The EU AI Act does not have a single, standalone 'AI Act notified body list' that you can download as one document. Instead, conformity assessment bodies are designated under the EU's NANDO (New Approach Notified and Designated Organisations) database, which is maintained by the European Commission. When a notified body is accredited to carry out third-party conformity assessments for high-risk AI systems under Article 43 of the AI Act (Regulation (EU) 2024/1689), it appears in NANDO with the relevant legislation code attached — in this case, Regulation 2024/1689. So the practical answer is: search NANDO at the Commission's website, filter by EU legislation '2024/1689', and you will see every body currently authorised to issue AI Act certificates.

Why there is no separate AI Act register

Also worth reading: How do I find a high-signal AI founder network in NYC for private deal-flow? · Where can I find a verified NYC angel investor list for 2026 to secure early-stage funding? · How should founders and operators approach AI investment risk mitigation in 2027?

The AI Act deliberately reuses the machinery of existing EU product-safety law rather than inventing a new certification ecosystem from scratch. Under Articles 28 through 39 of the regulation, a notified body is a public or private organisation that a Member State has formally designated to assess the conformity of high-risk AI systems before they are placed on the market. The designation process runs through each national accreditation authority — for example, UKAS in the United Kingdom historically, COFRAC in France, DAkkS in Germany, and ENAC in Italy — which assess candidates against the requirements of Article 31: independence, technical competence, an adequate quality management system, sufficient staff with AI-specific expertise, and freedom from conflicts of interest.

Once designated, the Member State notifies the Commission, which publishes the body in NANDO. This is why the phrase 'EU AI Act notified body list' is slightly misleading: what exists is a live database, not a static PDF, and entries change as designations are granted, extended, suspended, or withdrawn. The Commission also maintains a public database of certificates issued and a separate registration requirement for high-risk AI systems themselves under Article 49, which should not be confused with the notified body list.

The timeline that shaped the current list

The AI Act entered into force on 1 August 2024, and its obligations phase in over roughly three years. Prohibited practices applied from 2 February 2025. General-purpose AI model obligations began applying on 2 August 2025. The bulk of the high-risk system obligations — Annex III use cases such as biometric identification, critical infrastructure management, education and employment decision-making, and essential services eligibility — apply from 2 August 2026, with embedded-product high-risk systems under Annex I following on 2 August 2027.

This staggered rollout matters for the notified body list because demand for conformity assessments is concentrated in a narrow window. Most providers of Annex III high-risk systems need a certificate or a technical-file assessment in place by mid-2026, yet notified body designation is slow. Candidate organisations must build AI expertise that barely existed as an accreditation discipline five years ago, and national authorities have been cautious about granting designations they may later have to suspend. As of late 2025 and into 2026, the number of bodies designated specifically for the AI Act remained small relative to the thousands of companies expected to need assessments — a genuine bottleneck that procurement teams should plan around now rather than in the summer of 2026.

How to actually find and verify a notified body

Start at the European Commission's NANDO information system. Filter by country if you want a domestic partner, or leave it open to see all EU-designated bodies plus those in EEA countries and certain partner countries such as Turkey and Switzerland under mutual recognition arrangements. Each entry shows the four-digit identification number, the legislation covered, and the scope — and the scope is where most mistakes happen. A body notified for the Medical Device Regulation (MDR) or the In Vitro Diagnostic Regulation (IVDR) is not automatically competent for AI Act assessments unless Regulation 2024/1689 appears explicitly in its NANDO listing.

Second, cross-check against harmonised standards work. CEN-CENELEC JTC 21 has been drafting the European harmonised standards for AI risk management, data governance, transparency, and accuracy. A notified body whose staff contributed to or actively monitors these standards will be better positioned to assess your technical file quickly. Third, ask any candidate body directly for evidence of designation, scope limits, sector experience, and current lead times. Reputable bodies publish accreditation scopes openly; reluctance to do so is a warning sign.

Conformity assessment routes: who needs a notified body at all

Not every high-risk AI provider faces a third-party audit. The AI Act creates two distinct pathways depending on whether the system falls under Annex III or is a safety component of a regulated product under Annex I.

FeatureAnnex III high-risk systemsAnnex I safety-component systems
ExamplesBiometrics, employment screening, credit scoring, exam proctoringAI in machinery, medical devices, vehicles, toys
Default routeInternal control (Annex VI)Third-party conformity assessment via notified body
When notified body requiredOnly if no harmonised standard applies AND provider chooses not to use internal control, per Art. 43(1)Always, unless another EU law already mandates third-party assessment
Typical cost driverDocumentation, logging, human oversight designFull QMS audit plus product testing
Deadline2 August 20262 August 2027
RegistrationEU database under Art. 49Same, plus existing sector registers
For Annex III systems, the default is self-assessment using internal controls — provided harmonised standards exist and the provider follows them. Because many JTC 21 standards were still being finalised into 2026, some providers voluntarily opt for notified body involvement anyway, both to de-risk enforcement exposure and to signal credibility to enterprise buyers. For Annex I products, third-party assessment is mandatory unless the product already goes through a notified body under another regime, in which case that single assessment must cover the AI requirements too.

Costs, timelines, and commercial reality

Published fee schedules for notified body conformity assessments vary widely by sector and scope, but realistic planning figures matter. For a medium-complexity Annex III AI system, expect a full conformity assessment engagement — documentation review, quality management system audit, sampling-based technical evaluation, and surveillance — to run from roughly €20,000 to well over €100,000 depending on the body, the number of AI models involved, and re-audit cycles. Annual surveillance fees commonly add €10,000–€30,000. These figures are indicative; bodies quote individually and medical-device-adjacent assessments tend toward the higher end because they stack MDR or IVDR requirements on top.

Lead times are the bigger problem than price. Industry reporting through 2025 consistently flagged multi-month backlogs at newly designated bodies, with some quoting six to twelve months from application to certificate for complex systems. If your system must comply by 2 August 2026, engaging a body in early-to-mid 2025 was the safe play; engaging one in spring 2026 leaves almost no margin for remediation cycles after a non-conformity finding. Budget for at least one corrective-action round in your project plan.

Common mistakes when working with the notified body list

The most frequent error is assuming a notified body for one regime covers another. A laboratory celebrated for CE testing under the Cyber Resilience Act, or a veteran MDR body, cannot touch your AI Act file unless 2024/1689 appears in its NANDO scope. Verify the exact legislation code every time, because scopes get amended and occasionally withdrawn.

Second, companies confuse the notified body list with the Article 49 EU database for registered high-risk AI systems. Providers register their own systems there; notified bodies appear only in NANDO. Third, some teams treat designation as a quality endorsement. It is not — it means the body met minimum competence criteria at designation time. Due diligence on sector experience, auditor seniority, and turnaround statistics remains your job. Fourth, importers and deployers sometimes assume they need a notified body relationship at all. Deployers generally do not; obligations fall mainly on providers, with deployers responsible for use-phase duties like human oversight and logging. Finally, beware consultancies advertising 'AI Act certification' — only a NANDO-listed body can issue a certificate, and no private consultancy can substitute for one.

What happens if the list stays short

A structural tension sits at the heart of the 2026 deadline: hundreds of thousands of companies estimate exposure to AI Act obligations, while the pool of designated bodies grows slowly. The Commission has acknowledged this through guidance drafts on high-risk classification and targeted consultations, and Member States have been urged to accelerate designations. If capacity remains tight, expect three consequences: premium pricing at established bodies, longer queue times pushing some providers toward voluntary early compliance audits to secure slots, and heavier reliance on harmonised standards so that more Annex III providers can legitimately use the internal-control route and skip third-party assessment entirely.

For founders and operators building AI products, the practical takeaway is unglamorous: classify your system honestly first. Many feared-obligation cases turn out not to be high-risk at all once measured against the Commission's classification guidelines — a determination worth documenting carefully, since it can eliminate the notified body question altogether. Where the obligation is real, start body selection eighteen months before your compliance date, negotiate surveillance terms up front, and keep your technical documentation audit-ready continuously rather than assembling it reactively. In a deal-flow environment where enterprise buyers increasingly ask for AI Act posture during diligence, having a named notified body engagement — or a defensible internal-control file — is becoming a commercial asset independent of the legal mandate.

Enforcement and what the list means legally

Market surveillance authorities in each Member State enforce the AI Act, with penalties reaching €35 million or 7% of global annual turnover for prohibited practices, and €15 million or 3% for most other violations including improper conformity assessment. Using a properly designated notified body does not immunise you from enforcement — the provider retains full responsibility for conformity — but a valid certificate creates a presumption of conformity that materially shifts the burden in any investigation. Conversely, discovering post-hoc that your assessor's designation was defective can invalidate the certificate. That is why checking NANDO on the day you sign, and periodically thereafter, is cheap insurance against a seven-figure problem.