Direct answer
How do conformity assessment and CE marking work for AI?
This falls under articles 43-49: conformity assessment, CE and registration. That obligation applies today. The provision itself applies then, but it only acquires an object once a high-risk AI system exists; through Annex III that is from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- For most Annex III systems internal control suffices (Annex VI); a notified body is required for certain biometrics and where harmonised standards are lacking.
First step: Complete the conformity route before market placement.
You describe: You want to know when an AI system needs a conformity assessment and CE marking and who performs it. Likely role: provider (the deployer checks for it when buying).
This applies now
Coming up
- Annex III: high-risk AIfrom 2 December 2027
- Article 20: corrective actions and duty of informationfrom 2 December 2027
- Article 16: the twelve duties of a provider of a high-risk AI systemfrom 2 December 2027
- Article 18: documentation keepingfrom 2 December 2027
Depends on your situation
- Article 61: informed consent of test subjects for testing in real world conditionsArticle 60(4), point (i), with Article 61(1)
These provisions only apply once the stated fact is established. The locator says which provision settles it.
High-risk AI undergoes a conformity assessment before market placement and then carries a CE marking. For most Annex III systems this runs via the provider’s internal control; for certain biometrics and for AI in regulated products a notified body is involved. The duty follows the timeline: Annex III from 2 December 2027, Annex I from 2 August 2028. For buyers: ask your supplier for it.
Your first actions
- Complete the conformity route before market placement. Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
- Set up the procedure for corrective actions and notification. Work out the four measures in paragraph 1 as scenarios with an owner and a lead time, keep a record per system version of who runs it and how you reach that party, and set out the route along which the investigation of causes, the notification to the market surveillance authorities and the message to the notified body run once paragraph 2 comes into play.
Record this
- Conformity file
- Article 49(2) registration record for the system assessed as not high-risk
- Record of corrective actions
education
Toys: manufacturer opts for internal control based on standards
A toy manufacturer whose product contains an AI system as a safety component applies harmonised standards and thereby opts for a conformity assessment procedure without third-party involvement.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether AI as a safety component falls under the Annex I product legislation. The document is a consultation version: non-binding and not yet final.
Opting for internal control based on harmonised standards without a third party changes your procedure but not the classification: the system remains high-risk and the accompanying obligations still apply.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex I and product legislation
education
Admission system at a higher education institution: who registers in the EU database
A higher education institution procures an AI system that organises student applications and enrolment and produces an admission recommendation for each candidate in its vocational programmes. The supplier says it handles the conformity assessment itself and affixes the CE marking. What is left unresolved is whether the institution still has a step of its own to take before the system goes into use in its teaching.
Provenance: Article 43(2) provides that for high-risk AI systems referred to in points 2 to 8 of Annex III, providers follow the conformity assessment procedure based on internal control set out in Annex VI, which does not provide for the involvement of a notified body. Article 47(1) requires the provider to draw up, for each high-risk AI system, a written machine-readable, physical or electronically signed EU declaration of conformity and to keep it at the disposal of the national competent authorities for ten years after the system has been placed on the market or put into service. Article 49(1) requires the provider or, where applicable, the authorised representative to register themselves and their system in the EU database referred to in Article 71 before an Annex III high-risk system is placed on the market or put into service, with the exception of the systems listed in point 2 of Annex III. Article 49(3) provides that deployers that are public authorities or Union institutions, bodies, offices or agencies, or persons acting on their behalf, register themselves, select the system and register its use in that same database before putting such a system into service or using it, again with the exception of the systems listed in point 2 of Annex III.
We read Article 49 as two separate registrations: paragraph 1 covers the provider and its system, paragraph 3 covers your own use, and on that reading the first does not relieve you of the second. The hinge question for the institution is therefore not whether the supplier does its job, but whether it is a public authority within the meaning of paragraph 3. The Regulation does not define that term, and until that is settled it remains open whether the institution must itself appear in the EU database. In practice we would move the request for the EU declaration of conformity and the registration number into the procurement stage, so that the question does not turn into a blocker just before an application period opens.
Editorial example. The rule above is in the Regulation. The situation was written by us to show how that rule plays out in this sector, and is not taken from a worked case in official guidance.
Article 43(2), Article 47(1) and Article 49(1) and (3)
education
Candidate recommendation that automatically becomes a decision
An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
education
Application file handling at an educational institution
An educational institution uses AI for application file handling: indexing, searching, text and speech processing, translation of documents submitted with applications, and extracting, transforming and organising the collected data into a usable format.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Indexing, searching, translating and reorganising application files remains preparatory work, as long as the system leaves the substantive judgment on the application entirely to the institution.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
Annex I lists legislation, not products
The draft guidelines of 19 May 2026, published for consultation and expressly non-binding, clarify that Annex I AI Act does not list individual products to be classified as high-risk, but Union harmonisation legislation regulating the safety aspects of certain products. Whether an AI system falls within the scope of Annex I therefore depends on whether the system, or the product of which it is a safety component, falls within the material scope of one of the listed legislative acts. According to the draft guidelines the list in Annex I is exhaustive; products can only be added or removed by amending the scope of the harmonisation legislation itself or by adding new harmonisation legislation to Annex I. The draft guidelines also state that through Article 6(1) the AI Act does not itself extend the scope of harmonisation legislation to new or additional products, and that the AI Act does not determine or change the risk profile of a product but builds on the sectoral risk classification. Products mentioned include machinery, toys, lifts, equipment and protective systems for potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, and products in the automotive and aviation sectors.
Draft guidelines Annex I, points (23) to (26)
Section A and Section B of Annex I trigger different requirement sets
The Commission draft guidelines of 19 May 2026, which are non-binding as long as the final version has not been adopted, draw a distinction that is often missed in practice. AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section A of Annex I are subject to the requirements for high-risk systems in Section 2 of Chapter III AI Act. By contrast, for AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 AI Act apply. The draft guidelines refer to Article 2(2) AI Act for this. Section A contains harmonisation legislation based on the New Legislative Framework, Section B the other Union harmonisation legislation.
Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act
Two cumulative conditions for high-risk under Annex I
The European Commission draft guidelines of 19 May 2026, which are expressly non-binding and not final, read Article 6(1) as two cumulative conditions. First, the AI system must be intended to be used as a safety component of a product, or the AI system must itself be a product, covered by the Union harmonisation legislation listed in Annex I. Second, that product, or the AI system itself where it is the product, must be required to undergo a third-party conformity assessment. The draft guidelines state explicitly that not all AI systems that are components of regulated products are high-risk, but only the subset that satisfies both criteria.
Draft guidelines Annex I, points (27) and (21)
The Article 6(3) filter: four exhaustive grounds, to be read narrowly
According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, Article 6(3) sets out four grounds on which a provider may exempt a system from high-risk classification: performing a narrow procedural task, improving the result of a previously completed human activity, detecting decision-making patterns or deviations from prior patterns without replacing or influencing the previously completed human assessment absent proper human review, and performing a preparatory task. Paragraph (88) of this draft states these grounds are exhaustive but alternative, that there is no separate independent risk test, and that they must be interpreted narrowly because Article 6(3) is an exception to rules that among other things protect fundamental rights. Paragraph (87) states the filter applies only to systems under Article 6(2) and not to systems under Article 6(1). Paragraph (89) states a system always remains high-risk where it performs profiling. Paragraph (90) adds that the filter does not apply where the system forms part of a complex system whose combined intended purpose or joint outputs materially influence an individual decision, including agentic AI. Paragraphs (113) to (116) of this draft describe that this is a self-assessment by the provider, that Article 6(4) requires documenting the assessment before placing on the market and registering in the Article 71 EU database, and that the assessment must contain at least the intended purpose, why the system falls under Article 6(2), which Article 6(3) condition applies and why, and why the system does not perform profiling. Paragraph (117) of these draft guidelines points to Articles 80 and 99 where an authority finds a system was misclassified as non high-risk to circumvent the rules.
Draft guidelines on high-risk AI classification (19 May 2026), Annex III chapter, sections 2.7, 2.7.1, 2.7.3 and 2.7.4, paragraphs (84) to (90) and (113) to (117)
prEN 18285: conformity assessment framework for AI systems
prEN 18285 (Conformity assessment framework) is the JTC 21 deliverable under M/613 covering the conformity assessment of high-risk AI systems under Article 43 and Annex VII of the AI Act. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal. Standardisation request M/613 was amended by Implementing Decision C(2025)3871 of 23 June 2025 and expires on 28 February 2027.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation