Begin with the purpose of the system
The same technology can have different legal and operational implications. Summarising an internal document is not equivalent to assessing a person or influencing access to a public service. Describe the inputs, outputs, decision-maker and possible consequences.
An inventory of systems and pilots prevents tools purchased by different teams from sitting outside institutional governance.
Risk classification and impact assessment
Not every use of AI in public administration is automatically high-risk. Uses that affect rights, eligibility, enforcement or decisions about individuals nevertheless require particular care and appropriate legal advice.
Assessment should consider data quality, affected groups, the ability to challenge an outcome, reliance on the output and the practical effectiveness of human oversight.
Transparency, documentation and oversight
The authority should know which model or service it uses, which versions are in production, what data is processed and how quality is evaluated. Internal users need instructions, limits and training proportionate to the task.
When a person interacts with an automated system, the information provided should be clear and a route to human support should exist where necessary.
What to require from suppliers
Contracts should address security, subprocessors, data location and use, service levels, logs, audit, change management, deletion and exit. The authority should be able to suspend or replace a service without losing control of the process.
This content is for general information and does not replace legal advice on a particular system or procedure.
Frequently asked questions
Is every municipal use of AI high-risk?
No. Classification depends on the purpose and role of the system. Uses affecting people or rights need especially careful assessment.
Does a pilot also need rules?
Yes. Even a small test should have a purpose, authorised data, an owner, oversight and a procedure for stopping it.
Is a supplier's claim of AI Act compliance enough?
No. The deployer also has responsibilities and must verify that documentation, contract and operation fit the specific use case.
Architecture: AI for complaint handling in local government →