The EU AI Act establishes a tiered conformity assessment regime that determines whether your organisation can self-certify a system or must engage an accredited third party before placing it on the EU market. For fashion organisations deploying recommendation engines, computer vision quality-control tools, or demand-forecasting models, the classification of each system—and the documentation burden that follows—will define your compliance roadmap for the next several years.
Key takeaways
- Most AI systems deployed in fashion today fall outside the high-risk category and require only limited transparency obligations, not full conformity assessment.
- High-risk classification triggers a structured assessment procedure under Article 43 of the AI Act, with a choice between internal control and notified-body review depending on the use case.
- Technical documentation, conformity declarations, and post-market monitoring logs must be maintained for the life of the system plus ten years.
- Harmonised standards from CEN and CENELEC are still being developed, which creates short-term uncertainty about exactly which technical specifications satisfy the Act's requirements.
- Governance leads should map every deployed AI system to a risk tier now, before the high-risk obligations enter full effect.
What does the EU AI Act actually require at the conformity stage?
The AI Act does not impose a single conformity procedure on every AI system. It creates a layered structure in which the obligations attached to a system depend on its classification. Prohibited systems cannot be placed on the market at all. High-risk systems—those listed in Annex III or embedded in regulated products covered by Annex I—must pass a conformity assessment before deployment. Systems that are not high-risk face lighter transparency or registration requirements, or none at all.
Conformity assessment, in the Act's terms, is the process by which a provider demonstrates that a high-risk AI system meets the mandatory requirements set out in Chapter III, Section 2: risk management, data governance, technical documentation, logging, transparency toward deployers, human oversight, accuracy, robustness, and cybersecurity. The output of a successful assessment is a CE mark and an EU declaration of conformity, both of which must accompany the system when it enters the market.
Article 43 of the Act sets out two procedural routes for high-risk systems listed in Annex III: internal control (Annex VI) and third-party assessment by a notified body (Annex VII). The choice between them is not entirely at the provider's discretion—it depends on the system's subject matter and whether harmonised standards or common specifications have been applied.
How do you classify a fashion AI system under the Act?
The first question your governance team must answer is whether any deployed system falls within Annex III. That annex lists eight areas of high-risk application. For fashion organisations, the most relevant are:
- Employment, workers management, and access to self-employment (Annex III, point 4): AI used to make or materially influence decisions on recruitment, task allocation, performance monitoring, or termination of work relationships. A system that automatically ranks job applicants for a warehouse role, or that monitors production-floor workers against output targets, is likely in scope here.
- Access to and enjoyment of essential private services and public services (Annex III, point 5): AI used in credit scoring or insurance risk assessment. A fashion brand's buy-now-pay-later integration that uses an AI credit model would fall here.
- Biometric categorisation (Annex III, point 1): systems that categorise individuals by sensitive attributes from biometric data. A computer vision tool that infers body type for sizing is not automatically in this category, but the boundary requires careful legal analysis.
The vast majority of AI systems currently deployed in fashion—personalised product recommendations, trend-forecasting models, visual search, inventory optimisation, and demand planning—do not fall into any Annex III category. Taylor Wessing's sector analysis characterises most fashion AI as low-risk, subject at most to transparency obligations rather than conformity assessment. That characterisation is consistent with the Act's text, though it does not eliminate the need for a documented classification exercise: the Act places the burden of classification on the provider, and an undocumented assumption that a system is low-risk is not a defensible position.
What is the difference between internal control and notified-body assessment?
Internal control (Annex VI)
Internal control is the default route for high-risk systems listed in Annex III where the provider has applied harmonised standards covering all relevant requirements, or where common specifications adopted by the Commission apply. Under this route, the provider conducts the assessment itself, generates the required technical documentation, and signs the EU declaration of conformity without external validation.
This does not mean the process is light. The technical documentation required under Annex IV is extensive: it must describe the system's intended purpose, the development methodology, the training, validation, and test datasets and their provenance, the performance metrics and their measurement, the known limitations, the risk management measures, and the post-market monitoring plan. For a recommendation engine, that means documenting not only the model architecture but the data pipelines, the fairness evaluations, and the human oversight mechanisms built into the production system.
Third-party assessment (Annex VII)
For certain categories of high-risk system—specifically, those involving biometric identification or categorisation of natural persons—the Act requires involvement of a notified body. A notified body is an organisation designated by an EU member state to assess conformity against specific legislation; the European Commission publishes the list of designated notified bodies across product categories. For AI, the notified-body infrastructure is still being established: member states must designate bodies, and those bodies must be accredited against the competence requirements the Act sets out.
Under Annex VII, the notified body reviews the technical documentation, may request additional information or testing, and issues a certificate of conformity. The provider cannot affix the CE mark until that certificate is in hand. The certificate is time-limited and subject to surveillance audits.
For fashion organisations, third-party assessment is most likely to arise if a system processes biometric data—for example, a body-scanning tool that derives measurements from images of identified individuals, or a virtual try-on system that stores biometric templates. The precise boundary between a sizing tool and a biometric categorisation system is one of the open interpretive questions the Act leaves to national market surveillance authorities and, ultimately, to the AI Office.
What must the technical documentation contain for a fashion AI system?
Annex IV of the Act specifies the minimum content of technical documentation. Mapped to a fashion recommendation engine or computer vision tool, the key elements are:
- System description and intended purpose: what the system does, the specific deployment context (e.g., product recommendation on an e-commerce platform, defect detection on a production line), and the categories of users and affected persons.
- Design and development information: the overall architecture, the choice of training approach, the external tools or pre-trained models incorporated (and their own documentation), and the version control process.
- Training data documentation: the sources of training and validation data, the data governance procedures applied, the steps taken to detect and address bias, and the geographic and demographic coverage of the dataset.
- Performance metrics: the accuracy, precision, recall, or other task-appropriate metrics measured on the validation and test sets, together with the conditions under which those measurements were made.
- Risk management system records: the iterative risk identification and mitigation process required by Article 9, including residual risks accepted and the rationale.
- Post-market monitoring plan: how the system's performance will be tracked after deployment, what metrics trigger review, and how serious incidents will be reported to the AI Office.
- Human oversight measures: the technical and organisational mechanisms that allow a human operator to understand, monitor, and intervene in the system's outputs.
For a computer vision quality-control tool on a garment production line, point 3 is particularly demanding: the training dataset must be documented with enough specificity that an auditor can assess whether it was representative of the defect types and fabric categories the system will encounter in production.
Where do harmonised standards fit, and why does their absence matter now?
The Act's internal-control route is conditional on the provider having applied harmonised standards or common specifications. Harmonised standards are technical specifications developed by European standardisation bodies—CEN and CENELEC—under a mandate from the Commission, and published in the Official Journal. When a provider applies a harmonised standard in full, it benefits from a presumption of conformity with the requirements that standard covers.
For AI, those standards are not yet final. CEN and CENELEC adopted measures in October 2025 to accelerate delivery of the standards being developed under their Joint Technical Committee on Artificial Intelligence, in response to the standardisation requests linked to the AI Act. Until harmonised standards are published and referenced in the Official Journal, providers must demonstrate conformity by other means—typically by mapping their technical documentation and processes against the Act's requirements directly, or by applying existing ISO/IEC standards (such as ISO/IEC 42001 on AI management systems) as proxies, while accepting that the presumption of conformity does not yet attach.
This gap creates practical uncertainty. A fashion organisation that completes its technical documentation today cannot be certain that the specific controls it has documented will satisfy a market surveillance authority's interpretation once harmonised standards are in place. The prudent approach is to document the reasoning behind each control choice explicitly, so that the documentation can be updated incrementally as standards are finalised rather than rebuilt from scratch.
How are fashion organisations approaching this in practice?
Organisations such as H&M Group operate at a scale where AI systems span multiple functions—demand forecasting, assortment planning, logistics optimisation, and customer-facing personalisation. At that scale, the classification exercise alone is a significant undertaking: each system must be assessed individually, because a model that is low-risk in one deployment context (recommending products to anonymous visitors) may become high-risk if repurposed (scoring employees against productivity targets).
Research and advisory firms such as Gartner have observed that enterprise AI governance programmes are increasingly treating regulatory classification as an input to model lifecycle management rather than a one-time compliance exercise. That framing is consistent with the Act's post-market monitoring requirements: classification is not fixed at deployment; it must be revisited when the system's intended purpose, the population it affects, or the regulatory context changes.
For smaller fashion brands and technology providers supplying AI tools to the sector, the practical priority is establishing a documented classification process before the high-risk obligations enter full effect. The Act's implementation timeline has seen adjustments—the Morgan Lewis analysis of deadline changes notes that extended timelines represent additional preparation time rather than a reduced obligation—so the window for building compliant documentation practices is finite.
What is still unresolved?
Several questions remain open and will be settled through guidance from the AI Office, decisions by national market surveillance authorities, or litigation:
- The boundary of biometric categorisation: whether a computer vision sizing tool that infers body measurements from images constitutes a biometric categorisation system for Annex III purposes is not definitively answered by the Act's text.
- General-purpose AI components in fashion systems: many fashion AI systems are built on or incorporate general-purpose AI models. The Act has a separate regime for GPAI model providers, but the interaction between that regime and the high-risk system obligations for deployers who build on GPAI models is not fully elaborated in guidance.
- Third-country providers: fashion AI tools are frequently developed outside the EU and offered to EU-based deployers. The Act's extraterritorial scope means non-EU providers placing systems on the EU market must comply, but enforcement mechanisms against non-EU entities remain untested.
- The notified-body bottleneck: the number of accredited notified bodies for AI is currently very small. If demand for third-party assessment grows faster than the notified-body infrastructure, lead times could become a significant operational constraint.
FAQ
Does every AI system used in fashion need a conformity assessment? No. Only high-risk AI systems, as defined by Annex III or Annex I of the Act, require a formal conformity assessment. Most fashion AI applications—product recommendations, visual search, demand forecasting—are not high-risk under the Act's current classification, though they may carry lighter transparency obligations.
What triggers the need for a notified body rather than self-assessment? The Act requires notified-body involvement for high-risk systems that involve biometric identification or categorisation of natural persons, or where the provider cannot demonstrate full application of harmonised standards covering the relevant requirements. For most Annex III systems where harmonised standards apply, internal control is permitted.
How long must technical documentation be retained? The Act requires providers to retain technical documentation and the EU declaration of conformity for ten years after the system is placed on the market or put into service. Post-market monitoring logs must be kept for the same period.
What happens if harmonised standards do not cover our system's requirements? Providers may use common specifications adopted by the Commission, or demonstrate conformity directly against the Act's requirements through their own technical documentation. The presumption of conformity does not apply, but a well-documented direct mapping can still satisfy a market surveillance authority.
Is a recommendation engine that personalises product listings ever high-risk? Under the Act as currently written, a recommendation engine that suggests products to consumers is not listed in Annex III and is not high-risk. If the same engine were used to rank job applicants or allocate work tasks to employees, it would fall under Annex III, point 4, and would be high-risk. The deployment context, not the underlying model, determines the classification.
What should an AI governance lead do right now? Conduct a documented inventory of every AI system your organisation deploys or procures, classify each against Annex III, record the reasoning, and establish a review cadence tied to the Act's implementation milestones. Where a system is borderline, obtain legal analysis and document that analysis as part of the classification record.
Further reading
- Regulation (EU) 2024/1689 — full text of the AI Act
- European Commission: notified bodies
- CEN/CENELEC AI standardisation update
- Taylor Wessing: Fashion meets the AI Act
