Skip to main content
Praxikon
All answers

Direct answer

When are you a public-law body under the AI Act?

5 obligations under the AI Act bear on this, of which 2 apply today.

First step: Assign human oversight and give those people a mandate.

Whether you are a public-law body is not a matter of what you call yourself but of what you do with the system. Across the 5 obligations there are 16 conditions and exceptions that decide it. Below they are listed per provision, with the official source. Likely role: public-law body.

The conclusion and your first steps

This applies now

Coming up

What decides whether this is about you

Article 26: obligations of deployers of high-risk AI systems
  • Applies when: Applies as soon as you use a high-risk AI system under your own authority (Article 3(4)), whether you built it yourself or procured it. For the standalone Annex III route (Article 6(2)) the date is 2 December 2027; for the embedded Annex I route (Article 6(1)) the date is 2 August 2028.
  • Unless: Article 2(10) excludes natural persons using an AI system in the course of a purely personal, non-professional activity. For deployers that are financial institutions subject to internal governance requirements under Union financial services law, the monitoring obligation in paragraph 5 is deemed fulfilled by complying with those rules, and the logs under paragraph 6 are maintained as part of the documentation kept under that law.
Article 27: FRIA
  • Applies when: The system is high-risk under Article 6(2) and Annex III, excluding Annex III point 2.
  • Applies when: The deployer is a body governed by public law, a private provider of public services or uses a relevant system in Annex III point 5(b) or 5(c).
  • Unless: In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself.
Article 49: registration in the EU database before the system reaches the market
  • Applies when: Paragraph 4 does not except the registration but relocates it: for the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, the registration referred to in paragraphs 1, 2 and 3 goes into a secure non-public section of the EU database, with a limited list of fields from Annex VIII and Annex IX, and only the Commission and the national authorities referred to in Article 74(8) have access to it.
  • Applies when: Applies where a provider or, where applicable, an authorised representative places on the market or puts into service a high-risk AI system listed in Annex III, and where that same party places on the market or puts into service an AI system for which it has concluded that it is not high-risk according to Article 6(3).
  • Applies when: Applies where a deployer that is a public authority, Union institution, body, office or agency, or a person acting on their behalf, puts into service or uses a high-risk AI system listed in Annex III.
  • Applies when: Registration is a precondition and not a notification afterwards: paragraphs 1 and 2 attach to the moment before the system is placed on the market or put into service, paragraph 3 to the moment before it is put into service or used.
  • Unless: This is an exception to the route and not to the duty. Paragraphs 1 and 3 except the high-risk AI systems referred to in point 2 of Annex III from registration in the EU database, and paragraph 5 provides that those systems are registered at national level. For critical infrastructure the registration therefore does not fall away: it runs through the national register rather than through the Article 71 EU database.
Article 71: EU database for high-risk AI systems listed in Annex III
  • Applies when: Applies where a provider or authorised representative places an Annex III high-risk AI system on the market or puts it into service and registers itself and that system in accordance with Article 49, where that same party registers a system considered not to be high-risk pursuant to Article 6(3), or where a deployer that is, or that acts on behalf of, a public authority, agency or body registers itself, selects the system and registers its use.
  • Unless: Article 49(5) provides that high-risk AI systems referred to in point 2 of Annex III are registered at national level. For those systems the registration therefore does not run through the Article 71 EU database.
  • Unless: Paragraph 4 excludes the section referred to in Article 49(4) from public availability. For the systems referred to in points 1, 6 and 7 of Annex III in the areas of law enforcement, migration, asylum and border control management, registration takes place in a secure non-public section of the database, with fewer fields than the full Sections: Section A, points 1 to 10 with the exception of points 6, 8 and 9; Section B, points 1 to 5 and points 8 and 9; Section C, points 1, 2 and 3; and points 1, 2, 3 and 5 of Annex IX. Only the Commission and the national authorities referred to in Article 74(8) have access to those sections. Mind the cross-reference: Article 49(4) was not amended by Regulation (EU) 2026/1744 and therefore still names point 9 of Section B, while Article 1, point (42), of that same Regulation deleted that point. There is nothing left to fill in there.
  • Unless: Paragraph 4 additionally excludes the section referred to in Article 60(4), point (c). The main rule there is not a secure section: the provider or prospective provider registers the testing in real world conditions in accordance with Article 71(4), with a Union wide unique single identification number and the information specified in Annex IX. Under the third sentence of paragraph 4 that information is accessible only to market surveillance authorities and the Commission, unless the provider or prospective provider has given consent for also making it accessible to the public. Only for points 1, 6 and 7 of Annex III does the testing registration go into the secure non-public section under Article 49(4), point (d), and for point 2 of Annex III to national level under Article 49(5).
Articles 43-49: conformity assessment, CE and registration
  • Applies when: The provider places a high-risk system on the market; public deployers also register their use.
  • Unless: For most Annex III systems internal control suffices (Annex VI); a notified body is required for certain biometrics and where harmonised standards are lacking.

These are the questions you answer yourself. Praxikon shows which condition sits in which provision; whether your system meets it is yours to establish.

Read the official sourceChecked on

General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.

Full map for your situation

Your route

From your situation, via your role, to what applies and when it starts.

2 now · 3 later

Your situation

Whether you are a public-law body is not a matter of what you call yourself but of what you do with the system. Across the 5 obligations there are 16 conditions and exceptions that decide it. Below they are listed per provision, with the official source.

Role

public-law body

To record: Deployment dossier: logs, worker information and information to affected persons · Notification to the market surveillance authority with the completed template · Article 49 registration dossier

Source and locator

Every statement above rests on these texts. The locator points to the place in the text, the version and the date say which edition was checked.

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council, version original-oj-2024-07-12, checked on , ELI http://data.europa.eu/eli/reg/2024/1689/oj

    Locators in this source

    • Article 26(1)-(12)
    • Article 27(1)-(5)
    • Article 27(1)
    • Article 49(1)-(5)
    • Article 6(2)-(4), Article 49 and Annex III
    • Article 71(1)-(6)
    • Annex VIII, Sections A and C
    • Annex VIII, Section B
    • Article 49(4) and Annex IX
    • Article 60(4), point (c), Article 49(4) and (5)
    • Recital 131
    • Articles 43, 47, 48 and 49
    • Article 113, second paragraph
  • Digital Omnibus on AI 2026/1744

    European Parliament and Council, version official-journal-2026-07-24, checked on , ELI http://data.europa.eu/eli/reg/2026/1744/oj

    Locators in this source

    • Amended application schedule and Article 27 DPIA cross-reference
    • Article 27 amendment on DPIA inclusion or cross-reference
    • Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)
    • Article 1, point (42), deleting Annex VIII, Section B, points 7 and 9
    • Recital 22 of Regulation (EU) 2026/1744
    • Article 1, points (24) and (25), replacing Article 60(1), first subparagraph, and Article 60(2) and inserting Article 60a
    • Article 1, point (40)(b) and (c), replacing Article 113, third paragraph, point (c) and adding point (d)

Dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0, schema 1.5.0.

Execution

Where relevant, connect the FRIA to the DPIA, register and decision-making

Whether a FRIA is required depends on your role and the use case. Where it applies, you record the assessment and measures and, where relevant, connect them to the AI register, a DPIA and decision-making. Embed AI guides this connected assessment with your team. The source interpretation above is separate from this commercial referral by Praxikon to an affiliated brand.

See the FRIA and DPIA approach
Does this answer your question?
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist