The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is progressing toward full application of its high-risk provisions on 2 August 2026 (with some Annex I-integrated systems potentially extending to 2027 depending on harmonised standards availability and Digital Omnibus outcomes). Conformity assessment under Article 43 is the mandatory gateway for providers to place high-risk AI systems (Annex III) on the EU market or put them into service. It verifies that the system meets all essential requirements (Chapter III, Section 2) and that the provider maintains a compliant Quality Management System (QMS) per Article 17.
Planning effectively requires a structured, multi-phase approach that integrates classification, gap analysis, documentation preparation, route selection, resource allocation, and risk-based timelines. This article provides a comprehensive roadmap from regulatory, operational, strategic, and practical perspectives, covering core steps, decision points, edge cases, and current realities (including EN 18286 delays and notified body capacity constraints).
Phase 1: Early Preparation & Risk Classification (Now - Q2 2026)
Conformity assessment planning starts well before the deadline. Begin with accurate classification to determine scope and applicable procedures.
- Document top-management commitment, their roles and responsibilities: Set risk appetite, budget to establish and operate the quality management system, timelines, top management's expectations and reporting requirements.
- Appoint an AI QMS Manager: Assign responsibilities and deadlines for the QMS processes, procedures and activities covering Article 9 risk management, Article 10 data governance, Article 11/Annex IV technical documentation, human oversight (Article 14), robustness/cybersecurity (Article 15), and post-market monitoring (Article 72). Tools like EU AI Office compliance checkers and maturity models help identify shortfalls.
- Appoint a Regulatory Compliance Officer: Assign responsiility for regulatory compliance (not a cross-functional team). Allocate budget and timelines - conformity assessment can take 6-24 months depending on route and complexity.
- Assign roles and responsibilities to required staff: Update existing role descriptons, obtain budget recruit where necessary. Set timelines.
- Maintain a succession plan: Determine succession planning needs and assign responsibilities.
Edge case: Continuously learning quality management systems require early definition of "predetermined changes" in documentation to avoid re-assessment triggers on substantial modifications. SMEs should leverage proportionality principles and free EU AI Office resources.
Phase 2: Build & Document Compliance Foundations (Q1-Q3 2026)
Conformity assessment relies on robust evidence - primarily the QMS and technical documentation. Develop these in parallel.
- Start Building a Quality Management System: Identify the processes and procedures required for Article 17 QMS (13 elements), A
- Inventory & Classify AI Systems: Start identifying potentially high-rsk AI deployments and pipelines. Maintain an inventory, include dependencies. Use Article 6 and Annex III criteria (plus Annex I for product-safety integrations) to identify high-risk systems. Document rationale for each classification (high-risk vs. limited/minimal) - authorities may challenge this.
- Establish the QMS (Article 17): Define the quality policy, procedures procedures, mandatory records and sources for objective evidence covering the 13 mandatory elements. Integrate with existing systems (ISO 9001, ISO/IEC 42001, sectoral QMS) is unlikely to be possible. Document top-management commitment, roles, training, risk controls, supplier oversight, corrective actions, and post-market plans.
- Agree the Regulatory Compliance Strategy: Apply standards (or justifications), select performance metrics, data management, change logs, and post-market monitoring plan. Keep it up-to-date and accessible for 10 years (Article 18).
- Perform Internal Risk & Compliance Reviews: Conduct mock assessments against Annex VI (internal control) requirements - verify QMS existence, technical documentation completeness, and lifecycle consistency.
Use voluntary alignment with the current EN 18286 draft (despite its January 2026 vote failure and ongoing revisions with 1,288 comments under review) to structure QMS preparation - it maps closely to Article 17 and will provide presumption of conformity once cited (expected late 2026 or later).
Phase 3: Select & Execute the Conformity Assessment Route (Q2-Q3 2026)
Article 43 and Annexes VI-VII define the routes - choice depends on system category, standards/common specifications applied, and risk appetite.
- Determine Applicable Procedure: For Annex III points 2-8: internal control (Annex VI) is default. For point 1 (biometrics) or Annex I integrations: third-party (Annex VII) often mandatory unless harmonised standards/common specifications fully applied. Assess whether EN 18286 (or future standards) will be cited in time for presumption benefits.
- Internal Control (Self-Assessment - Annex VI): Perform thorough internal verification of QMS and technical documentation. Issue EU declaration of conformity, affix CE marking, register in EU database. Strengths: cost-effective, fast. Plan rigorous internal audits and evidence trails to withstand market-surveillance scrutiny.
- Third-Party Assessment (Annex VII): Engage a designated notified body early (capacity will limited). Submit QMS documentation and technical file for review (quality assurance or type-examination + production modules). Address findings promptly. Strengths: high credibility, reduced audit risk. Plan for 6-18+ month cycles and ongoing surveillance.
- Sectoral Integration Route: If under Annex I legislation (e.g., MDR, Machinery), integrate Article 17 elements into existing certified QMS and leverage sectoral conformity assessment where possible (Article 17(3)-(4)).
Edge case: If harmonised standards lag, fallback to internal or notified-body routes without presumption - plan contingency buffers. Engage notified bodies now for high-biometric or safety-critical systems.
Phase 4: Finalise, Register, and Maintain Post-Assessment (Q3 2026 onward)
Complete the process before market placement/putting into service.
- Issue Declaration & CE Marking: Draw up EU declaration of conformity (including unique identifier, standards applied, notified body details if applicable).
- Register in EU Database: Submit required information per Article 49/71 before deployment.
- Establish Ongoing Compliance: Activate post-market monitoring, incident reporting (Article 73), and change management. Schedule periodic QMS reviews and updates to technical documentation.
Treat conformity assessment as a lifecycle commitment - not a one-time event. Substantial modifications trigger re-assessment; plan change-control processes accordingly.
Strategic Considerations, Timelines, and 2026 Realities
Adopt a phased 12-18 month roadmap aligned to 2 August 2026 (or later backstop dates if standards delay). Prioritise high-visibility/risk systems first. Budget for external expertise (legal, consultants, notified bodies) and tools (compliance software, audit frameworks). Monitor EU AI Office guidance, JTC 21 standardisation progress (EN 18286 revisions ongoing March 2026), and Digital Omnibus developments for potential simplifications.
Edge cases: Start-ups/SMEs focus on internal routes + proportionality; global firms plan for "Brussels effect" across jurisdictions; legacy systems in transition may benefit from phased-in rules. Non-compliance risks fines up to €35M/7% turnover - proactive planning mitigates this while building trustworthy AI.
Content based on the EU AI Act (Regulation (EU) 2024/1689), Articles 17, 43, Annexes VI-VII, and EN 18286 draft standard. Always consult official sources, the EU AI Office, designated notified bodies, and legal experts for tailored compliance planning. High-risk provisions become fully applicable on 2 August 2026 (with potential extensions per harmonised standards timelines).