What is conformity assessment under the AI Act?
Conformity assessment is the procedure by which a provider demonstrates, before placing a high-risk AI system on the EU market, that the system satisfies the AI Act’s requirements: risk management, data governance, technical documentation, logging, transparency, human oversight, and accuracy, robustness and cybersecurity. The procedure concludes with an EU declaration of conformity, CE marking and registration in the EU database — the product-safety grammar Europe applies to machinery and medical devices, extended to software.
Two routes
- Internal control (self-assessment): the route for most Annex III systems; the provider audits itself against the requirements, applying harmonised standards where available;
- Notified body (third-party assessment): required for remote biometric identification where harmonised standards are not applied, and for Annex I products whose sectoral law already demands third-party assessment.
The legal dimension
Following the omnibus package, Annex III systems have a runway to 2 December 2027 (Annex I products: August 2028). The runway is shorter than it looks. The assessment file — evidence for each requirement, test results, the risk management record — takes quarters, not weeks, to assemble, and a substantial modification to the system re-triggers the whole procedure. The declaration also has an afterlife: post-market monitoring and serious incident reporting keep the file a living document.
Turkish context
Türkiye has no counterpart procedure in force — there is no domestic AI conformity regime; KVKK and general provisions apply. A Turkish provider placing a high-risk system on the EU market nonetheless runs the full EU procedure like any other provider, and enterprise buyers increasingly ask for the paperwork before signing. For a startup the practical translation is: classification first (is the system Annex III at all?), then a gap analysis against the requirements, then the file — starting from the classification memo stage, not after the sales team lands an EU customer.
Do: start the technical documentation while the system is being built, when evidence is cheap to capture. Don’t: ship “minor” architecture changes to an assessed system without checking whether they amount to substantial modifications.
Related guides: AI Compliance Hub: EU AI Act, Türkiye & KVKK Tracker, AI Act Readiness Checklist.
Sources. Regulation (EU) 2024/1689 (AI Act) and Law No. 6698 on the Protection of Personal Data (KVKK). Statute links open the official consolidated Turkish texts on mevzuat.gov.tr.