Skip to main content
FromNine
Menu

Public sectorAI engineering

The EU AI Act for public bodies: what to prepare by December 2027

The high-risk rules moved to December 2027, but prohibitions, AI literacy and transparency duties already apply. What changed in 2026, what a public deployer has to do, and a practical plan for the time that is left.

By
FromNine editorial team
Published
Reading time
7 min read

Key takeaways

  1. Prohibited practices and AI literacy have applied since February 2025, and transparency duties under Article 50 since August 2026.
  2. As amended in 2026, the AI Act applies the Annex III high-risk rules from 2 December 2027. Public deployers will then need a fundamental rights impact assessment and EU database registration before use.
  3. Use the extra time to build an inventory, classify use cases, fix contracts and set up oversight and logging, rather than to wait.
Contents

Where things stand in autumn 2026

The AI Act (opens external site), Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in stages. In July 2026 the EU adopted the Digital Omnibus on AI, Regulation (EU) 2026/1744 (opens external site), which postponed the high-risk rules and changed a number of other provisions. It entered into force on 27 July 2026, a few days before the original high-risk date.

The result is a timeline in which some obligations already apply, some arrive at the end of this year and the heaviest ones for public deployers follow in December 2027.

Table 1AI Act milestones relevant to public bodies, as amended in 2026
DateWhat appliesWhat it means for a public body
2 February 2025Prohibited practices (Article 5) and AI literacy (Article 4)Stop, or never start, prohibited uses such as social scoring. Take measures so staff understand the AI systems they use.
2 August 2025Rules for general-purpose AI models; governance and penalty frameworksMainly obligations for model providers. National competent authorities are designated.
2 August 2026Most remaining provisions, including the transparency obligations in Article 50Tell people when they interact with an AI system or see AI-generated content, where Article 50 applies.
2 December 2026New prohibitions on AI-generated non-consensual intimate content and child sexual abuse material; end of the transition for marking synthetic content of systems already on the marketCheck the generative tools you use and procure.
2 December 2027High-risk rules for Annex III use casesDeployer obligations, fundamental rights impact assessment and registration before use.
2 August 2028High-risk rules for AI in products covered by Annex IRelevant where AI is part of regulated products, such as medical devices or machinery.

The Omnibus also rewrote Article 4 on AI literacy. Providers and deployers now have to take measures to support the AI literacy of their staff, instead of ensuring a sufficient level of it. The duty remains; what you need to show has changed. Training that fits each role, and a record of it, is still the sensible answer.

Are you a provider or a deployer?

Most public bodies are deployers: they use an AI system under their own authority. You are a provider when you develop an AI system, or have one developed, and put it into service under your own name. That includes systems built in-house or by a contractor to your specification.

Roles can also shift. Under Article 25, a deployer that substantially modifies a high-risk system, or changes its intended purpose so that it becomes high-risk, takes on provider obligations. Write the intended roles into procurement documents and contracts, so that nobody discovers them during an audit.

Which of your use cases are high-risk?

Annex III lists the areas in which AI systems are considered high-risk. For public bodies the most relevant are:

  • Access to essential public services and benefits: assessing eligibility, and granting, reducing, revoking or reclaiming benefits and services.
  • Migration, asylum and border control, law enforcement and the administration of justice.
  • Education and vocational training: admission, assessment of learning outcomes, monitoring during tests.
  • Employment: recruitment, promotion, task allocation and monitoring of staff. Public bodies are employers too.
  • Critical infrastructure: safety components in the management of digital infrastructure, road traffic and utilities.

Being in an Annex III area is not the end of the analysis. Under Article 6(3), a system in such an area is not high-risk when it does not pose a significant risk of harm, for example because it performs a narrow procedural task, improves the result of work a person has already completed, detects patterns without replacing human assessment, or performs a preparatory task. A system that profiles people is always high-risk. If you rely on this exception, document the reasoning.

Many useful tools are not high-risk at all: drafting support, internal knowledge search, translation, summarising. Transparency duties and the GDPR still apply to them, but the high-risk regime does not.

Figure 1

From prohibitions to high-risk rulesApplication dates of the AI Act as amended by Regulation (EU) 2026/1744. The highlighted step is the main deadline for public deployers.
Read the diagram as text

2 February 2025: prohibited practices and AI literacy apply. 2 August 2025: rules for general-purpose AI models and governance apply. 2 August 2026: most remaining provisions apply, including transparency obligations.

2 December 2026: new prohibitions and the end of a transition period for marking synthetic content. 2 December 2027: high-risk rules for Annex III use cases apply, the main deadline for public deployers. 2 August 2028: high-risk rules for AI in products covered by Annex I apply.

What deployers of high-risk systems must do

From 2 December 2027, a public body that deploys a high-risk system from Annex III has obligations under Article 26 (opens external site). The main ones:

  • Use the system in line with the provider's instructions for use, with appropriate technical and organisational measures.
  • Assign human oversight to people with the necessary competence, training and authority, and give them support.
  • Make sure input data under your control is relevant and sufficiently representative for the intended purpose.
  • Monitor the operation, and inform the provider and the authorities without undue delay of risks and serious incidents.
  • Keep the automatically generated logs for at least six months, unless other Union or national law provides otherwise.
  • Inform workers' representatives and affected staff before using a high-risk system at work.
  • As a public authority, register your use of the system in the EU database before putting it into use (Article 26(8) and Article 49). An unregistered system may not be used.
  • Inform people when a high-risk system is used to make, or assist in making, decisions about them (Article 26(11)). People also have a right to an explanation of individual decisions (Article 86).

The fundamental rights impact assessment

Under Article 27 (opens external site), bodies governed by public law, and private organisations that provide public services, carry out a fundamental rights impact assessment before they first use most Annex III systems. Systems for critical infrastructure are excluded. The assessment describes:

  1. the processes in which the system will be used, in line with its intended purpose;
  2. the period and frequency of use;
  3. the categories of people and groups likely to be affected;
  4. the specific risks of harm to those people;
  5. how human oversight is implemented;
  6. what happens if risks materialise, including internal governance and complaint mechanisms.

You notify the results to the market surveillance authority. The assessment complements, and can build on, a data protection impact assessment under Article 35 of the GDPR, so run both together. Article 27(5) asks the AI Office to provide a template questionnaire; check its status before you design your own. Some countries already have methods, such as the Dutch government's Impact Assessment Mensenrechten en Algoritmes (IAMA).

Transparency duties that already apply

Since 2 August 2026, Article 50 applies. Providers must design systems that interact with people so that those people are told they are dealing with an AI system, unless that is obvious, and must mark synthetic content in a machine-readable way. Deployers must disclose deepfakes, and must disclose AI-generated or manipulated text published to inform the public on matters of public interest, unless a person has reviewed it and someone holds editorial responsibility.

For a public body, the most common case is a chat assistant on a website or in a service channel. Say clearly that it is an AI system, explain what it can and cannot help with, and offer a route to a person.

A preparation plan for 2026 and 2027

  1. Inventory, now. List every AI system in use or in procurement, including AI features inside platforms you already license. Record owner, purpose, provider, data used and the people affected.
  2. Classify, by early 2027. Prohibited, high-risk (with the Article 6(3) reasoning documented), transparency only, or minimal risk. Record your role as provider or deployer for each.
  3. Fix contracts, during 2027. Ask providers for instructions for use, conformity documentation and access to logs. Make support for your impact assessment and incident reporting a contract term.
  4. Design oversight. Name the roles, train them, give them authority to override and an escalation path. Design against automation bias; our article on where AI agents need human approval shows how.
  5. Set up logging and monitoring. Keep logs for at least six months, define what counts as a serious incident and who reports it.
  6. Before first use. Run the fundamental rights impact assessment together with the DPIA, register in the EU database, and inform staff and the people affected.
  7. Keep literacy going. Role-based training for users, reviewers and decision-makers, refreshed when systems change, with a record of who was trained.

Penalties and enforcement

Member States lay down the rules on penalties. Article 99(8) lets each Member State decide whether, and to what extent, administrative fines can be imposed on public authorities and bodies established in that state. That is not a reason to wait. Market surveillance authorities can still require corrective action, and the legitimacy of a public decision depends on whether it can be explained and challenged.

What to watch in the coming months

  • Commission guidelines on the classification of high-risk systems (Article 6(5)), and its existing guidelines on prohibited practices (opens external site).
  • Harmonised standards for high-risk requirements, which providers will use to show conformity.
  • The designation of market surveillance authorities in your Member State, and their first guidance for public deployers.
  • The AI Office template for the fundamental rights impact assessment.

The AI Act Service Desk (opens external site) of the European Commission keeps the official timeline and article-by-article explanations up to date. Bookmark it, and date every internal note you write about the Act: this is a text that is still moving.

Sources

  1. EUR-Lex. Regulation (EU) 2024/1689 (Artificial Intelligence Act) (accessed )
  2. EUR-Lex. Regulation (EU) 2026/1744 (Digital Omnibus on AI) (accessed )
  3. European Commission. AI Act: regulatory framework for AI (accessed )
  4. European Commission, AI Act Service Desk. Timeline for the implementation of the EU AI Act (accessed )
  5. European Commission, AI Act Service Desk. Article 26: Obligations of deployers of high-risk AI systems (accessed )
  6. European Commission, AI Act Service Desk. Article 27: Fundamental rights impact assessment for high-risk AI systems (accessed )
  7. European Commission. Commission guidelines on prohibited artificial intelligence practices (accessed )
  8. European Commission. AI Act Service Desk (accessed )
  9. EUR-Lex. Regulation (EU) 2016/679 (General Data Protection Regulation), Article 35 (accessed )

Preparing your AI inventory?

We help public bodies map their AI systems, classify use cases and design the oversight, logging and integrations the AI Act expects. The legal assessment stays with your counsel.