The EU AI Act conformity assessment is the formal process by which a high-risk AI system provider demonstrates compliance before placing a system on the EU market. It's not a one-off audit. It's a structured process involving risk classification, documentation, quality management, testing, EU database registration, and ongoing post-market monitoring. This article walks through each step in sequence, explains who needs to complete it, and covers what happens if you skip or fail the assessment.
What a conformity assessment is (and who needs one)
A conformity assessment is only required for providers of high-risk AI systems. The two categories of high-risk AI are:
- Annex II systems: AI components embedded in safety-critical products already governed by EU harmonised product legislation (medical devices, machinery, aviation systems, automotive safety components, lifts, toys, and others). For these, the conformity assessment follows the applicable product regulation's process, with AI-specific elements added.
- Annex III systems: AI systems in eight specific high-risk domains: biometric identification, critical infrastructure, education, employment and worker management, access to essential services (including credit and insurance), law enforcement, migration and border control, and administration of justice.
If your AI system doesn't fall into either of these categories, you don't need a conformity assessment. Deployers of high-risk AI systems (companies that use a high-risk system built by someone else) also don't complete a conformity assessment, though they do have their own obligations around appropriate use and human oversight.
Step 1: Determine your risk classification
Before you can begin a conformity assessment, you need to be confident about your system's risk classification. This is more than a checkbox; a wrong classification in either direction carries real risk. Over-classifying wastes resources on unnecessary conformity work. Under-classifying creates enforcement exposure.
The classification process involves:
- Mapping your AI system's intended purpose against the Annex III categories. Intended purpose is interpreted by the Act as the use for which the system was designed and documented, not all the ways it might theoretically be used.
- Checking whether your system is used as a safety component or embedded in a product covered by Annex II legislation.
- Assessing whether any prohibited practices under Article 5 apply (if they do, the system can't be deployed in the EU at all, regardless of any assessment).
- Determining whether exceptions apply. Not all AI used in Annex III contexts is automatically high-risk. The Act includes scope limitations for certain uses, such as AI systems used solely for narrow task-specific purposes where the output doesn't affect consequential decisions about individuals.
Document your classification rationale in writing. This documentation becomes part of your Annex IV technical file and will be reviewed by any authority that investigates your compliance.
Step 2: Build your Annex IV technical documentation file
Annex IV of the Act sets out the minimum content of the technical documentation that high-risk AI system providers must prepare and maintain. Building this file is typically the most time-consuming part of the conformity assessment process, especially for companies without existing model cards or AI system documentation.
The Annex IV file must include:
- General description: The system's intended purpose, the version number, how it interacts with other systems, the intended user categories, and any geographic, linguistic, or contextual limitations.
- Design and development description: The architecture and algorithms used, design choices made with their rationale, training methodology, and key design parameters.
- Training data information: The datasets used for training, validation, and testing; data provenance; data governance and examination procedures; and how the data was prepared (labelling methodology, data augmentation, cleaning steps).
- Performance metrics: The accuracy metrics used, the testing methodology, results across relevant population subgroups (demographic groups, geographic areas, operational scenarios), and known limitations in performance.
- Risk management: The risk management process used during development, including identified risks, residual risks, and the measures implemented to address them.
- Human oversight design: What human oversight mechanisms are built into the system, how users are informed about limitations, and how human override works in practice.
- Cybersecurity measures: Technical and organisational measures to protect the system against adversarial attacks, data poisoning, model theft, and unauthorised access.
- Change history: A log of substantial changes made to the system over time, with the rationale for each change and whether it triggered a new conformity assessment.
The technical file doesn't have a prescribed format, but it must be comprehensive, accurate, and kept up to date. National market surveillance authorities can request it at any time, and they typically do so at the start of any investigation.
2 August 2026 is the deadline for GPAI, Article 50 transparency, and enforcement provisions. High-risk Annex III conformity requirements may follow, with a proposed deferral to December 2027 under the Digital Omnibus. Don't wait for legal certainty to start your documentation work. Better Societies builds Annex IV technical files as part of the compliance engagement. Start your assessment.
Step 3: Implement the required quality management system
Article 17 requires providers of high-risk AI systems to establish a quality management system (QMS) before placing the system on the market. The QMS must cover the full AI lifecycle, from design through deployment and post-market monitoring.
The QMS must include documented policies and procedures for:
- Risk management (including the risk management process used during development and ongoing operation)
- Data governance (how training and validation data is selected, examined, and documented)
- Technical documentation management (keeping the Annex IV file current)
- Post-market monitoring (how the system's real-world performance will be tracked and reported)
- Incident reporting (processes for identifying and reporting serious incidents to national authorities)
- Staff training and AI literacy (ensuring people working with the system are competent to do so)
- Corrective action (how the company identifies and resolves non-conformities in the system)
Companies with an existing ISO 9001 or ISO 27001 quality management system can adapt their existing documentation significantly. The AI Act's QMS requirements are compatible with ISO 42001 (the AI management system standard), and some companies are pursuing dual certification. You don't need ISO certification to comply with the Act, but having a documented QMS of any kind makes the compliance path substantially shorter.
Step 4: Run the conformity assessment (internal vs third-party notified body)
With documentation and a QMS in place, the formal conformity assessment can begin. The Act provides two pathways:
- Internal conformity assessment (Annex VI): The provider conducts the assessment internally, verifying that the system meets all applicable requirements, producing a declaration of conformity, and maintaining the technical file. This pathway is available for most Annex III high-risk systems, including credit scoring, employment screening, and fraud detection systems.
- Third-party notified body assessment: Required for AI systems used in real-time biometric identification in public spaces by law enforcement, and for AI components in Annex II safety-critical products where the applicable product regulation requires third-party assessment. Notified bodies are designated and accredited by member states, and they conduct an independent technical audit of the system against the Act's requirements.
The internal assessment is not a rubber stamp. It requires a systematic review of every requirement in Articles 9 through 15 of the Act against your technical file and QMS documentation, with evidence of compliance for each. The output is a formal declaration of conformity, which is a legal document stating that the system meets the requirements of the Act, signed by an authorised representative of the provider.
Step 5: Affix the CE mark and register in the EU AI database
After a successful conformity assessment (whether internal or by a notified body), two actions are required before the system can be placed on the EU market:
- CE marking: High-risk AI systems must carry the CE mark, indicating conformity with the Act's requirements. For standalone AI systems, the provider affixes the CE mark after completing the conformity assessment. For AI embedded in Annex II products, the CE mark is affixed as part of the broader product conformity process and may incorporate the existing product's CE marking.
- EU AI database registration: Before placing a high-risk AI system on the EU market, providers must register it in the EU AI database. The registration includes: the provider's identity and contact details, the system's intended purpose and capabilities, the conformity assessment procedure used, a summary of the technical documentation, the declaration of conformity, and post-market monitoring contact information.
Registration in the EU database is public and searchable. It enables users, deployers, and competent authorities to look up registered systems and verify their compliance status. For companies operating multiple high-risk systems, each system requires a separate registration entry.
Step 6: Set up post-market monitoring
Conformity assessment doesn't end at deployment. Article 72 requires providers to implement a post-market monitoring system that actively collects and reviews data about the system's performance in real-world use throughout its operational life.
The post-market monitoring system must include:
- A plan specifying what data is collected, how it's analyzed, what performance thresholds trigger action, and how findings are reported internally and to authorities
- Mechanisms to detect and report serious incidents (incidents that result in death, serious bodily harm, or significant disruption of essential services) to national market surveillance authorities within 15 days
- Processes for identifying and acting on trends that suggest the system is drifting from its intended performance profile or generating unexpected outputs
- Procedures for deciding whether a change to the system constitutes a substantial modification (requiring a new conformity assessment) or a minor update (requiring documentation only)
The timeline: what needs to be done before 2 Aug 2026
The 2 August 2026 deadline applies to transparency (Article 50), GPAI obligations, and the enforcement and market surveillance framework. High-risk Annex III conformity requirements are potentially deferred to 2 December 2027 under the Digital Omnibus proposal, but this is not yet settled law.
What companies should have completed by 2 August 2026 regardless:
- Full AI inventory and risk classification, documented with rationale
- Article 50 transparency measures live for all customer-facing AI (chatbots, deepfake detectors, AI content pipelines)
- GPAI supply chain documentation requests sent to all API providers
- Conformity assessment process started for any high-risk Annex III systems (even if completion follows the proposed 2027 deadline)
- QMS framework in place or in implementation
Starting the conformity assessment process now avoids a cost and resource spike as the deadline approaches. Assessment work done before December 2027 (if the deferral passes) is not wasted; it's documentation and controls your business needs regardless.
What happens if you skip or fail the assessment
Failing to conduct a required conformity assessment, or placing a high-risk AI system on the EU market without completing the assessment, is a violation of the Act subject to penalties under Article 99. Specifically:
- Fines of up to EUR 15 million or 3% of global annual turnover (whichever is higher) for violations of high-risk AI obligations, including the conformity assessment requirement.
- National market surveillance authorities can require the system to be withdrawn from the EU market immediately, with no grace period, until compliance is demonstrated. This is a market access ban, not a warning.
- Authorities can require corrective action within a specified timeframe, and failure to comply within that timeframe escalates enforcement options.
- Serious or repeated violations can be publicised by the competent authority, with reputational consequences beyond the fine itself.
There's no provision for a lighter-touch "first warning" in lieu of fines for serious violations. The Act's enforcement is modelled on the EU's product safety framework, which has decades of precedent for real enforcement action, not just warnings.