Conformity assessment and CE marking
High-risk AI systems must undergo a formal conformity assessment to verify they comply with the mandatory requirements of the EU AI Act before being placed on the market or put into service. Once compliance is verified, the provider must affix the CE marking as visible evidence that the system meets all applicable European Union safety and transparency standards.
What it means
The conformity assessment serves as a regulatory gateway to ensure that high-risk AI systems are safe, transparent, and ethically governed before they reach users in the EU. It is not merely a checklist but a comprehensive verification process that confirms the provider has implemented necessary risk management, data governance, and technical documentation practices.
In practice, the scope of this requirement depends on the classification of the AI system. Some systems can be assessed via "internal control" (self-assessment), while others—particularly those involving sensitive biometric categories or specific high-risk use cases—may require a third-party audit by a "notified body."
The CE mark is the final output of this process. It functions as a legal declaration that the product conforms to the requirements of Regulation (EU) 2024/1689, allowing it to circulate freely within the European Single Market.
How to meet it
- Determine whether your AI system is classified as "high-risk" and identify which conformity assessment path applies (internal control vs. notified body).
- Implement a quality management system (QMS) that governs the design, development, and post-market monitoring of the AI system.
- Execute a formal risk management process to identify known and foreseeable risks and implement mitigation measures.
- Compile comprehensive technical documentation that describes the system's architecture, training datasets, validation methods, and performance metrics.
- Draft and sign an EU Declaration of Conformity stating that all requirements of the AI Act have been fulfilled.
- Affix the CE marking to the product or its packaging in a visible, legible, and indelible manner (or digitally for software-only products).
Evidence an auditor asks for
- The signed EU Declaration of Conformity.
- Complete Technical Documentation as specified by the Regulation's annexes.
- A certificate issued by a Notified Body (if third-party assessment was required) or internal audit records (if self-assessed).
- Visual evidence or screenshots showing the CE mark applied to the system, its interface, or accompanying documentation.
Common pitfalls
- Assuming that "internal control" means no formal documentation is needed; auditors require a full paper trail even for self-assessments.
- Affixing the CE marking before the conformity assessment process is fully completed and documented.
- Failing to re-evaluate conformity or update technical documentation after making "substantial modifications" to the AI system post-launch.