AI Assurance Institute Logo AI Assurance Institute

Planning for Conformity Assessment
under the EU Artificial Intelligence Act

AI Quality Management Systems Series

The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is progressing toward full application of its high-risk provisions on 2 August 2026 (with some Annex I-integrated systems potentially extending to 2027 depending on harmonised standards availability and Digital Omnibus outcomes). Conformity assessment under Article 43 is the mandatory gateway for providers to place high-risk AI systems (Annex III) on the EU market or put them into service. It verifies that the system meets all essential requirements (Chapter III, Section 2) and that the provider maintains a compliant Quality Management System (QMS) per Article 17.

Planning effectively requires a structured, multi-phase approach that integrates classification, gap analysis, documentation preparation, route selection, resource allocation, and risk-based timelines. This article provides a comprehensive roadmap from regulatory, operational, strategic, and practical perspectives, covering core steps, decision points, edge cases, and current realities (including EN 18286 delays and notified body capacity constraints).

Phase 1: Early Preparation & Risk Classification (Now - Q2 2026)

Conformity assessment planning starts well before the deadline. Begin with accurate classification to determine scope and applicable procedures.

Edge case: Continuously learning quality management systems require early definition of "predetermined changes" in documentation to avoid re-assessment triggers on substantial modifications. SMEs should leverage proportionality principles and free EU AI Office resources.

Phase 2: Build & Document Compliance Foundations (Q1-Q3 2026)

Conformity assessment relies on robust evidence - primarily the QMS and technical documentation. Develop these in parallel.

  1. Start Building a Quality Management System: Identify the processes and procedures required for Article 17 QMS (13 elements), A
  2. Inventory & Classify AI Systems: Start identifying potentially high-rsk AI deployments and pipelines. Maintain an inventory, include dependencies. Use Article 6 and Annex III criteria (plus Annex I for product-safety integrations) to identify high-risk systems. Document rationale for each classification (high-risk vs. limited/minimal) - authorities may challenge this.
  3. Establish the QMS (Article 17): Define the quality policy, procedures procedures, mandatory records and sources for objective evidence covering the 13 mandatory elements. Integrate with existing systems (ISO 9001, ISO/IEC 42001, sectoral QMS) is unlikely to be possible. Document top-management commitment, roles, training, risk controls, supplier oversight, corrective actions, and post-market plans.
  4. Agree the Regulatory Compliance Strategy: Apply standards (or justifications), select performance metrics, data management, change logs, and post-market monitoring plan. Keep it up-to-date and accessible for 10 years (Article 18).
  5. Perform Internal Risk & Compliance Reviews: Conduct mock assessments against Annex VI (internal control) requirements - verify QMS existence, technical documentation completeness, and lifecycle consistency.

Use voluntary alignment with the current EN 18286 draft (despite its January 2026 vote failure and ongoing revisions with 1,288 comments under review) to structure QMS preparation - it maps closely to Article 17 and will provide presumption of conformity once cited (expected late 2026 or later).

Phase 3: Select & Execute the Conformity Assessment Route (Q2-Q3 2026)

Article 43 and Annexes VI-VII define the routes - choice depends on system category, standards/common specifications applied, and risk appetite.

Edge case: If harmonised standards lag, fallback to internal or notified-body routes without presumption - plan contingency buffers. Engage notified bodies now for high-biometric or safety-critical systems.

Phase 4: Finalise, Register, and Maintain Post-Assessment (Q3 2026 onward)

Complete the process before market placement/putting into service.

Treat conformity assessment as a lifecycle commitment - not a one-time event. Substantial modifications trigger re-assessment; plan change-control processes accordingly.

Strategic Considerations, Timelines, and 2026 Realities

Adopt a phased 12-18 month roadmap aligned to 2 August 2026 (or later backstop dates if standards delay). Prioritise high-visibility/risk systems first. Budget for external expertise (legal, consultants, notified bodies) and tools (compliance software, audit frameworks). Monitor EU AI Office guidance, JTC 21 standardisation progress (EN 18286 revisions ongoing March 2026), and Digital Omnibus developments for potential simplifications.

Edge cases: Start-ups/SMEs focus on internal routes + proportionality; global firms plan for "Brussels effect" across jurisdictions; legacy systems in transition may benefit from phased-in rules. Non-compliance risks fines up to €35M/7% turnover - proactive planning mitigates this while building trustworthy AI.

Content based on the EU AI Act (Regulation (EU) 2024/1689), Articles 17, 43, Annexes VI-VII, and EN 18286 draft standard. Always consult official sources, the EU AI Office, designated notified bodies, and legal experts for tailored compliance planning. High-risk provisions become fully applicable on 2 August 2026 (with potential extensions per harmonised standards timelines).