Conformity assessment
Conformity assessment is the procedure by which a provider demonstrates that a high-risk AI system meets the requirements laid down in Section 2 of Chapter III of the Regulation — risk management, data governance, documentation, human oversight, and the rest. For systems falling under points 2–8 of Annex III, internal control suffices; involvement of a notified body is typically mandatory only for biometric systems.
The procedure is governed by Article 43. Self-assessment through internal control (Annex VI) is the dominant route: in HR, education, creditworthiness assessment and essential-services areas, the provider itself declares conformity, without involving a notified body. The exception is the category of biometric systems, where third-party assessment becomes mandatory if no harmonised standard has been applied. For AI embedded in regulated products under Annex I, conformity assessment must be carried out within the applicable sectoral procedure, integrated into a single set of documentation. In the absence of a harmonised standard, conformity assessment does not become less mandatory — only the manner of proof becomes harder: the provider must itself demonstrate that it meets the requirement level set out in Annex IV, without a presumption of conformity. Once conformity assessment is complete, the EU declaration of conformity can be issued and the CE marking affixed.
Good news for most SMEs introducing high-risk AI: internal control suffices — there is no need to engage an expensive external certification body, but documented self-assessment is not optional either.
Need documented AI-literacy training?
Article 4 is a duty of diligence: what counts is not knowledge in the abstract, but demonstrable, documented effort. Our starter package lets you begin free.
Start freeRelated terms
- High-risk AI systemAn AI system is high-risk if it is a safety component of, or is itself, a product covered by the Union product-safety legislation listed in Annex I, or if it falls within one of the eight areas and listed use cases of Annex III. Classification attaches to the intended purpose, not to the underlying technology.
- EU declaration of conformityThe EU declaration of conformity is the provider's written statement that a high-risk AI system meets the applicable requirements of the Regulation. It must be drawn up per system, made available to the market surveillance authority, and kept for at least ten years after the system is withdrawn from the market.
- CE markingThe CE marking is the high-risk AI system provider's declaration that the system complies with the Regulation's requirements. It must be affixed, after the conformity assessment procedure is completed, visibly, legibly and indelibly to the system or its packaging, or — where this is not possible — to the accompanying documentation.
- Notified bodyA notified body is an independent third party designated by a Member State to take part in the conformity assessment of certain high-risk AI systems. For systems falling under points 2–8 of Annex III — HR, education, creditworthiness assessment, essential services — internal control always suffices; a notified body is practically relevant only for biometric systems, and even there it is mandatory only in the absence of a harmonised standard.
- Harmonised standardA harmonised standard is a technical standard developed on the basis of a Union standardisation request, whose application creates a presumption of conformity: a provider that follows it is presumed to meet the corresponding requirement. As of mid-2026, harmonised standards covering the AI Act's high-risk requirements had not yet been finalised, so the presumption of conformity is not currently available.
Related questions in the knowledge base (Hungarian)
- Mikor elég a belső kontroll, és mikor kell bejelentett szervezet a magas kockázatú AI-nál?A III. melléklet 2–8. pontja szerinti rendszereknél — HR, oktatás, hitelbírálat, alapvető szolgáltatások — mindig elég a VI. melléklet szerinti belső kontroll, bejelentett szervezet nélkül. A szolgáltató maga nyilatkozik. Bejelentett szervezet gyakorlatilag csak a biometrikus rendszereknél kerül szóba, és ott is csak akkor kötelező, ha harmonizált szabvány nem áll rendelkezésre vagy nem alkalmazták.
- Mit jelent a 2027. december 2-i és 2028. augusztus 2-i határidő egy fejlesztő cégnek?Nem szünetet jelent, hanem eltolt kapudátumot. A megfelelőségértékelést nem lehet utólag ráilleszteni egy kész rendszerre, ezért a tervezési döntéseket most kell meghozni. Az önálló, III. melléklet szerinti magas kockázatú rendszerekre 2027. december 2., a szabályozott termékbe ágyazottakra 2028. augusztus 2. a határidő.
- Kötelező-e tanúsított minőségirányítási rendszer, és elég-e az ISO/IEC 42001?Tanúsított rendszer nem kötelező: a 17. cikk dokumentált minőségirányítási rendszert követel, nem akkreditált tanúsítványt. Az ISO/IEC 42001 hasznos váz, de nem harmonizált szabvány, így a 40. cikk szerinti megfelelőségi vélelmet nem keletkezteti, és önmagában nem fedi le a 17. cikk (1) valamennyi pontját.