Every provision quoted below was read on the European Commission's AI Act Service Desk on 31 August 2026 and is attributed to the article or annex it comes from. Where a page carried a notice that the provision has been amended and the displayed text not yet updated, that is stated in place rather than omitted. Nothing here is legal advice, and the operative wording should be read in the Official Journal text before any decision is taken on it.

In short
  • Article 43 provides that for Annex III points 2 to 8, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body. Those points are employment, education, essential services and credit, law enforcement, migration and justice.
  • Annex VI is three verifications performed by the provider on its own work: the quality management system against Article 17, the technical documentation against the essential requirements, and the consistency of design, development and post-market monitoring with that documentation. No external party takes part.
  • A third-party route exists only for Annex III point 1, biometrics, where the provider may choose it and where it becomes obligatory if harmonised standards do not exist, are only partially applied, or common specifications are unavailable.
  • The consequence for a deployer is precise rather than alarming: a CE mark on such a system rests on the provider's own file, and it does not evidence, reduce or discharge any Article 26 obligation, which attaches to use rather than to construction.
  • This is the structural reason a private audit market for AI agents formed before a European public one did. The demand for outside evidence is commercial and present; the public route is later and, for these categories, absent by design.

The question underneath

Compliance teams arrive at this question from two directions. Providers ask who has to sign off before they can place a system on the market. Deployers ask what the mark on a system they are buying actually certifies. Both are asking about conformity assessment, and both tend to assume the answer resembles the answer in adjacent fields, where a product in a regulated category typically meets an external body at some point before it is sold.

The AI Act is not built that way for most of its high-risk scope, and the reason is visible in the drafting rather than hidden in it. The Act's high-risk regime is a set of substantive obligations on providers, backed by documentation duties, market surveillance and penalties. Verification of those obligations before market entry is, for the large majority of Annex III, left to the provider. This is a legitimate regulatory design choice with a long history in Union product law. It is also very commonly misdescribed, including by people selling services against it, and the misdescription runs in both directions: some readers believe an audit is required when it is not, and others conclude that nothing is required at all, which is further from the truth.

What Article 43 provides

Article 43 divides the Annex III high-risk population in two, and the division is the whole substance of this article.

For Annex III point 1, which is biometrics, the provider chooses. The text sets out that the provider shall opt for one of the following conformity assessment procedures based on the internal control referred to in Annex VI, or the assessment of the quality management system and the assessment of the technical documentation with the involvement of a notified body referred to in Annex VII. The choice is not unconditional. Where harmonised standards do not exist, where the provider has applied them only in part, or where common specifications are not available, the route through a notified body becomes obligatory rather than optional.

For Annex III points 2 to 8, the text does not offer a choice. It provides that providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body. That final clause is not commentary added by this desk. It is in the provision, describing the procedure it has just directed providers to use.

It is worth naming what points 2 to 8 contain, because the abstraction hides the significance. They cover AI in critical infrastructure, in education and vocational training, in employment and worker management, in access to and enjoyment of essential private and public services including creditworthiness evaluation and risk assessment and pricing in life and health insurance, in law enforcement, in migration, asylum and border control, and in the administration of justice and democratic processes. Set against the biometrics category at point 1, that is nearly the entire enterprise deployment surface. The sector-by-sector reading of what falls inside is at the Annex III sector guide.

What Annex VI is

Annex VI describes the conformity assessment procedure based on internal control, and it is short. Three things happen, and the same party does all three.

First, the provider verifies that the quality management system it has established complies with the requirements of Article 17. Second, it examines the information contained in the technical documentation in order to assess compliance of the AI system with the relevant essential requirements set out in Chapter III, Section 2, which is the block of obligations running through risk management, data governance, documentation, logging, transparency, human oversight, accuracy, robustness and cybersecurity. Third, it verifies that the design and development process of the system, and its post-market monitoring, are consistent with that technical documentation.

No third party appears at any step. The provider examines its own quality system, reads its own file and satisfies itself that its own practice matches what the file says. That is the assurance mechanism that stands behind a declaration of conformity for an employment screening system, a credit decisioning system or a system used in the administration of justice.

Two things should be said in the same breath, because leaving either out produces a distorted picture. The first is that this is genuinely less than an audit, and pretending otherwise helps nobody. The second is that it is genuinely more than nothing: the technical documentation obligations under Articles 11 and 17 are substantial, the declaration is a legal statement carrying real exposure, and market surveillance authorities can demand the file after the fact. The Act relies on documentation plus enforcement rather than on ex ante inspection. Our reading of the documentation obligation itself is at Article 11 and the technical documentation, and the enforcement architecture that sits behind it is at the AI Office and national supervisors.

What a notified body would have been

It is worth reading Article 31 even though it will apply to few AI systems, because it shows what the Act considers third-party assessment to mean when it asks for it. The standard is high.

A notified body must be independent of the provider of a high-risk AI system, and must not be involved in the design, development, marketing or use of high-risk AI systems. It must maintain procedures ensuring the independence, objectivity and impartiality of its activities, and documented structures safeguarding impartiality throughout the organisation. It must have sufficient internal competences, including the permanent availability of sufficient administrative, technical, legal and scientific personnel. It must obtain appropriate liability insurance for its conformity assessment activities. It must maintain documented procedures under which its personnel observe the confidentiality of information obtained during assessments. And it must participate in coordination activities and remain aware and up to date in respect of relevant standards.

The liability insurance requirement deserves a moment on a publication that covers coverage. The Act's answer to the question of who bears the risk when an assessor is wrong is that the assessor must be insured for it. That is a familiar and sensible pattern in conformity assessment generally. It also quietly indicates how seriously the Act takes the act of certifying, which makes the routing of most of Annex III away from that process a deliberate choice rather than an oversight.

What the deployer is relying on

A deployer buying an Annex III system falling within points 2 to 8 will, in due course, see a declaration of conformity and a mark. What that mark represents is now precisely statable: the provider has verified its own quality management system, examined its own technical documentation, and satisfied itself that its process matches the file. It is a statement by the provider that carries legal weight against the provider.

Three practical consequences follow for a deployer, and none of them is a reason to distrust suppliers generally.

It is not evidence of an audit, so do not represent it as one. A procurement summary or a board paper describing a purchased system as independently certified because it carries a mark is describing something that did not happen. That is a small error until somebody relies on it.

It does not touch Article 26. Deployer obligations attach to use: operating the system in accordance with the instructions for use, assigning human oversight to people with the competence, training and authority to exercise it, ensuring input data is relevant and sufficiently representative for the intended purpose, monitoring operation, keeping logs, and informing the provider and the market surveillance authority where a risk or serious incident arises. Nothing a provider does in its own conformity assessment discharges any of that. The complete reading is at the Article 26 complete guide.

It shifts the useful question from the mark to the file. If the assurance is documentary, then the sensible thing to ask a provider for is documentary: what is in the technical documentation, what the instructions for use say about intended purpose and known limitations, what the logging design retains and for how long, and what the post-market monitoring plan actually monitors. Those are the things a deployer will need anyway to perform its own duties, and asking for them is ordinary commercial diligence rather than an accusation. Where the deployer's own conduct starts to make it a provider in its own right, a different set of obligations attaches, and that boundary is at Article 25 and the value chain.

Why the private market got there first

Set the architecture above beside what has happened commercially in 2026 and the shape of the European gap becomes concrete rather than rhetorical.

Independent assurance for AI agents now exists, and it is private. Schellman published on 3 February 2026 that it had become the first accredited auditor for AIUC-1, describing a division of labour in which Schellman provides independent audit evidence collection, detailed reporting and certification guidance while the Artificial Intelligence Underwriting Company conducts technical evaluations and issues certification, with agent behaviour tested quarterly to ensure ongoing compliance. On 27 August 2026 KPMG published that KPMG LLP is the first of the Big Four to achieve AIUC-1 certification, for a platform it states underwent more than 900 technical tests including hallucinations, high-risk domain interactions, content safety and prompt injection attacks.

None of that is European, none of it is required by the AI Act, and none of it produces anything a market surveillance authority is obliged to recognise. It exists because enterprise buyers, procurement functions and insurers all want evidence produced by somebody other than the vendor, and because for Annex III points 2 to 8 the Act does not oblige anybody to produce it. Demand that a regulation does not serve is served by a market. The certification-side reading of that development is at agentcertified.eu, on the arrival of an accredited audit layer, and the buyer-facing version for smaller operators is at insureyouragent.com, on what a vendor certificate means.

Two things are worth saying plainly so this is not read as a complaint about the Act. Regulation and certification are different instruments and the Act is not obliged to be the second. And a private certificate is not a compliance substitute: nothing offered commercially today satisfies an Annex VI obligation, and any supplier suggesting otherwise should be read carefully.

A note on the page these provisions were read from

The Article 43 page as served on 31 August 2026 carried a Digital Omnibus notice stating that the provision has been amended and that the displayed text has not yet been updated to reflect those changes, directing readers to the Digital Omnibus material for detail. That is the third occasion in eight days on which this desk has recorded a currency problem on official pages, following findings on 24 and 28 August about unamended article text and about consultation pages carrying pre-Omnibus application sentences.

The operating rule that follows is worth stating as a rule rather than an observation. A Service Desk article page is an excellent way to read the shape of a provision and an unreliable way to establish its current wording. Anything load-bearing should be confirmed against the consolidated text before it goes into a compliance file, and any citation taken from these pages before late August 2026 is worth re-checking. Our running record of that problem is at the Service Desk and unamended article text.

What to do with this

For a provider, the practical reading is that the absence of a notified body raises rather than lowers the importance of the file, because the file is the entire assurance. Build the Article 17 quality management system and the Article 11 technical documentation as though somebody will read them adversarially, since in the only scenario that matters somebody will.

For a deployer, the practical reading is to stop treating the mark as the answer to a diligence question and start treating the documentation as the answer. Ask for the instructions for use, the stated intended purpose, the known limitations, the logging design and the monitoring plan. Those documents are what you need to perform Article 26 anyway, and requesting them before contract is considerably easier than requesting them after an incident.

For both, the timing is the Omnibus timing. Annex III standalone high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028, so this is preparation rather than emergency. The nearer fixed date remains 2 December 2026, when the new prohibitions take effect and the Article 50 transitional period ends, and that one is not deferred. What lands then is set out at what lands on 2 December 2026.

Questions

Does the EU AI Act require an independent audit of high-risk AI systems?

For most high-risk categories, no. Article 43 provides that for Annex III points 2 to 8, providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body. Those points cover employment and worker management, education, access to essential private and public services including credit, law enforcement, migration and border control, and the administration of justice. Only Annex III point 1, biometrics, offers a route through a notified body, and Annex I products bring third-party assessment through the sectoral legislation that already regulates them.

What does Annex VI internal control actually require?

Three verifications, all performed by the provider on its own work. The provider verifies that its established quality management system complies with the requirements of Article 17. It examines the information in the technical documentation to assess compliance of the system with the relevant essential requirements in Chapter III, Section 2. And it verifies that the design and development process and the post-market monitoring are consistent with that technical documentation. No external assessor takes any part in the procedure.

What is a notified body under the AI Act and when is one involved?

A conformity assessment body designated to perform third-party assessment. Article 31 requires notified bodies to be independent of the provider and not involved in the design, development, marketing or use of high-risk AI systems, to maintain documented structures safeguarding impartiality, to hold sufficient internal competences including permanent availability of sufficient administrative, technical, legal and scientific personnel, and to obtain appropriate liability insurance for their conformity assessment activities. Under Article 43 a notified body is available for Annex III point 1 by the provider's choice, and becomes obligatory there where harmonised standards do not exist, are applied only in part, or common specifications are unavailable.

If the provider self-assesses, what is a deployer relying on when it sees a CE mark?

On the provider's own file. For an Annex III system in points 2 to 8, the declaration of conformity rests on the provider's internal verification of its own quality management system and its own technical documentation. That is a real legal statement with real consequences for the provider, and it is not an audit. It does not discharge, reduce or evidence any deployer obligation under Article 26, which attaches to how a system is used rather than to how it was built.

When do Annex III conformity assessment obligations start to apply?

The AI Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, moved standalone Annex III high-risk obligations to 2 December 2027 and Annex I obligations to 2 August 2028. Article 43 sits in the high-risk chapter, so the route described here becomes operative on those dates. Prohibitions under Article 5, general-purpose AI obligations and Article 50 transparency duties were not deferred and are already live.

Why has a private certification market for AI agents formed before a European one?

Because the demand for independent assurance is commercial and immediate while the public route is later and, for most categories, absent by design. Enterprise buyers, procurement teams and insurers want evidence produced by somebody other than the vendor, and the Act does not oblige anyone to produce it for Annex III points 2 to 8. Private standards moved into that space with an audit structure of their own. That is not a criticism of the Act, which regulates rather than certifies, but it explains why a European enterprise asking for a certificate today will be offered a private one, and why no private certificate satisfies an Annex VI obligation.

Sources

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 12.7.2024.
  2. Article 43, conformity assessment. The routing of Annex III points 2 to 8 to internal control, and the quoted clause which does not provide for the involvement of a notified body, read at ai-act-service-desk.ec.europa.eu on 31 August 2026. That page carried a Digital Omnibus notice stating the provision has been amended and that the displayed text has not yet been updated.
  3. Annex VI, conformity assessment procedure based on internal control. The three verifications described in this article, and the absence of any third party in the procedure, read at ai-act-service-desk.ec.europa.eu on 31 August 2026.
  4. Article 31, requirements relating to notified bodies. Independence, impartiality, internal competence, personnel availability, liability insurance for conformity assessment activities, confidentiality and participation in coordination activities, read at ai-act-service-desk.ec.europa.eu on 31 August 2026. No count of designated notified bodies is stated in this article, because none was verified in this pass.
  5. Article 17, quality management system, and Article 11, technical documentation. Referenced as the obligations Annex VI directs the provider to verify against.
  6. Article 26, obligations of deployers of high-risk AI systems.
  7. Regulation (EU) 2026/1744, the AI Omnibus, in force 27 July 2026. Annex III standalone high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028. digital-strategy.ec.europa.eu.
  8. Schellman, "Schellman Becomes the First Accredited Auditor for AIUC-1", dated 3 February 2026, read at schellman.com on 31 August 2026.
  9. KPMG, "KPMG LLP Becomes First Big Four Firm with AIUC-1 Certified AI Capability", dated 27 August 2026, read at kpmg.com on 31 August 2026. The figure of more than 900 technical tests and the categories tested are as stated in that announcement.
  10. No relationship exists between Future Proof Intelligence and AIUC, Schellman or KPMG. Each is named here because it published the statement attributed to it on its own domain on the date given.