A conformity assessment body notified under the AI Act is an independent third-party organisation accredited by a national accreditation body and formally designated by an EU member state to evaluate whether a high-risk AI system meets the requirements of Regulation (EU) 2024/1689. For government agencies, hospitals, financial institutions and legal-sector organisations, engaging such a body raises an immediate sovereign data question: what exactly must be handed over, to whom, and under what legal protections?
Which High-Risk AI Systems Require a Notified Body Under Article 43
Article 43 of the AI Act establishes a two-track conformity assessment regime. Most high-risk AI systems listed in Annex III can follow a self-assessment route if the provider applies harmonised European standards. A mandatory notified body assessment applies in two circumstances: when the high-risk system also falls under Union harmonisation legislation listed in Annex I (for example, medical devices regulated under Regulation (EU) 2017/745 or machinery under Directive 2006/42/EC), and when the system involves real-time or remote biometric identification of natural persons in publicly accessible spaces, as specified in Article 43(1)(b).
Systems in Annex III categories that are not covered by Annex I legislation, such as AI used in recruitment, credit scoring or educational assessment, can in principle complete a conformity assessment internally. However, this self-assessment route still requires the provider to produce and maintain full Annex IV technical documentation, and any national market surveillance authority can request that documentation at any time.
What the Notified Body Actually Needs to See
The scope of disclosure during a conformity assessment is defined by AI Act Annex IV, which specifies a mandatory technical documentation package. That package is considerably more sensitive than a typical compliance checklist.
Annex IV requires at minimum: a general description of the AI system and its intended purpose; the design choices and the assumptions that underpin the model; the training, validation and testing datasets, including their provenance, composition, labelling procedures and any data gaps identified; the model architecture, including weights in sufficient detail to allow reproducibility of the evaluation; test logs and performance metrics, broken down across demographic subgroups where relevant; and the post-market monitoring plan. For a sovereign organisation running a locally hosted model based on an open-source foundation such as Mistral or Llama, this documentation includes artefacts that could reveal security-sensitive architectural decisions, data sources that may themselves be classified or regulated, and operational parameters that define the system’s limitations.
According to IBM’s Cost of a Data Breach Report 2024, the global average cost of a data breach has reached USD 4.88 million, the highest figure ever recorded in that annual study. For regulated organisations, the exposure of model documentation to a notified body that subsequently suffers a security incident is not a hypothetical concern.
Structuring the Assessment to Protect Sovereign Infrastructure
Nothing in AI Act (EU) 2024/1689 requires that a notified body assessment be conducted remotely, in a cloud environment or through external data transfer. Organisations that structure the engagement correctly can require that the entire assessment takes place within their own jurisdiction-controlled infrastructure.
The practical approach involves three layers. First, the organisation designates a secure, isolated assessment environment, either a physically separated network segment or an air-gapped system where Annex IV documentation is made available to the notified body’s evaluators without network egress. Second, the notified body’s personnel operate under a contractual data handling agreement, signed before any access is granted, that prohibits extraction, copying or transmission of training data, model weights or test outputs outside that environment. Third, all interactions between the evaluators and the documentation are logged in a tamper-evident audit trail that remains under the organisation’s control.
This structure is consistent with the accreditation requirements that notified bodies must meet. Under the European Accreditation (EA) framework, notified bodies designated under EU harmonisation legislation are required to demonstrate competence according to ISO/IEC 17065 (for product certification) or ISO/IEC 17020 (for inspection), both of which demand documented procedures for handling confidential client information. Choosing a notified body that has been accredited by a European national accreditation body, for example the Deutsche Akkreditierungsstelle (DAkkS) in Germany or the Raad voor Accreditatie (RvA) in the Netherlands, rather than a body based outside the EU, is a first-order sovereign data decision.
Confidentiality Obligations of the Notified Body Under Article 78
AI Act Article 78 imposes a statutory confidentiality obligation on notified bodies. The regulation states that notified bodies must treat all information obtained in the course of their tasks as confidential, except where disclosure is required by applicable Union or national law. This obligation extends to the body’s staff, subcontractors and any affiliated entities involved in the assessment.
Article 78 is a legal floor, not a ceiling. Regulated organisations should treat it as the baseline and add contractual and technical controls on top. Contractual controls should specify: the categories of data the notified body is authorised to access; the prohibition on using assessment data for any purpose other than the evaluation; the obligation to destroy or return all copies of documentation upon completion; and the notified body’s liability regime in the event of an unauthorised disclosure. Technical controls should include read-only access to documentation repositories, session recording for all evaluator interactions, and prohibition on personal storage devices in the assessment environment.
The AI Act Omnibus and Its Effect on Sovereign Data Exposure
In May 2025, the European Commission reached a political agreement on a simplification package commonly referred to as the AI Act Omnibus, forming part of the broader COM(2025) simplification initiative. The package proposed a reduction in mandatory conformity assessment obligations for certain categories of operators, with the stated goal of reducing compliance burden for smaller providers and general-purpose AI system deployers.
For regulated sectors, the practical effect of the Omnibus is limited. The mandatory third-party assessment requirement under Article 43(1) for systems covered by Annex I legislation and for biometric identification systems was not removed in the political agreement. The simplification primarily benefits operators of lower-risk AI tools and reduces some documentation obligations for providers of general-purpose AI models that fall below the most capable tier. A hospital deploying an AI diagnostic support tool classified as a medical device, or a financial institution using AI for credit risk scoring, still faces the same Annex IV documentation obligations and the same third-party assessment pathway as before the Omnibus.
There is, however, a sovereign data-exposure dimension to watch. If the Omnibus reduces the proportion of systems subject to mandatory third-party oversight, organisations in regulated sectors that voluntarily engage notified bodies for assurance purposes may face less standardised market practice around on-premises assessment. This makes it more important, not less, for those organisations to specify their sovereign data requirements explicitly in the engagement contract rather than relying on market norms.
Building an Audit-Ready Annex IV Documentation Package in Sovereign Infrastructure
Annex IV documentation must be maintained for ten years after an AI system is placed on the market, as required by Article 18. For a regulated organisation running a sovereign AI deployment on locally hosted infrastructure, this creates a long-term records management obligation that must be built into the infrastructure architecture from the outset.
| Annex IV Requirement | Sovereign Implementation Approach | Relevant Standard |
|---|---|---|
| General description and intended purpose | Versioned document repository on sovereign infrastructure, access-controlled and audit-logged | ISO/IEC 42001 clause 6.1 |
| Training data provenance and composition | Data lineage records stored in sovereign data lake, no external transfer during assessment | ISO/IEC 42001 clause 8.4 |
| Model weights and architecture | Stored in air-gapped model registry; read-only notified body access via isolated terminal | AI Act Article 43, Annex IV |
| Test logs and performance metrics | Immutable log storage (WORM) within sovereign infrastructure; exportable only as signed PDF summaries | AI Act Annex IV, NIS-2 Article 21 |
| Post-market monitoring plan | Documented in sovereign ITSM system; linked to incident response and SIEM dashboards | AI Act Article 72, ISO/IEC 42001 clause 9.1 |
ISO/IEC 42001, published in 2023 as the first international standard for AI management systems, provides a documentation framework that maps closely to Annex IV. Organisations that implement 42001 and achieve third-party certification against it gain two practical advantages: their documentation structures are already organised in a way that a notified body can navigate efficiently, and the certification itself serves as evidence of systematic AI governance for sector regulators under NIS-2, DORA and the GDPR.
The European Data Protection Board reported that in 2023 supervisory authorities across the EEA issued GDPR fines totalling EUR 2.1 billion. A significant portion of those enforcement actions involved failures in data governance and lawful processing, areas where inadequate AI documentation contributed directly to the regulatory exposure. Maintaining Annex IV records in sovereign infrastructure, with tamper-evident controls, removes one category of regulatory risk while simultaneously preparing the organisation for a notified body assessment that does not require external data transfer.
ENISA has noted in its AI cybersecurity risk assessment guidance that the assessment of AI systems requires access to technical documentation that may include proprietary training data and model architecture, and that the framework must ensure such access does not undermine the fundamental rights or security interests of the deploying organisation. This framing is operationally useful: it justifies on-premises assessment as a security control in itself, not merely a commercial preference.
Organisations evaluating notified bodies should verify accreditation status directly through the national accreditation body database published by European Accreditation (EA) at european-accreditation.org, and should confirm that the body holds accreditation specifically relevant to the AI system’s product category, whether medical devices, financial software or critical infrastructure components, rather than accepting generic IT security certification as a substitute.
FAQ
Which high-risk AI systems under AI Act Article 43 always require a notified body, regardless of harmonised standards?
Systems covered by Annex III that also fall within the scope of Union harmonisation legislation listed in Annex I (such as medical devices or machinery) must always undergo third-party conformity assessment via a notified body under Article 43(1). Biometric identification systems and AI used in critical infrastructure management face a similarly strict third-party requirement under Article 43(1)(b).
Can a notified body perform an AI Act assessment entirely on the provider’s or deployer’s premises?
Yes. Nothing in AI Act (EU) 2024/1689 prohibits on-premises or air-gapped assessment. Organisations should contractually require that all document review, model testing and log analysis take place within their sovereign environment, and that the notified body’s personnel sign data handling agreements prohibiting extraction of training data, model weights or test outputs.
What does AI Act Annex IV require in terms of technical documentation, and how long must it be retained?
Annex IV lists a detailed set of documentation: a general description of the system and its intended purpose, the design logic and assumptions, training data characteristics, validation and testing results, cybersecurity measures, and post-market monitoring plans. Providers must retain this documentation for ten years after the system is placed on the market under Article 18, making sovereign, tamper-evident storage a long-term infrastructure requirement.
What did the AI Act Omnibus simplification change for conformity assessment obligations?
The Omnibus package, part of the Commission’s COM(2025) simplification initiative, proposed reducing mandatory third-party assessment obligations for a subset of general-purpose AI system providers and smaller operators. For high-risk systems deployed by regulated sectors (finance, healthcare, law enforcement), the core Article 43 third-party requirement was maintained. The reduction in scope applies mainly to lower-risk AI tools, and does not eliminate sovereign data-exposure risk for organisations handling sensitive or special-category data.
How does ISO/IEC 42001 certification help an organisation prepare for an AI Act notified body assessment?
ISO/IEC 42001 defines an AI management system framework covering risk management, data governance, transparency and accountability. Organisations certified under 42001 have pre-built documentation structures that map closely to AI Act Annex IV requirements. A notified body can use that existing documentation package as the primary evidence base, reducing the need for real-time access to production systems and limiting data-exposure windows during the assessment.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
