CECheck The reference for CE marking

The AI Act and CE marking

Last reviewed: August 2026 · Legal status verified against EUR-Lex.

Regulation (EU) 2024/1689 — the AI Act — is often described as if it were a self-contained body of technology law. For manufacturers, the more useful description is this: for high-risk AI systems, the AI Act is a piece of Union harmonisation legislation built on the New Legislative Framework, and it ends the same way the Machinery Regulation or the Medical Devices Regulation ends: with a conformity assessment, an EU declaration of conformity, and CE marking. Article 48 of the AI Act states it directly — high-risk AI systems bear the CE marking, applied in accordance with the general principles of Article 30 of Regulation (EC) No 765/2008.

The consequence is that everything this site describes for physical products — assessment modules, technical documentation, declarations of conformity, notified bodies, harmonised standards, market surveillance — has an AI Act counterpart. This page maps the correspondence and the points where the AI Act departs from the familiar pattern.

Which AI systems are high-risk: the two routes

Only high-risk AI systems enter the CE system. The AI Act's other tiers — prohibited practices, transparency obligations for certain systems such as chatbots and deepfakes, and the separate regime for general-purpose AI models — involve no conformity assessment and no marking. Article 6 defines high-risk through two independent routes.

Route 1: Annex I — AI inside regulated products

An AI system is high-risk under Article 6(1) when both of the following hold:

Annex I Section A lists the core New Legislative Framework acts: machinery, toys, recreational craft, lifts, ATEX equipment, radio equipment, pressure equipment, cableways, personal protective equipment, gas appliances, medical devices, and in vitro diagnostics. Section B lists old-approach sectors — aviation, motor vehicles, marine equipment, rail — where the AI Act's requirements feed into the sectoral type-approval systems rather than applying directly.

The third-party condition matters. An AI-driven feature in a product self-certified under internal production control (Module A) does not become high-risk by this route. A machine-learning-based safety component in a medical device assessed by a notified body, or in machinery falling within the Machinery Regulation's third-party categories, does.

Route 2: Annex III — standalone use cases

Article 6(2) designates as high-risk the AI systems listed in Annex III by use case, independent of any product context: biometric identification and categorisation, AI as a safety component in critical infrastructure management, education and vocational training, employment and worker management, access to essential private and public services (including credit scoring and insurance pricing), law enforcement, migration and border control, and administration of justice and democratic processes. A derogation lets providers document that a listed system nonetheless poses no significant risk of harm in its specific role, subject to conditions and registration.

What conformity is assessed against

High-risk AI systems must meet the requirements of Chapter III, Section 2 of the AI Act (Articles 8 to 15): a risk management system operated across the lifecycle (Article 9 — the AI counterpart of a product risk assessment, but continuous rather than one-off), data and data governance for training, validation and test sets (Article 10), technical documentation per Annex IV (Article 11), automatic event logging (Article 12), transparency and instructions for deployers (Article 13), human oversight (Article 14), and accuracy, robustness and cybersecurity (Article 15). Providers must also operate a quality management system and post-market monitoring, and report serious incidents — the architecture will be recognisable to anyone who has worked under the MDR.

Conformity assessment and CE marking

Article 43 sets the assessment routes:

After assessment, the provider draws up an EU declaration of conformity (Article 47) and affixes CE marking under Article 48. For AI systems provided only digitally, the CE marking may itself be digital, on the interface or accompanying documentation, rather than a physical graphic — the first explicit provision for digital CE marking in a horizontal act. Where a notified body was involved, its identification number accompanies the mark, exactly as described in affixing the CE mark. A single declaration may cover both the AI Act and the sectoral legislation; for products under acts such as the MDR, the intention throughout is one assessment, one declaration, one mark.

One procedure, not two. A manufacturer of an Annex I product embedding high-risk AI should not plan for a second, parallel certification. The AI Act was drafted so that the existing notified body — where designated for the AI Act's requirements — checks Articles 8 to 15 as part of the sectoral assessment, and the technical documentation may be integrated into the existing technical file (a single set of documentation covering both acts). The planning burden is real, but it lands inside the existing procedure: extended documentation, extended audit scope, extended assessment cost — not a separate CE regime.

Timeline

The AI Act entered into force on 1 August 2024 and applies in stages: the prohibitions on certain AI practices (with AI-literacy duties) from 2 February 2025; the rules on general-purpose AI models, governance, and notified bodies from 2 August 2025; general application — including Annex III high-risk systems — from 2 August 2026; and the high-risk regime for Annex I products from 2 August 2027. The 2027 date is the one most product manufacturers should plan against, and it deliberately allows the sectoral notified-body infrastructure to extend into AI competence first. Transitional provisions ease the position of high-risk systems already placed on the market before the relevant dates, broadly tying new obligations to significant design changes; the details are in Article 111 and are worth reading in the original for any legacy system.

Notified bodies for AI

The AI Act establishes its own notification regime: Member States designate notifying authorities, and conformity assessment bodies are notified against the AI Act's competence requirements, appearing in NANDO like any other notified body. For Annex I products the practically important cohort is existing sectoral notified bodies extending their designation to cover the AI Act — an MDR notified body adding AI Act scope can then run the combined assessment. Capacity is a live concern: the number of bodies designated for AI remains small relative to the expected 2026–2027 demand, and providers who will need Annex VII assessments should engage bodies early, as the MDR experience taught the medical device sector.

Harmonised standards: the open flank

As with every NLF act, presumption of conformity comes from harmonised standards cited in the Official Journal. The Commission issued a standardisation request to CEN and CENELEC, whose joint technical committee JTC 21 is developing the AI standards programme — covering risk management, data quality, robustness, human oversight, and the other Article 8 to 15 requirements. At the time of review, the set of cited harmonised standards under the AI Act remains incomplete; providers should verify the current citation list in the Official Journal before relying on a presumption of conformity, and the Commission may adopt common specifications where standards are delayed. Until standards are cited, the Annex III biometrics route effectively requires notified-body involvement, and internal-control assessments elsewhere must be argued requirement by requirement.

Overlap with the Machinery Regulation

The Machinery Regulation (EU) 2023/1230, applying from 20 January 2027, contains its own AI-adjacent provisions: essential requirements addressing safety functions with self-evolving behaviour, software integrity, and protection against corruption, and third-party assessment for certain machinery embedding machine-learning safety components. From 2 August 2027 the AI Act's Annex I route sits on top of this. The two acts are designed to interlock — the Machinery Regulation governs the machine, the AI Act the AI system within it, with one combined assessment — but manufacturers of AI-enabled machinery face both texts and should map requirements jointly rather than sequentially. The same holds for radio equipment with the cybersecurity requirements applying since August 2025.

Who holds the obligations

The AI Act's "provider" corresponds to the manufacturer role in product law, with equivalents of the full economic-operator chain: authorised representatives for non-EU providers, importers, and distributors, with obligations closely modelled on the NLF template described in manufacturer obligations. A deployer, importer or distributor that puts its name on a high-risk system, or substantially modifies one, becomes the provider — the same re-qualification rule familiar from Decision 768/2008/EC. Penalties are set in the AI Act itself, scaled to global turnover; see penalties for non-compliance for how these compare with sectoral regimes.

Sources