RatedWithAI

RatedWithAI

Accessibility scanner

EU AI ActSeptember 13, 2026

If You Need a Notified Body, the Queue Is Your Real Deadline

Most high-risk AI never touches one. For the products that do, capacity — not documentation quality — is what decides whether you ship into Europe on time. The first question to answer is which of those two worlds you are in.

Annex VI
Internal control is the default route for most Annex III high-risk systems — no third party required
Check NANDO
Designation is scope-specific; a body notified under another regulation is not automatically notified under the AI Act
Queue Early
Capacity is the scarce input, and a dated application is itself evidence of good faith

First, Establish Whether You Need One At All

A striking number of AI Act programmes begin with a procurement exercise for a notified body that the company does not need. The Act's conformity assessment architecture is inherited from EU product law, and in that architecture third-party involvement is the exception rather than the rule.

For standalone high-risk systems in the Annex III list — the hiring, credit, education, essential services and similar categories that most software companies land in — the route is internal control. You assess the system against the requirements yourself, assemble the technical documentation described in Annex IV, operate a quality management system, sign the declaration of conformity and affix the CE marking. No external certificate exists to obtain, and no one issues you a passing grade.

Third-party assessment enters in two families of case. The first is biometrics: remote biometric identification and the neighbouring biometric categories carry a third-party route, with a narrow path back to internal control where the provider has applied harmonised standards in full. The second is AI embedded as a safety component in products already regulated by sectoral EU legislation — medical devices, machinery, and the rest of the Annex I list — where the AI requirements are folded into the conformity assessment that product already had to undergo. If you are a medical device manufacturer, your notified body relationship already exists and the question is scope, not selection.

The Classification Work That Precedes Everything

  • Are you a provider or a deployer? Only providers run conformity assessment. A deployer who rebrands a system, changes its intended purpose, or substantially modifies it becomes a provider and inherits the whole obligation set, which is how companies end up in assessment unexpectedly.
  • Is the system high-risk in the first place? The Annex III listing is a starting point, not a conclusion. The Article 6(3) derogation lets a provider conclude a listed system does not pose significant risk — a determination that must be documented and registered, not simply assumed.
  • Which annex procedure applies? Internal control, or assessment of the quality management system and technical documentation by a notified body. The answer follows from the classification, not from preference.
  • Is your product already in a regulated pipeline? If the AI is a safety component of a CE-marked product, the AI requirements travel with the existing sectoral assessment rather than creating a parallel one.

Reading a Designation Before You Sign

Conformity assessment bodies are designated by national notifying authorities and listed in the Commission's NANDO database. The listing is not a general endorsement. It is legislation-specific and scope-specific: a body appears under a particular legal act with a set of scope lines describing the procedures it may operate and the product or technology categories it covers.

Two checks take minutes and prevent an expensive mistake. Confirm the body is designated under the AI Act specifically, rather than under a sectoral regulation it has served for years. Then confirm the scope line covers your procedure and your technology. Firms in this market advertise "AI Act readiness" services long before designation completes, and those services can be genuinely useful as gap assessment — they are simply not the same thing as a certificate, and the engagement letter should say which one you are buying.

Ask directly: are you designated under the AI Act today, for which scope lines, and can you point me at your NANDO entry? A body that answers with a link is a body you can plan around. A body that answers with a brochure is telling you something about the timeline.

Capacity Is the Constraint Nobody Budgets For

Designation under the AI Act has proceeded more slowly than the compliance dates imply, and the pool of bodies with real competence in machine learning is small. The same organisations are absorbing demand from adjacent regimes, and the assessors qualified to review a model's evaluation methodology are not a resource that scales quickly.

The result is a market where the binding constraint on an EU launch is often not your technical file at all. Teams plan backwards from the compliance date, allow a generous window for documentation, and allocate a few weeks for "the audit" — then discover the first available slot is months out and the body wants a completed file before it will even hold one.

Treat the queue as the critical path. Open the conversation while the documentation is still in draft, ask what the body requires to accept an application versus to begin assessment, and get the application date on record. If the calendar does not work, the honest options are to narrow the product scope so the high-risk component shrinks or disappears, to sequence the EU launch behind other markets, or to ship a reduced feature set — each of which is a decision a business can make deliberately in March and cannot make at all in November.

What a Standards-Based File Buys You

Harmonised standards matter here in a way that is easy to miss. Conformity with a harmonised standard published in the Official Journal carries a presumption of conformity with the requirements it covers, which narrows what has to be argued from first principles. In the biometric route, full application of harmonised standards is also what opens the internal-control path.

The delay in publishing those standards has left providers building files against draft standards and internationally recognised frameworks instead. That is a defensible position when it is documented as such: state which standard or framework each control maps to, note where the reference is a draft, and record the reasoning. An assessor can work with a mapped file and a stated rationale. An assessor cannot work with a claim of alignment that has no trace.

Frequently Asked Questions

Can we use a notified body in any member state, or must it be in the country where we are established?

Any designated body in any member state may issue a certificate valid across the Union — that is the point of the single market architecture. Practical considerations still push toward a particular choice: working language, availability of assessors with relevant domain competence, the body's familiarity with your sector, and travel or remote-assessment policy. What should not drive the choice is the perception that one national authority is more lenient. Certificates are mutually recognised and market surveillance happens everywhere the product is placed.

What does third-party assessment actually cost?

Costs vary widely with system complexity and the scope of the quality management system being assessed, and public rate cards are rare in this market. The honest planning advice is to get two or three written quotations early and to budget separately for the internal work, which is usually the larger number. Remediation cycles are the variable that blows budgets: an assessment that surfaces gaps requires you to fix them and return, and the return visit competes for the same scarce calendar. Money spent making the technical file complete before the first submission is the cheapest money in the project.

We are a US company with no EU entity. Who handles this?

A provider established outside the Union that places a high-risk system on the EU market must appoint an authorised representative established in the Union, who holds the documentation and acts as the contact point for authorities. That is a separate role from the notified body and does not substitute for assessment. Appoint the representative early, because the mandate has to define what they can do on your behalf, and a representative who first sees the technical file during a regulator's inquiry is not in a position to be useful.

If our system changes frequently, does every model update require re-assessment?

Not if you plan for it. The framework anticipates that AI systems learn and are updated, and changes that were pre-determined by the provider and described in the technical documentation at the time of assessment — including the performance ranges and the retraining process — do not amount to substantial modifications. The work is to define those ranges honestly and in advance rather than to define them so broadly that the description stops being meaningful. Changes to intended purpose are a different matter and generally do trigger reassessment.

Does a certificate from a notified body protect us from enforcement?

It closes one question and leaves the others open. A certificate evidences that the system as assessed met the requirements under the applicable procedure; it does not immunise you against obligations that operate continuously — post-market monitoring, incident reporting, record-keeping, and the deployer-side duties of your customers. Market surveillance authorities can and do examine certified products. The certificate is the entry ticket, not the end state.

The Two-Hour Version of This Work

Write down every AI system you place on the EU market. For each one, record three things: your role, whether it is high-risk and under which classification, and which conformity assessment procedure follows. Most rows will resolve to internal control, and those rows become a documentation project with no external dependency.

The rows that resolve to third-party assessment are the ones with a queue attached. Those go on the calendar first, with the application date — not the assessment date — as the milestone you manage. Everything else in the programme can be compressed. Someone else's availability cannot.