The AI Act and CE marking
Regulation (EU) 2024/1689 — the AI Act — is often described as if it were a self-contained body of technology law. For manufacturers, the more useful description is this: for high-risk AI systems, the AI Act is a piece of Union harmonisation legislation built on the New Legislative Framework, and it ends the same way the Machinery Regulation or the Medical Devices Regulation ends: with a conformity assessment, an EU declaration of conformity, and CE marking. Article 48 of the AI Act states it directly — high-risk AI systems bear the CE marking, applied in accordance with the general principles of Article 30 of Regulation (EC) No 765/2008.
The consequence is that everything this site describes for physical products — assessment modules, technical documentation, declarations of conformity, notified bodies, harmonised standards, market surveillance — has an AI Act counterpart. This page maps the correspondence and the points where the AI Act departs from the familiar pattern.
Which AI systems are high-risk: the two routes
Only high-risk AI systems enter the CE system. The AI Act's other tiers — prohibited practices, transparency obligations for certain systems such as chatbots and deepfakes, and the separate regime for general-purpose AI models — involve no conformity assessment and no marking. Article 6 defines high-risk through two independent routes.
Route 1: Annex I — AI inside regulated products
An AI system is high-risk under Article 6(1) when both of the following hold:
- it is a product, or a safety component of a product, covered by the Union harmonisation legislation listed in Annex I of the AI Act; and
- that product is required to undergo third-party conformity assessment under the listed act.
Annex I Section A lists the core New Legislative Framework acts: machinery, toys, recreational craft, lifts, ATEX equipment, radio equipment, pressure equipment, cableways, personal protective equipment, gas appliances, medical devices, and in vitro diagnostics. Section B lists old-approach sectors — aviation, motor vehicles, marine equipment, rail — where the AI Act's requirements feed into the sectoral type-approval systems rather than applying directly.
The third-party condition matters. An AI-driven feature in a product self-certified under internal production control (Module A) does not become high-risk by this route. A machine-learning-based safety component in a medical device assessed by a notified body, or in machinery falling within the Machinery Regulation's third-party categories, does.
Route 2: Annex III — standalone use cases
Article 6(2) designates as high-risk the AI systems listed in Annex III by use case, independent of any product context: biometric identification and categorisation, AI as a safety component in critical infrastructure management, education and vocational training, employment and worker management, access to essential private and public services (including credit scoring and insurance pricing), law enforcement, migration and border control, and administration of justice and democratic processes. A derogation lets providers document that a listed system nonetheless poses no significant risk of harm in its specific role, subject to conditions and registration.
What conformity is assessed against
High-risk AI systems must meet the requirements of Chapter III, Section 2 of the AI Act (Articles 8 to 15): a risk management system operated across the lifecycle (Article 9 — the AI counterpart of a product risk assessment, but continuous rather than one-off), data and data governance for training, validation and test sets (Article 10), technical documentation per Annex IV (Article 11), automatic event logging (Article 12), transparency and instructions for deployers (Article 13), human oversight (Article 14), and accuracy, robustness and cybersecurity (Article 15). Providers must also operate a quality management system and post-market monitoring, and report serious incidents — the architecture will be recognisable to anyone who has worked under the MDR.
Conformity assessment and CE marking
Article 43 sets the assessment routes:
- Annex III, biometrics (point 1): the provider chooses between internal control (Annex VI) and an assessment involving a notified body (Annex VII) — but internal control is only available where harmonised standards or common specifications covering the requirements have been applied. Absent usable standards, the notified-body route is mandatory.
- Annex III, other use cases (points 2 to 8): internal control under Annex VI. No notified body is involved — a deliberate parallel to Module A self-assessment, paired with the obligation to register the system in the EU database (Article 49).
- Annex I products: no separate AI Act procedure. The AI requirements are verified within the conformity assessment already required by the sectoral act, by the notified body acting under that act. The AI Act's checks extend the sectoral procedure rather than duplicating it.
After assessment, the provider draws up an EU declaration of conformity (Article 47) and affixes CE marking under Article 48. For AI systems provided only digitally, the CE marking may itself be digital, on the interface or accompanying documentation, rather than a physical graphic — the first explicit provision for digital CE marking in a horizontal act. Where a notified body was involved, its identification number accompanies the mark, exactly as described in affixing the CE mark. A single declaration may cover both the AI Act and the sectoral legislation; for products under acts such as the MDR, the intention throughout is one assessment, one declaration, one mark.
Timeline
The AI Act entered into force on 1 August 2024 and applies in stages: the prohibitions on certain AI practices (with AI-literacy duties) from 2 February 2025; the rules on general-purpose AI models, governance, and notified bodies from 2 August 2025; general application — including Annex III high-risk systems — from 2 August 2026; and the high-risk regime for Annex I products from 2 August 2027. The 2027 date is the one most product manufacturers should plan against, and it deliberately allows the sectoral notified-body infrastructure to extend into AI competence first. Transitional provisions ease the position of high-risk systems already placed on the market before the relevant dates, broadly tying new obligations to significant design changes; the details are in Article 111 and are worth reading in the original for any legacy system.
Notified bodies for AI
The AI Act establishes its own notification regime: Member States designate notifying authorities, and conformity assessment bodies are notified against the AI Act's competence requirements, appearing in NANDO like any other notified body. For Annex I products the practically important cohort is existing sectoral notified bodies extending their designation to cover the AI Act — an MDR notified body adding AI Act scope can then run the combined assessment. Capacity is a live concern: the number of bodies designated for AI remains small relative to the expected 2026–2027 demand, and providers who will need Annex VII assessments should engage bodies early, as the MDR experience taught the medical device sector.
Harmonised standards: the open flank
As with every NLF act, presumption of conformity comes from harmonised standards cited in the Official Journal. The Commission issued a standardisation request to CEN and CENELEC, whose joint technical committee JTC 21 is developing the AI standards programme — covering risk management, data quality, robustness, human oversight, and the other Article 8 to 15 requirements. At the time of review, the set of cited harmonised standards under the AI Act remains incomplete; providers should verify the current citation list in the Official Journal before relying on a presumption of conformity, and the Commission may adopt common specifications where standards are delayed. Until standards are cited, the Annex III biometrics route effectively requires notified-body involvement, and internal-control assessments elsewhere must be argued requirement by requirement.
Overlap with the Machinery Regulation
The Machinery Regulation (EU) 2023/1230, applying from 20 January 2027, contains its own AI-adjacent provisions: essential requirements addressing safety functions with self-evolving behaviour, software integrity, and protection against corruption, and third-party assessment for certain machinery embedding machine-learning safety components. From 2 August 2027 the AI Act's Annex I route sits on top of this. The two acts are designed to interlock — the Machinery Regulation governs the machine, the AI Act the AI system within it, with one combined assessment — but manufacturers of AI-enabled machinery face both texts and should map requirements jointly rather than sequentially. The same holds for radio equipment with the cybersecurity requirements applying since August 2025.
Who holds the obligations
The AI Act's "provider" corresponds to the manufacturer role in product law, with equivalents of the full economic-operator chain: authorised representatives for non-EU providers, importers, and distributors, with obligations closely modelled on the NLF template described in manufacturer obligations. A deployer, importer or distributor that puts its name on a high-risk system, or substantially modifies one, becomes the provider — the same re-qualification rule familiar from Decision 768/2008/EC. Penalties are set in the AI Act itself, scaled to global turnover; see penalties for non-compliance for how these compare with sectoral regimes.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — EUR-Lex.
- Regulation (EC) No 765/2008 setting out the requirements for accreditation and market surveillance, Article 30 (general principles of CE marking) — EUR-Lex.
- Decision No 768/2008/EC on a common framework for the marketing of products — EUR-Lex.
- Regulation (EU) 2023/1230 of the European Parliament and of the Council of 14 June 2023 on machinery — EUR-Lex.
- European Commission — Regulatory framework for AI (AI Act policy page).