Key findings
- • High-risk AI under Annex III is subject to binding infrastructure requirements — not just documentation obligations.
- • Art. 50 is the core technical obligation: transparency and provenance must be demonstrable; the machine-readable marking requirement (para. 2) applies only to providers of generative AI systems.
- • The Conformity Assessment Dossier (Art. 43) needs concrete evidence — not general statements.
- • Infrastructure evidence such as CERTavia can be integrated directly into the CAD dossier.
Step 1: Am I affected? — Annex III check
The EU AI Act distinguishes between general-purpose AI systems and high-risk AI. High-risk AI is exhaustively defined in Annex III (DE). Before you work through the infrastructure checklist, make sure your system is actually affected.
Typical Annex III categories:
- Biometric systems (identification, categorization, emotion recognition)
- AI in critical infrastructure (energy, water, transport)
- AI in education (assessment, admission)
- AI in employment and workforce management (screening, evaluation)
- AI for essential private and public services (credit, insurance)
- AI in law enforcement and migration control
- AI in the administration of justice
Not sure whether you're affected? The CERTavia quick test (DE) helps with the assessment.
Step 2: Checklist Art. 9 — Risk management system
Art. 9 requires a documented risk management system spanning the AI system's entire lifecycle.
Step 3: Checklist Art. 50 — Transparency, marking, provenance
Art. 50 is the critical technical requirement. Here are concrete infrastructure checkpoints:
Infrastructure cybersecurity
Robustness and availability
The CERTavia scan checks all technical parameters from the cybersecurity checklist automatically and delivers cryptographically signed evidence.
Step 4: Checklist Art. 17 — Quality management system
Step 5: Checklist Art. 43 — Conformity Assessment Dossier
The Conformity Assessment Dossier (CAD) (DE) under Art. 43 is the formal evidence submitted to market surveillance authorities. It must contain concrete evidence — not general statements.
Timeline: what applies from when?
The EU AI Act has been in force since August 2024. The transparency obligations under Art. 50 apply from August 2, 2026. The transition period for high-risk AI under Annex III was postponed via the AI Omnibus (finally adopted by the Council on June 29, 2026) to December 2, 2027 (Annex I to August 2, 2028). From the respective date, systems must be demonstrably compliant before being placed on the EU market or put into service.
Important: this means infrastructure must be demonstrably compliant by a reference date before the respective regulatory deadline. Retroactive evidence will be harder to establish.
Next steps
Once you've worked through this checklist, you have an overview of your compliance status. The technical infrastructure evidence under Art. 50 is often the gap that can be closed fastest — because it's automated and available in 90 seconds.
Get started with the free CERTavia scan and receive your CERTIFIED/FAILED verdict instantly, with a full cluster report.