monitoring links to serious incident reporting before CE marking and database registration.
Defensible Conformity, Lawful Deployment
EU AI Act conformity assessment is not a one-time checkbox before launch. It is an ongoing program connecting classification decisions, technical documentation, quality management, and post-market monitoring into evidence regulators and enterprise customers can verify. Organizations that begin assessment planning eighteen months before enforcement deadlines avoid the compressed timelines and notified body queue delays that penalize late starters. Start with your highest-risk deployed tools and expand coverage systematically.