The situation at Kompas
Inside Kompas much has been built: the RMS lives as a process, the technical file grows, oversight is embedded in the UX, logs are written, model due diligence is done. But compliance exists only when it can be proven from the outside. The regulator doesn't come in to read your code; the auditor and the corporate client look at artifacts and declarations. This chapter is about the proof machine: how Kompas certifies conformity, labels and registers the system, and what happens if it doesn't certify.
In parallel, the market presses, not just the law: European clients in RFPs ask for an ISO/IEC 42001 certificate before a regulator knocks with an inspection. Proof is needed for two audiences at once.
What the rule says
Conformity assessment (Art. 43). For most high-risk systems from Annex III — including HR — an internal conformity assessment (self-assessment) under Annex VI is provided for, without mandatory involvement of an external notified body. That is a relief on procedure, not on substance: responsibility for the correctness of the assessment is on the provider.
EU Declaration of Conformity + CE marking (Art. 47–48). The provider draws up a declaration of conformity and affixes the CE marking, indicating conformity with the AI Act.
Registration in the EU database (Art. 49). High-risk systems are registered in a public EU database before being placed on the market — transparency for the regulator and the public.
Harmonized standards and presumption of conformity. Conformity with an officially adopted harmonized standard grants a presumption of conformity with the law — this is the main practical mechanism. But as of September 2026 the standards are largely still in development, so you can't lean on the presumption in full yet.
ISO/IEC 42001 (AI Management System, published December 2023) — a certifiable governance standard. It is not harmonized under the AI Act and therefore does not grant a presumption of conformity, but it has de facto become a requirement of B2B RFPs in the EU and a certifiable proof of governance maturity. NIST AI RMF — a voluntary, non-certifiable framework, a convenient bridge to ISO 42001.
Penalties (Art. 99), three tiers: up to €35M or 7% of global turnover (prohibited practices, Art. 5); up to €15M or 3% (breach of obligations, including high-risk ones); up to €7.5M or 1% (providing incorrect information to the regulator). For SMEs and startups — the lower of the two figures (sum or percentage).
Dates (current as of September 2026). Art. 5 + GPAI — from 02.08.2025; Art. 50 transparency and supervisory structures (AI Office) — from 02.08.2026; stand-alone high-risk (Annex III) shifted by the Digital Omnibus (Regulation (EU) 2026/1744, in force from 27.07.2026) to 02.12.2027; embedded high-risk (Annex I) — to 02.08.2028.
How it lands on the product
Kompas passes an internal conformity assessment under Annex VI, draws up the Declaration of Conformity and affixes CE, and registers in the EU database before placing the high-risk function on the market.
On a separate track, Kompas sets up ISO/IEC 42001 — not for the presumption (this standard doesn't grant it), but as a market pass: without it, part of the European deals simply won't start.
The chapter's artifact is a compliance dossier: a dossier that isn't rewritten from scratch but assembled from the artifacts of chapters 1–7 (applicability memo, classification record, RMS, technical file per Annex IV, transparency map, model due diligence) into a presentable set.
Where it breaks
The standards aren't ready. While harmonized standards aren't finalized, there's nothing to fully lean the presumption of conformity on — you have to prove conformity "on the merits," which is more expensive and more subjective.
Self-assessment tempts you to cut corners. An internal assessment without an external body is trust that's easy to eat away: "we ticked the box ourselves." Until the first serious inspection or incident, such an assessment looks passed; after — it falls apart.
The date shift creates false calm. Moving the high-risk deadline to the end of 2027 reads as "there's time." But the real deadline is not the date an article enters into force, but the time it takes to prepare the data, the RMS and the documentation — and that's years, not months.
What to do as engineer/product
Assemble the dossier incrementally from the artifacts of previous chapters along the way through development, not in a rush for the audit date. Then "proof" is a byproduct of normal work, not a separate project.
Don't put off preparation because of the date shift: the readiness date is governed by data preparation and a living RMS, not by the article's calendar of entry into force. A dossier started earlier is cheaper finished.
Provocation
Conformity assembled by hand for the audit date is theater; conformity that assembles itself from artifacts accumulated along the way through development is proof. And the shift of entry-into-force dates is not a postponement of work but a trap: it cancels the sense of urgency without canceling the fact that only the one who started before it became urgent can prepare a high-risk system in the remaining time.
Read next
Shipping an AI product under regulatory risk?
A read of your product against the EU AI Act: risk class, role in the value chain, obligations and dossier — as a design constraint on the way in, not a lawyer's check at the end.
Email meThe transition engine
Next Move Engine — the system that takes a team to an autonomous delivery loop.
Next Move Engine →