The EU AI Act's high-risk conformity assessment is the legal procedure a provider must complete before placing certain AI systems on the EU market or putting them into service. If your system is classified as high-risk under Annex III (or is a safety component under Annex I), you must demonstrate compliance with the Act's requirements — risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness — and then affix CE marking. This guide explains how the classification works, what the conformity assessment actually involves, and what practical steps providers should take, with particular attention to software companies that convert or process technical documents, drawings, and code, where classification questions are genuinely unsettled.

The Direct Answer: What the Conformity Assessment Is

Also worth reading: How does the EU AI Act define high-risk AI classification for construction and architectural software? · How do I implement an AI plan review system for architectural and technical specifications in 2026? · What are the essential AI system requirements for automating architectural drawing to code conversion?

The conformity assessment for high-risk AI systems is set out in Article 43 of the EU AI Act (Regulation (EU) 2024/1689). For most Annex III high-risk systems, the procedure is an internal control: the provider self-assesses conformity using the harmonised standards or common specifications once available, compiles the technical documentation required under Annex IV, and issues an EU Declaration of Conformity. For high-risk AI systems that are safety components of products, or that are themselves products requiring third-party assessment under other EU harmonisation legislation (such as machinery, medical devices, or toys), the assessment must involve a notified body instead.

The assessment is not a one-off exam. Article 43(4) requires providers to keep the technical documentation and the declaration of conformity available for ten years after the system is placed on the market. National market surveillance authorities can demand it at any time, and if your system is substantially modified, the assessment must be repeated. In practice, this means conformity assessment is a continuous compliance discipline built on a living documentation file, not a certificate you frame and forget.

How Classification Works: Annex III and the Draft Guidelines

Before any conformity assessment, you must determine whether your system is high-risk at all. Article 6(2) makes high-risk any AI system used in the Annex III areas: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice and democratic processes. Crucially, Article 6(3) provides an exception: if a system in those areas does not pose a significant risk of harm to health, safety or fundamental rights — for example, because it only performs a narrow procedural task, or merely prepares a human assessment — it is not high-risk.

In 2025 and into 2026, the European Commission published draft Guidelines on the classification of high-risk AI systems to clarify exactly this filter, and ran a targeted consultation on them. The draft guidance confirms that the Article 6(3) filter is a genuine exemption, not a loophole: a system that ranks CVs for a hiring decision is high-risk, but a system that merely formats CVs is not. The Commission also signalled, through the Digital Omnibus discussions reported by firms like Dentons, that some Annex III obligations may be adjusted or their timing reconsidered to reduce burden on smaller providers. Companies should treat the final guidelines as the authoritative reference once adopted, because classification errors in either direction carry real consequences: over-classification wastes money, under-classification invites enforcement.

Why This Matters for Document, Drawing, and Code Processing AI

Many AI products sit in a grey zone. Consider a platform that converts architectural drawings into structured code or machine-readable outputs. On its face, this is not an Annex III use case — construction software is not listed, and building design tools are not biometrics, employment tools, or essential services. However, classification depends on the specific use, not the technology. If the same drawing-to-code engine were marketed as a component for safety-critical infrastructure planning, or embedded in a product that qualifies as a safety component under Annex I, the analysis changes. Providers must therefore assess intended purpose and reasonably foreseeable misuse, as Article 6(4) requires, and document that assessment.

There is a second, often overlooked angle: general-purpose AI models. A model that processes drawings, documents, or code and is capable of a wide range of tasks may fall under the GPAI obligations in Chapter V instead — transparency, copyright policy, and training-data summaries — with additional systemic-risk obligations if compute thresholds are exceeded. The GPAI Code of Practice, finalised in 2025, gives providers a route to demonstrate compliance. For most document-conversion vendors, the realistic obligations are transparency duties under Article 50 (making clear users are interacting with AI) and GPAI duties, not the full high-risk conformity regime. But the analysis must be written down and defensible, because market surveillance authorities will ask.

The Practical Steps of the Assessment

The conformity assessment follows a defined sequence. First, confirm the classification and record the reasoning, including any Article 6(3) exemption analysis. Second, if high-risk, build the risk management system required by Article 9 — a continuous, iterative process running through the entire lifecycle that identifies and mitigates foreseeable risks to health, safety, and fundamental rights. Third, address data governance under Article 10: training, validation, and test data must be relevant, sufficiently representative, and examined for biases that could lead to discrimination. Fourth, compile the Annex IV technical documentation, which includes a general description of the system, its architecture, development methodology, validation results, and the human oversight measures under Article 14.

Fifth, establish logging, record-keeping, transparency to deployers, and the accuracy, robustness, and cybersecurity measures of Articles 12, 13, and 15. Sixth, register the system in the EU database (Article 71) — for Annex III systems, registration happens before market placement; for Annex I safety-component systems, after CE marking. Seventh, draw up the EU Declaration of Conformity (Article 48) and affix the CE mark. Finally, put in place post-market monitoring under Article 72 and a serious-incident reporting procedure under Article 73, and keep everything updated. Providers must also ensure deployers can meet their own obligations, including the human oversight the deployer is required to exercise.

Internal Control Versus Notified Body: A Comparison

The route you take depends on your product category, and the difference matters for cost, timeline, and independence.

FeatureInternal Control (Annex III, Art. 43(2))Notified Body (Annex I safety components, Art. 43(1))
Who assessesThe provider itselfIndependent third-party conformity assessment body
Applies toMost Annex III high-risk systemsHigh-risk AI as safety components of regulated products (machinery, medical devices, toys, lifts, etc.)
Typical costInternal staff time; external counsel/consultants optionalNotified body fees, commonly tens of thousands of euros depending on scope
TimelineWeeks to months, driven by documentation readinessOften 6–18 months including audit cycles
Basis of assessmentHarmonised standards or common specifications (when published)Same standards plus module-based conformity assessment
Ongoing burdenPost-market monitoring, 10-year documentation retentionSurveillance audits by the notified body
IndependenceNone — self-declaration carries legal liabilityThird-party verification, stronger defensibility
A word of caution: harmonised standards for the AI Act were still being developed as of 2026, led by CEN-CENELEC JTC 21. Until they are cited in the Official Journal, providers cannot yet claim presumption of conformity through them, which makes the documentation burden heavier in the interim. ISO 9001 and ISO 27001 certifications help with quality and information-security credibility but do not by themselves confer AI Act conformity.

Common Mistakes and Enforcement Reality

The most frequent error is skipping the classification step and either assuming a product is exempt or assuming it is high-risk without analysis. Both are dangerous. The second mistake is treating the technical documentation as a marketing document rather than the evidentiary file it is — Annex IV requires specific, verifiable content, including validation and testing results. Third, many providers ignore the Article 25 rules on the AI value chain: if you modify a high-risk system someone else placed on the market so that it remains high-risk, you become a provider with full obligations. Distributors and importers have their own duties under Articles 27–29 and cannot outsource them.

Enforcement is not theoretical. Penalties for placing a prohibited AI system reach €35 million or 7% of global annual turnover, whichever is higher; breaches of most other obligations, including conformity assessment failures, carry fines up to €15 million or 3% of turnover; and supplying incorrect or misleading information can cost up to €7.5 million or 1%. Member State authorities began applying the high-risk regime's obligations on 2 August 2026 for most systems, following the prohibitions and AI-literacy duties that applied from 2 February 2025 and the GPAI rules from 2 August 2025. The Digital Omnibus proposals discussed in 2025–2026 may adjust some dates and obligations, so monitor the final texts rather than relying on second-hand summaries.

When to Act and What It Costs

If your system is plausibly high-risk, the work should already be underway. Building a compliant risk management system, data governance process, and Annex IV documentation typically takes a well-prepared mid-size provider three to nine months; companies starting from scratch should budget six to twelve months. Costs vary widely: internal control assessments for a single product might cost €20,000–€100,000 in combined legal, technical, and consulting effort, while notified-body routes for safety-component systems routinely run from €50,000 into six figures, plus annual surveillance. Small and micro-enterprises get some relief — simplified documentation under Article 19, regulatory sandboxes under Article 57, and priority access to them — but no exemption from the core obligations.

For vendors whose products are clearly outside Annex III and Annex I — as most standalone document, drawing, and code conversion tools are — the honest advice is different: do a documented classification analysis, implement the Article 50 transparency measures, check whether your underlying model triggers GPAI duties, and stop there. Over-complying with a regime that does not apply to you burns budget that competitors will spend on product quality. Conversely, if your customers deploy your output in employment screening, credit scoring, or critical infrastructure, expect contractual flow-down of high-risk obligations and be ready to support deployers with the documentation they need.

A Balanced View for Software Providers

The conformity assessment regime is demanding but navigable, and it rewards companies that already practise disciplined engineering. The genuine pain points are the lagging harmonised standards, the unsettled classification guidance (still in draft as of 2026), and the ambiguity at the edges of the value-chain rules. For architectural drawing-to-code platforms and similar tools, the realistic exposure is transparency and GPAI compliance, with high-risk duties triggered only by specific customer use cases. The correct posture is a written, defensible classification memo, a compliance monitoring routine tied to the Commission's final guidelines, and documentation practices that would satisfy Annex IV if your classification ever changes. That is proportionate compliance — neither panic nor denial.