Glossary · AI Act

Conformity Assessment

The process of verifying that a high-risk AI system meets the AI Act's requirements before it can be CE-marked and sold in the EU.

Explained in depth: AI Act overview

Before placing a high-risk AI system on the market, the provider must demonstrate that it meets the requirements of the act: risk management, data and data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy, robustness, and cybersecurity. For most Annex III use cases the provider performs this assessment itself, based on internal control, particularly where harmonised standards have been applied. For certain biometric systems, and for high-risk AI embedded in products already subject to third-party assessment, an independent notified body participates. The assessment concludes with an EU declaration of conformity and CE marking, plus registration in the EU database for high-risk systems. A substantial modification of the system triggers a new assessment.

Why it matters

Conformity assessment is where AI governance becomes evidence: the documentation must exist, be current, and survive scrutiny by market surveillance authorities. Providers who build the technical file alongside development, rather than reconstructing it afterwards, spend far less on this step.

Used in

See also

← All glossary terms