Guide · Requirements · Article 43 and Annexes VI and VII

What does an AI Act conformity assessment require under Article 43?

A conformity assessment is the procedure a provider runs before a high-risk AI system is placed on the market or put into service, to show it meets the Chapter III, Section 2 requirements (Article 16, point (f)). Article 43 decides which procedure: internal control under Annex VI, or a notified body under Annex VII. If you are looking for AI Act conformity assessment software: Complipath does not run a conformity assessment. It keeps the classification, the technical documentation and the evidence the assessment reads.

Written and last checked 9 October 2026 against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.

The short answer

  • Who: the provider of a high-risk AI system, before it is placed on the market or put into service (Article 16, point (f)).
  • Point 1 of Annex III (biometrics): Annex VI or Annex VII where harmonised standards or common specifications were applied; Annex VII where they were not (Article 43(1)).
  • Annex III, points 2 to 8: internal control under Annex VI, with no notified body (Article 43(2)).
  • Products under Section A of Annex I: the product legislation's procedure, with the Section 2 requirements and parts of Annex VII (Article 43(3), as replaced by Regulation (EU) 2026/1744).
  • Again after a substantial modification, except changes pre-determined in the technical documentation of a system that continues to learn (Article 43(4)).

Which procedure applies to your system?

For the biometric systems in point 1 of Annex III, Article 43(1) gives the provider a choice between internal control under Annex VI and an assessment of the quality management system and the technical documentation with a notified body under Annex VII, where the provider has applied harmonised standards under Article 40 or, where applicable, common specifications under Article 41. Article 43(1) does not leave the choice in four cases, and Annex VII is then the procedure: where harmonised standards do not exist and common specifications are not available; where the provider applied only part of the harmonised standard or none of it; where common specifications exist but were not applied; and where a harmonised standard was published with a restriction, and then only on the restricted part. The provider may choose any notified body, except that for a system to be put into service by law enforcement, immigration or asylum authorities or by Union institutions, bodies, offices or agencies, the market surveillance authority under Article 74(8) or (9) acts as the notified body.

For every other use case in Annex III, points 2 to 8, Article 43(2) is short: the provider follows internal control under Annex VI, "which does not provide for the involvement of a notified body". The Annex III guide has every point and letter.

Whether a harmonised standard exists is a fact to check on the day you read this. Our guide to EN 18286:2026 records its state on the day it was written.

What does internal control under Annex VI involve?

Three verifications by the provider itself (Annex VI, points 2 to 4). It verifies that its quality management system complies with Article 17. It examines the technical documentation to assess the system's compliance with the requirements of Chapter III, Section 2. And it verifies that the design and development process and the post-market monitoring under Article 72 are consistent with that documentation. With no outside body involved, the technical documentation carries the evidence: the Annex IV checklist walks its nine points.

What changes for products under Annex I?

Article 43(3), as replaced by Regulation (EU) 2026/1744, sends the provider of a high-risk system covered by the Union harmonisation legislation in Section A of Annex I to the conformity assessment procedure of that legislation. The Section 2 requirements apply and are part of that assessment, the quality management system under Article 17 is assessed too, and points 3, 4.3, 4.4 and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII apply. Notified bodies under that legislation may assess the AI requirements where their compliance with Article 31(4), (5), (10) and (11) was assessed in their notification; they apply for designation under Chapter III, Section 4 by 28 January 2028, without prejudice to Article 28.

Where the product legislation lets the manufacturer skip a third-party assessment by applying harmonised standards, the manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications covering all the Section 2 requirements. Classification as high-risk under Article 6(1) does not change the choice of procedure, and does not force a third-party assessment merely because the product includes a high-risk AI system as a safety component, if the product legislation does not require one. A system that is both under Section A of Annex I and in an Annex III category follows the product legislation's procedure.

When do you need a new assessment?

After a substantial modification, a system already assessed undergoes a new conformity assessment, whether it is distributed further or stays with the current deployer (Article 43(4)). For a system that continues to learn after it is placed on the market or put into service, changes the provider pre-determined at the initial assessment, and recorded in the technical documentation under point 2(f) of Annex IV, are not a substantial modification.

When does this apply?

Article 43 sits in Chapter III, Section 5, which Article 113 does not except from its general date of 2 August 2026. The duty to put the system through it is the provider's under Article 16, point (f), in Section 3. What the assessment checks is Section 2. Both apply from 2 December 2027 for systems that are high-risk under Article 6(2) and Annex III, and from 2 August 2028 for systems that are high-risk under Article 6(1) and Annex I (Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744). The amending regulation does not say how Section 5 operates while the classification rules in Section 1 are not yet in application. That is an open question, and this guide does not resolve it.

What does Complipath do here, and what does it not?

The row for Article 43 in Complipath's status table says Not supported. Complipath does not draft the EU declaration of conformity either: the documentation workspace asks for a copy and you upload it. What it does is the groundwork the assessment reads. Each system is classified with the article behind the outcome, and the obligations that follow carry an owner, a status and a date. The Annex IV documentation workspace asks for every point Annex IV lists. The evidence for each requirement is linked with the passage and its page.

What this means for you

If you're a provider: decide the procedure per system first. Outside point 1 of Annex III no notified body is involved, so your technical documentation is the assessment; a biometric system or an Annex I product may need one, so plan for one.

If you're a deployer: the provider runs the assessment; ask for the EU declaration of conformity. If you modify it substantially or change its intended purpose so that it becomes high-risk, you become the provider under Article 25(1) and the assessment is yours: when a deployer becomes a provider.

FAQ

Can software run a conformity assessment for us? No software runs it for you. Under Annex VI the provider itself verifies its quality management system, examines the technical documentation and checks it against the design and post-market monitoring; under Annex VII a notified body assesses. Software can keep the documentation and the evidence that assessment reads, which is what Complipath does.

Do we need a notified body? Only in some cases. Systems in Annex III, points 2 to 8, use internal control under Annex VI with no notified body (Article 43(2)). Biometric systems in point 1 need one where harmonised standards or common specifications were not fully applied (Article 43(1)), and Annex I products follow their own legislation (Article 43(3)).

Is a conformity assessment a certification? Under Annex VI it is the provider's own verification, with no outside body involved. Under Annex VII a notified body assesses the quality management system and the technical documentation. Either way the provider then draws up the EU declaration of conformity under Article 47 and affixes the CE marking under Article 48.

Does every change need a new conformity assessment? No, only a substantial modification does (Article 43(4)), whether the modified system is distributed further or stays with the current deployer. For a system that continues to learn, changes the provider pre-determined at the initial assessment and recorded under point 2(f) of Annex IV are not a substantial modification.

Where this question meets the product: AI Act technical documentation software. Answering it in a customer's questionnaire: how to answer AI questions in a supplier questionnaire.

Read nextAI Act quality management system (Article 17)Article 17AI Act declaration of conformity (Article 47)Article 47 and Annex VEU AI Act post-market monitoring (Article 72)Article 72

See which of your AI systems the Act covers.

No account needed. Every answer cites the article it rests on.

Get your free readiness review

Check your AI systems, free