Article 43(2) of the EU AI Act (Regulation (EU) 2024/1689) sends providers of Annex III points 2 to 8 — critical infrastructure, education, employment, essential services, law enforcement, migration, justice and democratic processes — down the internal-control route in Annex VI. No notified body reviews the system, no third party signs off on it. Only biometrics, Annex III point 1, ever has a notified-body option, and product AI embedded under Annex I legislation follows its own sectoral procedure instead. “The AI Act means certification” is the wrong mental model for the large majority of high-risk providers, and treating it as true is costing some of them time and money they don’t need to spend.
Which route are you on?
Three answers cover every high-risk AI system:
- Annex VI internal control — for every Annex III category except biometrics: critical infrastructure, education, employment, essential private and public services, law enforcement, migration and border control, the administration of justice, and democratic processes. No notified body is involved at all.
- A choice between Annex VI and Annex VII — for Annex III point 1, biometrics, but only where the provider has applied harmonised standards or common specifications to demonstrate compliance. Where that condition isn’t met, the choice disappears; that case gets its own section below.
- The sectoral procedure — for high-risk AI covered by Annex I product legislation, such as the Medical Devices Regulation. The provider follows whatever conformity assessment that sectoral law already requires, with the AI Act’s Chapter III Section 2 requirements folded into the same assessment rather than run as a second, parallel process. Specific Annex VII provisions on quality management and change control still apply within that sectoral assessment, and a notified body already designated under the sectoral law can assess the AI-specific requirements too — provided its competence to do so has itself been separately confirmed.
The Digital Omnibus reform added a practical fix here: where a single system could plausibly fall under two different conformity regimes at once — an emotion-recognition function built into a medical device is the example regulators point to — the provider follows the sectoral procedure rather than attempting to satisfy two separate assessment programmes. Notified bodies already designated under sectoral product law have until 2 February 2028 to apply for a corresponding AI Act designation if they want to assess the AI-specific requirements themselves.
What Annex VI actually asks of you
Internal control isn’t an honour system. The provider has to verify that its quality management system complies with Article 17 — covering regulatory compliance, technical specifications, data management, risk management, monitoring and reporting — and examine its own technical documentation to confirm the system meets the Chapter III Section 2 requirements for high-risk AI.
Once that’s done, Article 47 requires a written declaration of conformity: machine-readable, signed, containing the information set out in Annex V, and translated into the language required by each Member State where the system is placed on the market or put into service. The provider keeps it, and the underlying technical documentation, available to national authorities. CE marking follows under Article 48 — visible on the system or its documentation, affixed before the system is placed on the market, and required regardless of which conformity route was used. What differs is what sits behind the mark: for Annex VI self-assessment, there’s no notified body number to attach because no notified body was involved.
The one case where the choice disappears: biometrics without applied standards
Article 43(1) makes the Annex VI/Annex VII choice conditional, not automatic, even for biometrics. It’s only available where the provider has applied harmonised standards under Article 40, or common specifications under Article 41. If those standards haven’t been fully applied, aren’t available at all, or are themselves restricted in scope, Annex VII — the notified body route — becomes mandatory. Given how much of the AI Act’s harmonised-standards work is still in progress, that’s a live trap rather than a theoretical one, and it deserves its own treatment.
The other case where the choice disappears: law enforcement and EU institutions
Separately from the standards question, Article 43(1) removes the provider’s choice of notified body entirely where a high-risk system is intended to be put into service by law enforcement, immigration or asylum authorities, or by an EU institution, body, office or agency. In those cases, the market surveillance authority named in Article 74(8) or (9) acts as the notified body. There’s no shopping for a preferred assessor; the assessor is fixed by who the deployer is.
Two free presumptions people miss
Article 42 hands providers two presumptions of conformity that a lot of compliance programmes never claim, simply because nobody goes looking for them.
First: a high-risk system trained and tested on data reflecting the specific geographical, behavioural, contextual and functional setting it’s intended to be used in is presumed to comply with the data governance requirements in Article 10(4). You still have to be able to show that fit — provenance, the population the data represents, the gap (if any) between training conditions and deployment conditions — but where you can show it, you don’t have to separately argue Article 10(4) compliance from scratch.
Second: a system already certified, or holding a statement of conformity, under a cybersecurity scheme adopted under the EU Cybersecurity Act (Regulation (EU) 2019/881) is presumed to meet Article 15’s cybersecurity requirements — to the extent the certificate actually covers them. Both halves of that qualifier matter: the scheme’s reference has to be published in the Official Journal for the presumption to attach at all, and the presumption only reaches the specific requirements the certificate scope actually addresses, not Article 15 wholesale. A certificate covering resilience to adversarial attacks doesn’t hand you a presumption on data poisoning if poisoning wasn’t in scope of the assessment.
Frequently asked questions
Does self-assessment mean no audit, ever?
No — it means no third-party notified-body audit before you place the system on the market. Annex VI still requires a genuine internal verification against Article 17, not a box-ticking exercise, and market surveillance authorities keep their ordinary ex-post inspection and enforcement powers regardless of which conformity route a provider used. Self-assessment shifts who checks first, not whether anyone ever checks.
Who signs the declaration of conformity?
The provider, or its authorised representative, under the provider’s sole responsibility. Article 47 doesn’t contemplate a notified body’s signature for Annex VI systems, because none was involved in producing it.
Do we still CE mark if we self-assessed?
Yes. CE marking under Article 48 applies to every high-risk AI system regardless of conformity route. The difference shows up in what accompanies the mark: a notified body identification number appears alongside it only where Annex VII applied.
What’s the four-year certificate rule, and does it apply to us?
Only if a notified body was involved. Article 44 caps certificates issued under Annex VII at four years for Annex III systems (five years for Annex I systems), renewable on reassessment. A pure Annex VI self-assessment never produces a notified-body certificate in the first place, so there’s no four-year clock running — what you keep instead is your technical documentation and declaration of conformity, available to authorities on request rather than expiring on a schedule.
What actually changes on 2 December 2027?
That’s when the Annex III high-risk obligations apply, following the Digital Omnibus deferral from the original 2 August 2026 date. For providers on the Annex VI route, that’s the date by which the Article 17 quality management verification and the Article 47 declaration of conformity need to actually be in place — not a date that changes which route you’re on. Don’t confuse it with the separate 2 February 2028 deadline for sectoral notified bodies to seek an AI Act designation; the two dates come from the same reform but govern different things.
