EU AI Act
What does the EU AI Act require of public authorities using AI?

Public authorities carry more of the EU AI Act than private deployers. A public body using a high-risk system must register that use in the EU database before it starts, must carry out a fundamental rights impact assessment, and has a hard deadline for systems it already uses. Several of the high-risk areas in Annex III are public functions: benefits, law enforcement, migration and justice.
Quotations are from Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, read in the consolidated text of 27 July 2026 on 2 October 2026. This is not legal advice.
Which public uses of AI are high-risk?
Annex III names several public functions. Point 5(a) covers "AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services". Points 6, 7 and 8 list uses in law enforcement, migration, asylum and border control, and the administration of justice and democratic processes. Points 3 and 4, education and employment, reach public schools and public employers too. Our Annex III guide lists every area.
What must a public body do before using a high-risk system?
Register. Article 49(3) says that before putting into service or using a high-risk system listed in Annex III, other than critical infrastructure, "deployers that are public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf shall register themselves, select the system and register its use in the EU database". Article 26(8) adds that if the system has not been registered by its provider, the public deployer "shall not use that system and shall inform the provider or the distributor". For law enforcement, migration, asylum and border control, registration goes to a secure, non-public section of the database under Article 49(4).
Is the impact assessment mandatory?
Yes. Article 27(1) requires deployers "that are bodies governed by public law, or are private entities providing public services" to carry out a fundamental rights impact assessment before deploying an Annex III high-risk system, other than critical infrastructure. It covers the processes, the period and frequency of use, the people and groups affected, the risks of harm, human oversight, and what will happen if the risks materialize, including governance and complaint mechanisms. The results are notified to the market surveillance authority. Since July 2026, it can cross-refer to the DPIA. Our guide to AI impact assessments covers it.
AI Act public sector checklist
AI system,Public function it supports,Annex III point (5(a) benefits; 6 law enforcement; 7 migration; 8 justice and elections; other),Prohibited use? (Article 5: social scoring; emotion inference at work or in education; others),Registered our use in the EU database before use (Art. 49(3) and 26(8)),Provider registered the system (Art. 49(1)),FRIA done before deployment (Art. 27(1)),FRIA results notified to the market surveillance authority (Art. 27(3)),Human overseers named and trained (Art. 26(2)),People told they are subject to it (Art. 26(11)),Staff AI literacy measures (Art. 4),Legacy system: compliance plan for 2 Aug 2030 (Art. 111(2)),Owner,Review date ,,,,,,,,,,,,, ,,,,,,,,,,,,, "EU AI Act, as amended by Regulation (EU) 2026/1744: Annex III duties apply from 2 December 2027. Template from credentialpress.com/guides/eu-ai-act-public-sector. Not legal advice.",,,,,,,,,,,,,
What about systems already in use?
Article 111(2), as amended in July 2026, applies the Act to high-risk systems placed on the market or put into service before the Chapter III date only if, from that date, "those systems are subject to significant changes in their designs". But it adds: "In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030." So legacy public systems cannot wait indefinitely.
What applies already?
Two things, since 2 February 2025. Article 5 bans several practices outright, including social scoring that leads to detrimental or unfavorable treatment in unrelated contexts, and most real-time remote biometric identification in public spaces for law enforcement. And Article 4 requires deployers to take measures to support the AI literacy of their staff. Our guides to the Article 5 bans and to Article 4 AI literacy cover both.
What else does a public deployer owe?
Everything any deployer of a high-risk system owes under Article 26 from 2 December 2027: use it per the instructions, trained human oversight, logs for at least six months, monitoring, informing workers before workplace use, and telling people when the system makes or assists decisions about them. Our guide to deployer obligations has the full list, and the DPO guide covers the data protection side most public bodies already run.
What should a public body do this year?
Inventory the AI systems in use and planned, and mark which fall under Annex III. For each, check that the provider will register it, plan your own registration and the impact assessment, and set a 2 August 2030 date for any legacy high-risk system. Credential Press is independent of the EU institutions.
Frequently asked questions
Do public authorities have extra duties under the EU AI Act?
Yes. A public authority deploying a high-risk Annex III system, other than critical infrastructure, must register itself, select the system and register its use in the EU database before use (Article 49(3)), must not use a system that is not registered (Article 26(8)), and must carry out a fundamental rights impact assessment (Article 27(1)).
Which public uses of AI are high-risk?
Among others: AI used by or for public authorities to evaluate eligibility for essential public assistance benefits and services, including healthcare, or to grant, reduce, revoke or reclaim them (Annex III, point 5(a)); and listed uses in law enforcement, migration, asylum and border control, and the administration of justice (points 6 to 8).
When do the public-sector duties apply?
From 2 December 2027 for Annex III systems, after Regulation (EU) 2026/1744 moved the date in July 2026. AI literacy and the Article 5 bans have applied since 2 February 2025.
What about AI systems a public body already uses?
Article 111(2) applies the Act to high-risk systems already on the market before the Chapter III date only if their design changes significantly from that date, but providers and deployers of high-risk systems intended for use by public authorities must comply by 2 August 2030 in any case.
Is social scoring banned for public bodies?
Article 5(1)(c) prohibits AI social scoring that leads to detrimental or unfavorable treatment in unrelated social contexts, or treatment that is unjustified or disproportionate to the behavior. The ban has applied to everyone, public and private, since 2 February 2025.
EU AI Act: test yourself in five minutes
Which books go deeper on the EU AI Act?

Building one that survives the EU AI Act. 22 chapters, 384 pages.

AI Governance Worked Scenarios
24 worked situations under the EU AI Act, decided against the Articles. 81 pages.
Sources
Every quotation above was read on 2 October 2026 through the EU Publications Office.
- Regulation (EU) 2024/1689 (AI Act), Articles 4, 5, 26, 27, 49, 111 and Annex III
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- Regulation (EU) 2024/1689, consolidated text dated 27 July 2026 (no legal effect)
Credential Press is independent of the European Commission. This is not legal advice.