NO AI ACT.

Adoption · Procurement · Public services · Rights

EU AI Act for public administration and AI procurement

A public authority is not merely a vendor's customer. When it uses an AI system, it will commonly be a deployer responsible for purpose, data, oversight, monitoring and effects on people. If it develops, rebrands or modifies the system, its role may change.

01First ask what the system will do

“Using AI” is too broad to determine risk. The intended purpose, administrative process, affected people and effect of the output matter. A document-sorting assistant is not equivalent to a system that influences benefits, employment, healthcare, education or policing.

  • Which public decision or administrative activity does it support?
  • Does the output produce or influence legal effects or access to an essential service?
  • Which groups may experience false positives, exclusion or unequal treatment?
  • Is there a genuinely accessible human channel with authority to correct the result?

02A public body can be deployer or provider

The role follows the activity performed on the system
SituationInitial readingWhat to verify
The authority buys and uses a vendor-branded productUsually deployerConcrete purpose, instructions, input data, assigned oversight, logs and monitoring.
The authority commissions a system and puts it into service under its own nameIt may be providerWho sets purpose and specifications, under whose name it is used and who carries conformity duties.
The authority changes the purpose or substantially modifies a high-risk systemIt may take on the provider roleScope of the change, new intended purpose, resulting classification and available documentation.

The guide to providers and deployers explains the Article 25 role change in more detail.

The equivalent path for a private company is on AI Act for business.

03AI procurement checklist

An effective specification asks for more than accuracy. It must keep the system verifiable throughout the contract and enable the public body to exercise its own duties.

Questions from planning through contract performance
Purpose and riskWhat public problem does it solve? Is AI necessary? Is the use prohibited, high-risk, subject to transparency duties or outside those categories?
Data and performanceOn which populations was it validated? Which errors are measured? Are local input data relevant and representative for the intended use?
Explanations and recordsWill the authority receive instructions, limitations, documentation, logs and enough information for audits, complaints and contract control?
Human oversightWho can disregard, correct or suspend the output? Do they have time, competence, authority and an interface that permits intervention?
Updates and incidentsHow are changes in models, performance, data or purpose communicated? Who reports a serious risk and who may stop the system?
Exit and portabilityHow are data and logs exported? How are service continuity, reversibility and manageable vendor dependence secured?

04If the system is high-risk

Article 26 places specific duties on deployers. For a public body these may include use according to instructions, oversight by competent and authorised people, control of input data within its responsibility, monitoring, retention of logs under its control and reporting risks or incidents.

  • A public authority must not use a registrable high-risk system if it is not registered in the relevant EU database.
  • When an Annex III system makes or assists decisions about people, information duties towards affected persons may apply.
  • Public-law bodies and other deployers covered by Article 27 may need a fundamental rights impact assessment before first use.
Not every public-sector use of AI requires a FRIA. First determine whether the system is high-risk and whether the deployer and use fall within Article 27.

05Human oversight needs real authority

Adding a human signature at the end of a process is not enough if the person sees only a score, cannot understand limitations, lacks necessary information or cannot disagree. In the game, many reports become contestable precisely when oversight exists on paper but not in practice.

06The AI Act and Italian AgID material

The EU Regulation is the primary legal source for this guide. Italy's digital agency AgID also publishes public-sector material and guidance. Determination no. 43 of 10 March 2026 documents the start of consultation and information procedures for AI development and procurement guidelines, with draft documents attached.

Document status matters. We do not present consultation drafts as the Regulation or as finally adopted binding rules. Before relying on them in a real process, check AgID's current artificial intelligence page.

07The “Opaque Tender” case

In the game, a platform for awarding public contracts is purchased with inadequate documentation. The lesson is not that all AI procurement is prohibited. It is that a sensitive function cannot be inserted into a public process without understanding validation, control and how an output can be challenged.

08Official sources and limits

Read Regulation (EU) 2024/1689 on EUR-Lex, especially Articles 3, 25, 26 and 27, the Commission's Navigating the AI Act FAQ and the institutional AgID AI pages. Duties vary with the system, purpose and applicable sector law.

Simplified educational version. This is not a procurement procedure, legal opinion or conformity assessment.