MDR

Most high-risk AI never sees a notified body

Article 43(2) of the EU AI Act (Regulation (EU) 2024/1689) sends providers of Annex III points 2 to 8 — critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes — down the internal-control route in Annex VI. No notified body reviews the system, no third party signs off on it. Only biometrics, Annex III point 1, ever has a notified-body option, and product AI embedded under Annex I legislation follows its own sectoral procedure instead. “The AI Act means certification” is the wrong mental model for the large majority of high-risk providers, and treating it as true is costing some of them time and money they don’t need to spend.

Which route are you on?

Three answers cover every high-risk AI system:

  • Annex VI internal control — for every Annex III category except biometrics: critical infrastructure, education, employment, essential private and public services, law enforcement, migration and border control, the administration of justice, and democratic processes. No notified body is involved at all.
  • A choice between Annex VI and Annex VII — for Annex III point 1, biometrics, but only where the provider has applied harmonised standards or common specifications to demonstrate compliance. Where that condition isn’t met, the choice disappears; that case gets its own section below.
  • The sectoral procedure — for high-risk AI covered by Annex I product legislation, such as the Medical Devices Regulation. The provider follows whatever conformity assessment that sectoral law already requires, with the AI Act’s Chapter III Section 2 requirements folded into the same assessment rather than run as a second, parallel process. Specific Annex VII provisions on quality management and change control still apply within that sectoral assessment, and a notified body already designated under the sectoral law can assess the AI-specific requirements too — provided its competence to do so has itself been separately confirmed.

The Digital Omnibus reform added a practical fix here: where a single system could plausibly fall under two different conformity regimes at once — an emotion-recognition function built into a medical device is the example regulators point to — the provider follows the sectoral procedure rather than attempting to satisfy two separate assessment programmes. Notified bodies already designated under sectoral product law have until 2 February 2028 to apply for a corresponding AI Act designation if they want to assess the AI-specific requirements themselves.

What Annex VI actually asks of you

Internal control isn’t an honour system. The provider has to verify that its quality management system complies with Article 17 — covering regulatory compliance, technical specifications, data management, risk management, monitoring and reporting — and examine its own technical documentation to confirm the system meets the Chapter III Section 2 requirements for high-risk AI.

Once that’s done, Article 47 requires a written declaration of conformity: machine-readable, signed, containing the information set out in Annex V, and translated into the language required by each Member State where the system is placed on the market or put into service. The provider keeps it, and the underlying technical documentation, available to national authorities. CE marking follows under Article 48 — visible on the system or its documentation, affixed before the system is placed on the market, and required regardless of which conformity route was used. What differs is what sits behind the mark: for Annex VI self-assessment, there’s no notified body number to attach because no notified body was involved.

The one case where the choice disappears: biometrics without applied standards

Article 43(1) makes the Annex VI/Annex VII choice conditional, not automatic, even for biometrics. It’s only available where the provider has applied harmonised standards under Article 40, or common specifications under Article 41. If those standards haven’t been fully applied, aren’t available at all, or are themselves restricted in scope, Annex VII — the notified body route — becomes mandatory. Given how much of the AI Act’s harmonised-standards work is still in progress, that’s a live trap rather than a theoretical one, and it deserves its own treatment.

The other case where the choice disappears: law enforcement and EU institutions

Separately from the standards question, Article 43(1) removes the provider’s choice of notified body entirely where a high-risk system is intended to be put into service by law enforcement, immigration or asylum authorities, or by an EU institution, body, office or agency. In those cases, the market surveillance authority named in Article 74(8) or (9) acts as the notified body. There’s no shopping for a preferred assessor; the assessor is fixed by who the deployer is.

Two free presumptions people miss

Article 42 hands providers two presumptions of conformity that a lot of compliance programmes never claim, simply because nobody goes looking for them.

First: a high-risk system trained and tested on data reflecting the specific geographical, behavioural, contextual and functional setting it’s intended to be used in is presumed to comply with the data governance requirements in Article 10(4). You still have to be able to show that fit — provenance, the population the data represents, the gap (if any) between training conditions and deployment conditions — but where you can show it, you don’t have to separately argue Article 10(4) compliance from scratch.

Second: a system already certified, or holding a statement of conformity, under a cybersecurity scheme adopted under the EU Cybersecurity Act (Regulation (EU) 2019/881) is presumed to meet Article 15’s cybersecurity requirements — to the extent the certificate actually covers them. Both halves of that qualifier matter: the scheme’s reference has to be published in the Official Journal for the presumption to attach at all, and the presumption only reaches the specific requirements the certificate scope actually addresses, not Article 15 wholesale. A certificate covering resilience to adversarial attacks doesn’t hand you a presumption on data poisoning if poisoning wasn’t in scope of the assessment.

Frequently asked questions

Does self-assessment mean no audit, ever?

No — it means no third-party notified-body audit before you place the system on the market. Annex VI still requires a genuine internal verification against Article 17, not a box-ticking exercise, and market surveillance authorities keep their ordinary ex-post inspection and enforcement powers regardless of which conformity route a provider used. Self-assessment shifts who checks first, not whether anyone ever checks.

Who signs the declaration of conformity?

The provider, or its authorised representative, under the provider’s sole responsibility. Article 47 doesn’t contemplate a notified body’s signature for Annex VI systems, because none was involved in producing it.

Do we still CE mark if we self-assessed?

Yes. CE marking under Article 48 applies to every high-risk AI system regardless of conformity route. The difference shows up in what accompanies the mark: a notified body identification number appears alongside it only where Annex VII applied.

What’s the four-year certificate rule, and does it apply to us?

Only if a notified body was involved. Article 44 caps certificates issued under Annex VII at four years for Annex III systems (five years for Annex I systems), renewable on reassessment. A pure Annex VI self-assessment never produces a notified-body certificate in the first place, so there’s no four-year clock running — what you keep instead is your technical documentation and declaration of conformity, available to authorities on request rather than expiring on a schedule.

What actually changes on 2 December 2027?

That’s when the Annex III high-risk obligations apply, following the Digital Omnibus deferral from the original 2 August 2026 date. For providers on the Annex VI route, that’s the date by which the Article 17 quality management verification and the Article 47 declaration of conformity need to actually be in place — not a date that changes which route you’re on. Don’t confuse it with the separate 2 February 2028 deadline for sectoral notified bodies to seek an AI Act designation; the two dates come from the same reform but govern different things.

Posted by admin in Public Authority & Certified Provider Integrations Knowledge Base

“Safety component” after the Omnibus: a narrower test

The Digital Omnibus narrows the definition that decides whether AI embedded in a regulated product counts as high-risk under the EU AI Act (Regulation (EU) 2024/1689). AI used solely for user assistance, performance optimisation, service efficiency or automation, or convenience or quality control no longer makes a component a “safety component” — and doesn’t trigger high-risk classification by virtue of sitting inside a regulated product — unless its failure or malfunction would actually endanger health or safety. Separately, the Machinery Regulation moved out of Annex I Section A into Section B entirely, so AI-enabled machinery now complies with sectoral safety rules instead of both regimes at once. Every guide written before May 2026 is describing a test that no longer applies.

The old test and why it swept too wide

Article 6(1) classifies an AI system as high-risk when two conditions are both met: it’s intended for use as a safety component of a product, or is itself a product, covered by the Annex I Union harmonisation legislation; and that product requires third-party conformity assessment under that legislation before it can be placed on the market. Whether an AI function counts as a “safety component” in the first place decides whether this whole test even applies.

The original definition of safety component covers a component that fulfils a safety function for a product or AI system, or whose failure or malfunction endangers the health and safety of persons or property. That second limb is where the trouble sits. Read expansively, almost any function embedded in a regulated product can be argued into it — an optimisation model inside a lift or a boiler doesn’t itself perform a safety function, but a sufficiently loose reading of “failure… endangers health and safety” could sweep it in anyway, on the theory that anything going wrong inside safety-regulated machinery carries some attenuated safety implication.

What the new test asks

The narrowed definition collapses this to one question: could the component’s failure or malfunction actually endanger health or safety? If the answer is no, and the function is assistance, optimisation, efficiency, automation, convenience, or quality control, it isn’t a safety component — regardless of what product it happens to sit inside.

Two examples on either side of the line. A predictive-maintenance model that flags when industrial machinery needs servicing is squarely an optimisation function: if it fails, the direct consequence is a missed maintenance window, not an immediate safety event, so it’s a strong candidate for falling outside the safety-component definition under the new test. A torque-limiting or collision-avoidance function built into the same machinery is a different case entirely — its failure directly creates a safety risk, which is exactly what the carve-out was never meant to exempt. The label attached to a function matters far less than what actually happens when it fails.

Annex I Section A vs Section B

This distinction decides how much of the Act applies at all. Section A covers New Legislative Framework legislation — medical devices, toys, personal protective equipment, gas appliances, and, until this reform, machinery. Section B covers other Union harmonisation legislation, including aviation security, agricultural and forestry vehicles, motor vehicle type-approval, marine equipment, and rail interoperability. For systems in Section B, only Article 6(1) itself, Articles 102 to 109, and Article 112 apply — essentially none of the Act’s substantive high-risk apparatus, the conformity assessment procedures, or the registration duties reach them at all.

The Omnibus moved only the Machinery Regulation from Section A to Section B. That’s a narrower outcome than what was actually on the table during trilogue: the deadlock that briefly collapsed negotiations centred on a Parliament proposal to exclude far more broadly — medical devices, toys, connected cars, and industrial machinery all together. The final compromise pulled back to Machinery alone. It isn’t a deregulation of industrial AI, either — the Commission is empowered to adopt delegated acts under the Machinery Regulation itself, not the AI Act, adding AI-specific health and safety requirements for systems that would otherwise have been high-risk. Oversight doesn’t disappear; it moves into the sectoral regime.

The other overlap relief, and its condition

Products that stayed in Section A — medical devices and toys among them — get a different, conditional form of relief instead of a full carve-out. Where the sectoral legislation already contains AI-specific requirements equivalent to or higher than the AI Act’s own, the Commission may, by implementing act, limit how far Articles 9 to 15 and 17 to 25 actually apply to those systems. That’s a genuinely different legal instrument from the Machinery-specific delegated acts, and it comes with its own timing: implementing acts addressing this general sectoral overlap are expected by 2 August 2027, while the Machinery-specific delegated acts are expected by 2 August 2028, tied to when Annex I obligations actually start binding. Both dates are worth putting on a calendar. Neither is a rule you can rely on today — nothing is actually limited until the Commission acts.

When any of this binds

Annex I high-risk obligations now apply from 2 August 2028 rather than 2 August 2027, under the same Digital Omnibus reform that deferred Annex III obligations to 2 December 2027. As with every date in this reform, it binds only once the amending regulation is published in the Official Journal and enters into force — as of this writing, formal adoption and publication were still pending, with the original 2 August 2026/2027 calendar remaining the legally operative one until that happens.

Frequently asked questions

Is a predictive maintenance model a safety component?

Generally not, under the narrowed test — unless the specific machine’s failure mode makes a missed service interval itself a direct safety event rather than an efficiency loss. That’s genuinely fact-specific: the same category of model can land on either side depending on what actually happens when the maintenance flag is missed.

Does the Medical Devices Regulation change?

Not in the same way. Medical devices remain in Annex I Section A — they didn’t get the Machinery-style move to Section B. What they get instead is the conditional relief described above: if the Commission determines, by implementing act, that the sectoral legislation already imposes equivalent AI-specific requirements, application of the relevant AI Act articles can be limited. Until that happens, the full parallel regime still applies.

What about toys and lifts?

Both stay in Section A, on the same footing as medical devices — eligible for the conditional implementing-act relief if the Commission acts, but not moved to Section B the way Machinery was. Lifts in particular sit under their own directive, separate from the Machinery Regulation, and nothing in this reform touched that separately.

Does “quality control” cover visual inspection?

Often, but not automatically. A visual-inspection model that flags defective units for human review before they’re used is a strong fit for the quality-control carve-out — its failure means a defect goes unflagged, not an immediate safety event. But if that inspection is the only safeguard standing between a genuinely dangerous defective unit and its use, the “failure would endanger health or safety” test can still catch it. The function’s name doesn’t decide the answer; the actual consequence of it failing does.

Who decides — us or the notified body?

The provider makes the initial classification call, consistent with how Article 6 works generally — nobody else does it for you upfront. Where third-party conformity assessment still applies, a notified body’s scope determination matters downstream, but a market surveillance authority retains the ordinary power to review a provider’s classification later and require correction if it disagrees, the same oversight mechanism that applies to Article 6(3) classification calls elsewhere in the Act.

Posted by admin in RegTech Glossary & Standards