EU AI Act Chapter III - High Risk AI System - Article 33 - Subsidiaries of Notified Bodies and Subcontracting

Oct 13, 2025by Maya G

Introduction

High-risk AI systems are those with significant potential to impact people's rights and safety. These systems could include AI used in critical infrastructure, education, employment, law enforcement, and other areas where their failure or misuse could have severe consequences. The EU AI Act identifies these systems and sets stringent requirements to ensure their safety, transparency, and accountability.

EU AI Act Chapter III - High Risk AI System - Article 33 - Subsidiaries of Notified Bodies and Subcontracting

Key Characteristics Of High-Risk AI Systems

  • High-risk AI systems are defined by their potential impact on individuals and society.

  • They often operate in contexts where errors can lead to significant harm or injustice.

  • Such systems might be involved in decision-making processes that affect personal freedom, health, or financial stability.

  • Understanding these characteristics is crucial for developing appropriate regulatory frameworks.

Examples of High-Risk AI Systems

High-risk AI systems can be found in numerous sectors. For instance, in healthcare, AI systems might be used for diagnosing diseases or recommending treatments, where inaccuracies can have severe consequences. In law enforcement, AI might be employed for predictive policing, raising concerns about bias and fairness. Each sector presents unique challenges and risks, requiring tailored regulatory approaches.

Regulatory Requirements for High-Risk AI

The EU AI Act imposes rigorous requirements on high-risk AI systems to ensure they are safe, transparent, and accountable. These include obligations for data quality, documentation, and human oversight. Compliance with these requirements is essential to mitigate risks and protect public interests. Ensuring that AI systems meet these standards is a critical step in fostering trust and adoption.

Why Is AI Risk Management Important?

AI risk management is essential because AI systems are increasingly being integrated into various sectors, influencing decisions that can affect lives. Proper risk management ensures that these systems operate reliably and ethically, reducing the possibility of errors and misuse.

1. The Growing Influence of AI- AI technologies are rapidly advancing and becoming integral to many industries. From automating routine tasks to making complex decisions, AI systems are reshaping businesses and society. As their influence grows, so do the potential risks. Effective risk management is crucial to harnessing the benefits of AI while minimizing potential downsides.

2. Ethical Considerations in AI- Ethical considerations are at the heart of AI risk management. AI systems must be designed and implemented in ways that respect human rights and promote fairness. This involves addressing issues like bias, transparency, and accountability. By prioritizing ethical considerations, organizations can ensure that their AI systems are aligned with societal values and expectations.

3. Strategies For Effective AI Risk Management- Effective AI risk management involves several strategies. These include implementing robust governance frameworks, conducting thorough risk assessments, and ensuring continuous monitoring and evaluation. Organizations must also foster a culture of accountability and transparency. By adopting these strategies, they can mitigate risks and enhance the reliability and trustworthiness of their AI systems.

The Role Of Notified Bodies

Notified bodies are organizations designated to assess the conformity of certain products before they can be marketed in the EU. For high-risk AI systems, notified bodies play a crucial role in ensuring these systems meet EU standards.

Functions Of Notified Bodies

Notified bodies are responsible for conducting conformity assessments to ensure that products meet regulatory requirements. In the context of AI, they evaluate whether high-risk AI systems comply with the EU AI Act. Their assessments cover various aspects, including safety, performance, and transparency. By doing so, they help protect consumers and ensure that AI systems are used responsibly.

Importance Of Notified Bodies In AI Regulation

Notified bodies are essential to the regulatory ecosystem. They provide an independent and objective evaluation of AI systems, ensuring compliance with standards. Their role is particularly important for high-risk AI systems, where the stakes are high. By certifying that these systems meet regulatory requirements, notified bodies contribute to building trust in AI technologies.

Challenges Faced By Notified Bodies

Notified bodies face several challenges in the rapidly evolving field of AI. These include keeping up with technological advancements, managing resource constraints, and ensuring consistency in assessments. Addressing these challenges requires ongoing collaboration with stakeholders, continuous learning, and investment in capacity building. By overcoming these challenges, notified bodies can effectively fulfill their role in AI regulation.

Subsidiaries Of Notified Bodies

Article 33 of the EU AI Act allows notified bodies to use subsidiaries to carry out specific tasks related to conformity assessments. This provision is crucial for expanding the capacity and expertise available to handle the complex evaluations required for high-risk AI systems.

The Role Of Subsidiaries In Conformity Assessments

  • Subsidiaries play a vital role in supporting notified bodies.

  • They provide additional resources and expertise that can enhance the assessment process.

  • By leveraging subsidiaries, notified bodies can ensure that conformity assessments are thorough and efficient.

  • This is particularly important for high-risk AI systems, where detailed evaluations are necessary to ensure compliance with regulatory requirements.

Advantages Of Utilizing Subsidiaries

Utilizing subsidiaries offers several advantages for notified bodies:

  • It allows them to access specialized knowledge and skills that may not be available internally.

  • Subsidiaries can also help manage workload and improve efficiency by taking on specific assessment tasks.

  • By expanding their capabilities, notified bodies can better meet the demands of AI regulation.

Ensuring Effective Collaboration with Subsidiaries

Effective collaboration between notified bodies and their subsidiaries is essential for successful conformity assessments. This involves clear communication, defined roles and responsibilities, and robust oversight mechanisms. By fostering strong partnerships, notified bodies can ensure that subsidiaries contribute effectively to the assessment process while maintaining high standards of quality and accountability.

How Do Subsidiaries Contribute?

Subsidiaries can provide specialized knowledge and resources that notified bodies might not possess internally. By leveraging these subsidiaries, notified bodies can ensure a more thorough and efficient assessment process, ensuring that high-risk AI systems comply with the necessary regulations.

1. Enhancing Expertise and Capacity- Subsidiaries enhance the expertise and capacity of notified bodies by providing access to specialized skills and knowledge. This is particularly valuable for assessing complex AI systems that require a deep understanding of specific technologies or industries. By tapping into these resources, notified bodies can conduct more comprehensive evaluations.

2. Streamlining Assessment Processes- Subsidiaries can streamline assessment processes by handling specific tasks or components of conformity assessments. This allows notified bodies to focus on core aspects of the evaluation while benefiting from the subsidiary's expertise. By optimizing the division of labor, notified bodies can improve the efficiency and effectiveness of their assessments.

3. Ensuring Compliance with Regulations- Subsidiaries play a crucial role in ensuring that high-risk AI systems comply with regulatory requirements. They contribute to the thorough evaluation of systems, identifying potential risks and recommending necessary improvements. By supporting notified bodies in this way, subsidiaries help ensure that AI systems are safe, transparent, and accountable.

Conditions For Subcontracting

The EU AI Act sets out specific conditions for subcontracting to ensure that the quality and reliability of the assessments are not compromised. These conditions include:

  • The subcontractor must have the necessary competence and resources.

  • The notified body must maintain full responsibility for the subcontracted work.

  • The subcontracting arrangement must be transparent, and the subcontractor's identity must be disclosed.

  • Ensuring Competence and Resources- A fundamental condition for subcontracting is ensuring that subcontractors possess the necessary competence and resources. This involves assessing the qualifications and capabilities of potential subcontractors to ensure they can effectively perform the delegated tasks. By doing so, notified bodies can maintain the quality and integrity of conformity assessments.

  • Upholding Responsibility and Accountability- Even when subcontracting tasks, notified bodies must uphold their responsibility and accountability for the assessment process. This means that they remain ultimately responsible for the outcomes of the assessments, regardless of who performs the tasks. Clear agreements and oversight mechanisms are essential to ensure that subcontractors meet the required standards.

  • Transparency and Disclosure- Transparency and disclosure are critical components of the subcontracting process. Notified bodies must clearly communicate subcontracting arrangements and disclose the identity of subcontractors. This transparency helps build trust in the assessment process and ensures that stakeholders are aware of who is involved in evaluating high-risk AI systems.

Benefits Of Subcontracting

Subcontracting can provide several advantages, including:

  • Access to Expertise: Subcontracting allows notified bodies to tap into a broader pool of expertise, which can be crucial for assessing complex AI systems.

  • Increased Efficiency: By delegating specific tasks, notified bodies can streamline the assessment process, ensuring quicker and more efficient evaluations.

  • Resource Optimization: Subcontracting enables better allocation of resources, allowing notified bodies to focus on their core competencies while subcontractors handle specialized tasks.

  • Expanding Expertise And Capabilities- Subcontracting enables notified bodies to access a wider range of expertise and capabilities. This is particularly valuable for assessing complex AI systems that require specialized knowledge. By collaborating with subcontractors, notified bodies can enhance their ability to conduct thorough and accurate evaluations.

  • Improving Efficiency And Timeliness- By delegating specific tasks to subcontractors, notified bodies can improve the efficiency and timeliness of conformity assessments. Subcontractors can help manage workload and expedite the evaluation process, allowing notified bodies to complete assessments more quickly without compromising quality.

  • Optimizing Resource Allocation- Subcontracting allows notified bodies to optimize their resource allocation by focusing on core competencies while subcontractors handle specialized tasks. This enables notified bodies to make better use of their resources and capabilities, enhancing the overall effectiveness of the assessment process.

Challenges And Considerations

While subsidiaries and subcontracting offer significant benefits, they also pose challenges that need careful management.

1. Ensuring Quality and Accountability- Maintaining high standards of quality and accountability is paramount. Notified bodies must ensure that subsidiaries and subcontractors adhere to the same rigorous standards expected of them. This requires robust oversight and clear communication channels.

2. Managing Conflicts of Interest- Conflicts of interest can arise when subsidiaries or subcontractors have other business interests that might affect their impartiality. It's essential to have measures in place to identify and manage these conflicts to preserve the integrity of the assessment process.

3. Balancing Efficiency and Integrity- Balancing efficiency and integrity is a critical consideration when working with subsidiaries and subcontractors. While these arrangements can enhance efficiency, they must not compromise the integrity of conformity assessments. Notified bodies must carefully evaluate and manage these relationships to ensure that assessments remain rigorous and trustworthy.

Conclusion

Article 33 of the EU AI Act outlines critical provisions for the involvement of subsidiaries and subcontracting in the governance of high-risk AI systems. By allowing notified bodies to utilize these mechanisms, the Act aims to enhance the efficiency and effectiveness of AI risk management while ensuring that these powerful technologies are deployed safely and responsibly.