Book my free AI audit
    We use cookies to analyse site usage and improve your experience. No tracking occurs until you accept.

    AI Act Conformity Assessment: Who Signs Off Your AI?

    (Updated )
    EU AI Act
    AI Act Conformity Assessment: Who Signs Off Your AI?

    Quick answer: For most Annex III high-risk AI systems, the AI Act allows internal conformity assessment — you self-assess against the requirements, sign the EU declaration of conformity, affix the CE marking, and register the system in the EU AI database. A notified body only enters the picture for biometric identification and categorisation systems (Annex III §1) and for AI as a safety component under sectoral CE-marking regimes (machinery, medical devices, in-vitro diagnostics, toys, radio equipment and the rest). In Luxembourg, ILNAS is the notifying authority; no Luxembourg-based body had been notified for AI Act scope at the time of writing, so cross-border notification via a Belgian, French or German body is the practical path. The deadline is no longer August 2026: Regulation (EU) 2026/1744 moved stand-alone Annex III obligations to 2 December 2027 and product-embedded AI to 2 August 2028.

    Last verified 7 August 2026.

    The question in every Luxembourg compliance-scoping call has moved on from "am I in scope" to "who actually signs off my system, and when?" This piece answers that — plainly, in the Luxembourg context, with the practical next steps.

    The date changed in July 2026. Read this first

    If you built a conformity-assessment plan against 2 August 2026, rebuild it. The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July — rewrote Article 113 of the AI Act:

    • Stand-alone Annex III high-risk systems (Article 6(2)): 2 December 2027.
    • AI as a safety component of Annex I Section A products (Article 6(1)): 2 August 2028.

    What did take effect on 2 August 2026 is the Article 50 transparency regime and the Commission's power to fine general-purpose AI model providers — neither of which involves a notified body or a CE mark. The full corrected timeline is in our August 2026 guide.

    The omnibus also did two things that directly affect the work described below. It introduced a simplified technical documentation form for SMEs and small mid-caps placing high-risk systems on the market, and it kept the registration obligation for Article 6(3) exemption self-assessments — the Commission had proposed removing it and both co-legislators refused.

    If you have not yet worked out whether you are a provider or a deployer, start with the 5-minute provider-vs-deployer test; if you have not classified your system as high-risk, use the high-risk systems overview. This post picks up where those leave off — for providers of high-risk systems who need to know how they get to CE marking.

    Book a free 30-minute AI Act scoping call — we will map your system to the right conformity-assessment route on the call.

    What conformity assessment actually is

    Conformity assessment is the AI Act's version of what CE-marked products have done for decades: before the product goes on the EU market, the provider (or a body acting on the provider's behalf) verifies against the applicable requirements. For AI, those requirements are set out in Articles 8–15 (risk-management system, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy/robustness/cybersecurity) plus quality-management system requirements in Article 17.

    You end up with three physical artefacts:

    1. Technical documentation (Annex IV) — the design file: what the system does, its intended purpose, training data provenance, performance metrics, risk analysis, human oversight measures.
    2. EU declaration of conformity — a one-to-two-page legal document signed by the provider, listing the system and the standards it conforms to.
    3. CE marking on the system + a listing in the EU AI database (Article 71) for standalone high-risk systems.

    The conformity assessment procedure is the sequence of steps you follow between "we're building this" and "we've signed the declaration." The Act lays out two procedures: internal control (self-assessment against Annex VI) and third-party involvement via a notified body (Annex VII).

    Which route applies to your system

    This is the single most useful table in the whole AI Act to memorise as a provider:

    Your systemRoute to CE marking
    Any Annex III use case except biometric identification/categorisationInternal control (Annex VI) — you self-assess
    Biometric identification or biometric categorisation (Annex III §1)Notified body (Annex VII), unless the provider fully applied harmonised standards and has no doubts about them — then internal control is available
    AI as safety component of a product already covered by an EU harmonisation regulation listed in Annex I §A (machinery, medical devices, in-vitro diagnostics, toys, lifts, pressure equipment, radio equipment, etc.)The existing sectoral conformity assessment absorbs the AI Act obligations — you use the notified body already required by that sectoral regime
    AI as safety component of an Annex I Section B product (aviation, rail, motor vehicles, marine equipment)Outside the AI Act's own conformity-assessment machinery; the AI Act requirements are to be taken into account when those sectoral regimes are next amended

    The consequence for most Luxembourg SME AI providers: you are on the internal-control route. That is a good news story and a bad news story. Good: no external body to book, no external fee, no queue. Bad: the responsibility for interpreting Articles 8–15 correctly sits with you. If you miss something, the fine (up to 3% of worldwide turnover under Article 99) is on your firm — see the fines-and-penalties breakdown for the arithmetic on a Luxembourg turnover.

    Who is a "notified body" and where are Luxembourg's?

    A notified body is a third-party conformity assessment body designated by an EU member state and notified to the Commission to perform a specific piece of conformity assessment work. Each member state has a designating authority responsible for the process.

    In Luxembourg, the notifying authority under the AI Act is ILNAS (Institut Luxembourgeois de la Normalisation, de l'Accréditation, de la Sécurité et qualité des produits et services), under bill of law n°8476 — the same bill that makes the CNPD the national competent authority, single point of contact and default market surveillance authority, with the CSSF, the CAA and the ILR holding sectoral remits. ILNAS already handles notified-body designation for other EU harmonisation regimes, which is why the role sits there. Note the distinction: ILNAS designates and notifies the bodies; it is not the general market surveillance authority for AI. Bill 8476 was still in the parliamentary process at the time of writing.

    At the time of writing no Luxembourg-based body has been notified for AI Act scope. For biometric systems, or for AI as a safety component in a machinery / medical device / IVD product, Luxembourg providers use notified bodies from Belgium (e.g. Vinçotte, SGS), France (LNE, Bureau Veritas) or Germany (TÜV SÜD, TÜV Rheinland, DEKRA). This is normal — cross-border use of notified bodies is a feature of the CE-marking system, not a workaround.

    The authoritative live list of notified bodies per regulation is the European Commission's NANDO database. Check it rather than any secondary list, including this one.

    What "internal control" actually requires

    Do not underestimate this. "Self-assessment" is the phrase most people hear as "unregulated." Under Annex VI you must:

    1. Have a documented quality management system covering the items in Article 17 — including a change-management procedure, a data-governance procedure, and a serious-incident reporting procedure. The omnibus extended proportionate QMS requirements across the SME category and to small mid-caps; check your eligibility before you build the enterprise version.
    2. Compile the technical documentation as per Annex IV, and keep it current with every material change to the system. SMEs and small mid-caps may use the simplified technical documentation form introduced by Regulation (EU) 2026/1744.
    3. Execute the conformity assessment — check the system against every applicable requirement in Articles 8–15, document the check, retain the evidence.
    4. Sign the EU declaration of conformity, affix the CE marking, register the system in the EU AI database.
    5. Keep everything available for competent authorities for 10 years after the system is placed on the market.

    For a Luxembourg SME with a small technical team, this is realistically 6–10 weeks of consulting-plus-internal work for a first system, and 2–4 weeks for subsequent systems once the template QMS is in place. Get the AI literacy training done in parallel — the two feed each other.

    The real timeline, post-omnibus

    WhatWhenNotified body involved?
    Article 5 prohibitionsApplicable since 2 Feb 2025 (two additions 2 Dec 2026)No
    Article 4 AI literacyApplicable since 2 Feb 2025, amended July 2026No
    GPAI provider obligationsApplicable since 2 Aug 2025; Commission fining powers since 2 Aug 2026; legacy models to comply by 2 Aug 2027No
    Article 50 transparencyApplicable since 2 Aug 2026; machine-readable marking for pre-existing generative systems by 2 Dec 2026No
    Stand-alone Annex III high-risk — QMS, Annex IV documentation, conformity assessment, EU declaration, CE marking, EU database registration2 Dec 2027Only for Annex III §1 biometrics
    AI as safety component of Annex I Section A products2 Aug 2028Yes — via the existing sectoral regime

    Two implications for a provider planning the work:

    First, nothing about the CE marking is due right now. If a consultant is telling you otherwise, ask them which article. The article they need is 113, and it was rewritten in July 2026.

    Second, sixteen months is not a lot for a first system. The realistic sequence is 6–10 weeks for the QMS and technical documentation of a first system, plus the risk-management, data-governance and testing evidence that feeds them, plus 4–8 weeks of queue time if you need a cross-border notified body. Start the classification now and the December 2027 date is comfortable. Start in 2027 and it is not.

    Running a Luxembourg SME?

    Book a free 30-minute AI audit — we’ll tell you honestly where AI pays off for your business, and where it doesn’t.

    Book a free AI audit

    Practical steps, in order

    1. Confirm classification. Provider or deployer? High-risk or not? Which Annex III use case — and does the Article 6(3) filter apply? Remember the filter never survives profiling of natural persons, and that relying on it means documenting and registering the assessment. Use the provider-vs-deployer test and the high-risk overview.
    2. Close the Article 50 gaps. This is the only part of the regime that is legally due today, and it needs no notified body — just disclosure, in FR / DE / EN, on every surface where a person meets your AI.
    3. Pick the conformity route. Internal control for almost everyone; notified body if you are in Annex III §1 biometrics or AI-as-safety-component of a machinery / medical device / IVD product.
    4. Stand up the QMS. Article 17 items, evidence-based, using the proportionate SME variant if you qualify. Templates exist; starting from a blank page is a mistake.
    5. Compile the technical documentation. Annex IV — or the simplified SME form. Get the training-data provenance section right first; that is where market surveillance attention goes first.
    6. Book the notified body if you need one. Cross-border booking with a Belgian, French or German body currently takes 4–8 weeks. Plan for it well ahead of December 2027, because every provider in the EU is now working to the same revised date.
    7. Train your people. Article 4 has been in force since February 2025 and most Luxembourg firms are still not evidencing it. Fix it in the same sprint.

    Bottom line for Luxembourg providers

    Most Luxembourg high-risk-AI providers will self-assess under internal control. That is neither a shortcut nor a loophole — it is a fully valid conformity assessment route with real obligations, real documentation, and real exposure if you get it wrong. The work to do now is the infrastructure work — classification, QMS, technical documentation, literacy training — not the CE-marking-on-shelf work. Get the infrastructure right and the marking follows on a release; skip the infrastructure and you have no path forward in December 2027.


    Know which route your system is on — in ten working days

    The most expensive mistake in this area is not a failed assessment. It is building a full provider-grade file for a system that turned out to be filtered out under Article 6(3), or the reverse: discovering in mid-2027 that a system you treated as ordinary tooling needs a notified body with a two-month queue.

    The 20 More AI Act Readiness Assessment settles that. Fixed scope, ten working days:

    1. The AI system register — every system and AI feature, with the provider-or-deployer determination made and evidenced per system.
    2. The conformity route determination — for each high-risk system: internal control under Annex VI, notified body under Annex VII, or absorbed into a sectoral CE regime. With the reasoning written down, and the Article 6(3) filter assessed and documented where it applies.
    3. The Article 50 gap report — the disclosures legally due today, mapped to the exact surfaces missing them.
    4. The costed plan to 2 December 2027 — QMS skeleton, Annex IV structure (or the simplified SME form), the evidence still to be produced, and notified-body lead time where relevant, in a one-page board memo you can hand to the CNPD, the CSSF or a client unedited.

    From there we run the build alongside your DPO, internal counsel or external compliance support.

    See the AI Act readiness service, or book the 30-minute scoping call and we will map your system to the right route on the call.

    Is your AI project eligible for up to 70% Luxembourg funding?

    Max €17,500 per project. Instant estimate — 4 quick questions, no email required.

    Check my eligibility (2 min)

    Ready to put this into practice?

    Two ways to start — pick whichever fits your timing.

    Tags:
    Luxembourg
    EU AI Act
    Compliance
    Regulation
    Conformity Assessment

    Related Resources

    AI Implementation in Luxembourg

    Explore our comprehensive guide to AI adoption, implementation, and governance in Luxembourg.

    Read the Guide

    Work with an AI consultant in Luxembourg

    See what we build, what it costs, and how projects qualify for up to 70% SME co-funding.

    AI Consultant in Luxembourg