← Glossary

What is an EU AI Act conformity assessment?

A conformity assessment under Article 43 is the process a provider must complete before placing a high-risk AI system on the EU market — confirming it meets the Act's requirements before a declaration of conformity and CE marking are issued.

Two routes

For Annex III points 2 through 8 (critical infrastructure, education, employment, essential services, law enforcement, migration, and justice), providers follow internal control under Annex VI — a self-assessment, with no notified body involved. For Annex III point 1 (biometric systems), the route depends on whether harmonized standards or common specifications were fully applied: if so, the provider can still self-assess; if not, a third-party notified body assessment under Annex VII is required. Systems embedded as safety components in already-regulated products (Annex I — medical devices, machinery, toys, etc.) follow that product category's existing sectoral assessment procedure instead.

What either route needs

Both routes require the same underlying Annex IV technical documentation as their evidence base — the assessment procedure differs, but the documentation it's built on doesn't. Building that documentation early, rather than scrambling right before an audit, is worth doing regardless of which route eventually applies.

This is general educational information, not legal advice. Regulatory timelines and interpretations have changed multiple times in 2026 — verify current status before making compliance decisions.
Check your system's risk tier →See Attestly's pricing →