Module 7 of the AI Act Provider certification: choosing between Annex VI internal control and Annex VII notified body assessment, the EU declaration of conformity, CE marking, and the Art. 49 database entry.

This module covers the sequence that turns a compliant system into a lawfully marketable one, and the order matters: assessment, then declaration, then marking, then registration, then market.

Art. 43 — which route

The choice is set by the annex the system falls under and, within Annex III, by which point.

Annex III, points 2 to 8. Conformity assessment based on internal control (Annex VI). The provider verifies that its quality management system complies with Art. 17, examines the technical documentation, and verifies consistency between the design and development process and the system as built. No notified body.

Annex III, point 1 — biometrics. Where the provider has applied harmonised standards or, where applicable, common specifications, it may use Annex VI. Where it has not applied them, or where they do not exist, the route is Annex VII — assessment of the quality management system and of the technical documentation by a notified body.

Annex I products. The AI Act conformity assessment is carried out as part of the conformity assessment procedure required under the relevant sectoral legislation. If that legislation requires third-party assessment, the notified body designated under it also assesses the AI Act requirements. There is no separate parallel AI Act procedure.

The single most common planning error here is budgeting for a notified body on an Annex III point 4 employment system. It does not need one.

Reassessment

A high-risk system that has undergone a conformity assessment shall undergo a new conformity assessment whenever it is substantially modified, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer.

For systems that continue to learn after being placed on the market, changes to the system and its performance that have been pre-determined by the provider at the moment of the initial conformity assessment and are part of the information in the technical documentation are not a substantial modification. This is why Module 5 insisted that continuous-learning behaviour and its bounds be declared up front: declaring them is what keeps ordinary model updates out of the reassessment cycle.

Art. 47 — the EU declaration of conformity

The provider shall draw up a written machine-readable, physical or electronically signed EU declaration of conformity for each high-risk system, and keep it at the disposal of national competent authorities for ten years after the system has been placed on the market or put into service. It shall identify the system for which it has been drawn up.

The declaration shall state that the high-risk system meets the requirements set out in Chapter III Section 2, contain the information set out in Annex V, and be translated into a language that can be easily understood by the national competent authorities of the Member States in which the system is placed on the market or made available.

Where a system is subject to other Union harmonisation legislation also requiring a declaration of conformity, a single declaration shall be drawn up in respect of all applicable acts — one document, all regimes.

And the sentence that matters most: by drawing up the declaration, the provider assumes responsibility for compliance. It is a signature, not a formality, and the natural person who signs should understand what the technical documentation does and does not demonstrate.

Art. 48 — CE marking

The CE marking is subject to the general principles of Regulation (EU) 765/2008. It shall be affixed visibly, legibly and indelibly for high-risk AI systems; where that is not possible or warranted given the nature of the system, it shall be affixed to the packaging or the accompanying documentation.

For digital high-risk systems, a digital CE marking shall be used only if it can be easily accessed via the interface from which the system is accessed, or via an easily accessible machine-readable code or other electronic means.

Where applicable, the CE marking shall be followed by the identification number of the notified body responsible for the conformity assessment procedures — and that number shall also be indicated in any promotional material stating that the system fulfils the CE marking requirements.

Two points that cause trouble. A software high-risk system still bears a CE marking; there is no exemption for the absence of a physical object. And the marking must not be affixed before the assessment and the declaration are complete, which is why the sequence in this module runs the way it does.

Art. 49 — registration in the EU database

Before placing on the market or putting into service an Annex III high-risk system, the provider or, where applicable, the authorised representative shall register themselves and their system in the EU database referred to in Art. 71.

Providers that have concluded, under Art. 6(3), that their Annex III system is not high-risk shall register themselves and that system under Art. 49(2). The derogation removes obligations; it does not remove you from the database.

Before putting into service or using a high-risk system listed in Annex III, deployers that are public authorities, Union institutions, bodies, offices or agencies, or persons acting on their behalf, shall register themselves, select the system and register its use.

The database is publicly accessible, with the exception of systems in the law enforcement, migration, asylum and border control areas, whose registration sits in a secure non-public section accessible to the Commission and to national authorities.

The public nature of the database is a strategic fact, not a filing detail: your registration is visible to your customers, your competitors and to anyone doing vendor due diligence — including deployers who have been taught to ask for your Art. 49 reference.

The order, and the dates

  1. Complete the technical documentation (Art. 11) — before market placement.
  2. Run the conformity assessment (Art. 43) against it.
  3. Draw up and sign the EU declaration of conformity (Art. 47).
  4. Affix the CE marking (Art. 48).
  5. Register in the EU database (Art. 49).
  6. Place on the market or put into service.
  7. Keep everything for ten years (Art. 18), and monitor (Art. 72).

Those obligations apply to standalone Annex III systems from 2 December 2027, and to AI embedded in Annex I regulated products from 2 August 2028, following the Digital Omnibus deferrals.

Check yourself

  1. We need a notified body for our recruitment screening system.Almost certainly not. Annex III point 4 uses Annex VI internal control; the notified body route applies to point 1 biometrics in defined circumstances and to Annex I products via sectoral law.
  2. Our system is software only, so CE marking does not apply.It does. Where physical affixing is not possible, the marking goes on packaging or accompanying documentation, and a digital marking must be easily accessible from the interface.
  3. We rely on Art. 6(3), so we are not in the database.Art. 49(2) requires registration precisely in that case.
  4. Our model updates weekly. Does each update need a new conformity assessment?Not if the changes were pre-determined at the initial assessment and are described in the technical documentation. Otherwise a substantial modification triggers reassessment.

Previous: Module 6 — Accuracy, robustness, cybersecurity, and the QMS Next: Module 8 — After the market: monitoring and incidents →

Frequently Asked Questions

Less often than assumed. For most Annex III systems, Art. 43 allows conformity assessment based on internal control under Annex VI. A notified body under Annex VII is required for Annex III point 1 biometric systems in defined circumstances — broadly, where the provider has not applied harmonised standards or common specifications. For Annex I products, the route follows the underlying sectoral legislation, which frequently does require a third party.

A written, machine-readable, physical or electronically signed statement drawn up by the provider for each high-risk AI system, asserting that the system meets the Chapter III Section 2 requirements. It identifies the system, names the provider, and is kept at the disposal of national competent authorities for ten years. By drawing it up, the provider assumes responsibility for compliance.

Providers of Annex III high-risk systems register the system before placing it on the market or putting it into service, under Art. 49(1). Providers relying on the Art. 6(3) derogation still register, under Art. 49(2). Public authority deployers of Annex III systems also register. The database is public, with restricted sections for law enforcement and migration contexts.

Take compliance further with the AI Act Academy

A free course, a server-graded exam, a verifiable certificate — and the working templates.