A conformity assessment under the AI Act is a formal procedure set out in Article 43, and it only applies to providers of high-risk AI systems. If your company uses ChatGPT, Copilot or a CRM with an AI feature bolted on, you are almost certainly outside its scope. What you do need to run is a compliance self-assessment: establish your role, classify your systems, document your decisions.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
A conformity assessment under the AI Act is a formal procedure set out in Article 43, and it only applies to providers of high-risk AI systems. If your company uses ChatGPT, Copilot or a CRM with an AI feature bolted on, you are almost certainly outside its scope. What you do need to run is a compliance self-assessment: establish your role, classify your systems, document your decisions.
Confusing these two exercises is the single biggest waste of time we see in the field. Business owners call us convinced they must produce a technical file and affix a CE marking to their use of Copilot. That is not what the text says. This article puts things back in order, based on Regulation (EU) 2024/1689 as amended by the AI Omnibus that entered into force on 27 July 2026. For the wider picture, our AI Act compliance guide for SMEs and non-profits remains the entry point.
The Article 43 conformity assessment is a market-access procedure, not an annual internal audit. It takes place before a high-risk AI system is placed on the market or put into service, and it falls on the provider, meaning whoever develops the system and sells it under their own name.
The regulation sets out two routes:
At the end of the procedure, the provider draws up an EU declaration of conformity (Article 47), affixes the CE marking (Article 48) and registers the system in the EU database (Article 49). The logic here is product safety law, not GDPR.
One detail that matters for buyers: a substantial modification triggers a fresh conformity assessment, even if the modified system stays with the same deployer. Learning-related changes pre-determined by the provider and documented at the initial assessment do not count as substantial modifications.
Your legal role drives 90% of your obligations, and it is settled before you even look at risk level. A company using an off-the-shelf tool is a deployer. A company that builds a system and sells it is a provider. The gap in obligations is wide.
| Role | Who it covers | Article 43 assessment | Main obligations |
|---|---|---|---|
| Provider | Develops and places on the market under its own name | Yes, if high-risk | Technical documentation, QMS, CE marking, post-market monitoring |
| Deployer | Uses the system under its own authority | No | Use in line with instructions, human oversight, informing affected people, logging |
| Importer | Places a third-country system on the EU market | No, but must verify it was done | Documentary checks before placing on the market |
| Distributor | Makes available without being provider or importer | No | Verification of CE marking and documentation |
The trap sits in Article 25. A deployer becomes a provider, with every obligation that follows, in three situations: putting the system on the market under its own brand, substantially modifying it, or repurposing it beyond its intended use. In practice, a company that wraps a model under its own brand inside a product sold to customers becomes a provider. The same company using that model internally stays a deployer. The line is finer than it looks, and it deserves to be settled in writing. Scope is covered in detail in AI Act: who is affected.
The AI Act does not classify organisations, it classifies systems, one at a time. The same company can hold a minimal-risk use (marketing copy), a limited-risk use subject to transparency (customer chatbot) and a high-risk use (CV screening tool) side by side.
Work through the checks in this order:
The inventory that comes first is the most time-consuming part of the job, and the one most often rushed. We published a method and a template in mapping your AI systems. Budget half a day for a 20-person company, closer to two days above 100 employees, because you have to interview each team: roughly half of an SME's AI usage sits in subscriptions nobody cleared with management.
If you are a provider of a high-risk system, the conformity assessment is the last brick in a build that has seven. You cannot run it until the requirements of Chapter III, Section 2 are met:
The assessment itself then consists of verifying that the quality management system complies with Article 17, that the technical documentation demonstrates compliance with those requirements, and that design, development and post-market monitoring are consistent with that documentation.
For an SME in this position, budgets run from a few tens of thousands of euros under internal control to several times that with a notified body. The figure depends too much on the specific system to be quoted seriously in advance, and we give it here only as an order of magnitude to be confirmed project by project. Note that Article 62 provides dedicated support measures for SMEs and start-ups, including priority access to regulatory sandboxes.
For the vast majority of SMEs, compliance comes down to five internal deliverables, not to an assessment procedure. Here is what we put in place:
That last point deserves a clear position. Training your teams is still worth doing, but the legal argument about automatic fines is false and we do not use it. The real reason to train is that a colleague who does not know what an LLM is, or how it hallucinates, produces errors that cost more than the training.
A minimal-risk classification needs to be written down and dated exactly like a high-risk one. This is the most neglected step, and it is the one that will protect you if a market surveillance authority comes asking.
For each system, keep a record of the question asked, the reasoning applied, the conclusion reached and who signed off. Three lines is enough. What counts is being able to show the question was handled, not producing an impressive document. This is the same accountability logic as the GDPR, and the two texts overlap heavily, as set out in AI Act vs GDPR.
Plan a review at every tool change or major version bump. A vendor adding CV-screening to your HR system can flip your classification overnight, without anyone on your side asking for it.
Obligations for high-risk systems under Annex III do not apply from 2 August 2026 but from 2 December 2027. The delay comes from the AI Omnibus, politically agreed on 7 May 2026 and in force since 27 July 2026. High-risk systems embedded in regulated products (Annex I) follow on 2 August 2028.
That shift changes how you prioritise. You do not have a few weeks to close out a conformity file, you have more than a year. What already applies has not moved, though: Article 5 prohibitions since February 2025, GPAI obligations since August 2025, Article 50 transparency and full enforcement powers since 2 August 2026. The full AI Act timeline covers every deadline.
Plenty of articles online, including recent ones, still put the high-risk deadline at 2 August 2026. That is out of date. Always check the update date of the sources you read on this topic, and prefer the official timeline published by the European Commission's AI Act Service Desk.
Does an SME using ChatGPT need a conformity assessment? No. Using a generative AI tool under your own authority makes you a deployer, not a provider. The Article 43 assessment does not apply. You remain subject to Article 50 transparency obligations if you publish generated content or run a conversational agent.
How long does a compliance self-assessment take for an SME? Between half a day and three days depending on size and number of tools. The inventory is two thirds of the effort. Writing the deliverables goes quickly once the scope is settled.
Who enforces this? National market surveillance authorities designated under Article 70. Their full enforcement powers have been effective since 2 August 2026. The Article 99 penalty regime reaches EUR 35 million or 7% of worldwide turnover for prohibited practices, with SMEs capped at the lower of the two figures.
Do we need a notified body? Only for biometric systems under Annex III point 1 where harmonised standards were not applied, and for certain regulated products under Annex I. Other high-risk use cases fall under Annex VI internal control.
Does modifying our tool trigger a new assessment? Yes if the modification is substantial, meaning it affects the compliance, safety or intended purpose of the system. Learning-related changes planned and documented by the provider at the initial assessment are not treated as substantial.
Is CE marking mandatory for our internal chatbot? No, unless that chatbot is a high-risk system you provide. An internal support assistant falls at most under transparency obligations.
What if we get the classification wrong? A classification that turns out to be wrong but was documented and reasoned puts you in a very different position from having no analysis at all. That is why we insist on the written record, including for negative decisions.
We work on three fronts: mapping systems and classifying risk, producing the internal deliverables (register, usage policy, transparency notices), and training the teams who actually use these tools day to day. We are a Qualiopi-certified training provider, which opens up OPCO funding on the training side for French companies.
Our position is straightforward: we do not sell regulatory fear. Most SMEs we work with discover they are less exposed on the AI Act than they assumed, and far more exposed on the quality of their AI usage than they assumed. That second issue is what actually moves results. For the full framework, see the AI Act guide for SMEs and non-profits, and for the financial exposure, AI Act penalties.
If you want clarity on your own situation, we offer a guided 30-minute audit: quick inventory, classification of your three or four main systems, and a list of the deliverables you are missing. No commitment, and no 40-page report at the end.