Versatile AI Risk Assessment

Who it is for Public sector

Implementing the EU AI Act in the public sector

You are assessing the use of AI in a public authority or institution. Alongside data protection and information security, you need to consider requirements for the public sector. Find guidance on procurement, impact assessments, registration and deadlines.

The starting point

A public authority is normally a deployer and therefore has the 24 deployer obligations. Three obligations apply additionally or in stricter form: registration in the EU database before putting into service under Art. 26(8), the fundamental rights impact assessment under Art. 27, which mainly affects public bodies, and, for post-remote biometric identification, authorisation by a judicial or administrative authority within 48 hours.

The heaviest point is the deadline. For existing systems in the public sector the transition period ends on 2 August 2030, regardless of whether the system was modified. Four years sounds long but in public administration rarely covers more than one procurement cycle.

For existing systems in the public sector the transition period ends on 2 August 2030, regardless of whether the system was modified.

Art. 111(2) second sentence

Assessments step by step (2)

Each step links to the relevant features and information.

  1. Register Authority and system in the EU database, before putting into service.
  2. Check fundamental rights Clarify whether Art. 27 applies, then assessment and notification if so.

Questions and answers (8)

Answers with sources and links for further review.

What applies to public authorities on top of the deployer obligations?

Three points. First, registration in the EU database before putting an Annex III system into service. Second, the fundamental rights impact assessment under Art. 27, which affects the group named in the provision and there mainly public bodies. Third, for post-remote biometric identification, authorisation by a judicial or administrative authority.

By when must our existing systems meet the requirements?

By 2 August 2030. Unlike in the private sector, where existing systems are only covered upon a substantial modification, a fixed deadline applies to systems intended to be used by public authorities. An implementation plan per existing system with milestones is the usual evidence.

Evidence
Implementation plan per existing system with milestones

How do we register a system in the EU database?

Before putting the system into service the authority registers itself and enters the system. The registration doubles as a pre-check: if the provider entry is missing, that is a solid signal that the procurement should not yet be concluded.

What applies to post-remote biometric identification?

Anyone using it in the course of an investigation applies in advance or without delay, at the latest within 48 hours, for authorisation by a judicial or administrative authority. What matters is a procedure that holds the 48 hours at night and at weekends too. An annual report to the market surveillance and data protection authorities is also required.

Must we inform staff and their representatives?

Yes, in advance, where a high-risk system is used at the workplace, under Art. 26(7). Affected persons must be informed under Art. 26(11), and at the point where the decision is made. A note in a general statement usually does not reach them.

May we use the free edition in a public authority?

As a rule, no. The Community Edition licence permits general public administration activity only where it itself constitutes permitted non-commercial education or academic research. For ongoing administrative work the professional edition is the right one. The three single modules are open for a first orientation.

How do we start with a single system?

With the quick check for a first classification, then the application itself for role, risk class, threats and mitigations. The report captures header data, every assessment step with result, reasoning and evidence, and the open points, and it is that report which serves as evidence in the file.

What does the application explicitly not do for a public authority?

It registers nothing in the EU database and files no application. It replaces neither legal advice nor an assessment of the individual case. It keeps no record of processing activities and replaces no case file. And it makes no decision on a procurement.

Limits of the application (4)

These tasks require additional tools or professional review.

Tasks outside the application

  • It registers nothing in the EU database and files no application.
  • It replaces neither legal advice nor an assessment of the individual case.
  • It keeps no record of processing activities and replaces no case file.
  • The free edition does not cover ongoing administrative work under its licence.

Suitable editions

€2,490 once

Professional Offline

For regular work across several systems: reports as PDF and workbook, machine-readable exports, extended evidence packages.

Open
free of charge

Live demo to get to know it

The complete Community Edition with example data, directly in the browser and without sign-up. For trying out the method; your own work inside a company or a public body is not covered by the Community licence.

Open

Compare the features, licence terms and prices of the Community, Professional and Enterprise editions. Compare editions

Other audiences (7)

Guidance for other responsibilities within your organisation or your clients’ organisations.

← Back to the overview