The CE mark on a high-risk AI system is not a certificate, not an approval, and not something the European Commission issues. It is a statement the provider makes about its own product, and Article 48 of the AI Act is unusually precise about the form that statement takes and about where it has to be visible.
What the mark actually asserts
CE marking under Article 48 of Regulation (EU) 2024/1689 follows the general principles set out in Article 30 of Regulation (EC) No 765/2008, the horizontal accreditation and market surveillance regulation that governs the mark across all New Legislative Framework instruments. Those principles are the reason the mark is so widely misread. Article 30 of Regulation (EC) No 765/2008 says the mark is affixed only by the manufacturer or its authorised representative, and that by affixing it the manufacturer indicates that it takes responsibility for the product’s conformity with all applicable requirements.
So the mark says: we say this complies, and we are accountable for that statement. It does not say that a European authority looked at the system. In the AI Act the substantive statement lives in the EU declaration of conformity under Article 47, which the provider draws up, keeps for ten years after the system is placed on the market or put into service, and hands to national competent authorities on request. The content of that declaration is fixed by Annex V. The CE mark is the visible shorthand for a document that already exists; if the declaration is not written, the mark is a false statement rather than a premature one.
This page describes what the Regulation says. It is not legal advice, and whether a particular system is high-risk at all — the question that decides whether any of this applies — turns on facts about your product and its intended purpose. Take advice on those facts.
Who affixes it, and after what
Affixing the mark is the last step of a sequence, and the order is not optional. The provider builds the system to the Chapter III Section 2 requirements (Articles 8 to 15), assembles the technical documentation required by Article 11 and Annex IV, runs the conformity assessment procedure that Article 43 assigns to that system, draws up the Article 47 declaration, affixes the mark under Article 48, and then registers the system in the EU database under Article 49 before placing it on the market. The conformity assessment route decides how much of that a third party touches; the marking step itself is always the provider’s.
The deployer never affixes it. Neither does the importer or the distributor — their duties under Articles 23 and 24 are to check that the mark and the accompanying documentation are present and to refuse to place the system on the market if they are not. A deployer who modifies a system enough to become a provider under Article 25 inherits the whole sequence, marking included, which is the practical reason substantial modification is worth understanding before you fine-tune somebody else’s high-risk system.
Where it goes on software
Article 48(1) requires the mark to be affixed visibly, legibly and indelibly to the high-risk AI system, and adds the escape hatch that hardware instruments have always had: where that is not possible or not warranted given the nature of the system, it goes on the packaging or on the accompanying documentation instead. For a model served over an API there is no surface, so the accompanying documentation route is the normal one.
Article 48(2) is the provision that is specific to this Regulation and the one most often missed. For digital-only AI systems a digital CE marking is used, and it counts only if it can easily be accessed through the interface from which the system is accessed, or through an easily accessible machine-readable code or other electronic means. The operative words are easily accessed and machine-readable. A mark buried three clicks into a settings panel, or present only in a PDF sent at contract signature, is arguably not accessible “via the interface from which the AI system is accessed”. In practice providers satisfy this by putting the mark and the declaration reference on the same screen or endpoint the user reaches the system through, and by exposing a machine-readable pointer alongside it.
There is no defined file format for that machine-readable pointer in the Regulation itself. That is one of the gaps harmonised standards are expected to fill, and until they do, two providers can both be defensibly compliant with visibly different implementations. Do not treat any particular pattern you see in the market as the required one.
The four-digit number after the mark
Where a notified body was involved in the conformity assessment under Article 43, Article 48 requires the CE marking to be followed by that body’s identification number. The number is assigned by the Commission under Article 35 and is a single number per body even where it is notified under several Union acts; the bodies and their numbers are listed publicly in the Commission’s NANDO database. The same provision requires the identification number to be indicated in any promotional material that states the system meets the CE marking requirements.
The corollary matters more than the rule. A CE mark with no number after it asserts that no notified body was required — that the system went through the internal control procedure in Annex VI. Since Article 43 routes most Annex III use cases to internal control and only reaches a notified body for biometrics under Annex III point 1 in defined circumstances, a bare mark is the common case, not a defect. A number that does not correspond to a body listed in NANDO for this Regulation is a different matter, and is exactly the kind of thing an importer is expected to catch under Article 23.
When more than one instrument requires it
An AI system that is a safety component of a machine, a medical device or a toy is already inside a CE marking regime. Article 48 handles this by making the mark cumulative: where a high-risk AI system is subject to other Union law that also provides for CE marking, the mark indicates that the system meets the requirements of all of those instruments, not just this one. There is no second AI-specific mark and no suffix.
This is also why the Annex I product families get longer — their conformity assessment already runs through sectoral notified bodies, and the AI requirements are folded into that existing procedure rather than bolted alongside it. That deadline was originally 2 August 2027 and is now 2 August 2028, moved by Regulation (EU) 2026/1744, the Digital Omnibus on AI, which entered into force on 27 July 2026.
What getting it wrong looks like
- Marking without the declaration. The declaration is the substance; the mark is the sign. Affixing the sign without the substance is a provider obligation failure under Article 16, which sits in the Article 99(4) fine tier.
- Marking a system that is not high-risk. The mark is not a quality badge to be applied voluntarily. Regulation (EC) No 765/2008 prohibits affixing markings that mislead third parties as to the meaning of the CE mark.
- A number with no body behind it. Quoting a notified body number for a certificate that has expired, been withdrawn or was never issued for this system is a misrepresentation an importer, distributor or market surveillance authority can check in an afternoon.
- Treating the mark as permanent. A substantial modification triggers a fresh conformity assessment under Article 43(4), and therefore a fresh declaration. The mark stays only if the paperwork behind it is refreshed.
The formal non-compliance provisions of Chapter IX give market surveillance authorities a route to act on marking defects specifically, separate from any finding that the system is unsafe — see what those authorities can actually do.
Top comments (0)