Source-linked AI summary
Conformity Assessments and Post-market Monitoring: A Guide to the Role of Auditing in the Proposed European AI Regulation
Jakob Mokander, Maria Axente, Federico Casolari, Luciano Floridi
TL;DR
The proposed EU legislation raises unresolved questions about how AI systems should be regulated and assessed. This article examines it through an auditing perspective and argues that it sketches a Europe-wide AI-auditing ecosystem while offering a good starting point for balancing innovation and safeguards.
Problem
The proposed EU legislation leaves central questions, including which metrics AI systems should be assessed according to, unresolved.
Method
The article uses auditing in a broad sense to interpret the AIA as sketching a Europe-wide ecosystem for auditing AI systems.
Results
The authors conclude that the proposed EU legislation is a good starting point for balancing responsible innovation with proportionate safeguards against AI risks.
Takeaways & Limitations
The AIA should make its Europe-wide AI-auditing ecosystem explicit and clarify how it can be implemented.
Takeaways & Limitations
The article identifies the AIA's simplified process representation as a limitation and notes that regulators could do more to support feasibility.
Abstract
from arXiv · showhide
The proposed European Artificial Intelligence Act (AIA) is the first attempt to elaborate a general legal framework for AI carried out by any major global economy. As such, the AIA is likely to become a point of reference in the larger discourse on how AI systems can (and should) be regulated. In this article, we describe and discuss the two primary enforcement mechanisms proposed in the AIA: the conformity assessments that providers of high-risk AI systems are expected to conduct, and the post-market monitoring plans that providers must establish to document the performance of high-risk AI systems throughout their lifetimes. We argue that AIA can be interpreted as a proposal to establish a Europe-wide ecosystem for conducting AI auditing, albeit in other words. Our analysis offers two main contributions. First, by describing the enforcement mechanisms included in the AIA in terminology borrowed from existing literature on AI auditing, we help providers of AI systems understand how they can prove adherence to the requirements set out in the AIA in practice. Second, by examining the AIA from an auditing perspective, we seek to provide transferable lessons from previous research about how to refine further the regulatory approach outlined in the AIA. We conclude by highlighting seven aspects of the AIA where amendments (or simply clarifications) would be helpful. These include, above all, the need to translate vague concepts into verifiable criteria and to strengthen the institutional safeguards concerning conformity assessments based on internal checks.
This is a pre-print
The article is identified as a pre-print and is available online under its full title.
- The article is available online.
- Its title is “Conformity Assessments and Post-market Monitoring: A Guide to the Role of Auditing in the Proposed European AI Regulation.”
- The passage labels the article as a pre-print.
1 Introduction
The introduction frames the AIA as a globally significant regulatory proposal and asks how auditing operates within it. The article interprets conformity assessments and post-market monitoring as an emerging European AI-auditing ecosystem, while identifying areas needing clarification and stronger safeguards.
- The AIA is presented as the first general legal framework for AI proposed by a major global economy and a likely reference point for AI regulation.
- The article asks how auditing functions within the proposed EU legislation rather than offering a general commentary on stakeholder reactions.
- Auditing is defined broadly as structured assessment of present or past behaviour and performance against relevant principles, standards, regulations, or norms.
- The AIA’s conformity assessments and post-market monitoring plans are interpreted as components of a Europe-wide ecosystem for auditing AI systems.
- The article aims to help organisations operationalise AIA compliance and connect the proposal to research on AI auditing.
- The conclusion calls for vague concepts to become verifiable criteria and for stronger safeguards around conformity assessments based on internal checks.
2 The Artificial Intelligence Act: a risk-based approach
The AIA uses a proportionate, risk-based model that differentiates obligations across unacceptable-, high-, and little-or-no-risk AI systems. Its broad scope and procedural requirements seek to manage harms while supporting AI adoption, but may impose unnecessary burdens and leave important discretion unresolved.
- The proposal combines AI uptake with management of associated challenges, reflecting a balance between innovation and safeguards.
- The AIA’s broad definition may cover longstanding decision-making systems and risk over-inclusion, unnecessary financial and administrative costs, and reduced regulatory legitimacy.
- The AIA distinguishes unacceptable-, high-, and little-or-no-risk AI systems and assigns different governance requirements to each category.
- Unacceptable-risk systems, including general-purpose social scoring, are prohibited, while little-or-no-risk systems face few interventions beyond some transparency duties.
- High-risk systems must satisfy strict obligations before market placement, including risk management, risk mitigation, documentation, training, testing, and validation.
- The AIA emphasises processes, intended purposes, design choices, assumptions, and monitoring rather than rules tied to specific technologies.
3 Previous research: enforcement mechanisms and AI auditing
The paper situates AI auditing within broader enforcement approaches and defines it as structured assessment against normative or regulatory baselines. It then identifies conformity assessments and post-market monitoring as the AIA’s two especially relevant auditing mechanisms.
- Effective enforcement is necessary for regulation, because legality requires mechanisms for establishing an AI system’s behaviour and performance.
- AI auditing is a structured process for assessing an entity’s behaviour and performance against relevant principles, regulations, and norms.
- The audited entity may be a person, organisational unit, or technical system, and these audit types are complementary.
- Auditing differs from publishing a code of conduct because it aims to demonstrate adherence to a predefined baseline.
- AI auditing can support regulators, providers, end-users, customers, investors, and civil-rights groups in evaluating or engaging with AI systems.
- The AIA’s two especially relevant auditing mechanisms are pre-market conformity assessments and post-market monitoring of high-risk systems.
4 Conformity assessments and post-market monitoring in the AIA
The AIA combines ex-ante conformity assessments with post-market monitoring to enforce requirements for high-risk AI systems. Providers may use internal control or third-party assessment routes, but the framework leaves important implementation details unresolved.
- High-risk AI systems must demonstrate conformity before market access, with sectoral systems assessed through existing third-party procedures.For AI systems embedded in products such as medical devices or toys, AIA requirements are integrated into existing sectoral safety legislation rather than assessed through AI-specific procedures.
- Stand-alone high-risk AI providers can use internal control when fully compliant and harmonised standards exist, or involve a notified body otherwise.Third-party auditors assess the provider’s quality management system and technical documentation.
- All high-risk systems face the same core obligations, including documenting intended purpose, user instructions, development methods, and critical design choices.Providers must also maintain quality, risk-management, technical-documentation, and governance processes.
- Internal and external audits involve different trade-offs: external audits support formal verification but have limited access to internal processes, while internal audits risk collusion.The AIA’s reliance on internal checks is linked to providers’ ability to intervene during early development stages.
- The AIA provides limited guidance on sector-specific assessment standards and documentation requirements, leaving conformity procedures open to interpretation.The article identifies this lack of practical guidance as an area requiring clarification.
- The AIA combines ex-ante conformity assessments and post-market monitoring into a coordinated basis for enforcing the proposed regulation.Ex-ante checks occur before market placement, while post-market monitoring documents and analyses system performance throughout its lifetime.
5 The emergence of an EU AI auditing ecosystem
The AIA sketches a Europe-wide AI auditing ecosystem linking providers, notified bodies, national authorities, the Commission, and a central database. The proposed structure coordinates oversight but remains idealised and institutionally ambiguous.
- The proposed AIA establishes an emerging European AI auditing ecosystem with institutional and technical components.The article describes an institutional structure alongside auditing tools and expertise needed to assess compliance.
- The European Artificial Intelligence Board is conceived as a Commission-chaired coordinating structure rather than an independent agency.It is intended to facilitate implementation, share best practices, and issue recommendations on uniform administrative practices.
- A centralised database for stand-alone high-risk AI systems is intended to increase public transparency and enable ex-post supervision.Providers and users may also need new organisational roles to meet reporting and access obligations.
- National authorities supervise implementation and notify third-party organisations, while notified bodies assess providers’ quality-management systems and technical documentation.Where conformity is established, notified bodies issue an EU technical documentation assessment certificate.
- Figure 3 presents an idealised process because relationships are bidirectional and the AIA leaves substantial room for interpretation.Terminology is also inconsistent, with notified bodies performing tasks that resemble auditing bodies and notifying authorities resembling accreditation bodies.
6 The scope for soft governance within the AIA
The AIA is primarily a hard-governance framework but also supports voluntary codes of conduct and ethics-based auditing. These mechanisms can extend assurance beyond mandatory compliance, although the AIA does not explain how voluntary adherence should be assessed.
- The AIA combines legally binding enforcement with room for voluntary, post-compliance ethics-based auditing.The article treats conformity assessments and mandatory post-market monitoring as hard enforcement, while codes of conduct provide a soft-governance layer.
- Voluntary codes of conduct focus on process management and may be adopted by non-high-risk providers or organisations seeking standards beyond mandatory requirements.Providers can develop their own principles, adopt Board guidance, or use industry-specific standards.
- The Commission encourages voluntary codes to extend AIA-related practices to use cases not subject to mandatory conformity assessments.This includes systems classified as little or no risk, such as AI-enabled video games and spam filters.
- Ethics-based audits can document how AI systems are designed and deployed, supporting procedural regularity, risk management, public relations, and competitive positioning.The article compares this assurance role with sustainability certification and nutritional labelling.
- The AIA does not specify whether or how adherence to voluntary codes of conduct will be assessed.The article argues that regulators could use the emerging institutional structure to support assurance for post-compliance ethics-based audits.
7 The need for further guidance
The article identifies seven areas where the AIA needs further guidance to make its regulatory and auditing framework workable. Central concerns are translating abstract requirements into verifiable criteria and clarifying scope, concepts, and institutional safeguards.
- I. Level of abstraction: The AIA needs lower-level guidance that translates high-level visions into industry standards, evaluation metrics, and realistic audit benchmarks.Without operational criteria, requirements may become box-ticking exercises or undermine the framework’s legitimacy.
- II. Material scope: The AIA’s broad material scope and exhaustive high-risk list may make it difficult to target auditing resources and preserve a genuinely risk-based approach.The article calls for clarification linking the material scope to the regulation’s stated goals.
- III. Conceptual precision: Vague terms such as ‘risk to fundamental rights’ and prohibited subliminal distortion require greater conceptual precision and guidance.The article also calls for alignment with EU data-protection legislation and clarification of ambiguous derogations.
- The AIA should clarify how conformity assessments and post-market monitoring operate in practice, including how audits are triggered and repeated.The article notes uncertainty about whether periodic audits concern certificate renewal or continuous operation.
- The authors propose stronger transparency obligations, independent third-party audits, and possible use of the existing institutional structure for ethics-based assurance.These options would expose design trade-offs and support assurance beyond mandatory conformity assessment.
8 Conclusions
The proposed AIA is a promising policy-focused framework whose conformity assessments and post-market monitoring sketch a Europe-wide AI-auditing ecosystem. The article supports the approach while calling for clearer verifiable criteria and stronger safeguards for internal assessments.
- The AIA’s risk-based, policy-focused approach shifts attention from labeling systems as AI toward scrutinising the normative ends for which they are used.
- The AIA’s conformity assessments and post-market monitoring bridge a critical gap by replacing voluntary ethics principles with proposed enforcement mechanisms.
- The framework provides hard enforcement mechanisms and an institutional structure for preventing, reporting, and allocating accountability for system failures.
- The article interprets the AIA as sketching a Europe-wide ecosystem for AI auditing, with internal, external, and continuous-auditing analogues.Internal-control conformity assessments resemble internal audits; notified-body involvement resembles external audits; post-market monitoring follows continuous auditing’s logic.
- The AIA should translate vague concepts into practically verifiable criteria so providers can demonstrate adherence to its requirements.
- The legislation would benefit from additional institutional safeguards for conformity assessments based on internal control.The article presents these amendments or clarifications as ways to strengthen the AIA’s overall effectiveness.