Does the EU AI Act Require a Conformity Assessment for Your System?
Yes, if the system is high-risk, and for most high-risk systems the assessment is one you perform yourself. Article 43(2) sends every system in points 2 to 8 of Annex III through the internal control procedure in Annex VI, "which does not provide for the involvement of a notified body." A notified body enters in exactly two places: biometric systems under Annex III point 1 where you have not applied harmonised standards in full, and AI that is a safety component of a product which already needs third-party assessment under the product legislation in Annex I, where the sectoral procedure runs and the AI requirements are folded into it. The contrarian part is that the expensive question is not "which procedure" but "are we high-risk at all," and the Act gives you a documented way to answer no. The other thing that changed: since the Digital Omnibus on AI entered into force on 27 July 2026, the high-risk obligations apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products, fixed dates rather than the standards-linked trigger the proposal had floated.
What follows: the classification decision, the route each classification forces, what internal control and the notified body procedure each actually require, the standards variable, when you have to do it again, and the dates as amended.
Key takeaways
- A conformity assessment is required before a high-risk AI system is placed on the market, but for Annex III points 2 to 8 it is the Annex VI internal control procedure, performed by the provider with no notified body.
- A notified body is involved only for Annex III point 1 biometrics without harmonised standards applied in full, and for Annex I products where the sectoral legislation already requires third-party assessment.
- Article 6(3) lets you conclude that an Annex III system is not high-risk under four narrow conditions, never where it profiles natural persons. You must document that assessment and register the system.
- The Omnibus fixed the clock: 2 December 2027 for Annex III systems, 2 August 2028 for Annex I. Systems already on the market before those dates are caught only on a significant change in design.
- The Commission's standardisation page lists no harmonised standard for the Act as referenced in the Official Journal as of August 2026, so a biometrics provider planning today should plan for the notified body route.
First decide whether you are high-risk at all
The Act has two doors into high-risk, and Article 6 describes both.
The first, Article 6(1), is product-based: the AI system is a safety component of a product, or is itself a product, covered by the Union harmonisation legislation in Annex I, and that product is required to undergo a third-party conformity assessment under that legislation. Annex I Section A lists the New Legislative Framework acts: machinery, toys, recreational craft, lifts, equipment for explosive atmospheres, radio equipment, pressure equipment, cableways, personal protective equipment, gas appliances, medical devices and in vitro diagnostics. The Omnibus narrowed this door. The adopted text inserts Article 6(1a), under which AI systems "solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components," and Article 6(1c), under which a product that needs third-party assessment "solely due to risks other than risks to health and safety," radio spectrum and electromagnetic interference being the named examples, does not satisfy the second condition. Article 6(1b) keeps the door open for anything whose failure "would endanger health and safety."
The second, Article 6(2), is use-based: the system falls within one of the eight areas in Annex III. Biometrics (remote identification, categorisation by sensitive attributes, emotion recognition), critical infrastructure safety components, education and vocational training, employment and workers' management, access to essential private and public services (public benefits, creditworthiness, life and health insurance risk, emergency dispatch), law enforcement, migration and border control, and the administration of justice and democratic processes. Read the sub-points, not the area headings: Annex III point 1(a) says biometric verification "the sole purpose of which is to confirm that a specific natural person is the person he or she claims to be" is excluded from remote identification, which takes a large share of authentication products out at the first step.
Then comes the part that decides most of the money. Article 6(3) says an Annex III system "shall not be considered to be high-risk where it does not pose a significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision making," and it names four conditions under which that holds: the system performs a narrow procedural task; it improves the result of a previously completed human activity; it detects decision-making patterns or deviations from them without replacing or influencing the human assessment "without proper human review"; or it performs a preparatory task to an assessment relevant to an Annex III use case. The sentence after the list is the one to read twice: an Annex III system "shall always be considered to be high-risk where the AI system performs profiling of natural persons."
Concluding that you are exempt is not free. Article 6(4) requires the provider to document the assessment before the system is placed on the market, make it available to national authorities on request, and register the system under Article 49(2). The Omnibus kept that registration and, per its recital 22, simplified it "by streamlining the content required under Annex VIII," deleting two of the data points in Section B. The Commission published draft guidelines on the classification of high-risk AI systems on 19 May 2026 under Article 6(5), with practical examples of systems that should and should not be classified as high-risk; as of August 2026 that page still presents them as a draft. Build your Article 6(3) file against the draft, and expect to revisit it when the final text lands.
If you have not yet listed the systems you would run this test on, the AI system inventory is the artifact to build first; the classification is a per-row exercise.
The routes, by where your system sits
| Where your system sits | Procedure | Notified body |
|---|---|---|
| Annex III point 1 (biometrics), harmonised standards or common specifications applied in full | Provider chooses between Annex VI internal control and Annex VII | Optional |
| Annex III point 1, standards do not exist, were not applied, or were applied only in part | Annex VII, quality management system plus technical documentation assessment | Required, any notified body of the provider's choosing |
| Annex III points 2 to 8 | Annex VI internal control | None, unless the Commission adds it by delegated act under Article 43(6) |
| Safety component of, or product under, Annex I Section A legislation | The sectoral conformity assessment procedure, with the Act's Section 2 requirements assessed inside it | As that sectoral legislation requires |
| Annex III system exempt under Article 6(3) | No conformity assessment; documented assessment plus registration under Article 49(2) | None |
Three details behind the table. First, Article 43(1) lists precisely when the biometrics provider loses the choice: where harmonised standards "do not exist, and common specifications ... are not available," where the provider "has not applied, or has applied only part of, the harmonised standard," where common specifications exist but were not applied, or where a standard was published with a restriction, on the restricted part. Second, where a biometric system is to be put into service by law enforcement, immigration or asylum authorities or by Union institutions, the market surveillance authority "shall act as a notified body." Third, Article 43(6) is a standing option for the Commission to move points 2 to 8 to the notified body route by delegated act, "taking into account the effectiveness of the conformity assessment procedure based on internal control ... as well as the availability of adequate capacities and resources among notified bodies." Internal control for those systems is the rule today; it is not guaranteed forever.
For Annex I products the Omnibus rewrote Article 43(3). The provider follows the sectoral procedure, the Section 2 requirements "shall be part of that assessment," and points 3, 4.3, 4.4, 4.5, the fifth paragraph of 4.6 and point 5 of Annex VII apply. The paragraph the Omnibus added is the one manufacturers were waiting for: classification as high-risk under Article 6(1) "does not affect the choice of the conformity assessment procedure" available under the sectoral legislation, and manufacturers "are not required to choose a conformity assessment procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component." Where the sectoral act lets you self-assess by applying harmonised standards, you keep that option, provided you have also applied harmonised standards or common specifications covering all of the Act's Section 2 requirements. Notified bodies already notified under the sectoral legislation may assess the AI requirements too, and have eighteen months from the Omnibus entering into force to apply for designation under the Act.
What internal control actually requires
"Self-assessment" undersells it. Annex VI is three verifications the provider performs and stands behind: that the quality management system complies with Article 17; that the technical documentation demonstrates compliance with the Chapter III Section 2 requirements; and that "the design and development process of the AI system and its post-market monitoring as referred to in Article 72 is consistent with the technical documentation." Nobody checks that work before the system ships. Someone can check it afterwards, which is why the file has to be built as if it will be read.
Two documents come out of it. Article 47 requires a written, machine-readable EU declaration of conformity for each high-risk system, stating that it meets the Section 2 requirements, kept for ten years after placing on the market, and "by drawing up the EU declaration of conformity, the provider shall assume responsibility for compliance." Then Article 49: before placing an Annex III system on the market, the provider or its authorised representative registers itself and the system in the EU database, with the exception of critical infrastructure systems under point 2, which are registered at national level, and with a secure non-public section for law enforcement, migration, asylum and border control systems.
One relief for smaller providers arrived with the Omnibus. The amended Article 11(1) lets SMEs, start-ups and small mid-caps provide the Annex IV technical documentation "in a simplified manner" on a form the Commission is to establish, and "notified bodies shall accept the form for the purposes of the conformity assessment." The content still has to be true; the container gets lighter.
What the notified body route looks like
Annex VII is two assessments, not one. The provider applies for assessment of its quality management system, listing the AI systems it covers and supplying the technical documentation and quality documentation; the notified body decides whether the system satisfies Article 17, and any change to an approved system goes back to the notified body for examination. Separately, the provider applies for assessment of the technical documentation of each system. The notified body gets access to training, validation and testing datasets, can require further evidence or carry out tests, and on a positive outcome issues a "Union technical documentation assessment certificate." After that comes surveillance: periodic audits, and a duty on the provider to give the notified body access to the relevant premises and information.
Under Article 43(1) the provider "may choose any of the notified bodies." Capacity is the practical constraint, and Article 43(6) shows the legislator knew it: the availability of notified body resources is written into the test for extending the route to more systems. If your product is a remote biometric identification system and the standards do not land in time, the Annex VII queue is where you will be, and joining it late is the avoidable mistake.
Standards: the variable that decides the biometrics route
Article 43(1) makes the biometrics route turn on harmonised standards and common specifications. On the Commission's AI Act standardisation page, CEN and CENELEC are developing standards in ten areas, "companies that apply harmonised standards are presumed to be compliant with the legal requirements," and the first one, prEN 18286 on a quality management system for EU AI, entered public enquiry on 30 October 2025. The page says harmonised standards will be referenced in the Official Journal after Commission assessment, and lists none as referenced yet. The page also says "the application of standards remains voluntary." That is true for points 2 to 8; for point 1 it is what decides whether a notified body is in the room.
Two consequences. A biometrics provider planning in August 2026 should plan for Annex VII and treat a cited standard as an upside. And a provider of an Annex III point 2 to 8 system has no route decision to make, but still has to demonstrate the Section 2 requirements somehow; where a harmonised standard exists it is the cheapest demonstration, and where one does not, the technical file has to carry the argument on its own. The management system half of that argument is where ISO/IEC 42001 and the NIST AI RMF earn their keep, and it is worth being precise about what they do not do: a management system certificate is not a harmonised standard cited in the Official Journal and carries no presumption of conformity under Article 40. It evidences the Article 17 quality management system; it does not evidence a single Section 2 product requirement on its own.
When you have to do it again
Article 43(4): a system that has already been assessed "shall undergo a new conformity assessment procedure in the event of a substantial modification, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer." The relief for systems that keep learning is specific: changes "pre-determined by the provider at the moment of the initial conformity assessment" and described in the technical documentation under point 2(f) of Annex IV "shall not constitute a substantial modification." Write the envelope of expected change into the technical file at the first assessment, or every retrain is a legal question.
Systems already on the market get a different rule. The Omnibus replaced Article 111(2): the Regulation applies to operators of high-risk systems placed on the market or put into service before the Chapter III application date "only if, as from that date, those systems are subject to significant changes in their designs," with one carve-out, that providers and deployers of high-risk systems "intended to be used by public authorities" comply by 2 August 2030. A system you ship in 2026 and never redesign is outside the high-risk regime; a system you ship in 2026 and materially redesign in 2028 is inside it from the redesign.
The dates, after the Omnibus
The Commission's AI Act page records the sequence: the Omnibus proposal was adopted on 19 November 2025, a political agreement was reached on 7 May 2026, and the amending Regulation, published as Regulation (EU) 2026/1744, entered into force on 27 July 2026. The adopted text amends Article 113 so that Chapter III Sections 1, 2 and 3, with the exception of Article 6(5), apply from 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems classified under Article 6(1) and Annex I. Recital 40 gives the reason in plain terms: "the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities."
One thing to notice if you read commentary from earlier in the year. The Service Desk's Omnibus FAQ describes the proposal's mechanism as aligning the timeline "to the availability of standards and other support tools," with the rules applying after the Commission confirmed those were in place. The adopted Article 113 contains no such trigger. The dates are fixed, and the FAQ's own framing is that they are at most sixteen months later than originally envisaged for Annex III and twelve months later for Annex I. Do not plan for a further slip that the text does not provide.
The survey of everything else the Act asks of a US company, the roles, the authorised representative, the transparency and prohibited-practice obligations that are already in force, is in our EU AI Act guide. This article is only the classification and the assessment.
When this is not your problem
If nothing you build or deploy is in Annex III or is a safety component of an Annex I product, no conformity assessment applies and the Act reaches you, if at all, through the transparency and literacy provisions. If you are a deployer rather than a provider, the conformity assessment is your supplier's, though you will want to see their declaration of conformity and their database entry before you rely on either. And if you have run the Article 6(3) test honestly, documented it, and registered the system, you have done what the Act asks; the work then is keeping that assessment true as the system changes, since a later feature that starts profiling people converts the answer.
The case where the right advice is to stop reading is the company whose AI exposure is a general-purpose model called through an API for internal drafting. That is an acceptable use policy and an inventory row, not a conformity file.
Where Top Floor fits
We do the classification memo and the technical file, and we are explicit that we are not a notified body and do not issue certificates or declarations on anyone's behalf. Our ISO 42001 work builds the quality management system that Annex VI point 2 and Annex VII point 3 both assess, and our NIST AI RMF engagements produce the risk management and post-market monitoring evidence the Section 2 requirements and Annex IV documentation call for; how long ISO 42001 takes is a fair proxy for the management-system half of the timeline, and what 42001 certification costs is the budgeting companion to it. Where the Act is one of several regimes, because the same product is a medical device or is sold under Colorado's AI statute, that belongs inside a single international compliance program rather than a stack of parallel files.
We will also say, in writing, when your system is not high-risk. That memo is often the whole engagement.
How to decide this week
Take every row of your AI inventory and answer three questions in order. Is it a safety component of a product in Annex I Section A that needs third-party assessment, after the Omnibus's exclusion of non-safety functions and non-safety risks? Does it fall within one of the eight Annex III areas, read at the sub-point level? If yes to Annex III, does one of the four Article 6(3) conditions apply, and does the system profile natural persons?
Then put each high-risk row in the table above and note the date beside it: 2 December 2027 for Annex III, 2 August 2028 for Annex I. For the biometrics rows, assume Annex VII and open the conversation with a notified body now. For everything else in Annex III, start the Article 17 quality management system and the Annex IV technical documentation, because those are the whole assessment.
Frequently asked questions
Does every high-risk AI system need a notified body?
No. Article 43(2) sends high-risk systems in points 2 to 8 of Annex III through the internal control procedure in Annex VI, which does not involve a notified body. A notified body is required for Annex III point 1 biometric systems where harmonised standards or common specifications have not been applied in full, and it is involved for Annex I products only to the extent the sectoral product legislation already requires third-party assessment. The Commission can extend the notified body route to other Annex III systems by delegated act under Article 43(6), but it has to weigh notified body capacity in doing so.
Do we need a conformity assessment if our system is exempt under Article 6(3)?
No conformity assessment, but two obligations remain. Article 6(4) requires you to document the assessment that led you to conclude the system is not high-risk before placing it on the market, and to provide that documentation to national authorities on request. Article 49(2) requires you to register yourself and the system in the EU database, on the simplified content the Omnibus introduced. The exemption never applies where the system performs profiling of natural persons.
When do the high-risk conformity assessment obligations apply?
From 2 December 2027 for AI systems classified as high-risk under Article 6(2) and Annex III, and from 2 August 2028 for AI systems classified under Article 6(1) and Annex I, as set by Article 113 as amended by Regulation (EU) 2026/1744, in force since 27 July 2026. Systems placed on the market before those dates come into scope only if they are then subject to significant changes in their designs, except that high-risk systems intended for use by public authorities must comply by 2 August 2030.
Does ISO 42001 certification count as a conformity assessment?
No. ISO/IEC 42001 is a management system standard, and the presumption of conformity in the Act attaches to harmonised standards whose references the Commission has published in the Official Journal, and as of August 2026 the Commission's standardisation page listed none as referenced. A 42001 certificate is useful evidence for the Article 17 quality management system that both Annex VI and Annex VII assess, and it shortens the management-system part of the work. It does not demonstrate the Section 2 product requirements, and it does not replace the declaration of conformity, the technical documentation or the registration.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.