Skip to content

Notified Bodies Under the EU AI Act, Explained

9 min read · updated August 11, 2026

Most providers of Annex III high-risk AI systems will never engage a notified body, because Article 43 routes most Annex III use cases to internal control. Knowing why, and knowing the exceptions, saves a procurement exercise that is not required.

What a notified body is

A notified body is a conformity assessment body that a Member State has notified to the Commission and the other Member States as competent to carry out third-party conformity assessment under a particular Union instrument. Chapter III Section 4 of Regulation (EU) 2024/1689 — Articles 28 to 39 — sets up the machinery: each Member State designates a notifying authority (Article 28), bodies apply to it (Article 29), notification follows a defined procedure (Article 30), and the body must meet the requirements in Article 31, which include independence from the providers it assesses, competence, and professional secrecy.

The body is private or public, it is paid by the provider, and it is accredited and supervised rather than sovereign. The Commission assigns each one a single identification number even where it is notified under several Union acts, and publishes the list in the NANDO database. That number is the one that appears after the CE mark where a body was involved.

This describes the designation framework. It is not legal advice, and whether your specific system requires third-party assessment depends on its Annex III sub-category and on whether harmonised standards were applied — get that determination checked rather than inferred from a summary.

Chapter III Section 4 has applied since 2 August 2025, ahead of the high-risk obligations themselves. That sequencing is deliberate: the bodies have to exist and be designated before the systems that need them come into scope. The gap is now considerably wider than it was drafted to be. Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force from 27 July 2026, moved the stand-alone Annex III high-risk date from 2 August 2026 to 2 December 2027, so the designation machinery has been live for well over two years before the systems it serves arrive.

How it differs from a market surveillance authority

These two are routinely conflated and they sit on opposite sides of the product lifecycle.

  • When. A notified body acts before the system is placed on the market, as part of conformity assessment. A market surveillance authority acts after, on systems already on the market.
  • Who pays. The provider engages and pays the notified body. Nobody engages a market surveillance authority.
  • Powers. A notified body issues, refuses, restricts, suspends or withdraws certificates. It cannot fine you, order a recall or restrict your market access. A market surveillance authority can order corrective action, withdrawal and recall, and can demand training data and, conditionally, source code.
  • Who supervises them. Notifying authorities supervise notified bodies, and Article 37 lets the Commission investigate where there is reason to doubt a body’s competence. Market surveillance authorities answer to their Member State and coordinate through the structures in Chapter VII.

A notified body is also not a regulator you can appeal to about a competitor, and not a source of legal interpretation. Its output is a certificate about one system against one assessment procedure.

Which systems need one

This is the question worth getting right, and Article 43 answers it by routing rather than by a general rule.

  • Annex III point 1 — biometrics. This is the only Annex III category where a notified body can be required. If the provider has applied the harmonised standards referred to in Article 40, or the common specifications under Article 41 where they exist, it may choose between the internal control procedure in Annex VI and the quality-management-system-plus-technical-documentation assessment in Annex VII, which involves a notified body. Where those standards were not applied, or were applied only in part, or where common specifications do not exist, the Annex VII route is mandatory. See the Annex III biometrics category for what falls inside it.
  • Annex III points 2 to 8. Critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and the administration of justice and democratic processes all follow the internal control procedure in Annex VI. No notified body. The provider assesses its own conformity — which is not a light duty, since it still requires the quality management system under Article 17 and the full technical documentation, but it does not require a third party.
  • Annex I products. Where the AI system is a safety component of, or is itself, a product covered by the harmonisation legislation in Annex I Section A, the conformity assessment is the one required by that sectoral legislation, and the notified body already designated under that act assesses the AI requirements as part of it. You do not gain a second body; the one you already have gains a new scope. That alignment is the reason those products got the longest runway of all — a deadline that moved from 2 August 2027 to 2 August 2028 when Regulation (EU) 2026/1744 entered into force on 27 July 2026.

The practical read: for the great majority of Annex III systems, the honest answer to “which notified body should we approach?” is “none — build the quality management system instead”.

Certificates, validity and what suspends them

Where a body is involved, Article 44 governs its certificates. They are issued in a language easily understood by the relevant authorities of the Member State in which the body is established, and are valid for the period they indicate — not exceeding five years for systems under Annex I, and not exceeding four years for those under Annex III, with extensions possible on reassessment following the applicable procedures.

A certificate is conditional in operation, not just at issue. Where a body finds that a system no longer meets the requirements, it must, having regard to proportionality, suspend or withdraw the certificate or impose restrictions on it, unless the provider takes appropriate corrective action within a deadline the body sets. The body gives reasons and provides an appeal procedure against its decisions.

A separate trap: Article 43(4) requires a fresh conformity assessment whenever a high-risk system is substantially modified, regardless of whether the modification was planned or whether the system is placed on the market again. Changes that were pre-determined by the provider and assessed as part of the initial technical documentation — including continued-learning behaviour described up front — are not substantial modifications. Describing the intended adaptation envelope in the technical file at assessment time is therefore worth doing carefully; it is the difference between shipping an update and reopening an assessment.

Choosing and working with one

If you are in the narrow set that needs one, three things are worth checking before signing anything. First, confirm in NANDO that the body is notified under this Regulation and for the relevant scope — a body notified under the Medical Devices Regulation is not thereby notified under the AI Act. Second, check its capacity: the population of bodies designated for AI is new and small, and lead time rather than price is likely to be the binding constraint on a launch date. Third, understand the subcontracting position under Article 33, which permits subcontracting and the use of subsidiaries subject to conditions including the provider’s agreement, and requires the body to keep responsibility.

Finally, remember that engaging a notified body does not transfer responsibility. The provider remains responsible for conformity, draws up the EU declaration of conformity, affixes the mark, registers the system and carries the post-market monitoring duty. A certificate is evidence, not a shield.