News
•
30/9/2026

AESIA Guidelines on the AI Act – Guide No. 3

Share this post
Blog authors
Silvia Martinelli
Strategic Research Manager
Sign up for the Data Valley newsletter
By clicking on “Sign Up” you consent to the processing of data according to our Privacy Policy.
Thank you, your subscription to the newsletter has been received!
An error occurred while submitting the form.

How can compliance of high-risk AI systems with the AI Act be demonstrated? The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) has published its third guideline, Conformity Assessment. While Guides No. 1 and No. 2 provide an introduction to the AI Act and illustrate its application through practical examples, Guide No. 3 focuses on the conformity assessment procedure for high-risk AI systems. Its purpose is to explain how providers can demonstrate that their systems comply with the requirements established by the AI Act before they are placed on the market or put into service. The Guide is addressed primarily to providers of high-risk AI systems and is based on Article 43 and Annexes VI and VII of Regulation 2024/1689.

Conformity assessment is defined as the process through which compliance of a high-risk AI system with the requirements established in Chapter III, Section 2 of the AI Act is demonstrated. These requirements concern, in particular, risk management, data and data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness and cybersecurity. The responsibility for carrying out the conformity assessment lies with the provider, even where the design or production of the AI system has been outsourced. In certain cases, the procedure requires the involvement of a notified body.

The Guide places the conformity assessment procedure within the broader framework of the European Union's harmonisation legislation and the New Legislative Framework. This framework is based on a common structure for demonstrating the conformity of products before they are placed on the European market. Its main elements include harmonised standards, common specifications, conformity assessment procedures, technical documentation, the EU declaration of conformity, CE marking, notifying authorities and notified bodies.

Harmonised standards provide technical specifications that can be used to demonstrate compliance with the requirements of EU harmonisation legislation. Where harmonised standards are not available, common specifications adopted by the European Commission may provide an alternative means of demonstrating conformity. The use of these instruments is particularly relevant because the choice of conformity assessment procedure under the AI Act depends, among other things, on whether and to what extent the provider has applied the relevant harmonised standards or common specifications.

The AI Act establishes two principal conformity assessment procedures for high-risk AI systems. The first is based on internal control by the provider and is set out in Annex VI. The second is based on an assessment of the provider's quality management system and technical documentation, with the involvement of a notified body, and is set out in Annex VII. The applicable procedure depends on the type of high-risk AI system and the circumstances specified in Article 43.

Under the internal control procedure, the provider itself verifies compliance with the requirements of the AI Act. The provider must verify that its quality management system complies with Article 17, examine the technical documentation to determine whether the AI system satisfies the applicable requirements, and verify that the design and development process and post-market monitoring are consistent with the technical documentation.

For certain high-risk AI systems listed in Annex III, where the provider has applied the relevant harmonised standards or common specifications, the provider may choose between the internal control procedure and the procedure involving a notified body. However, where the relevant harmonised standards or common specifications do not exist, have not been applied, or have been applied only partially, the procedure involving a notified body under Annex VII becomes applicable in the circumstances specified by Article 43.

For other high-risk AI systems listed in points 2 to 8 of Annex III, the AI Act provides for conformity assessment based on internal control, without the involvement of a notified body. The Guide also explains that AI systems covered by Union harmonisation legislation listed in Annex I are subject to the relevant conformity assessment procedure established under that legislation. The requirements of the AI Act for high-risk AI systems must be incorporated into that assessment. This is particularly relevant for AI systems incorporated into regulated products, including certain medical devices and other products covered by Union harmonisation legislation.

The Guide also addresses the relationship between the AI Act and existing product legislation. Where an AI system constitutes a safety component of a product covered by Union harmonisation legislation, the conformity assessment procedure applicable to the product remains relevant. The classification of the AI component as high-risk does not, by itself, necessarily require a separate third-party conformity assessment where the applicable product legislation permits an internal conformity assessment and its conditions are satisfied.

A central element of the procedure is the assessment of the quality management system. Under the procedure involving a notified body, the provider must establish and maintain a quality management system covering the relevant organisational and technical processes for the design, development and testing of the AI system. The system must remain adequate and effective throughout its operation, and changes to the approved quality management system or to the AI systems covered by it must be communicated to the notified body.

The second major element is the assessment of technical documentation. The provider must submit the relevant technical documentation concerning the AI system to the notified body. The documentation allows the conformity of the system to be assessed and must contain sufficient information concerning its design, development and operation. The notified body may request additional evidence or further testing where necessary to establish conformity.

In certain circumstances, the notified body may obtain access to the training, validation and testing datasets used by the provider. Where all other reasonable means of verification have been exhausted and are insufficient, access may also extend to the training and trained models and their relevant parameters. Such access is subject to applicable Union rules concerning intellectual property and trade secrets.

The Guide explains that conformity assessment is therefore not limited to a formal examination of documents. Depending on the circumstances, it may involve examination of the quality management system, analysis of technical documentation, additional evidence and testing, and, where necessary, access to datasets and models. The objective is to establish whether the AI system satisfies the substantive requirements applicable to high-risk systems.

The Guide also considers the consequences of substantial modifications to a high-risk AI system. A system that has already undergone conformity assessment must undergo a new conformity assessment where it is substantially modified, regardless of whether the modified system is placed on the market again or continues to be used by the existing deployer. Changes in continuously learning systems that were predetermined by the provider at the time of the initial conformity assessment and documented in the technical documentation do not constitute substantial modifications.

Once conformity has been established, the provider must complete the relevant formal steps associated with placing the AI system on the market or putting it into service. These include the preparation of the EU declaration of conformity and the affixing of the CE marking. The CE marking indicates conformity with the applicable EU legislation and permits the product to circulate within the European market; it is an indicator of conformity rather than a certification of the product's quality or safety in itself.

The EU declaration of conformity is the formal declaration by which the provider assumes responsibility for the conformity of the AI system with the applicable requirements. It must accompany the placing of the system on the market or putting it into service and must be maintained in accordance with the requirements of the AI Act.

The Guide further explains the role of notifying authorities and notified bodies. Notifying authorities are responsible for assessing, designating and notifying conformity assessment bodies, while notified bodies are organisations that have been officially designated to perform conformity assessment activities under the applicable Union legislation. Depending on the procedure applicable to the AI system, a notified body may assess the provider's quality management system and technical documentation and may conduct surveillance activities after conformity has been established.

The Guide uses two main examples to illustrate the conformity assessment process: a smart insulin pump for chronic disease management and a system for controlling attendance at work through biometric recognition. The first example illustrates conformity assessment in the context of an AI system incorporated into a medical technology, while the second concerns a high-risk AI system used for biometric recognition in the workplace.In the case of the smart insulin pump, the conformity assessment process must take into account the interaction between the AI Act and the legislation applicable to the underlying medical device. The example illustrates how the provider must demonstrate compliance with the relevant requirements and integrate the AI Act requirements into the applicable conformity assessment framework for the product.

The biometric attendance-control example illustrates a different type of high-risk AI system and focuses on the requirements applicable to biometric identification or categorisation systems used in the employment context. The example demonstrates how the conformity assessment procedure changes depending on the classification and regulatory framework applicable to the specific AI system.

The Guide therefore presents conformity assessment as a structured process connecting the different compliance requirements of the AI Act. Risk management, data governance, human oversight, accuracy, robustness, cybersecurity, technical documentation and quality management are not treated as isolated obligations. Their implementation must ultimately be capable of being demonstrated through the conformity assessment process.

Overall, Guide No. 3 explains the pathway that a provider of a high-risk AI system must follow to demonstrate compliance with the AI Act: identifying the applicable conformity assessment procedure, implementing the relevant quality management and technical requirements, preparing and examining the necessary documentation, carrying out the required testing and assessments, involving a notified body where required, addressing substantial modifications, and finally completing the EU declaration of conformity and CE marking before the system is placed on the market or put into service.

Are you ready to transform the Data in value for your business?