Application, Requirements, and When This Route Applies
Annex VI of the EU AI Act sets out the "internal control" procedure - a self-assessment route that allows providers of most high-risk AI systems to demonstrate conformity without mandatory third-party (notified body) involvement. It is the default conformity assessment pathway for the majority of Annex III high-risk systems and represents the least burdensome route when applicable. This article articulates when and how the Annex VI internal controls route applies, its detailed requirements, practical application, advantages and limitations, edge cases, and the interplay with prEN 18286 once cited.
Article 43(1) and Annex VI establish that the internal control procedure is the default conformity assessment route for high-risk AI systems listed in Annex III, except where:
In practice, Annex VI applies to the large majority of high-risk systems in Annex III points 2-8 (critical infrastructure, education, employment, essential services, law enforcement, migration, justice), provided harmonised standards (e.g., future prEN 18286) or common specifications are applied where available, or the provider can demonstrate full compliance through internal evidence alone.
Annex VI requires the provider to perform a complete internal conformity assessment before placing the high-risk AI system on the market or putting it into service. The core obligations include:
When prEN 18286 is cited in the Official Journal, full alignment with it grants presumption of conformity for the QMS element - dramatically reducing the evidential burden during internal verification and future market surveillance audits.
The internal controls route places full responsibility on the provider but offers flexibility and cost/time savings when executed well:
Examples:
Advantage: Faster to market, lower cost (€10k-€50k vs. €50k-€200k+ for notified-body), full control over timing. Limitation: Higher burden of proof during market surveillance - authorities can challenge any element at any time.
Applies:
Does Not Apply / Not Recommended:
Edge case: Continuously learning systems using Annex VI must document robust change-control and post-market monitoring procedures internally; auditors/authorities will scrutinise these heavily due to dynamic risk profile.
Annex VI integrates directly with prEN 18286: once cited, alignment with the standard provides presumption of conformity for the QMS element, making internal verification substantially easier and more defensible. Providers should map existing processes to prEN 18286 draft Clauses 5-10, conduct gap analyses, and prepare internal audit trails that mirror notified-body expectations - even when using the self-assessment route.
Strategic implications: Choosing Annex VI accelerates time-to-market and reduces cost for eligible systems, but requires strong internal governance and documentation discipline. Missteps can lead to post-market enforcement actions. Best practice: Document classification rationale clearly, implement a risk-based internal audit programme, use prEN 18286 draft as a checklist for readiness, and maintain a living compliance file ready for unannounced authority requests.
In summary, Annex VI internal controls is the proportionate, self-assessment route that applies to most high-risk AI systems in Annex III points 2-8. It demands rigorous internal verification of QMS and essential requirements compliance, achieves faster and less costly market access when executed well, and - once prEN 18286 is cited - benefits from strong presumption of conformity, balancing innovation with robust regulatory oversight.
Content based on the EU AI Act (Regulation (EU) 2024/1689), Articles 17 & 43, Annexes VI & VII, and the prEN 18286 draft standard. The standard remains under revision; always consult the latest CEN/CENELEC drafts, EU AI Office guidance, and legal experts for implementation. High-risk provisions become fully applicable on 2 August 2026.