EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · PUBLIC ADMINISTRATION · GOVERNMENT AI · HIGH-RISK DEPLOYMENT

WHEN GOVERNMENT AI CAN AFFECT A PERSON,
THE PUBLIC DECISION HAS TO STAY REVIEWABLE.

Public authorities can benefit from AI, but government deployment carries a distinct evidentiary burden when the system falls into a high-risk route. Classification, fundamental-rights impact assessment, registration, human oversight, affected-person notice and revalidation all need to remain connected to the actual administrative decision process.

BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR

EUR-Lex · Regulation (EU) 2024/1689 · Articles 6, 26, 27, 49 and 71

The AI Act does not classify all public-sector AI as high-risk. But when a public authority deploys an Annex III high-risk system, additional deployer duties can apply, including fundamental-rights impact assessment, human oversight, affected-person information and EU-database registration, with specific exceptions and restricted-access routes for certain sectors.

OPEN OFFICIAL EU SOURCE ↗
WHAT BUSINESSES NEED TO ESTABLISH

Do not start with a generic checklist.

Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.

01

IS THE PUBLIC AUTHORITY USING AN ANNEX III HIGH-RISK SYSTEM?

Government use is not automatically high-risk. The system still has to fall within Article 6 or an Annex III use case, such as public benefits, employment, education, law enforcement, migration, justice or other listed domains.

02

DOES A FUNDAMENTAL-RIGHTS IMPACT ASSESSMENT APPLY?

Before first use of most Annex III high-risk systems, deployers that are bodies governed by public law must carry out a fundamental-rights impact assessment. The assessment must address the use context, affected groups, risks, human oversight and mitigation measures.

03

MUST THE DEPLOYMENT BE REGISTERED IN THE EU DATABASE?

Public authorities and entities acting on their behalf generally have registration duties for high-risk Annex III systems. The Regulation provides special treatment for certain critical-infrastructure, law-enforcement and migration records.

04

CAN THE AFFECTED PERSON UNDERSTAND THAT AI HELPED SHAPE THE DECISION?

Where a high-risk system is used to make or assist decisions about natural persons, deployers may have information duties toward affected people. Preserve the notice, decision path, human review, authority, logs and any challenge or redress route.

THE TA-14 OPERATING ROUTE

Turn the question into a governed record.

The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.

01

Classify the exact government use—not the agency label

Identify the system, intended purpose, provider and deployer roles, and whether it falls within Annex III or another Article 6 route. A public authority can use both high-risk and non-high-risk AI.

02

Complete the FRIA and align it with other impact assessments

For covered public-law deployers, document the processes, period and frequency of use, affected persons and groups, specific fundamental-rights risks, human-oversight measures and risk-mitigation steps. Where relevant, coordinate this with the data-protection impact assessment.

03

Bind registration, notice and human oversight to the deployment record

Preserve the EU-database registration state where required, the responsible public body, operator roles, instructions of use, human-oversight assignment, notices to affected persons, incident pathways and authority to intervene or stop use.

04

Revalidate after policy, model, legal or service changes

A new model, changed statutory basis, broader population, new administrative decision, altered data source, changed threshold or expanded intended purpose can make the previous classification, FRIA and evidence stale.

READY TO OPERATE · START PAID ACCESS NOW

Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.

1–3 AI systems

Evidence Passport

$19/MO

Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.

START EVIDENCE PASSPORT
Up to 10 AI systems

Compliance Workspace

$49/MO

Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.

START COMPLIANCE WORKSPACE
Up to 25 AI systems

Governance Pro

$99/MO

Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.

START GOVERNANCE PRO
Up to 50 AI systems

Institution

$499/MO

Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.

START INSTITUTION
Need an independent human readiness examination?A governed readiness review is separate from software access and starts at $750.
REQUEST READINESS REVIEW →
START WITH ONE SYSTEM

Not ready to subscribe? Classify first.

Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.

COMMON QUESTIONS

Questions businesses are asking now.

Is all government AI high-risk under the EU AI Act?

No. Public-sector use is not automatically high-risk. Classification still depends on Article 6 and the intended purpose of the system, including whether it falls within an Annex III use case.

Do public authorities have to carry out a fundamental-rights impact assessment?

For most Annex III high-risk systems, yes. Article 27 requires deployers that are bodies governed by public law to perform a fundamental-rights impact assessment before first use, subject to the Regulation’s stated exceptions.

Do public authorities have to register high-risk AI systems?

Public authorities and entities acting on their behalf generally have EU-database registration duties for Annex III high-risk systems. The Regulation provides special handling for certain critical-infrastructure, law-enforcement and migration deployments.

Do people have to be told when government AI helps make a decision about them?

The Commission’s current AI Act guidance states that if a high-risk AI system is designed to make or assist in making decisions about natural persons, the deployer must inform the affected person. Other transparency and sector-specific duties may also apply.

What evidence should a government deployer preserve?

Preserve system identity and version, intended purpose, classification basis, provider and deployer roles, statutory or administrative authority, FRIA, input-data governance, human-oversight assignment, notices, registration state, logs, incidents, complaints, changes and revalidation history.

Does TA-14 certify a government AI deployment as lawful or compliant?

No. TA-14 can preserve the classification basis, authority claim, FRIA evidence, notices, human oversight, registration state, gaps and revalidation history. It does not provide legal advice, certification, conformity assessment or regulatory approval.

EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION

Understand the requirement. Preserve the evidence. Revalidate when reality changes.

TA-14 Exchange Activity

Public network activity

Live cumulative activity recorded across the public Exchange surface.

Refreshing public totals

···

Visitors

Recorded public visitors

···

Page Views

Recorded Exchange views