LinkedInInstagramXTikTok

Conformity assessment and CE marking for high-risk AI under the EU AI Act

If your business builds an AI system that falls into the EU AI Act’s high-risk category, deciding that it is high-risk is only the beginning. Before such a system can be placed on the market or put into service, it must go through a conformity assessment and, in most cases, carry a CE marking. This guide explains what that process involves, the two routes through it, and when the obligations bite.

What conformity assessment means

Conformity assessment is the formal process of demonstrating — and documenting — that a high-risk AI system meets the Act’s requirements before it goes to market. Those requirements include a risk management system, data governance, technical documentation, record-keeping, transparency, human oversight, and an appropriate level of accuracy, robustness and cybersecurity. The assessment is the provider’s evidence that all of this is genuinely in place.

Two routes through the assessment

Internal control (self-assessment)

For most high-risk systems listed in Annex III, the provider can carry out the assessment itself through an internal-control procedure. The provider verifies that its quality management system and technical documentation meet the requirements, without a third party signing off. This does not make it light-touch: the obligations are substantial and must be genuinely met.

Notified body involvement

In certain cases — and for high-risk AI that forms a safety component of products already regulated under EU law — an independent notified body must assess conformity. Where a third party is involved, they examine the technical documentation and the provider’s systems before conformity can be declared.

The core steps

Whichever route applies, providers need to establish a risk management system that runs across the AI’s lifecycle; ensure data governance and quality for training, validation and testing data; prepare technical documentation demonstrating compliance; put a quality management system in place; and test that the system performs to the required standard. These are ongoing disciplines, not a one-off checklist.

Declaration of conformity, CE marking and registration

Once the assessment is complete, the provider draws up an EU declaration of conformity and affixes the CE marking, signalling that the system complies with the applicable EU rules. Providers must also register high-risk systems in the EU database maintained for that purpose before placing them on the market. Together these steps make compliance visible to authorities and downstream users.

When the obligations apply

Timing depends on the type of high-risk system. Obligations for the high-risk uses listed in Annex III — such as recruitment or credit scoring — apply from 2 December 2027. That date was originally 2 August 2026, but the Digital Omnibus on AI, Regulation (EU) 2026/1744, deferred it when it entered into force on 27 July 2026. For high-risk AI that is a safety component of products covered by existing EU product legislation under Annex I, the obligations follow a longer runway, applying from 2 August 2028 after the same deferral. Providers should confirm which category and date apply to them.

It does not stop at launch

Conformity is not a moment but a continuing state. Providers must operate post-market monitoring, keep documentation current, and reassess conformity after substantial modifications to the system. Serious incidents must be reported. In short, the CE marking is a commitment to ongoing compliance, not a one-time certificate.

How Lawgent can help

Lawgent helps providers of high-risk AI navigate conformity assessment — from classification and technical documentation to declarations, registration and post-market duties. Contact us for practical support in bringing a compliant AI system to market.

0Varukorg0,00 

Inga produkter i varukorgen.

Gå tillbaka till butiken