AI Assurance Institute Logo AI Assurance Institute

Demonstrating Compliance with the EU AI Act for High-Risk Systems:
The Four Core Options, Plus Additional Avenues

AI Quality Management Systems Series

Under the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) high-risk AI systems must undergo conformity assessment before market placement or putting into service (Article 43), with full obligations - including the Article 17 Quality Management System (QMS) - applying from 2 August 2026. The Act provides four principal, legally recognised routes to demonstrate compliance with the essential requirements (Chapter III, Section 2) and the mandatory QMS. These routes combine self-assessment (Annex VI), third-party involvement (Annex VII), harmonised standards (Article 40), and sectoral integration (Article 17(3) - (4)).

However, the regulatory landscape is not limited to these four alone. Additional avenues - such as voluntary alignment with international standards (e.g., ISO/IEC 42001), industry consortia practices, bespoke internal solutions, common specifications (Article 41), and forthcoming Commission guidelines - offer supplementary or bridging strategies, especially during the current transition where harmonised standards like EN 18286 remain uncited. This article examines the four core options in depth (with strengths, weaknesses, and nuances), then explores these additional pathways, their interplay, and strategic considerations for providers.

Core Option 1: Internal Conformity Assessment (Annex VI) - Pure Self-Assessment

The default for most Annex III (points 2-8) high-risk systems when harmonised standards or common specifications are applied or when the provider opts for no third-party involvement. The provider internally verifies QMS and technical documentation compliance, issues the EU declaration of conformity, affixes CE marking, and registers in the EU database.

Edge case: Suitable for narrow-use or procedural AI in high-risk areas (e.g., internal HR screening tools), but risky for adaptive ML systems where post-market changes could invalidate self-assessment.

Core Option 2: Notified Body Assessment (Annex VII) - Third-Party QMS or Type Examination

Mandatory for certain biometric/high-safety systems (Annex III point 1, some Annex I integrations); voluntary for others. A designated notified body assesses the QMS and/or technical documentation (quality assurance or type-examination + production modules), issuing certificates that support the declaration of conformity.

Best for high-visibility or liability-sensitive applications (e.g., biometric border control, medical AI), where trust and audit protection outweigh cost.

Core Option 3: Presumption of Conformity via Harmonised Standards (Article 40) - EN 18286 & Future Standards

Full implementation of cited harmonised standards (once published in the Official Journal) grants legal presumption that the QMS and other requirements are met. EN 18286 targets Article 17 QMS directly; other JTC 21 standards may cover risk management, data quality, etc.

Until citation, providers voluntarily align with the draft but must fall back to Option 1 or 2 for formal demonstration - a common hybrid approach in 2026.

Core Option 4: Integration with Existing Sectoral QMS Frameworks (Article 17(3)-(4) & Article 43)

Providers subject to other EU harmonisation legislation (Annex I products, e.g., medical devices MDR/IVDR, machinery, aviation) integrate Article 17 QMS elements into existing certified systems rather than duplicating. Sectoral conformity assessment may satisfy AI Act needs.

Most efficient for established industries already under strict product-safety rules - but documentation of integration is critical to withstand scrutiny.

Additional Avenues: Other Standards, Industry Practices, Internal Solutions, and Common Specifications

Beyond the four core routes, providers employ supplementary strategies, especially during the 2025-2027 transition when harmonised standards lag and the Digital Omnibus (November 2025 proposal) seeks simplifications.

Strategic Implications, Hybrids, and 2026 Outlook

Most providers adopt hybrids - e.g., ISO/IEC 42001 foundation + internal self-assessment (Option 1) while awaiting EN 18286 citation (Option 3), or sectoral integration (Option 4) + notified body for high-biometric risk. The Digital Omnibus proposals (simplified documentation, extended SME relief, flexibility in post-market plans) may further ease burdens if adopted. Until EN 18286 is cited, Option 1 remains dominant for non-mandatory third-party cases, supplemented by voluntary standards and guidelines.

The Act rewards proactive, layered approaches: build robust governance early (via ISO 42001/industry practices), choose the least burdensome core route feasible, and monitor standardisation/common-spec developments closely to pivot toward presumption-based compliance.

Content based on the EU AI Act (Regulation (EU) 2024/1689), Annexes VI-VII, Articles 17, 40-43, ISO/IEC 42001:2023, and EN 18286 draft standard. Always consult official sources, the EU AI Office, designated notified bodies, and legal experts for compliance. High-risk provisions become fully applicable on 2 August 2026.