Under the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) high-risk AI systems must undergo conformity assessment before market placement or putting into service (Article 43), with full obligations - including the Article 17 Quality Management System (QMS) - applying from 2 August 2026. The Act provides four principal, legally recognised routes to demonstrate compliance with the essential requirements (Chapter III, Section 2) and the mandatory QMS. These routes combine self-assessment (Annex VI), third-party involvement (Annex VII), harmonised standards (Article 40), and sectoral integration (Article 17(3) - (4)).
However, the regulatory landscape is not limited to these four alone. Additional avenues - such as voluntary alignment with international standards (e.g., ISO/IEC 42001), industry consortia practices, bespoke internal solutions, common specifications (Article 41), and forthcoming Commission guidelines - offer supplementary or bridging strategies, especially during the current transition where harmonised standards like EN 18286 remain uncited. This article examines the four core options in depth (with strengths, weaknesses, and nuances), then explores these additional pathways, their interplay, and strategic considerations for providers.
Core Option 1: Internal Conformity Assessment (Annex VI) - Pure Self-Assessment
The default for most Annex III (points 2-8) high-risk systems when harmonised standards or common specifications are applied or when the provider opts for no third-party involvement. The provider internally verifies QMS and technical documentation compliance, issues the EU declaration of conformity, affixes CE marking, and registers in the EU database.
- Strengths: Zero external cost; complete internal control and speed; ideal for SMEs or lower-complexity systems; flexible adaptation during development.
- Weaknesses: No presumption of conformity - full evidential burden during market surveillance audits; higher risk of non-compliance findings; requires exceptional internal expertise and documentation discipline; least credible to customers/investors/regulators.
Edge case: Suitable for narrow-use or procedural AI in high-risk areas (e.g., internal HR screening tools), but risky for adaptive ML systems where post-market changes could invalidate self-assessment.
Core Option 2: Notified Body Assessment (Annex VII) - Third-Party QMS or Type Examination
Mandatory for certain biometric/high-safety systems (Annex III point 1, some Annex I integrations); voluntary for others. A designated notified body assesses the QMS and/or technical documentation (quality assurance or type-examination + production modules), issuing certificates that support the declaration of conformity.
- Strengths: Maximum external credibility and legal defensibility; notified body expertise often uncovers gaps early; strong market/insurance/partner signal; reduces authority challenge risk.
- Weaknesses: High cost and timelines (6-24 months cycles); scarcity of AI-competent notified bodies in 2026; ongoing surveillance fees; dependency on third-party scheduling and interpretation.
Best for high-visibility or liability-sensitive applications (e.g., biometric border control, medical AI), where trust and audit protection outweigh cost.
Core Option 3: Presumption of Conformity via Harmonised Standards (Article 40) - EN 18286 & Future Standards
Full implementation of cited harmonised standards (once published in the Official Journal) grants legal presumption that the QMS and other requirements are met. EN 18286 targets Article 17 QMS directly; other JTC 21 standards may cover risk management, data quality, etc.
- Strengths: Reverses burden of proof (authorities must disprove compliance); streamlines audits and documentation; aligns with New Legislative Framework philosophy; facilitates multi-system or multi-jurisdiction scaling once cited.
- Weaknesses: EN 18286 failed January 2026 vote (1,288 comments under review, revisions/discussions ongoing March 2026); citation unlikely before late 2026/2027; interim reliance on draft offers no full presumption; may still require gap-filling evidence.
Until citation, providers voluntarily align with the draft but must fall back to Option 1 or 2 for formal demonstration - a common hybrid approach in 2026.
Core Option 4: Integration with Existing Sectoral QMS Frameworks (Article 17(3)-(4) & Article 43)
Providers subject to other EU harmonisation legislation (Annex I products, e.g., medical devices MDR/IVDR, machinery, aviation) integrate Article 17 QMS elements into existing certified systems rather than duplicating. Sectoral conformity assessment may satisfy AI Act needs.
- Strengths: Leverages audited, mature processes; avoids redundancy and cost; familiar notified bodies; faster path for medtech, automotive, fintech; regulatory familiarity reduces interpretation risk.
- Weaknesses: Requires rigorous gap analysis/mapping (AI-specific elements like bias mitigation, human oversight, post-market AI monitoring may need additions); limited to qualifying sectoral regimes; multi-regime complexity for hybrid products.
Most efficient for established industries already under strict product-safety rules - but documentation of integration is critical to withstand scrutiny.
Additional Avenues: Other Standards, Industry Practices, Internal Solutions, and Common Specifications
Beyond the four core routes, providers employ supplementary strategies, especially during the 2025-2027 transition when harmonised standards lag and the Digital Omnibus (November 2025 proposal) seeks simplifications.
Strategic Implications, Hybrids, and 2026 Outlook
Most providers adopt hybrids - e.g., ISO/IEC 42001 foundation + internal self-assessment (Option 1) while awaiting EN 18286 citation (Option 3), or sectoral integration (Option 4) + notified body for high-biometric risk. The Digital Omnibus proposals (simplified documentation, extended SME relief, flexibility in post-market plans) may further ease burdens if adopted. Until EN 18286 is cited, Option 1 remains dominant for non-mandatory third-party cases, supplemented by voluntary standards and guidelines.
The Act rewards proactive, layered approaches: build robust governance early (via ISO 42001/industry practices), choose the least burdensome core route feasible, and monitor standardisation/common-spec developments closely to pivot toward presumption-based compliance.
Content based on the EU AI Act (Regulation (EU) 2024/1689), Annexes VI-VII, Articles 17, 40-43, ISO/IEC 42001:2023, and EN 18286 draft standard. Always consult official sources, the EU AI Office, designated notified bodies, and legal experts for compliance. High-risk provisions become fully applicable on 2 August 2026.