Article 43 sets out the conformity assessment procedures that providers of high-risk AI systems must complete before placing their systems on the market. The appropriate procedure depends on whether the AI system falls under Annex I product legislation or Annex III standalone high-risk categories.
Self-Assessment vs. Third-Party Assessment
For most Annex III high-risk AI systems, Article 43(2) allows providers to conduct a conformity assessment through an internal control procedure based on Annex VI. However, Article 43(1) requires third-party assessment by a notified body for: AI systems listed under Annex I (product safety legislation that already requires third-party assessment); and AI systems listed in Annex III, point 1 (biometric identification and categorisation of natural persons). This means that facial recognition, live biometric identification, and biometric categorisation systems require notified body involvement.
Regulation (EU) 2024/1689 — Article 43(4)
“High-risk AI systems shall undergo a new conformity assessment procedure whenever they are substantially modified, regardless of whether the modified system is intended to be further distributed or continues to be used by the current deployer.”
- Self-assessment is the default for most Annex III systems -- third-party assessment is the exception
- Biometric identification systems (Annex III point 1) always require notified body involvement
- A substantial modification triggers a new conformity assessment regardless of who made the change
- The EU declaration of conformity (Article 47) is the output of a successful conformity assessment
- CE marking under Article 48 signals completed conformity assessment for high-risk AI systems