TL;DR: The EU AI Act requires high-risk AI systems to complete conformity assessment by August 2, 2026, but most Annex III systems use internal self-assessment while biometric systems and cases without harmonized standards need notified body review, according to Openlayer. The practical issue is not just compliance timing but choosing the correct assessment path early enough to build the right evidence, governance, and monitoring records.
NHIMG editorial — based on content published by Openlayer: EU AI Act conformity assessment requirements and process guide for April 2026
By the numbers:
Questions worth separating out
Q: How should teams choose between self-assessment and notified body review for high-risk AI systems?
A: Start by classifying the system against the EU AI Act's high-risk categories.
Q: Why do high-risk AI systems create more governance work in identity-related use cases?
A: Because the decisions often affect access, eligibility, or verification, which means the model's outputs are tied to identity governance and accountability.
Q: What breaks when technical documentation is incomplete for EU AI Act conformity assessment?
A: Incomplete documentation stalls self-assessment and can fail a notified body review.
Practitioner guidance
- Classify high-risk AI systems before governance design Map each system to Annex I or Annex III and decide whether it falls into self-assessment or notified body review before the project enters release planning.
- Embed conformity evidence into release workflows Capture architecture, training data provenance, test results, limitations, and version history in the same pipeline that promotes model changes.
- Treat post-market monitoring as a control requirement Define logging, incident handling, and feedback loops so monitoring evidence is available after deployment, not assembled after a problem.
What's in the full article
Openlayer's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step breakdown of which Annex III cases qualify for internal control versus notified body review
- Detailed quality management system requirements and the evidence reviewers expect to see
- Practical documentation checklist for Annex IV, including architecture, data provenance, and performance metrics
- Post-market monitoring and reassessment triggers that affect ongoing compliance
👉 Read Openlayer's guide to EU AI Act conformity assessment requirements →
EU AI Act conformity assessment: are your controls on the right path?
Explore further
Assessment-path ambiguity is the real operational risk. The article shows that many organisations overestimate how often third-party certification applies, then underprepare for the internal control route's documentation burden. That creates a governance gap in the opposite direction too, where biometric or unstandardised systems may be treated like ordinary self-assessment cases. For AI governance teams, the lesson is that correct path selection is the control, not a paperwork exercise.
A question worth separating out:
Q: Who is accountable when a high-risk AI system needs reassessment after a substantial modification?
A: The provider remains accountable for tracking changes that alter performance, risk, or compliance status. Retraining, major configuration shifts, or deployment-context changes can invalidate the original assessment path, so governance should define explicit triggers for review, re-documentation, and, where required, new certification.
👉 Read our full editorial: EU AI Act conformity assessment hinges on the right path