CE Marking for AI: The Final Step in Your High-Risk Compliance Journey
CE Marking for AI: The Final Step in Your High-Risk Compliance Journey

CE Marking for AI: The Final Step in Your High-Risk Compliance Journey

Conformity & Registration · 9 min read · Updated March 2026

CE marking is the visible endpoint of the EU AI Act compliance process for high-risk AI systems. Once your conformity assessment is complete and your Declaration of Conformity is signed, affixing the CE mark is the final formal act before your high-risk AI system can legally be placed on the EU market. This guide explains what CE marking means for AI, when it applies, what the process is, and what comes next.

Key Takeaways
  • CE marking for high-risk AI systems is required under Articles 47–48 of the EU AI Act, and must be affixed before market placement.
  • CE marking signals that you have completed the conformity assessment, prepared a Declaration of Conformity, and accept full responsibility for the system’s compliance.
  • For standalone AI software, the CE mark appears on packaging and documentation. For AI embedded in physical products, a single CE mark covers the entire product including the AI component.
  • For most Annex III systems, CE marking follows self-conformity assessment — no third-party Notified Body is required. Exceptions apply for biometric AI and Annex I products.

1. What Is CE Marking and Why Does It Apply to AI?

The CE mark (from the French Conformité Européenne) is a mandatory conformity marking for certain products sold within the European Economic Area. It indicates that the manufacturer declares the product meets all applicable EU legislative requirements — including safety, health, and environmental requirements. CE marking has existed since the early 1990s and applies to a wide range of physical products: medical devices, machinery, toys, electrical equipment, personal protective equipment, and more.

The EU AI Act extends CE marking to high-risk AI systems. Article 48 requires that high-risk AI systems bear the CE marking before they are placed on the EU market or put into service. This aligns AI regulation with the broader EU product safety framework — treating high-risk AI systems with the same rigor applied to physical products that pose safety risks.

What CE marking signals to the market
The provider has completed a conformity assessment against the EU AI Act’s requirements
A Declaration of Conformity has been signed by an authorised representative
The system has been registered in the EU AI database (for Annex III systems)
The provider accepts full legal responsibility for the system’s compliance with EU law

2. When Is CE Marking Required for AI Systems?

AI System TypeCE Marking Required?How It Is Applied
Standalone high-risk AI software (Annex III)YesOn packaging, in the software interface, or in accompanying documentation
High-risk AI embedded in a regulated product (Annex I)Yes — combined markingA single CE mark on the overall product covers both the physical product and its AI component, provided both assessments are completed
Limited risk AI (chatbots, deepfakes — Article 50)NoTransparency disclosure obligations apply, but no conformity assessment or CE marking
Minimal risk AINoNo mandatory obligations
GPAI models (Chapter V)No — different regimeGPAI models are subject to Chapter V obligations, not the CE marking and conformity assessment regime. If a GPAI model is integrated into a high-risk AI system, the combined system requires CE marking.
💡
Not sure whether your AI system is high-risk and requires CE marking? Use our free 2-minute risk assessment tool to get an instant classification with a personalised obligations list.

The Four-Step CE Marking Process for AI

1
Complete the Conformity Assessment
Art. 43

Before affixing the CE mark, you must complete a conformity assessment demonstrating that your high-risk AI system meets all requirements of Articles 8–15. The conformity assessment is a systematic, documented review of your system against each of these requirements.

For most Annex III systems: Self-assessment is permitted. This means the provider conducts the assessment internally based on their own Annex IV technical documentation, without requiring an external auditor or Notified Body. The assessment must be documented with evidence for each Article 8–15 requirement.

What the self-assessment covers: A systematic review of risk management documentation (Art. 9), data governance practices (Art. 10), technical documentation completeness (Art. 11), logging implementation (Art. 12), transparency and instructions (Art. 13), human oversight mechanisms (Art. 14), and accuracy and cybersecurity testing (Art. 15). Each requirement must be addressed with documented evidence — not just assertions.

2
Prepare and Sign the Declaration of Conformity
Art. 47 + Annex V

Once the conformity assessment is complete, the provider must prepare an EU Declaration of Conformity (DoC). Annex V of the Act specifies what the DoC must contain:

DoC ElementWhat to Include
Provider identityFull legal name, registered address, and — for non-EU providers — the name and address of the Authorised Representative
AI system identificationSystem name, version, and a clear description of its intended purpose and Annex III classification
Conformity statementStatement that the AI system conforms to the EU AI Act and any other relevant EU legislation applied to the system
Standards and specifications appliedReference to harmonised standards applied, or common specifications used, during development and testing
Notified Body involvement (if any)Name and identification number of any Notified Body that conducted or reviewed the conformity assessment; reference to the Notified Body certificate issued
Place and dateWhere and when the DoC was drawn up
Authorised signatureSigned (wet or electronic) by a named, authorised senior person at the provider — typically CTO, Chief Compliance Officer, or equivalent

Key obligation: The DoC must be kept up to date. If the AI system changes in a way that affects compliance, the DoC must be revised and re-signed. The DoC must be retained for the 10-year period required by Article 18.

3
Affix the CE Marking
Art. 48

With the conformity assessment complete and the DoC signed, you may affix the CE marking. Article 48 specifies the rules for how the CE mark is applied:

For standalone AI software
The CE marking must appear visibly and legibly in the software interface (e.g. in the About screen or compliance section), on packaging, in the electronic instructions for use, and in any marketing materials that reference regulatory compliance. It does not need to appear on every screen.
For AI embedded in physical products
The CE mark is affixed to the physical product itself (or its packaging if physical space is insufficient) and covers the entire product including its AI component, provided the AI component’s conformity assessment is complete.
Format requirements
The CE marking must follow the standardised format specified in the EU Regulation 765/2008 — a specific graphical format with prescribed proportions. Do not use a custom or approximate version of the CE symbol. If a Notified Body was involved, the Notified Body’s four-digit identification number must appear alongside the CE mark.
Important: Affixing the CE mark without having completed a valid conformity assessment, or affixing it to a non-high-risk system that does not require it, is a violation of the Act and can result in market withdrawal orders and fines.
4
Register in the EU AI Database
Art. 49

Concurrent with CE marking, Annex III high-risk AI systems must be registered in the EU AI database managed by the EU AI Office. This is a separate step from CE marking — you cannot substitute one for the other.

Registration information includes: Provider’s name and contact details; EU Authorised Representative details (non-EU providers); AI system name, version, and intended purpose; Annex III category; geographic scope of deployment; summary of the conformity assessment; the DoC reference number; and the unique identification number assigned by the EU AI database.

Timing: Registration must be completed before the system is placed on the EU market — the same deadline as CE marking. In practice, registration and CE marking happen in the same compliance sprint: once the DoC is signed, both steps can be executed within days.

3. When Do You Need a Notified Body?

For most high-risk AI systems under Annex III, the EU AI Act permits self-assessment — the provider conducts and documents the conformity assessment internally. However, third-party assessment by an accredited Notified Body is mandatory in two circumstances:

Mandatory Notified Body — Biometric Identification AI
AI systems intended for real-time or post-hoc remote biometric identification of persons (Annex III, Category 1) must undergo third-party conformity assessment by a Notified Body before CE marking. Given the fundamental rights implications of biometric AI, the legislature determined that self-assessment is insufficient.
Mandatory Notified Body — High-Risk AI in Annex I Products
AI systems that are safety components of products regulated under Annex I legislation (medical devices, machinery, aviation equipment, vehicles, etc.) must undergo third-party assessment where the applicable sectoral legislation already requires a third-party conformity assessment. The AI Act assessment is conducted alongside — and integrated with — the sectoral product assessment.

Finding and Engaging a Notified Body

Notified Bodies for the EU AI Act are accredited by national accreditation bodies in each member state and listed in the NANDO (New Approach Notified and Designated Organisations) database maintained by the European Commission. When selecting a Notified Body:

  • Verify accreditation specifically for EU AI Act conformity assessment (not just ISO or MDR accreditation)
  • Confirm relevant sector expertise — a Notified Body with medical device experience is better placed to assess healthcare AI than one with only machinery expertise
  • Engage at least 6 months before your target CE marking date — Notified Bodies have limited capacity and significant lead times in 2026
  • Budget appropriately — Notified Body assessments for AI systems typically cost €15,000–€50,000 depending on system complexity and the Body’s fees
Timeline comparison: Self-assessment vs. Notified Body assessment
Self-Assessment (most Annex III systems)
  • Gather evidence and compile Annex IV: 3–6 months
  • Internal review and sign-off: 4–8 weeks
  • Prepare and sign DoC: 1–2 weeks
  • Affix CE mark and register: 1 week
  • Total: ~4–8 months from start
Notified Body Assessment (biometric AI / Annex I)
  • Identify and engage Notified Body: 4–8 weeks
  • Prepare Annex IV documentation: 3–6 months
  • Notified Body assessment: 2–4 months
  • Respond to queries, revisions: 4–8 weeks
  • Total: ~9–14 months from start

4. After CE Marking: Ongoing Obligations

CE marking is not the end of compliance — it is the beginning of ongoing obligations. The CE mark declares that your system was compliant at the point of market placement; maintaining that declaration requires active post-market management.

Art. 72
Post-Market Monitoring: Activate your post-market monitoring plan from day of deployment. Track the KPIs you documented in your Annex IV file. Conduct quarterly performance reviews and compare production metrics against pre-deployment benchmarks.
Art. 73
Serious Incident Reporting: Report any serious incident (as defined in Article 3(49)) to the national market surveillance authority of the member state where it occurred within 15 days of becoming aware of it. Have your reporting procedure tested and ready before deployment begins.
Art. 11
Documentation Maintenance: Keep the Annex IV technical documentation current. Any significant system change requires documentation update. A change that constitutes a “substantial modification” requires a new conformity assessment and potentially a new CE marking exercise.
Art. 18
10-Year Record Retention: Retain the Declaration of Conformity, Annex IV technical documentation, and all conformity assessment records for 10 years from the last date the system was placed on the EU market. Plan your document retention infrastructure to enforce this timeline automatically.
Plan your full compliance programme
CE marking is the final step of Phase 4 in our 4-phase compliance checklist. Start with Phase 1 — scoping and classification — and work systematically through to registration.
View Compliance Checklist →

5. Frequently Asked Questions

Can we place a high-risk AI system on the EU market before CE marking is complete? +
No. Article 48 is unambiguous: CE marking must be affixed before placing the high-risk AI system on the EU market. Any market placement prior to CE marking — even in a beta, pilot, or limited release — constitutes a violation. If you are running a limited pilot with EU customers to gather data for your conformity assessment, structure it as a research and development activity with explicit agreements that the system is not yet placed on the market. Seek legal advice on the precise boundary between R&D use and market placement in your specific context.
Does updating the AI model require re-doing the CE marking? +
Not automatically. Minor updates — bug fixes, performance optimisations, data refresh with no change in methodology — that do not change the system’s fundamental behaviour, accuracy profile, or risk level do not require a full new conformity assessment or new CE marking. However, a substantial modification does. Article 6 defines substantial modification as a change that affects the system’s compliance with the Act’s requirements or alters its risk profile. New model architecture, significant change in training data methodology, change in intended purpose, or a new deployment context that falls within a different Annex III category are all likely to constitute substantial modifications requiring reassessment.
Our AI is sold as a B2B SaaS tool — do we still need to CE mark it? +
Yes, if the SaaS AI system is high-risk under Annex III. The CE marking obligation applies to all providers who place high-risk AI systems on the EU market, regardless of the commercial model (SaaS, on-premise, embedded, or otherwise). “Placing on the market” includes making the system available to EU customers via a SaaS subscription. The CE mark would appear in the SaaS product interface (e.g. in an About or Compliance section), in your product documentation, and in your terms of service or compliance documentation provided to B2B customers.
What happens if we discover a compliance issue after CE marking? +
Article 20 requires providers to immediately take corrective actions if they have reason to believe their high-risk AI system does not conform to the Act’s requirements. This means: suspending the system if the non-conformity poses a risk to health, safety, or fundamental rights; notifying national market surveillance authorities in each member state where the system is deployed; notifying your Authorised Representative (if applicable); and updating your Annex IV documentation and — if required — your Declaration of Conformity. Voluntary disclosure and proactive corrective action significantly mitigate regulatory risk. See our full compliance guide at EU AI Act Summary 2026.
Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like