Conformity assessment and CE marking (AI Act)
What is conformity assessment and CE marking under the AI Act?
Conformity assessment is the check a manufacturer runs on its own product, against the rules for that product, before it may be sold in the EU. CE marking is the visible result: two letters saying the manufacturer did the check and takes responsibility for the answer. Machinery, toys, lifts and medical devices have worked this way for decades, and the AI Act slots high-risk AI into that same frame instead of inventing a new one.
The shape never changes. The law sets requirements, standards bodies write the technical detail, the manufacturer assesses its product against them, writes a declaration, affixes the mark and, for AI, registers the system in an EU database. A supervisor can then ask to see the file.
Two things follow, and they matter more than the detail. The mark is not a licence granted by an authority: in most cases nobody outside the company looks at anything before the product ships. And under the AI Act it covers high-risk systems only, so an "AI Act certified" badge on a chatbot or a forecasting tool is marketing, not compliance.
The two routes, and which one applies to you
Article 43 sorts every high-risk system into three situations.
Internal control, Annex VI. Article 43(2) puts points 2 to 8 of Annex III on this route, "without the involvement of a notified body". That covers everything from credit scoring and insurance pricing to recruitment, worker management and education. Every application that catches an ordinary company sits here, and the provider assesses itself.
A notified body, Annex VII. Only point 1 of Annex III, biometrics, reaches this route. Article 43(1) gives a provider that applied harmonised standards a choice between the two annexes, and makes Annex VII compulsory where no such standards exist or the provider did not apply them in full. An outside body then audits the quality management system and examines the technical documentation, with full access to the training, validation and testing data sets. Article 44(2) caps the certificate at four years for Annex III systems.
AI inside a regulated product, Annex I. Article 43(3) sends these to the assessment their own product law already requires. A machine builder runs no separate AI assessment: the AI requirements become part of the machinery assessment, and where that law brings in a notified body, it checks them too.
What has to be in place before the assessment means anything
Annex VI is three short checks. The provider verifies its quality management system complies with Article 17, examines the technical documentation to see whether the system meets the requirements of Chapter III Section 2, and verifies that the design process and the post-market monitoring match what that documentation says. All three point back at work done earlier. The assessment checks that work. It does not do it for you.
Those requirements are Articles 9 to 15: a risk management system running across the lifecycle rather than a document written once, data governance covering where the training and test data came from and what the gaps are, technical documentation in the shape of Annex IV, automatic logging, instructions for use, human oversight designed in rather than bolted on by the buyer, and accuracy, robustness and cybersecurity. Article 11(1) lets SMEs supply that documentation in a simplified form a notified body has to accept.
Article 17 adds the quality management system itself, thirteen documented aspects from design control through data management to serious incident reporting. Its second paragraph makes implementation proportionate to the size of the organisation, then adds that the rigour and the level of protection stay the same. Smaller company, shorter documents. You still answer every question.
What comes out at the end, and what sends you back to the start
The EU declaration of conformity. Article 47 asks for one per system, machine readable, physical or electronically signed, kept available to national authorities for ten years after it goes on the market. Annex V fixes the contents: system name and version, the provider's name and address, a statement that it is issued under the provider's sole responsibility, which harmonised standards were applied, and the notified body's name, identification number and certificate where one was involved.
The CE marking. Article 48 asks for it visibly, legibly and indelibly, or on the packaging where the nature of the system makes that impractical. Systems supplied digitally may use a digital CE marking, provided it can be reached from the interface the system runs in or through a machine-readable code. Where a notified body was involved, its identification number follows the mark.
The registration. Under Article 49 the provider registers itself and the system in the EU database before placing it on the market, and a provider that concluded under Article 6(3) that its Annex III system is not high-risk registers that conclusion too. Article 71 makes this information public and machine readable, which is the part a buyer can use.
Then it can send you back. Article 43(4) says a substantial modification means a new assessment. A change the provider planned for does not count: a system that keeps learning after it goes on the market stays inside its original assessment as long as the changes were pre-determined and written into the technical documentation.
This is where Article 25 bites a buyer. Modify a high-risk system substantially and you become its provider. The assessment is due before the system is placed on the market, so on the day you work out that you crossed the line, the right order is already broken.
The harmonised standards are not finished yet
Article 40 gives a presumption of conformity to a system that follows harmonised standards whose references have been published in the Official Journal. That is how a provider normally shows its risk management is adequate: point at the standard, show you applied it. Without one, you write your own definition of adequate and defend it to a supervisor.
The Commission asked CEN and CENELEC for standards in ten areas. The first arrived in July 2026: EN 18286:2026, "Artificial intelligence. Quality management system for EU AI Act regulatory purposes", written against Article 17. The rest were still drafts, among them prEN 18228 on risk management and prEN 18284 on data quality and governance.
Publication is not the finish line, and that distinction decides whether a supplier's paperwork means anything. A standard only carries the presumption once the Commission has assessed it and cited the reference in the Official Journal. On the Commission's own standardisation page, last updated 3 August 2026, no AI Act standard had been cited. Notified bodies are thin on the ground too: through the first half of 2026 none had appeared on the Commission's list for the AI Act.
That gap is the official reason the dates moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, pushed the high-risk obligations for stand-alone Annex III systems from 2 August 2026 to 2 December 2027, and for AI inside Annex I products to 2 August 2028. Articles 43, 47, 48 and 49 were not rewritten. Only the day they bite moved.
If you buy rather than build: the two documents to ask for
Almost no Belgian SME is the provider of a high-risk AI system. The value of understanding the assessment is being able to read what a supplier hands you and judge what it is worth.
Take a manufacturer of sixty people buying a CV screening tool. Recruitment sits in point 4 of Annex III, so the tool is high-risk and the vendor is the provider. Two documents belong in the purchase file.
The EU declaration of conformity. A page or two in the shape of Annex V. What tells you whether it is worth anything is point 6, the harmonised standards applied. Since no AI Act standard has been cited in the Official Journal yet, an honest declaration in 2026 names the internal method used instead. One that cites a published harmonised standard for risk management is describing something that does not exist, and one that names a notified body without an identification number is worth a second question.
The instructions for use. Article 13(3) fixes the contents: accuracy metrics and robustness testing results, foreseeable risks, how the system performs for specific groups of people, the input data it expects, the oversight measures built in, and how you collect and read the logs. That is not sales material. It is what Article 26 makes you answerable for using properly.
One caveat changes the tone of that conversation. Until 2 December 2027 the provider of a stand-alone high-risk system is not obliged to have any of it. A vendor who already holds a declaration is running ahead of the deadline. What you can reasonably ask today is when they expect one, and to be told in writing which uses the assessment will cover.
Conformity assessment versus a fundamental rights impact assessment
These two get named in the same breath and they belong to different parties at different moments.
The conformity assessment is the provider's, and it happens before the system is placed on the market. It asks whether the product is fit to be sold anywhere in the Union, once, for every buyer. Its output faces outward: a declaration, a mark, a public database entry.
The FRIA is the deployer's, and only some deployers owe one under Article 27. It happens before first use, inside one organisation, and asks what this system will do to the specific people it decides about here. Its output goes to the market surveillance authority, not to the market.
So the dimension is a supplier check against a use check. A system can carry a valid CE marking and still be the wrong system for your process, your data and the people you serve. Nothing in the provider's assessment says who in your office overrules it on a Tuesday afternoon.