The AI Act gives the public sector no exemption. Public bodies carry the same duties as companies, plus two that fall mainly on them: a fundamental rights impact assessment and public registration of high-risk use. The Digital Omnibus on AI, in force since 27 July 2026, moved the high-risk dates. Much of the guidance still online predates it.1,2

Summary

  1. Three duties already apply: the bans, AI literacy and disclosure of AI-generated text. High-risk duties start on 2 December 2027. Older systems used by public authorities must comply by 2 August 2030.
  2. Public administration is the most attacked sector in the EU. It drew 31.8 percent of the 8,257 incidents ENISA recorded in 2025, more than the next four sectors combined.
  3. Generative AI is already at work. In 2025, 15.4 percent of EU adults used it for their jobs, and over a quarter in Denmark and the Netherlands. Policy has to start from the tools staff already use.

What does the AI Act require from the public sector?

The Act defines a deployer as any person or public authority using an AI system under its own authority. Most ministries, municipalities and agencies are deployers. A body that builds a system and puts it into service under its own name is also its provider.1

The table lists the duties that reach public bodies, with dates as amended by Regulation (EU) 2026/1744.2,3

AI Act duties for public bodies, as amended by the Digital Omnibus

Date What public bodies must do Provision
2 Feb 2025 Stop banned practices, such as social scoring Art. 5
2 Feb 2025 Support the AI literacy of staff Art. 4
2 Aug 2026 Disclose AI-generated text on public matters Art. 50(4)
2 Dec 2027 Oversight, logs and notices for high-risk AI Art. 26
2 Dec 2027 Register high-risk use in the EU database Art. 26(8), 49
2 Dec 2027 Fundamental rights impact assessment Art. 27
2 Dec 2027 Explain AI-assisted decisions on request Art. 86
2 Aug 2030 Bring legacy high-risk systems into line Art. 111(2)

Applies now Upcoming

Sources: Regulation (EU) 2024/1689; Regulation (EU) 2026/1744; EUR-Lex, accessed 29 September 2026. Article 50(4) does not apply where a person holds editorial responsibility after human review. Status as of the access date.

Fines follow a national choice. Article 99(8) lets each Member State decide how far administrative fines can be imposed on its public bodies. The full sequence of dates is on the AI Act timeline.1

Which public-sector AI systems are high-risk?

Annex III lists the uses that make a system high-risk. Several are government work by nature:

  • evaluating eligibility for public assistance benefits and services, or granting, reducing or reclaiming them;
  • evaluating and classifying emergency calls, and dispatching emergency services;
  • migration, asylum and border control, and law enforcement uses;
  • admission and assessment in education, and hiring and promotion of the body's own staff;
  • assisting judicial authorities, and systems intended to influence elections.

Article 6(3) offers an exit. A listed system is not high-risk if it only performs a narrow procedural or preparatory task and does not materially influence the decision. A case file summary that a civil servant checks can qualify. A system that profiles people is always high-risk.1

The classification decides the workload. A high-risk system brings human oversight, logging, notices to the people affected, registration and the rights assessment. A misclassification found in 2028 is expensive to repair.

What have courts and regulators already decided?

The AI Act is not the first test for public algorithms. GDPR, human rights law and freedom of information already apply, and European bodies have used them. Most cases concern risk scoring for fraud control.

Public-sector algorithm cases in Europe, 2020 to 2025

Date Country System Outcome
Feb 2020 Netherlands SyRI fraud risk scoring Court: breaches Article 8 ECHR
Dec 2021 Netherlands Childcare benefit nationality data €2.75m GDPR fine
Apr 2022 Netherlands Tax fraud blacklist (FSV) €3.7m GDPR fine
Jan 2024 Italy Trento AI surveillance projects €50,000 GDPR fine
Mar 2024 Netherlands DUO student grant checks Apology for indirect discrimination
Oct 2024 France CNAF benefit risk scoring Challenged at the Conseil d'État
Sep 2025 Spain BOSCO energy subsidy software Supreme Court orders code access
Nov 2025 Sweden Parental benefit risk model Withdrawn; regulator closed case

Fine or court ruling No fine or ruling

Sources: Rechtbank Den Haag; Autoriteit Persoonsgegevens via NOS; Garante via Statewatch; Rijksoverheid; La Quadrature du Net; Tribunal Supremo via Civio; IMY; accessed 29 September 2026. CNAF published its source code in January 2026.

The pattern is consistent. The Hague District Court ruled the SyRI legislation unlawful, partly because its risk models were opaque.4 The Dutch data protection authority fined the Tax Administration twice, for using dual nationality in childcare benefit processing and for a fraud blacklist.5,6 Italy's Garante fined Trento for AI surveillance projects without a legal basis.7 The Dutch cabinet apologised for indirect discrimination in student grant checks.8 Civil society groups are challenging the French CNAF benefit scoring algorithm.9

Transparency is the other thread. Spain's Supreme Court ruled in September 2025 that the government must release the source code of BOSCO, which screens applicants for an energy subsidy.10 In Sweden, the social insurance agency withdrew a machine learning risk model once the privacy regulator opened an investigation.11 The fundamental rights impact assessment asks the questions these bodies failed to answer in advance.

Why does security shape where public-sector AI runs?

AI systems hold the case files, letters and decisions that attackers want. ENISA's Threat Landscape 2026 names public administration the most targeted sector in the EU for another year.12

Public administration draws a third of EU incidents

Its share is nearly four times that of business services, the next sector.

Public administration was the target of almost a third of recorded cyber incidents in the EU in 2025.

Share of recorded incidents in the EU, top five sectors, 2025, %

Other sectors in the top five Public administration
0 10 20 30 40 Public administration¹ 31.8% Business services 8.5% Transport 8.0% Manufacturing 6.9% Finance and banking 5.6%

¹ Includes central (35.1%), local (33.8%) and regional (10.1%) government entities. Base: 8,257 incidents recorded from 1 January to 31 December 2025, mainly from open sources and anonymised Member State information.

Source: ENISA, Threat Landscape 2026, Figure 5, 22 September 2026

Within public administration, central government entities drew 35.1 percent of incidents and local entities 33.8 percent. Most were DDoS attacks on public websites. Ransomware mainly hit municipalities. One attack on a Swedish IT supplier affected around 200 municipalities and regional authorities.12

ENISA also reports that attackers treat AI systems as targets, not only as tools. For public bodies in NIS2 scope, every AI supplier becomes part of the supply chain they must secure. Ownership matters as much as location: a US-owned provider remains subject to the CLOUD Act wherever the data sits. The European cloud GPU price index lists providers by owner, and the on-premise and private cloud guide sets out the hosting trade-offs.

How widely is generative AI already used in government work?

A Joint Research Centre study published in June 2026 names shadow use as a central governance problem: public servants using commercial tools without approval or guidelines. It drew on 31 interviews across seven countries and the Commission.13 Eurostat data show how common the habit is among Europeans at large.14

Staff bring generative AI to work

In 2025, 15 percent of EU adults used it for their job; in Denmark, the Netherlands and Finland, one in four.

Use of generative AI for work ranges from over a quarter of adults in Denmark and the Netherlands to one in twenty in Romania.

Individuals aged 16 to 74 who used generative AI tools for work in the last three months, 2025, % of individuals

EU-27 average Member State
0 5 10 15 20 25 30 Malta 29.5% Denmark 27.2% Netherlands 26.6% Finland 25.1% Sweden 21.0% France 18.4% Spain 17.9% Germany 15.8% EU-27² 15.4% Poland 8.4% Italy 8.0% Romania 5.2%

² Average of all 27 Member States. Use of generative AI for any purpose: 32.7%. Selected Member States. All individuals aged 16 to 74, not only employees; 2025 is the first year Eurostat asked about generative AI.

Source: Eurostat, isoc_ai_iaiu, updated 5 June 2026

Civil servants are part of this population. A ban without an approved alternative moves use out of sight. AI literacy under Article 4 has applied since February 2025, so staff rules and training are already due. The workable order is an approved tool, clear rules on citizen data, then training.

Governments are starting to buy together. In July 2026 the Commission announced EuropAI, in which the Netherlands, Denmark, Belgium and Luxembourg will jointly procure, test and deploy European generative AI for public administrations.15 The public sector page covers use cases such as case file summaries and plain-language letters.

How should public bodies buy AI under procurement rules?

From 1 January 2026, service contracts above €140,000 for central government and €216,000 for other contracting authorities fall under the EU procurement directive.16 Tenders run for months. Models change in weeks.

A specification built around one named model can be outdated before the contract starts. Stronger tenders describe required capabilities, hosting jurisdiction, evaluation on the body's own documents, and exit terms. They also oblige the provider to supply what the deployer needs under Articles 13 and 26: instructions for use, logs and performance limits. Lindstead's model selection service tests candidates on the organisation's own letters and case files before a tender is written.

What should a public body do before December 2027?

Fourteen months remain before the high-risk duties apply. Lindstead recommends this order:

  1. Register every AI system in use, including informal chatbot use, with provider, purpose, data and owner.
  2. Classify each system against Article 5, Annex III, Article 6(3) and Article 50, and record the reasoning.
  3. Close the duties that apply now: staff AI literacy and disclosure of AI-generated public texts.
  4. For likely high-risk systems, draft the fundamental rights impact assessment on top of the existing DPIA.
  5. Decide per workload whether it runs in-house, in a European-owned cloud or through an external API.

Lindstead maps AI Act, GDPR and NIS2 obligations to each AI system and builds the workload roadmap a board can adopt. It then deploys a first use case on infrastructure the organisation controls, with the logging and oversight the Act expects.

Frequently asked questions

  • Yes. The AI Act has no general exemption for the public sector. Most public bodies are deployers, and some duties apply only to them: the fundamental rights impact assessment and registration of high-risk use in the EU database. Each Member State decides whether, and how far, fines can be imposed on its public bodies.

  • Bans and AI literacy have applied since 2 February 2025, and Article 50 transparency since 2 August 2026. Duties for high-risk systems listed in Annex III apply from 2 December 2027, after the Digital Omnibus delay. High-risk systems intended for public authorities that were already in service must comply by 2 August 2030.

  • Usually not. A chatbot that answers general questions falls under Article 50: people must be told they are dealing with an AI system. It becomes high-risk if it evaluates whether a person is eligible for public benefits or services, which Annex III lists explicitly.

  • No. Article 27 applies to bodies governed by public law, and private entities providing public services, before they deploy a high-risk system listed in Annex III. Critical infrastructure systems are exempt. The duty starts on 2 December 2027, and the assessment can build on an existing data protection impact assessment.

  • The AI Act does not ban general-purpose chatbots. It requires the employer to support staff AI literacy, and GDPR still governs any personal data entered. The Dutch government, for example, requires a risk analysis first and recommends tools developed and managed in Europe.

Sources

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal, 12 July 2024. Articles 3, 4, 5, 6, 26, 27, 49, 50, 86, 99, 111 and Annex III. eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal, 24 July 2026. eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744
  3. European Commission, AI Omnibus enters into force, 27 July 2026. digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force
  4. Rechtbank Den Haag, SyRI judgment, ECLI:NL:RBDHA:2020:1878 (English), 5 February 2020. uitspraken.rechtspraak.nl/details?id=ECLI:NL:RBDHA:2020:1878
  5. NOS, Boete voor Belastingdienst van 2,7 miljoen voor discriminatie toeslagenouders, 7 December 2021. nos.nl/artikel/2408587-boete-voor-belastingdienst-van-2-7-miljoen-voor-discriminatie-toeslagenouders
  6. NOS, Recordboete voor Belastingdienst vanwege zwarte lijst, April 2022. nos.nl/artikel/2424861-recordboete-voor-belastingdienst-vanwege-zwarte-lijst
  7. Statewatch, Italy: Trento council fined for illegal AI video and audio surveillance projects, February 2024. statewatch.org/news/2024/february/italy-trento-council-fined-for-illegal-ai-video-and-audio-surveillance-projects/
  8. Rijksoverheid, Kabinet maakt excuses voor indirecte discriminatie bij controles op de uitwonendenbeurs, 1 March 2024. www.rijksoverheid.nl/actueel/nieuws/2024/03/01/kabinet-maakt-excuses-voor-indirecte-discriminatie-bij-controles-op-de-uitwonendenbeurs
  9. La Quadrature du Net, CNAF's discriminatory scoring algorithm: 10 new organisations join the case before the Conseil d'État, 20 January 2026. www.laquadrature.net/en/2026/01/20/cnafs-discriminatory-scoring-algorithm-10-new-organisations-join-the-case-before-the-conseil-detat-in-france/
  10. Civio, El Supremo condena al Gobierno a entregar el código fuente de BOSCO, 17 September 2025 (judgment 1119/2025 of 11 September 2025). civio.es/novedades/2025/09/17/civio-abre-camino-en-la-transparencia-algoritmica-el-supremo-condena-al-gobierno-a-entregar-el-codigo-fuente-de-bosco/
  11. IMY (Swedish Authority for Privacy Protection), Avslutad tillsyn efter att Försäkringskassan tagit AI-system ur bruk, 18 November 2025. www.imy.se/nyheter/avslutad-tillsyn-efter-att-forsakringskassan-tagit-ai-system-ur-bruk/
  12. ENISA, Threat Landscape 2026, 22 September 2026. Reporting period 1 January to 31 December 2025; 8,257 incidents. www.enisa.europa.eu/publications/enisa-threat-landscape-2026
  13. Joint Research Centre, The adoption of Generative AI in EU public administrations: exploring individual behaviours and organisational approaches, JRC147095, 19 June 2026. publications.jrc.ec.europa.eu/repository/handle/JRC147095
  14. Eurostat, Individuals: use of generative AI tools (isoc_ai_iaiu), 2025 data, updated 5 June 2026. ec.europa.eu/eurostat/databrowser/view/isoc_ai_iaiu/default/table
  15. European Commission, EuropAI: reusable European generative AI solutions for public administrations, 22 July 2026. digital-strategy.ec.europa.eu/en/news/europai-reusable-european-generative-ai-solutions-public-administrations
  16. European Commission, Public procurement thresholds 2026 to 2027 (Delegated Regulation (EU) 2025/2152). single-market-economy.ec.europa.eu/single-market/public-procurement/legal-rules-and-implementation/thresholds_en

Method: legal duties read from the AI Act and the Digital Omnibus on EUR-Lex; figures from ENISA and Eurostat; cases from court, regulator and government sources. All sources accessed 29 September 2026. This page is general information, not legal advice. Corrections: contact@lindstead.com.