What exactly is it?
The EU Declaration of Conformity, governed by Annex V of the AI Act, is the formal, signed document through which the provider of a high-risk AI system declares, under its sole responsibility, that the system meets the Regulation's requirements. It isn't an informal self-assessment — it's a legal declaration with a signature, and it underpins the CE marking that allows the system to be placed on the EU market.
Why it isn't a document you write from scratch
Here's the point that's both most reassuring and most commonly missed: if you're already working through the rest of the AI Act's obligations for a high-risk system — risk management, training data quality (Art. 10), technical documentation, human oversight (Art. 14) — the declaration of conformity doesn't add new work. It's the final summary that pulls together and signs off on everything you should already have documented along the way. Treating it as a separate task, left for the end, is the surest way to discover at the last minute that pieces you assumed already existed, don't.
Why a client may ask for it before a regulator does
It's increasingly common for a declaration of conformity — or at least equivalent evidence — to be requested in enterprise procurement processes, public tenders, or insurance reviews, as a trust signal, well before it's legally required. With AESIA already operational and processing compliance inquiries, and with the precedent of GPAI model documentation obligations — in force since August 2025, unaffected by the high-risk delay — the market is already used to asking for concrete paperwork, not generic assurances of "we comply with the regulation."
What to have ready before signing it
- Complete technical documentation of the system, not just a marketing summary.
- The risk management record and the mitigation measures applied.
- Evidence of training data quality, if the system was trained on proprietary data.
- The human oversight procedure actually in operation, not just written down.
- Clear identification of the provider and the person with authority to sign on its behalf.
Pulling each of these pieces together separately, at the moment a client or a regulator asks for them, costs far more in time and stress than having them already assembled when the question arrives.