Adoption · Procurement · Public services · Rights
EU AI Act for public administration and AI procurement
A public authority is not merely a vendor's customer. When it uses an AI system, it will commonly be a deployer responsible for purpose, data, oversight, monitoring and effects on people. If it develops, rebrands or modifies the system, its role may change.
01First ask what the system will do
“Using AI” is too broad to determine risk. The intended purpose, administrative process, affected people and effect of the output matter. A document-sorting assistant is not equivalent to a system that influences benefits, employment, healthcare, education or policing.
- Which public decision or administrative activity does it support?
- Does the output produce or influence legal effects or access to an essential service?
- Which groups may experience false positives, exclusion or unequal treatment?
- Is there a genuinely accessible human channel with authority to correct the result?
02A public body can be deployer or provider
| Situation | Initial reading | What to verify |
|---|---|---|
| The authority buys and uses a vendor-branded product | Usually deployer | Concrete purpose, instructions, input data, assigned oversight, logs and monitoring. |
| The authority commissions a system and puts it into service under its own name | It may be provider | Who sets purpose and specifications, under whose name it is used and who carries conformity duties. |
| The authority changes the purpose or substantially modifies a high-risk system | It may take on the provider role | Scope of the change, new intended purpose, resulting classification and available documentation. |
The guide to providers and deployers explains the Article 25 role change in more detail.
The equivalent path for a private company is on AI Act for business.
03AI procurement checklist
An effective specification asks for more than accuracy. It must keep the system verifiable throughout the contract and enable the public body to exercise its own duties.
| Purpose and risk | What public problem does it solve? Is AI necessary? Is the use prohibited, high-risk, subject to transparency duties or outside those categories? |
|---|---|
| Data and performance | On which populations was it validated? Which errors are measured? Are local input data relevant and representative for the intended use? |
| Explanations and records | Will the authority receive instructions, limitations, documentation, logs and enough information for audits, complaints and contract control? |
| Human oversight | Who can disregard, correct or suspend the output? Do they have time, competence, authority and an interface that permits intervention? |
| Updates and incidents | How are changes in models, performance, data or purpose communicated? Who reports a serious risk and who may stop the system? |
| Exit and portability | How are data and logs exported? How are service continuity, reversibility and manageable vendor dependence secured? |
04If the system is high-risk
Article 26 places specific duties on deployers. For a public body these may include use according to instructions, oversight by competent and authorised people, control of input data within its responsibility, monitoring, retention of logs under its control and reporting risks or incidents.
- A public authority must not use a registrable high-risk system if it is not registered in the relevant EU database.
- When an Annex III system makes or assists decisions about people, information duties towards affected persons may apply.
- Public-law bodies and other deployers covered by Article 27 may need a fundamental rights impact assessment before first use.
05Human oversight needs real authority
Adding a human signature at the end of a process is not enough if the person sees only a score, cannot understand limitations, lacks necessary information or cannot disagree. In the game, many reports become contestable precisely when oversight exists on paper but not in practice.
06The AI Act and Italian AgID material
The EU Regulation is the primary legal source for this guide. Italy's digital agency AgID also publishes public-sector material and guidance. Determination no. 43 of 10 March 2026 documents the start of consultation and information procedures for AI development and procurement guidelines, with draft documents attached.
07The “Opaque Tender” case
In the game, a platform for awarding public contracts is purchased with inadequate documentation. The lesson is not that all AI procurement is prohibited. It is that a sensitive function cannot be inserted into a public process without understanding validation, control and how an output can be challenged.
08Official sources and limits
Read Regulation (EU) 2024/1689 on EUR-Lex, especially Articles 3, 25, 26 and 27, the Commission's Navigating the AI Act FAQ and the institutional AgID AI pages. Duties vary with the system, purpose and applicable sector law.