Public sector AI governance: AI that decides about citizens.

For ministries, agencies, municipalities and operators of public services that buy, build or run AI: the duties you meet before buying, before first use and while it runs, in that order.

Who this is for.

Your systems often decide about people who cannot choose another provider, so the law asks more of you than of most deployers: an impact assessment before first use, registration, notice to the people affected and an explanation when they ask. Much of your AI arrives through procurement, so the contract is where evidence is won or lost. This route puts the duties in the order you meet them.

  • Public-sector CIOs and CDOs
  • Service and policy owners
  • Procurement officers
  • Public-sector DPOs
  • Audit and oversight bodies

On the learning path, start at Risk tiers and intake or FRIA and DPIA as code.

New to the field? Read AI governance explained: the definition, the frameworks and where engineering fits.

Three questions you bring.

Each one answered in brief here, and in full in the Body of Knowledge.

  1. Do we need a fundamental rights impact assessment?

    Yes, before first use of an Annex III high-risk system, if you are a body governed by public law or a private entity providing public services; systems for critical infrastructure (Annex III point 2) are excepted. Where your DPIA already meets part of it, the FRIA complements the DPIA (Art. 27(1), 27(4)) 1.

  2. What has to be public, and to whom?

    Public authorities that deploy high-risk systems register them in the EU database (Arts. 26(8), 49) 1. People subject to decisions an Annex III system makes or helps make are told so (Art. 26(11)) and can ask for an explanation of its role (Art. 86) 1. In the UK, the Algorithmic Transparency Recording Standard is mandatory for government departments and for arm's-length bodies that deliver public or frontline services 2.

  3. What about the systems we already run?

    Providers and deployers of high-risk systems intended for use by public authorities must comply by 2 Aug 2030 (Art. 111(2)) 1. The first step is an inventory that shows which of your systems are in scope.

Your route through the site.

In reading order: chapters at the section that matters, then the patterns, tools, templates, datasets and figures that turn them into work.

Start this week.

  1. Inventory every algorithmic system that decides or helps decide about people, including those bought as a service. AI system register entry
  2. Flag which of them fall in an Annex III area. High-risk through use (Annex III)
  3. Start a FRIA for the highest-stakes one, building on its DPIA. FRIA-as-Code
  4. Read two public-sector cases with the service owners. SyRI judgment
  5. Add the AI clause checklist to the next procurement. AI contract clause checklist

The obligations that matter most.

The duties that weigh most on a public deployer: the FRIA, deployer duties, registration, human oversight, the prohibitions (social scoring among them), transparency, literacy, and the UK safeguards for automated decisions.

Obligations for this route (Public sector), with status, date and evidence
Obligation Applies Evidence
EU AI Act Art. 27 Fundamental Rights Impact Assessment (FRIA) AIGE-OBL-EUAIA-ART27 Deferred · FRIA-as-code from a template; cross-reference to a GDPR Art. 35 DPIA
EU AI Act Art. 26 deployer obligations for high-risk systems AIGE-OBL-EUAIA-ART26 Deferred · Deployment registry; monitoring hooks; assigned oversight and logging retention
EU AI Act Art. 49/71 registration of high-risk systems in the EU database AIGE-OBL-EUAIA-ART49-71 Deferred · Agent/model registry with an API that feeds registration; owner and status per entry
EU AI Act Art. 14 human oversight AIGE-OBL-EUAIA-ART14 Deferred · Human-in-the-loop checkpoints; kill switch; override and escalation paths
EU AI Act Art. 5 prohibited practices (incl. new NCII and CSAM bans) AIGE-OBL-EUAIA-ART5 In force · Policy-as-code blocklist; input/output guardrails; refusal and abuse detection
EU AI Act Art. 50 transparency for certain AI systems AIGE-OBL-EUAIA-ART50 In force · Content labelling and machine-readable marking (e.g. C2PA-style); chatbot disclosure banner
EU AI Act Art. 4 AI literacy AIGE-OBL-EUAIA-ART4 In force · Literacy programme as code; role-based training records; onboarding gates
UK DUAA · UK GDPR Arts. 22A–22D permission-plus-safeguards model for significant, solely automated decisions (Data (Use and Access) Act 2025) AIGE-OBL-UK-ADM In force · ADM safeguards: meaningful-human-review path, contest and representation channel, decision notice

Every obligation in the register

Sources

  1. [1] Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 (Arts. 26(8), 26(11), 27(1), 27(4), 49, 86 and 111(2); Annex III). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)
  2. [2] Algorithmic Transparency Recording Standard hub (mandatory for government departments and for arm's-length bodies that deliver public or frontline services or deal directly with the public). Government Digital Service (GOV.UK). 2025-05-08. https://www.gov.uk/government/collections/algorithmic-transparency-recording-standard-hub (verified: primary)

Start at the top of the route.

Step 01 is High-risk through use (Annex III). Each step after it builds on the one before.