Direct answer
We are a public-sector organisation using AI. What needs to be in place?
This falls under Article 27: FRIA. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself.
First step: Map the affected groups and their specific risks of harm.
You describe: A municipality, executive agency or other public body using AI towards citizens, for example in benefits, enforcement or services. Likely role: body governed by public law (deployer).
This applies now
- Articles 43-49: conformity assessment, CE and registrationApplicable
- Article 4: AI literacyApplicable
Coming up
- Article 27: FRIAfrom 2 December 2027
- Article 26: obligations of deployers of high-risk AI systemsfrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
Depends on your situation
- Article 61: informed consent of test subjects for testing in real world conditionsArticle 60(4), point (i), with Article 61(1)
These provisions only apply once the stated fact is established. The locator says which provision settles it.
For public bodies the FRIA duty (Article 27) comes on top of classification. It follows the high-risk timeline to 2 December 2027, but the algorithm register, transparency and AI literacy matter now.
Your first actions
- Map the affected groups and their specific risks of harm. Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13.
- Assign human oversight and give those people a mandate. Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside.
- Complete the conformity route before market placement. Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.
Record this
- Notification to the market surveillance authority with the completed template
- Deployment dossier: logs, worker information and information to affected persons
- Conformity file
government and public services
Awarding social assistance in a municipality: the FRIA and the notification
A municipality wants to deploy an AI system that sorts applications for social assistance benefits and indicates which files merit extra scrutiny before a case worker decides. The application is already listed in the public algorithm register. The question is what has to be in place before the first citizen passes through this system.
Provenance: Article 27(1) requires deployers which are bodies governed by public law, or private entities providing public services, to perform an assessment of the impact on fundamental rights that the use of a high-risk AI system referred to in Article 6(2) may produce, prior to deploying it, with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment covers, among other elements, the categories of natural persons and groups likely to be affected, the specific risks of harm to those categories, the implementation of human oversight measures, and the measures to be taken if those risks materialise, including the arrangements for internal governance and complaint mechanisms. Article 27(3) provides that once the assessment has been performed, the deployer shall notify the market surveillance authority of its results and submit the filled-out template referred to in paragraph 5 as part of that notification, and that in the case referred to in Article 46(1) deployers may be exempt from that obligation to notify. Article 27(5) provides that the AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner.
We read Article 27 as making the municipality the most obvious deployer here, and as requiring the assessment to be complete before the first application runs through the system, not as an account rendered afterwards. That duty does depend first on whether this system is high-risk at all: does it help decide entitlement to social assistance, or does it stay within a preparatory or narrowly procedural task under Article 6(3), which closes its own exception again once the system profiles citizens? Answer that question before you start on paragraph 1. An entry in the public algorithm register is on our reading something different from the assessment under paragraph 1, and it does not replace notifying the market surveillance authority of the results. In practice it pays to record the citizen's complaint route and the case worker's room to depart from the signal in the same file, because paragraph 1 asks for precisely those two elements.
Editorial example. The rule above is in the Regulation. The situation was written by us to show how that rule plays out in this sector, and is not taken from a worked case in official guidance.
Article 27(1), (3) and (5)
government and public services
An induction call with the customer at the moment of go-live
Asimov AI is a micro organisation of at most fifteen people that supplies AI services for legislative work to government institutions and companies. With every new contract it holds one or more induction calls with the team leads and officials who will use the platform, explaining how the platform and the underlying models work and how hallucinations arise in this domain and can be mitigated.
Provenance: This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.
This practice puts literacy where the risk arises: with the people who will operate the system, at the moment they start. For a small provider that is also the only workable moment, because there is no training department to redo it later. Anyone adopting it should record who attended and what was explained, because otherwise the effort survives only in the participants memory a year on.
Living repository of AI literacy practices, practice submitted by the organisation concerned
government and public services
Chatbot answering factual questions from a benefits case handler
A chatbot answers a case handler's factual questions relating to the evaluation of a natural person's application for healthcare benefits, for instance the applicant's age. The case handler can grant or deny the benefits based on those answers.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
A chatbot that only returns existing facts in structured form falls under the exemption, but once it answers case-specific legal questions it steers the decision and is high-risk.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
government and public services
System that surfaces legal provisions and internal guidance for benefits decisions
An AI system is used in assessing data relevant to a decision, for example on public benefits, and provides the human operator with references to the relevant legal provisions, information on jurisdiction and possibly existing internal guidelines relevant to the decision-making process.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
General references to legislation and internal guidance remain preparatory, but the moment your system analyses the concrete file or gives a case-specific recommendation you lose that qualification.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
No mandatory course format, no certificate, no exam and no AI officer
The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.
Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)
Article 4 reaches beyond your own staff, and the national supervisor enforces it
The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.
Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)
Annex I lists legislation, not products
The draft guidelines of 19 May 2026, published for consultation and expressly non-binding, clarify that Annex I AI Act does not list individual products to be classified as high-risk, but Union harmonisation legislation regulating the safety aspects of certain products. Whether an AI system falls within the scope of Annex I therefore depends on whether the system, or the product of which it is a safety component, falls within the material scope of one of the listed legislative acts. According to the draft guidelines the list in Annex I is exhaustive; products can only be added or removed by amending the scope of the harmonisation legislation itself or by adding new harmonisation legislation to Annex I. The draft guidelines also state that through Article 6(1) the AI Act does not itself extend the scope of harmonisation legislation to new or additional products, and that the AI Act does not determine or change the risk profile of a product but builds on the sectoral risk classification. Products mentioned include machinery, toys, lifts, equipment and protective systems for potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, and products in the automotive and aviation sectors.
Draft guidelines Annex I, points (23) to (26)
Section A and Section B of Annex I trigger different requirement sets
The Commission draft guidelines of 19 May 2026, which are non-binding as long as the final version has not been adopted, draw a distinction that is often missed in practice. AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section A of Annex I are subject to the requirements for high-risk systems in Section 2 of Chapter III AI Act. By contrast, for AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 AI Act apply. The draft guidelines refer to Article 2(2) AI Act for this. Section A contains harmonisation legislation based on the New Legislative Framework, Section B the other Union harmonisation legislation.
Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act
prEN 18285: conformity assessment framework for AI systems
prEN 18285 (Conformity assessment framework) is the JTC 21 deliverable under M/613 covering the conformity assessment of high-risk AI systems under Article 43 and Annex VII of the AI Act. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal. Standardisation request M/613 was amended by Implementing Decision C(2025)3871 of 23 June 2025 and expires on 28 February 2027.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation