EU AI Act conformity: Self-assessment vs notified body review explained

5 min readLast reviewed 23 July 2026
In short

Article 43 of the EU AI Act sets two conformity assessment routes for high-risk AI systems: self-assessment (Annex VI) or notified body review (Annex VII). Most Annex III systems self-assess. Only biometric systems without harmonised standards, and AI embedded in regulated products, require a notified body.

What conformity assessment actually requires

Before a high-risk AI system can be placed on the EU market or put into service, its provider has to complete a conformity assessment: a formal check that the system meets the requirements of Chapter III of the EU AI Act (Articles 9 to 15), covering risk management, data governance, technical documentation, logging, transparency, and human oversight.

Article 43 sets out how that check happens, and it is not the same process for every high-risk system. For most standalone high-risk systems listed in Annex III, points 2 to 8 (employment, education, essential services, law enforcement, migration, and the administration of justice), the provider assesses compliance internally, with no external body reviewing the file before the system goes live. Biometric systems under Annex III, point 1, and AI systems embedded in products already regulated under Annex I (medical devices, machinery, and similar), follow a different path that can require a notified body. 

Confusing the two routes is one of the more common and costly mistakes in EU AI Act planning.

The two routes of assessment under Article 43

 
System categoryDefault routeIs a notified body required?Legal basis
Annex III, point 1: biometric identification, biometric categorisation, and covered emotion recognition use casesProvider's choice between self-assessment (Annex VI) and notified body assessment (Annex VII)Only if harmonised standards (Article 40) or common specifications (Article 41) are not available or not fully appliedArticle 43(1)
Annex III, points 2 to 8: critical infrastructure, education, employment, essential services, law enforcement, migration/asylum/border control, administration of justiceSelf-assessment (Annex VI)No, under the current textArticle 43(2)
Annex I safety components: medical devices, machinery, toys, lifts, and other regulated productsThe conformity assessment procedure required under that product's own sectoral legislationDepends on the sectoral legislation, but frequently yesArticle 43(3)
Any Annex III, point 1 biometric system intended for use by law enforcement, immigration, or asylum authorities, or by EU institutions, bodies, or agenciesAssessment under Annex VIIYes, but the relevant market surveillance authority performs the notified body role itselfArticle 43(1)

Note that Article 43(6) allows the European Commission to later require notified body involvement for some of the Annex III, points 2 to 8 categories through a delegated act. As of this writing, no such delegated act has been adopted, so self-assessment remains the only route for that group.

The Digital Omnibus also narrowed what counts as a safety component under Article 6(1) for the Annex I route in the table above: AI used solely for non-safety purposes, such as user assistance, optimisation, service efficiency, automation, convenience, or non-safety quality control, no longer qualifies, even where it is embedded in an otherwise regulated product. Only AI whose failure or malfunction would endanger health or safety still triggers this route. The Digital Omnibus also streamlines notified body designation and clarifies conformity assessment routes for products containing high-risk AI, though the detailed mechanics were not yet available at the time of writing.

What each route actually involves

Self-assessment (Annex VI):

  • The provider verifies that its quality management system complies with Article 17.
  • The provider examines its own technical documentation against the Chapter III, Section 2 requirements.
  • The provider verifies that the system’s design, development process, and post-market monitoring (Article 72) are consistent with that technical documentation.
  • The provider signs the EU declaration of conformity without external sign-off.

Notified body assessment (Annex VII):

  • The provider submits its quality management system and technical documentation to an accredited notified body.
  • The notified body reviews the file and, if compliant, issues a certificate.
  • The certificate is subject to ongoing surveillance audits by the notified body for as long as the system stays on the market.
  • The provider still signs the declaration of conformity, backed by the notified body’s certificate.

A successful assessment gets your organisation a EU declaration of conformity (Article 47), the right to affix the CE marking (Article 48) as well as a registration of the system in the EU database for high-risk AI systems (Article 49).

When companies need a new conformity assessment

Under Article 43(4), a high-risk AI system that has already completed conformity assessment must undergo a new assessment following a substantial modification, regardless of whether the modified system is distributed further or continues to be used by its original deployer. There is one carve-out: for AI systems that keep learning after deployment, changes that the provider already predetermined and documented in the Annex IV technical documentation at the time of the original assessment do not count as a substantial modification.

Overall, conformity assessment is not a badge earned once and kept forever. Retrain a model in a way that changes its risk profile, and the earlier assessment stops covering the system as it now actually exists, no matter how much time or money went into the original one.

Where the Digital Omnibus changes the timeline for conformity assessments

  • The Regulation (EU) 2026/1744 was published in the Official Journal in July 2026 and entered into force on 27 July 2026.
  • Stand-alone Annex III conformity assessment obligations now move from 2 August 2026 to 2 December 2027, and Annex I embedded high-risk systems move from 2 August 2027 to 2 August 2028.

The requirements themselves have not gotten any lighter. What has moved is the date by which a provider needs to have them ready, which currently is 2 December 2027 for most standalone high-risk systems.

How Deeploy helps conform with the EU AI Act

Whichever route applies, conformity assessment is not a one-time event. Both routes assume the technical documentation, risk management evidence, and monitoring data stay accurate for as long as the system is on the market, not only on the day the CE marking was affixed. Deeploy keeps the model cards, performance baselines, and monitoring logs that a self-assessed file depends on, and that a notified body will ask to see again at a surveillance audit, in one place, tied to how the system actually behaves in production.

Frequently asked questions

Disclaimer

This is general information, not legal advice. Please consult your legal/compliance team to confirm your organisation’s specific obligations. Deeploy supports your governance process; it does not constitute a guarantee of regulatory compliance.

Reading about compliance is step one. Operating it is Deeploy.See how teams use Deeploy to monitor, document and govern their AI against the EU AI Act.
Book a Demo

Thank you for subscribing!

You will receive a confirmation shortly.

Build audit-ready AI governance from day one