← Course outline
Aavistus Training · ai-act · AIA.07

Conformity assessment, CE marking and registration

What you'll learn

The route to market for high-risk systems: conformity-assessment procedures (internal control vs notified body), EU declaration of conformity, CE marking, and EU-database registration duties.

Regulation — cited to the current EU text

Which conformity assessment procedure applies

The procedure a provider must follow depends on which point of Annex III the system falls under and whether harmonised standards or common specifications exist.

Annex III point 1 systems. Where the provider has applied harmonised standards under Article 40 or, where applicable, common specifications under Article 41, the provider may choose between two routes: internal control under Annex VI, or assessment of the quality management system and technical documentation with involvement of a notified body under Annex VII 32024R1689 Article 43@2024-06-13.

That choice collapses into a mandatory Annex VII procedure where: harmonised standards do not exist and common specifications are not available; the provider has not applied, or has applied only part of, the harmonised standard; common specifications exist but the provider has not applied them; or one or more harmonised standards has been published with a restriction, and only on the restricted part 32024R1689 Article 43@2024-06-13.

Selection of notified body. Where Annex VII applies, the provider may generally choose any notified body. However, for the purposes of the conformity assessment procedure referred to in Annex VII, where the system is intended to be put into service by law enforcement, immigration or asylum authorities, or by Union institutions, bodies, offices or agencies, the market surveillance authority referred to in Article 74(8) or (9) shall act as a notified body 32024R1689 Article 43@2024-06-13.

Annex III points 2–8 systems. Providers follow the internal control procedure under Annex VI only. Notified body involvement is not provided for 32024R1689 Article 43@2024-06-13.

Systems covered by Union harmonisation legislation listed in Section A of Annex I. The provider follows the conformity assessment procedure required under those legal acts, with the AI Act's Section 2 requirements incorporated into that assessment. Points 4.3., 4.4., 4.5. and the fifth paragraph of point 4.6 of Annex VII shall also apply 32024R1689 Article 43@2024-06-13. Where a legal act listed in Section A of Annex I enables the product manufacturer to opt out from a third-party conformity assessment on the basis that all harmonised standards covering all relevant requirements have been applied, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter 32024R1689 Article 43@2024-06-13.

Substantial modifications and continuous-learning systems

A system that has already passed conformity assessment must undergo a new procedure upon any substantial modification, regardless of whether the modified system is further distributed or continues in use by the current deployer 32024R1689 Article 43@2024-06-13.

For systems that continue to learn after being placed on the market or put into service, changes to the system and its performance do not constitute a substantial modification where those changes were pre-determined by the provider at the moment of the initial conformity assessment and are part of the information contained in the technical documentation referred to in point 2(f) of Annex IV 32024R1689 Article 43@2024-06-13.

EU declaration of conformity

For each high-risk AI system, the provider draws up an EU declaration of conformity. The declaration may take the form of a machine-readable document, a physical document, or an electronically signed document — these are alternative forms, not cumulative requirements 32024R1689 Article 47@2024-06-13. The provider keeps the declaration available to national competent authorities for ten years after the system has been placed on the market or put into service 32024R1689 Article 47@2024-06-13.

The declaration states that the system meets the Section 2 requirements, contains the information set out in Annex V, and must be translated into a language easily understood by the national competent authorities of each Member State where the system is placed on the market or made available 32024R1689 Article 47@2024-06-13. Where the system is also subject to other Union harmonisation legislation requiring a declaration of conformity, a single declaration covering all applicable Union law is drawn up 32024R1689 Article 47@2024-06-13.

By drawing up the EU declaration of conformity, the provider assumes responsibility for compliance with the Section 2 requirements. The provider keeps the declaration up-to-date as appropriate 32024R1689 Article 47@2024-06-13.

CE marking

The CE marking is subject to the general principles set out in Article 30 of Regulation (EC) No 765/2008 32024R1689 Article 48@2024-06-13.

For high-risk AI systems provided digitally, a digital CE marking shall be used, but only if it can easily be accessed via the interface from which the system is accessed, or via an easily accessible machine-readable code, or via other electronic means 32024R1689 Article 48@2024-06-13.

For high-risk AI systems, the CE marking is affixed visibly, legibly and indelibly. Where that is not possible or not warranted on account of the nature of the high-risk AI system, it is affixed to the packaging or to the accompanying documentation, as appropriate 32024R1689 Article 48@2024-06-13.

Where a notified body was involved, the CE marking is followed by that body's identification number, affixed by the body itself or, under its instructions, by the provider or the provider's authorised representative. The identification number must also be indicated in any promotional material that mentions the system fulfils the requirements for CE marking 32024R1689 Article 48@2024-06-13.

Where the system is also subject to other Union law providing for CE marking, the marking indicates compliance with that other law as well 32024R1689 Article 48@2024-06-13.

Registration in the EU database

Before placing on the market or putting into service a high-risk AI system listed in Annex III — with the exception of systems referred to in point 2 of Annex III — the provider or, where applicable, the authorised representative registers themselves and their system in the EU database referred to in Article 71 32024R1689 Article 49@2024-06-13.

Before placing on the market or putting into service an AI system for which the provider has concluded under Article 6(3) that it is not high-risk, that provider or, where applicable, the authorised representative registers themselves and that system in the EU database 32024R1689 Article 49@2024-06-13.

Before putting into service or using a high-risk AI system listed in Annex III — again with the exception of point-2 systems — deployers that are public authorities, Union institutions, bodies, offices or agencies, or persons acting on their behalf, must register themselves, select the system, and register its use in the EU database 32024R1689 Article 49@2024-06-13.

For systems in the areas of law enforcement, migration, asylum and border control management (Annex III points 1, 6 and 7), registration takes place in a secure non-public section of the EU database; access is limited to the Commission and the national authorities referred to in Article 74(8) 32024R1689 Article 49@2024-06-13.

High-risk AI systems listed in Annex III point 2 are registered at national level rather than in the EU database 32024R1689 Article 49@2024-06-13.

Your operations manual

This block connects to your organisation's own AI governance policy. In the full product it shows, cited to your policy, how YOUR organisation implements the regulation above — private to your organisation. (Demo placeholder.)

Real-world context — illustrative only

The following material is labeled illustrative context only, not regulatory guidance or legal interpretation.

The Minneapolis police drone programme debate CASE-2 illustrates public sensitivity around law enforcement authorities deploying AI-assisted surveillance systems. Nearly fifty community members appeared at a City Council committee meeting to raise privacy objections to a proposed drone programme, reflecting the heightened scrutiny that attaches to systems used by public-safety bodies. This maps directly onto the EU AI Act's separate procedural track for such systems: where Annex VII applies to a system intended for law enforcement use, the market surveillance authority — not a commercial notified body chosen by the provider — shall act as conformity assessor; and registration for law enforcement, migration, asylum and border-control systems goes into a secure non-public section of the EU database rather than the public register. The political controversy visible in the Minneapolis case partly explains why the EU framework maintains a more controlled oversight pathway for this category.

CASE-1 (Quebec/US trade dispute over alcohol) has no substantive connection to AI conformity assessment and is not drawn upon here.

Check your understanding

1. Under what circumstance does an Annex III point 1 provider lose the option to use internal control (Annex VI) and must instead use the Annex VII procedure involving a notified body?

2. When a high-risk AI system covered by Annex VII is intended to be put into service by law enforcement authorities, who acts as the notified body?

3. After a continuous-learning system is placed on the market, under what condition do changes arising from its continued learning NOT constitute a substantial modification requiring a new conformity assessment?

4. For how long must a provider keep the EU declaration of conformity available to national competent authorities?

5. Which Annex III systems must be registered in the secure non-public section of the EU database rather than the general public section?