HomePostsDigital StateAlgorithmic Auditing and the Role of Notified Bodies under the AI Act

Related Posts

Algorithmic Auditing and the Role of Notified Bodies under the AI Act

A central feature of the AI Act framework is the delegation of algorithmic auditing of certain high-risk AI systems to “notified bodies”: third-party conformity-assessment institutions tasked with evaluating whether high-risk AI systems comply with regulatory requirements. While this institutional design appears technical, its implications are deeply constitutional. By delegating oversight to technical actors, the AI Act reshapes how state authority is exercised and experienced. The key question, therefore, is not merely whether algorithmic systems can be audited effectively, but how this model of delegated oversight affects the human experience of third-party conformity-assessment institutions tasked with evaluating whether high-risk AI systems comply with regulatory requirements. While this institutional design appears technical, its implications are deeply constitutional. By delegating oversight to technical actors, the AI Act reshapes how state authority is exercised and experienced. The key question, therefore, is not merely whether algorithmic systems can be audited effectively, but how this model of delegated oversight affects the human experience of governance.

One risk of delegated algorithmic auditing is the emergence of technical formalism, a situation in which complex social and legal issues are reduced to narrow technical tests. This could occur if bias auditing focuses exclusively on statistical parity metrics or other quantitative indicators without examining the broader institutional environment in which an algorithm operates.

Consider, for example, an automated system used to allocate social benefits. A technical audit might evaluate whether the algorithm produces statistically similar outcomes across demographic groups. While important, such analysis may overlook structural biases embedded in training data or administrative procedures. Treating fairness as a purely mathematical property may obscure how automated decisions interact with social inequality. In such cases, certification may provide a veneer of legitimacy without meaningfully protecting affected individuals.

This dynamic could transform conformity assessment into a form of regulatory theatre: a process that signals oversight while leaving deeper issues unaddressed. This blog post argues that notified bodies should be understood as regulatory intermediaries that translate legal norms into technical auditing practices. Their institutional capacity, independence, and epistemic orientation will significantly shape whether algorithmic governance strengthens or undermines fundamental values such as human dignity, accountability, and the rule of law. Without careful institutional design, algorithmic auditing risks becoming a compliance ritual. One that legitimizes automated decision-making without adequately protecting the individuals subject to it. The following sections examine the rise of delegated algorithmic oversight, analyze the intermediary role of notified bodies, and assess how this institutional arrangement shapes both the practice of auditing and the human experience of automated governance.

The Rise of Delegated Algorithmic Oversight

The AI Act adopts a risk-based regulatory model. AI systems classified as “high risk”, including many systems used in the public sector, must undergo conformity assessments before they can be placed on the European market or used by public authorities. These assessments verify compliance with requirements relating to data governance, transparency, risk management, and the prevention of discriminatory outcomes.

Rather than conducting these assessments directly, regulators frequently rely on notified bodies: independent organizations designated by national authorities to perform conformity assessments. This institutional model is not unique to AI governance. It originates in European product regulation, where third-party certification bodies evaluate compliance with safety standards for products such as medical devices or machinery.

However, the transplantation of this model into AI governance introduces new complexities. In traditional product safety regimes, conformity assessments often focus on measurable technical properties: durability, chemical composition, or mechanical safety. By contrast, auditing AI systems involves evaluating abstract and context-dependent legal norms such as fairness, non-discrimination, and transparency. These norms cannot be reduced easily to technical metrics.

Notified bodies must therefore translate legal and ethical principles into operational auditing methodologies, an inherently interpretive process. Decisions about datasets, bias metrics, and acceptable risk levels involve normative judgments with significant social consequences.

Notified Bodies as Regulatory Intermediaries

To understand the implications of this arrangement, it is useful to conceptualize notified bodies as regulatory intermediaries. Rather than acting merely as neutral technical inspectors, these institutions occupy a strategic position between regulators, technology developers, and the public. This framework was offered by Kenneth W. Abbott, David Levi-Faur, and Duncan Snidal in a highly cited article and soon became one of the main theories of regulation.

In this intermediary role, notified bodies perform several functions simultaneously. First, they interpret regulatory requirements and translate them into audit procedures. Second, they evaluate whether AI systems satisfy these requirements. Third, their certification decisions effectively determine whether a system is deemed legitimate for deployment.

This intermediary position grants notified bodies considerable influence over how regulatory norms are operationalized in practice. If auditing methodologies emphasize narrow statistical metrics, the evaluation of algorithmic bias may become a purely technical exercise. If, by contrast, auditors incorporate contextual analysis, considering how automated decisions affect vulnerable populations, the auditing process may better capture the real-world implications of AI deployment.

Consequently, the effectiveness of the AI Act’s governance model depends on the epistemic capacity and institutional independence of these intermediaries. Their expertise, incentives, and organizational cultures will shape how regulatory principles are interpreted and enforced.

Automation and the Experience of State Authority

Beyond technical considerations, the delegation of algorithmic auditing raises broader questions about the nature of state authority in the digital age. Traditionally, public administration involves identifiable human officials who exercise discretion and bear responsibility for decisions.

Algorithmic governance disrupts this relationship. When decisions are generated or heavily mediated by automated systems, the chain of responsibility becomes less visible. The involvement of notified bodies further complicates this picture. By inserting a private intermediary into the governance structure, the AI Act creates an additional layer of technical delegation between affected individuals and the actors responsible for evaluating the legality and safety of AI systems. Responsibility becomes fragmented among developers, deployers, notified bodies, and regulators, making it increasingly difficult for individuals to identify who should be held accountable for harmful or discriminatory outcomes.

Individuals affected by automated decisions may find it difficult to understand who evaluated the system, according to what criteria, and how undesired outcomes can be identified and challenged. In such a system, individuals risk being treated not as legal subjects but as data profiles: abstract representations within statistical models. The human dimension of administrative decision-making becomes attenuated.

 How to ensure the ‘risks’ don’t materialize?

The consequences of this governance model are not predetermined. The design and operation of notified bodies can vary significantly across jurisdictions and sectors. Several factors will likely influence these outcomes.

First, expertise. Effective algorithmic auditing requires interdisciplinary knowledge combining computer science, law, and social science, because AI systems raise not only technical questions of accuracy and model performance, but also legal questions of compliance and broader societal questions concerning discrimination, vulnerability, and institutional impact.

Second, independence. Notified bodies must maintain sufficient autonomy from both regulators and technology developers. Because notified bodies operate within a market-based certification system in which AI providers select and pay the entities responsible for assessing their systems, certification bodies may become economically dependent on the firms they audit. Competitive pressures may incentivize notified bodies to adopt more permissive interpretations, minimize compliance burdens, or avoid excessively stringent assessments in order to attract and retain clients. Similar concerns have emerged in other sectors relying on intermediary-based conformity assessment, including financial auditing and medical device regulation. If certification bodies depend heavily on the companies they audit for revenue, conflicts of interest may arise.

Third, transparency. Public visibility into auditing methodologies and certification decisions is crucial for maintaining trust. Conformity assessments are less likely to appear opaque and technocratic where notified bodies disclose the criteria, assumptions, testing methods, risk thresholds, and limitations underlying certification decisions, and where affected individuals, regulators, and civil society can understand how fundamental-rights risks were evaluated. Without such visibility, certification risks becoming a closed expert process, in which the public sees only the fact of approval but not the reasoning that justified it.

Fourth, engagement with affected communities. Auditing practices that incorporate feedback from individuals and civil society organizations can help ensure that evaluations reflect real-world impacts rather than purely technical benchmarks concerning accuracy, fairness, robustness, or acceptable risk are themselves shaped through processes of design, standard-setting, and regulatory interpretation, often dominated by technical experts, regulators, and private auditors. As a result, evaluations based exclusively on such metrics may fail to capture context-specific harms, lived experiences, or forms of discrimination affecting vulnerable communities. Mechanisms such as public consultations, stakeholder hearings, participatory impact assessments, complaint procedures, and post-deployment monitoring systems may therefore help notified bodies and regulators identify risks that are not visible through technical testing alone.

From Technical Auditors to Human-Facing Institutions

If the goal of the AI Act is to safeguard fundamental rights while enabling technological innovation, the role of notified bodies must evolve beyond narrow technical inspection. These institutions should be understood as human-facing governance actors. Such a reconceptualization requires institutional arrangements that operationalize the four conditions identified above: interdisciplinary expertise, structural independence, procedural transparency, and meaningful engagement with affected communities. Such a reconceptualization would involve several practical implications.

First, auditing methodologies should explicitly address the lived consequences of automated decision-making. Rather than focusing solely on statistical indicators, auditors should evaluate how systems affect individuals’ ability to understand, challenge, and influence, This can be done through fundamental-rights impact assessments, user-facing transparency reviews, analysis of complaint and appeal mechanisms, consultation with affected communities, and post-deployment monitoring of real-world harms.

Second, notified bodies should adopt transparency practices that allow external scrutiny of their methods and conclusions. Publishing audit summaries or methodological frameworks could help bridge the gap between technical assessment and public accountability. Such a bridge, however, depends on several conditions: disclosures must be sufficiently detailed and comprehensible to non-expert audiences; independent researchers, regulators, journalists, and civil society organizations must be able to evaluate and contest certification practices; and affected individuals must have access to mechanisms through which concerns regarding harmful outcomes can be raised and reviewed. Without these conditions, transparency risks becoming merely formal disclosure rather than meaningful accountability.

Third, institutional design should encourage interdisciplinary collaboration. Teams conducting algorithmic audits should include legal scholars, social scientists, and ethicists alongside technical experts.

Finally, regulators should consider mechanisms that connect conformity assessments more directly with individuals affected by automated systems. This could include stakeholder hearings before certification in high-risk contexts, consultation with civil society organizations representing affected groups, participatory impact assessments, user panels, accessible complaint channels, and post-deployment review processes in which reported harms are fed back into certification and supervisory decisions. Engagement should therefore be understood not as symbolic participation, but as a mechanism for identifying risks, contesting assumptions embedded in technical assessments, and ensuring that algorithmic governance remains responsive to human concerns.

Preserving Humanity in the Automated State

Discussions of AI governance often focus on technological capabilities such as accuracy and efficiency. Yet the deeper challenge is institutional and normative. As states increasingly rely on automated systems, they must ensure that technological efficiency does not come at the expense of human dignity and democratic accountability.

Delegating algorithmic auditing to notified bodies represents a pragmatic regulatory solution. It allows regulators to draw on specialized expertise while managing the complexity of modern technological systems. However, this model also redistributes authority within the governance ecosystem. Technical institutions become key actors in determining whether automated systems are considered legitimate.

Recognizing this reality is the first step toward ensuring that algorithmic governance remains aligned with fundamental legal principles. If notified bodies are treated merely as technical inspectors, the human consequences of automation may remain obscured. If, by contrast, they are designed and governed as institutions responsible for safeguarding public values, they can play a crucial role in preserving the human dimension of administrative power.

Ultimately, the question raised by the AI Act is not only how to regulate AI, but how to maintain the human character of governance in an increasingly automated state. Ensuring that individuals remain visible within systems of algorithmic decision-making will be essential to preserving both human dignity and the rule of law in the digital age.

Michael Sierra
Lawyer and a PhD student in Law at the Hebrew University of Jerusalem
Adv. Michael Sierra is a lawyer and a PhD student in Law at the Hebrew University of Jerusalem, where his research focuses on regulatory intermediaries, conformity assessment, and regulatory sandboxes as tools for AI governance. He holds an LL.B., LL.M., and B.A. in International Relations, all magna cum laude, from the Hebrew University. He serves as a research associate at the Federmann Cyber Security Research Center, the James J. Shasha Center for Strategic Studies, and the Cheshin Center for Advanced Legal Studies.
[citationic]

Featured Artist