WorkflowEU AI Act

EU AI Act High-risk conformity route selector

Choose the Article 43 conformity assessment path for a high-risk AI system before placing it on the EU market or putting it into service.

Use the selector to separate Annex I product-law systems from Annex III systems, identify when a notified body is required, and collect the declaration, CE marking, registration, and technical evidence needed for the file.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 26, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 26, 2026
Overview

Article 43 is the routing point for EU AI Act high-risk . Start with the system's high-risk basis: an AI system or safety component under Annex I Section A product legislation, an Annex III point 1 biometrics system, or another Annex III system. Annex I Section B systems follow the amended sector-law treatment instead of the full standalone Article 43 route. Then record whether harmonised standards or common specifications are fully applied, whether a notified body is involved, and which post-assessment outputs must be ready before market placement or use.

Section 1

1. Classify the high-risk basis before choosing the assessment path

Do not choose an assessment procedure until the high-risk basis is written down. The AI Act treats Annex I product-law systems differently from Annex III standalone use cases, and Article 43 routes them through different assessment mechanics.

For Annex I, identify the section and sector legislation first. Section A includes New Legislative Framework legislation such as toys, radio equipment, pressure equipment, lifts, PPE, gas appliances, medical devices, and in vitro diagnostic medical devices. Article 43 sends those systems through the procedure required by the sector law, with the AI Act Chapter III Section 2 requirements included in that assessment.

Regulation (EU) 2026/1744 moves machinery from Annex I Section A to Section B. For machinery and other Section B systems, only the AI Act provisions identified in amended Article 2(2) apply directly unless the relevant high-risk requirements have been integrated into the sector legislation. Do not route a Section B system through Article 43 merely because it appears in Annex I.

For Annex III, record the exact point and use case. Annex III covers biometrics, critical infrastructure, education and vocational training, employment and workers' management, access to essential private and public services, law enforcement, migration and border control, and justice and democratic processes.

Route selection and application timing are separate questions. Regulation (EU) 2026/1744 entered into force on 27 July 2026 and applies Chapter III Sections 1-3 from 2 December 2027 for systems classified under Article 6(2) and Annex III, and from 2 August 2028 for systems classified under Article 6(1) and Annex I. Record the applicable route and date even when conformity work starts earlier.

  • Annex I route: the AI system is itself a regulated product or a safety component of a product covered by Annex I Union harmonisation legislation.
  • Annex III point 1 route: biometrics systems have special Article 43 triggers for notified body involvement.
  • Annex III points 2 to 8 route: internal control under Annex VI is the default Article 43 procedure unless the Commission later changes that routing by delegated act.
  • Evidence to capture: intended purpose, product or use-case category, applicable Annex item, provider identity, affected Member States, and the source used for the classification.
Section 2

2. Apply the Article 43 route rules

Once the high-risk basis is known, apply Article 43 without collapsing the categories. Annex III point 1 systems can use internal control under Annex VI only when the provider has applied harmonised standards, or common specifications where applicable, that cover the relevant requirements. Otherwise Article 43 requires the Annex VII procedure with assessment of the quality management system and technical documentation by a notified body.

For Annex III point 1 systems, also use Annex VII when harmonised standards do not exist and common specifications are unavailable, when the provider has not applied the harmonised standard or has applied it only partly, when common specifications exist but are not applied, or when a harmonised standard is published with a restriction for the restricted part.

For Annex III points 2 to 8, Article 43 points providers to the internal-control procedure in Annex VI. That still requires the provider to verify the quality management system, examine the technical documentation, and confirm that design, development, and post-market monitoring are consistent with the documentation.

For Annex I Section A product-law systems, follow the procedure required by the relevant product legislation. If that legislation allows the manufacturer to opt out of third-party assessment because all relevant harmonised standards are applied, Article 43 allows that option only when harmonised standards or common specifications also cover all AI Act Chapter III Section 2 requirements.

  • Route A - Annex I Section A product law: use the sector and include AI Act high-risk requirements in that assessment.
  • Route B - Annex III point 1 with full standards or common specifications: provider may choose Annex VI internal control or Annex VII notified body assessment.
  • Route C - Annex III point 1 without full standards or common specifications: use Annex VII notified body assessment.
  • Route D - Annex III points 2 to 8: use Annex VI internal control unless a later delegated act makes Annex VII applicable.
  • Special authority rule: when an Annex VII system is intended for law enforcement, immigration or asylum authorities, or Union institutions, bodies, offices, or agencies, Article 43 assigns the relevant market surveillance authority to act as the notified body, unless Article 75(1e) gives the AI Office responsibility for a system under its exclusive competence.
Section 3

3. Record standards, common specifications, and notified body triggers

The standards decision changes whether Annex III point 1 can stay with internal control or must move to Annex VII. For every requirement relied on, record whether the provider applied an OJEU-referenced harmonised standard in full, applied it only in part, used a common specification, or adopted another technical solution.

Harmonised standards and common specifications can create a presumption of conformity only to the extent that they cover the relevant AI Act requirements or obligations. If the provider does not comply with common specifications, Article 41 requires justification that the adopted technical solutions meet the requirements to at least an equivalent level.

When Annex VII applies, the evidence package must be ready for a notified body review of both the quality management system and the technical documentation. Annex VII allows the notified body to request further evidence or tests, and in limited circumstances to access training, validation, and testing datasets or trained models where necessary for the assessment.

  • Standards record: standard or common specification used, OJEU reference status, covered requirement, full or partial application, and any restriction.
  • Notified body trigger record: Annex III point 1 trigger, standards gap, partial application, restricted standard, product-law requirement, or special public-authority route.
  • Annex VII submission record: quality management system documentation, Annex IV technical documentation, no-duplicate-application declaration, and the chosen notified body or relevant authority.
  • Alternative-solution record: technical solution, requirement covered, test evidence, risk-management link, and justification for equivalence where common specifications are not followed.
Section 4

4. Close the route with declaration, CE marking, registration, and evidence

The selector is complete only when the post-assessment outputs are assigned. Article 47 requires a written, machine-readable, physical or electronically signed EU declaration of conformity for each high-risk AI system and requires the provider to keep it available to national competent authorities for 10 years after placement on the market or putting into service.

Article 48 requires CE marking for high-risk AI systems. Digital systems can use a digital CE marking if it is easily accessible through the interface, a machine-readable code, or another electronic means. Where a notified body is responsible for the Article 43 , the CE marking must be followed by that body's identification number.

Registration depends on the high-risk basis and actor. Article 49 requires providers or authorised representatives to register Annex III high-risk systems, except point 2 critical infrastructure systems, in the EU database before placing them on the market or putting them into service. Providers that classify an Annex III system as not high-risk under Article 6(3) must also register that conclusion. Public authorities and Union bodies deploying Annex III systems, except point 2, must register themselves and the use of the system. Article 49 routes point 2 critical infrastructure systems to national registration.

A new is required after a substantial modification. A planned change to a continuously learning system does not count as a substantial modification when the provider predetermined the change and its performance in the initial conformity assessment and included it in the technical documentation. Store that predetermined-change evidence with the initial route decision.

Article 46 allows a market surveillance authority, on a duly justified request and for a limited period, to authorise a specific high-risk system before the conformity procedure is complete for exceptional public-security, life and health, environmental, or key industrial and infrastructure reasons. For high-risk systems related to products covered by Annex I Section A, only the derogations in the applicable sector legislation apply. Treat this as an authority-controlled derogation, not a fifth route: the required must still be completed without undue delay.

  • EU declaration record: system name and type, provider details, sole-responsibility statement, AI Act conformity statement, applicable data-protection statement, standards or common specifications, notified body and certificate details where applicable, place, date, signer, and signature.
  • CE marking record: marking location, digital access method where relevant, notified body identification number where applicable, and whether other Union law also requires CE marking.
  • Registration record: provider or deployer registration obligation, EU database or national registration path, Annex III exception check, certificate details where applicable, EU declaration copy, instructions for use, Member States, and status of the system.
  • Reassessment record: substantial modification, intended-purpose change, standards or common-specification change, notified body certificate supplement, and post-market monitoring evidence.
Primary sources

References and citations

ai-act-service-desk.ec.europa.eu
Referenced sections
  • Official AI Act Service Desk article explains registration before placing Annex III high-risk systems on the market or putting them into service, including EU database and non-public registration cases.
"Before placing on the market or putting into service a high-risk AI system"
digital-strategy.ec.europa.eu
Referenced sections
  • Commission overview confirms that, after conformity assessment and registration of standalone systems, a declaration of conformity is signed and the system bears CE marking before market placement.
"A declaration of conformity needs to be signed"
digital-strategy.ec.europa.eu
Referenced sections
  • Commission FAQ explains that high-risk classification depends on intended purpose and can arise from Annex I product legislation or Annex III use cases.
"AI systems can classify as high-risk in two cases"
digital-strategy.ec.europa.eu
Referenced sections
  • Commission standardisation page explains that harmonised standards are voluntary but, when referenced in the Official Journal, provide legal certainty and a presumption of compliance.
"The application of standards remains voluntary."
eur-lex.europa.eu
Referenced sections
  • Articles 47 to 49 and Annexes V and VIII support the declaration of conformity, CE marking, registration, and evidence fields listed here.
"The EU declaration of conformity shall identify the high-risk AI system"
Related guides

Explore more topics

Are industry AI use cases high-risk under EU AI Act Annex III?
FAQ answer on when an industry AI use case falls under EU AI Act Annex III, how Article 6 classification works, when Article 6(3) can support a non-high-risk conclusion, and what evidence providers should keep.
EU AI Act AI System Classification Edge Cases FAQ
Answers for EU AI Act edge cases: AI system definition, inference versus simple rules, GPAI models, embedded products, territorial scope, roles, and classification evidence.
EU AI Act Applicability and Roles: Scope, Actor Map, and Evidence
Determine whether the EU AI Act applies to an AI system or GPAI model, map provider, deployer, importer, distributor, and product manufacturer roles, and record evidence for classification.
EU AI Act applicability test: scope, role, and risk classification
Stepwise EU AI Act applicability test for AI-system status, exclusions, territorial scope, operator role, prohibited uses, high-risk systems, GPAI models, transparency duties, and evidence records.
EU AI Act Article 5 Prohibited AI Practices Screening Guide
Screen AI systems against EU AI Act Article 5, including manipulation, social scoring, biometrics, law enforcement, and the new prohibited-content category.
EU AI Act Article 50 transparency disclosures FAQ
Article 50 FAQ for EU AI Act transparency duties covering chatbot notices, synthetic content marking, biometric and emotion notices, deepfakes, public-interest text, timing, accessibility, and exceptions.
EU AI Act Article 50 transparency, labeling, and user disclosures
Source-backed guide to EU AI Act Article 50 duties for user interaction notices, synthetic content marking, deepfake labels, emotion recognition notices, biometric categorisation notices, and related high-risk AI instructions for use.
EU AI Act Article 73 serious incident FAQ
FAQ on EU AI Act serious incident handling for high-risk AI systems, including Article 73 reporting, deployer escalation, corrective action, and GPAI systemic-risk distinctions.
EU AI Act Compliance Checklist by Risk Class
A practical EU AI Act checklist for classifying AI systems, assigning operator roles, screening prohibited practices, and collecting evidence for high-risk, GPAI, transparency, monitoring, and incident duties.
EU AI Act Compliance Program: roles, high-risk evidence, GPAI and incidents
Build an EU AI Act compliance program around provider, deployer, importer, distributor, high-risk, GPAI, transparency, monitoring, and incident evidence duties.
EU AI Act conformity assessment and notified bodies for high-risk AI
Source-backed guide to EU AI Act high-risk AI conformity assessment routes, provider evidence, EU declaration of conformity, CE marking, and notified body involvement.
EU AI Act deadlines and compliance calendar | Article 113 dates
EU AI Act compliance calendar for Regulation (EU) 2026/1744, Article 113 dates, Article 111 transitions, GPAI enforcement, Article 50, and high-risk systems.
EU AI Act FAQ: scope, roles, high-risk AI, GPAI, FRIA, and dates
Source-backed EU AI Act FAQ covering scope, roles, risk classification, GPAI, transparency, AI literacy, rights and complaints, sandboxes, authorities, SME provisions, and current legal status.
EU AI Act FRIA FAQ: Article 27 Scope, Contents, and Notification
Source-backed FAQ on when Article 27 requires a fundamental rights impact assessment, which deployers are covered, what the FRIA must contain, and how it relates to DPIAs and registration.
EU AI Act FRIA for high-risk AI systems: Article 27 scope and evidence
Source-backed guide to EU AI Act Article 27 fundamental rights impact assessments: who must run a FRIA, Article 6(2) triggers, Annex III carveouts, DPIA overlap, notification, and registration evidence.
EU AI Act GPAI and Systemic-Risk Duties: Article 53 and 55 FAQ
FAQ on EU AI Act duties for general-purpose AI model providers, including Article 53 documentation, copyright and training-summary duties, Article 55 systemic-risk duties, serious incidents, cybersecurity, and staged enforcement.
EU AI Act GPAI evidence pack checklist for Article 53 and 55
Build a source-backed evidence pack for EU AI Act GPAI model obligations: technical documentation, downstream information, copyright policy, training-content summary, and systemic-risk records where applicable.
EU AI Act GPAI Provider Obligations: Articles 53 and 55
Source-backed guide to EU AI Act duties for general-purpose AI model providers: Article 53 documentation, copyright policy, training-content summary, downstream information, and Article 55 systemic-risk controls.
EU AI Act High-Risk AI Requirements: Articles 8-16 and 26
Map the EU AI Act requirements for high-risk AI systems: risk management, data governance, technical documentation, logs, transparency, human oversight, accuracy, robustness, cybersecurity, and deployer duties.
EU AI Act high-risk AI use cases by industry | Article 6 and Annex III guide
Industry-by-industry guide to EU AI Act high-risk classification under Article 6, Annex III, Annex I product safety routes, exclusions, and provider/deployer boundaries.
EU AI Act high-risk requirements checklist: Articles 8-15
Checklist for EU AI Act high-risk AI system requirements in Articles 8-15: risk management, data governance, documentation, logs, transparency, human oversight, accuracy, robustness, and cybersecurity.
EU AI Act penalties and fines: Article 99 tiers and GPAI exposure
EU AI Act penalties explained: Article 99 fine tiers, prohibited-practice exposure, incorrect information, SME caps, Member State rules, and GPAI model fines.
EU AI Act post-market monitoring and serious incident reporting
Source-backed guide to EU AI Act Articles 72 and 73 for high-risk AI: monitoring plans, serious incident reporting, deployer escalation, corrective action, and GPAI distinctions.
EU AI Act post-market monitoring FAQ for high-risk AI systems
Answer to how providers and deployers should handle EU AI Act post-market monitoring for high-risk AI systems under Article 72, with serious-incident, log, corrective-action, and lifecycle-change triggers.
EU AI Act provider vs deployer role boundaries: Article 3 and Article 25 FAQ
FAQ on EU AI Act provider, deployer, operator, importer, distributor, authorised representative, product manufacturer, downstream provider, and GPAI model provider boundaries.
EU AI Act risk classification intake workflow
A source-based intake structure for classifying EU AI Act scope, prohibited practices, high-risk routes, Annex III use cases, GPAI model status, roles, and reassessment triggers.
EU AI Act serious incident reporting triage workflow: Article 73 and Article 55
Triage EU AI Act serious incidents by definition, actor, reporting route, deadline, deployer escalation, corrective action, and separate GPAI systemic-risk reporting.
EU AI Act Technical Documentation and Provider Evidence Templates
Build AI Act evidence templates for high-risk AI providers: Article 11 technical documentation, Annex IV fields, quality management, conformity, CE marking, registration, logs, and post-market monitoring.
EU AI Act technical documentation FAQ | Article 11 and Annex IV
What Article 11 and Annex IV require in high-risk AI technical documentation: system identity, intended purpose, architecture, data, testing, oversight, cybersecurity, conformity, and post-market monitoring.
EU AI Act Timeline Roadmap: Dates, Legal Status, Owners, and Evidence
Turn EU AI Act milestones into an implementation roadmap by separating enacted dates, political agreements, draft guidance, consultations, and voluntary codes, then assigning actions and evidence.
EU AI Act vs ISO/IEC 42001: legal duties, controls, and evidence limits
Compare the EU AI Act and ISO/IEC 42001:2023, including legal status, Article 17 quality management, high-risk duties, GPAI, evidence reuse, and assurance limits.
EU AI Act vs NIST AI RMF: legal duties, risk controls, and evidence boundaries
Compare the EU AI Act with NIST AI RMF 1.0 across legal status, GOVERN-MAP-MEASURE-MANAGE, high-risk duties, GPAI, evidence reuse, and revision limits.
FAQ: EU AI Act conformity assessment procedures and notified body selection
cited FAQ on EU AI Act Article 43 conformity assessment routes, Annex VI internal control, Annex VII notified-body review, CE marking, declarations, and registration.