The EU AI Act’s high-risk conformity assessment system faces a problem that is both structural and surprisingly underreported: there are not nearly enough people qualified to do the work.

This isn’t a temporary capacity issue that will resolve as the market develops. It’s a problem of expertise pipeline, institutional accreditation timelines, and the fundamental difficulty of building a certified auditor corps for a technical domain that barely existed as a profession five years ago. Solving it will take a decade. The regulation assumed it could start enforcing in 2026. The enforcement machinery requires auditors who don’t exist in sufficient numbers.

Start with the basics. A conformity assessment for a high-risk AI system under the EU AI Act requires a Notified Body — an organization designated by an EU member state as competent to conduct the assessment. As of August 2026, there are 28 EU-designated Notified Bodies with AI competence under the Act. For context: the EU has approximately 5,600 Notified Bodies across all regulatory domains (construction products, medical devices, pressure equipment, etc.). The AI Act represents a tiny fraction of the overall Notified Body ecosystem.

The 28 AI-capable Notified Bodies are concentrated in a small number of member states: Germany (TÜV SÜD, TÜV Nord, TÜV Rheinland, DEKRA), France (Bureau Veritas, LCIE), Netherlands (Kiwa, DEKRA Netherlands), and UK (BSI, Lloyds Register — operating under a specific post-Brexit agreement). Several member states have no Notified Body with AI competence. A company headquartered in Bulgaria, Croatia, or Slovenia seeking AI Act conformity assessment must engage a foreign Notified Body, adding logistical complexity to an already complicated process.

What an AI Auditor Actually Needs to Know

The scarcity of Notified Bodies reflects the scarcity of a specific professional profile that doesn’t have a natural training pipeline. An AI Act conformity assessor needs:

Technical knowledge of AI/ML systems sufficient to evaluate whether the developer’s claims about system behavior are credible. This requires either a computer science background with machine learning specialization or years of practical experience with AI system evaluation.

Knowledge of the EU AI Act’s technical requirements — risk management frameworks, data governance standards, transparency documentation, post-market monitoring systems. These are specific to the regulation and require dedicated training.

Domain expertise in the application area being assessed. A high-risk employment AI assessment requires understanding of labor law, discriminatory impact analysis, and HR technology workflows. A high-risk medical AI assessment requires clinical knowledge. A high-risk infrastructure AI assessment requires relevant engineering expertise.

Quality management systems knowledge sufficient to evaluate the QMS that the Act requires developers to maintain.

Finding a single person with all four components at an auditable professional level is genuinely difficult. TÜV SÜD’s approach — which is more sophisticated than most — is to assemble assessment teams combining an AI/ML technical lead, a regulatory specialist, and a domain expert, each providing one component of the required expertise. Even this team-based approach requires assembling rare talent, and the assessment teams can only work on so many certifications simultaneously.

TÜV SÜD’s AI Act certification team as of mid-2026 numbers approximately 55 people, conducting an estimated 8-12 full conformity assessments per month. Bureau Veritas France has a smaller team handling roughly 4-6 per month. The other 26 Notified Bodies are handling fewer.

The total EU-wide capacity for high-risk AI conformity assessment is approximately 20 to 30 completed assessments per month. This number needs to be compared to the estimated number of high-risk AI systems in use across the EU. The EU AI Office’s June 2026 assessment put this number at “tens of thousands,” though they acknowledged the estimate was highly uncertain. Even using a conservative estimate of 20,000 high-risk AI systems, clearing the existing backlog at current capacity would take approximately 55 years.

The Accreditation Bottleneck

More Notified Bodies will be designated over time. The accreditation process for new Notified Bodies — which requires national accreditation bodies (TÜV, COFRAC in France, UKAS in the UK) to assess the applicant organization’s competence — takes 18 to 24 months in normal circumstances. As of August 2026, there are 43 applications for AI Act Notified Body designation pending across EU member state accreditation processes.

If all 43 are approved — which is unlikely, since some will fail technical competence assessments — the Notified Body count would grow from 28 to 71 by late 2027 or early 2028. At the same team sizes as existing Notified Bodies, this roughly triples capacity, from 20-30 assessments per month to 60-90 per month. At this level, the assessment backlog extends from 55 years to roughly 20 years.

These numbers are deliberately provocative in their precision — real uncertainty exists in both the demand and supply estimates — but the order-of-magnitude problem is real. The EU AI Act’s conformity assessment system cannot operate at the scale the regulation implicitly assumes at anything like current auditor capacity.

The EU AI Office is aware of this. Their preferred solution is graduated enforcement — prioritizing enforcement resources on the highest-risk systems and sectors, allowing less critical high-risk AI to operate under lighter assessment requirements while the Notified Body ecosystem develops. This is a reasonable accommodation to reality, but it amounts to a quiet admission that the regulation’s conformity assessment system is not designed to actually apply to all systems within its scope.

The regulation also provides a “self-assessment” track for some categories of high-risk AI — specifically high-risk AI systems not listed in Annex III whose providers claim conformity with harmonized standards. Self-assessment allows providers to certify conformity without Notified Body involvement, subject to internal documentation requirements. This track will see significant use as companies seek paths to compliance that don’t require waiting for an overwhelmed Notified Body.

Self-assessment is not weaker in principle than third-party assessment — ISO 9001 quality management, for example, often involves self-declaration against published standards. But it creates an honor-system compliance mechanism for AI systems that were classified as high-risk precisely because they were considered too consequential for honor-system governance.

Building the Profession That Doesn’t Exist

The longer-term response to auditor scarcity requires building the professional pipeline that currently doesn’t exist. Several European universities have launched postgraduate programs specifically oriented toward AI ethics and AI governance. ENAC (the European Network of Air Traffic Management) has developed an AI assessment curriculum for aviation AI auditors. The European Committee for Standardization (CEN) and CENELEC are developing European standards for AI system auditing that would create a recognized qualification framework.

These are important investments. A graduate entering a 2-year postgraduate AI governance program in October 2026 will be qualified for Notified Body work in 2028 at the earliest, and meaningfully experienced in 2031. The pipeline is real but operates on a multi-year lag behind the need.

In the interim, the most likely operational reality is: systematic enforcement against the highest-risk systems (the ones most likely to cause catastrophic harm if unassessed), tolerance of unassessed operation for lower-priority high-risk systems, and increasing reliance on self-assessment and AI Office guidance rather than third-party conformity assessment as the primary compliance mechanism.

This is not the system the Act describes. It is probably the system that will actually operate. The gap between the two is not unique to the EU AI Act — most major regulatory frameworks operate at partial capacity relative to their stated scope, and the GDPR was substantially under-enforced in its first years relative to what the regulation required. But the gap is larger here, because the AI Act’s conformity assessment system requires specialized expertise that didn’t exist as a profession before the regulation was written.

The regulation is a contract between the EU and its AI industry that promises: meet these requirements and you may operate. The Notified Body shortage means the EU cannot currently fulfill its side of that contract at scale. Companies are being asked to queue for a certification that may not be available on any reasonable timeline. Some will queue. Some will make their own compliance judgments and hope enforcement is slow. Some will leave the EU market. The ratio of these three responses will tell us more about the EU AI Act’s real-world effectiveness than any amount of enforcement guidance.

The International Competitiveness Angle

There’s a geopolitical dimension to the auditor shortage that rarely surfaces in the domestic EU compliance debate: the shortage is not symmetrically distributed globally.

US companies deploying AI in the EU face the same Notified Body bottleneck as European companies. But US companies operating primarily in their domestic market face no equivalent requirement — the FTC’s AI guidance and the emerging state-level AI regulations don’t include mandatory third-party conformity assessment for most AI applications. This means the scarce auditor capacity is a drag specifically on EU-market AI, not on global AI development.

Chinese AI companies domestically deploy AI under the China Cybersecurity Administration’s AI regulation framework, which operates on a registration and filing model rather than a Notified Body conformity assessment model. Deployment happens after filing, not after certification. The Chinese system is faster and less resource-intensive for developers, whatever its other limitations.

The EU AI Act’s conformity assessment model implicitly assumes that third-party certification produces better AI safety outcomes than the alternatives. This assumption is plausible but not empirically established. There are no studies comparing patient outcomes in healthcare AI systems that underwent Notified Body conformity assessment against those that underwent equivalent internal review processes. There are no studies showing that the specific documentation required for EU AI Act conformity assessment produces AI systems with fewer harmful failures than systems produced without it.

The assumption may be correct. But its correctness is assumed rather than demonstrated, and the cost of acting on the assumption — an auditor bottleneck that delays beneficial AI, concentrates market access in large incumbents, and potentially disadvantages European AI globally — is real and measurable. The case for mandatory third-party conformity assessment at scale would be considerably stronger if there were evidence that it produces the safety outcomes it claims to produce. That evidence doesn’t yet exist.

Get the best of Think Different in your inbox

One email a month: new articles, reviews and the upcoming live webinar + free recording. No spam, unsubscribe anytime.