AI Act readiness for the public sector: from algorithm to demonstrably responsible
Municipalities, executive agencies and other public bodies use AI for benefits, fraud detection and citizen services. Much of this falls under the high-risk regime of Annex III and requires a FRIA, registration and a fundamental rights assessment. The political agreement on the Digital Omnibus moves that regime to 2 December 2027. That is not a reason to wait, but runway to get ahead. We map your AI use cases, roles, obligations and evidence and translate them into a concrete readiness roadmap.
Readiness check
2 to 4 weeks
From AI use to demonstrably responsible
Overview of AI and algorithm use cases toward citizens
Per use case: risk class, role and obligations
FRIA Article 27 and algorithm register mapped
Readiness roadmap toward 2 December 2027
Postponement is runway, not a reason to wait
The political agreement on the Digital Omnibus moves the Annex III high-risk regime from 2 August 2026 to 2 December 2027. That agreement is not yet applicable law: until publication in the Official Journal, the original timeline formally stands. For the public sector this is no reason to wait. Registration, an evidence file and a FRIA are heavy and take lead time. On top of that, the Dutch algorithm register requirement and the fundamental rights assessment through IAMA already apply. The runway to 2 December 2027 is best used to get ahead.
What the AI Act asks of the public sector
Public bodies deploy AI for decisions that directly affect citizens. A large share of that is high-risk under Annex III. We test your use cases against the core obligations.
Annex III essential services
AI for access to and granting of benefits, social services and essential public services falls under high-risk. The same applies to risk profiling and fraud detection toward citizens.
FRIA Article 27
Public bodies and providers of public services must carry out a fundamental rights impact assessment (FRIA) for high-risk AI before the system is put into use. This duty follows the high-risk date of 2 December 2027.
Algorithm register
The Dutch government has its own obligation to register impactful algorithms in the algorithm register. This is separate from the EU timeline and already applies to many public bodies.
Human oversight Article 14
High-risk AI requires effective human oversight. That depends on staff who can interpret and, where needed, override the output. AI literacy is a precondition here, not a formality.
Note the overlap of regimes: the EU AI Act, the GDPR (with DPIA), the Dutch algorithm register and the IAMA instrument partly overlap. We map that coherence so you do not do the same work four times, but build a shared evidence file.
When this readiness check fits
This check is for municipalities, executive agencies and other public bodies that deploy AI or algorithms toward citizens and need to get ahead of the high-risk regime.
You use AI in service delivery
Benefits, permits, allowances or other decisions where algorithms or AI directly affect citizens.
You do risk profiling or fraud detection
Use cases that select, score or profile citizens and are extra sensitive on fundamental rights and transparency.
You must register and account
You deal with the algorithm register, a fundamental rights assessment and soon the FRIA, and want to tackle this coherently.
What the readiness check delivers
Inventory of AI and algorithm use cases within scope, focused on citizen-facing decisions
Per use case: risk class under the AI Act and placement under Annex III
Role determination: whether you act as provider or deployer per use case
FRIA setup Article 27: scope, fundamental rights involved and required input
Link to the algorithm register: what must be registered and when
Overlap analysis AI Act, GDPR/DPIA and IAMA so evidence is reusable
Readiness roadmap with owner, priority and milestones toward 2 December 2027
Points of attention for human oversight and AI literacy per role
Approach in 2 to 4 weeks
Scope and intake
We define which AI and algorithm use cases toward citizens fall within scope and who the owners are.
Inventory
We map per use case how AI is deployed, which decisions it affects and which data is used.
Classification and roles
We connect each use case to the right risk class and Annex III category and determine whether you are provider or deployer.
FRIA, register and overlap
We set up the FRIA Article 27, link to the algorithm register and record the coherence with GDPR and IAMA.
Readiness roadmap
You get a roadmap with actions, owners and milestones to get ahead of 2 December 2027.
Who this works for
Municipalities
Teams that deploy AI or algorithms in service delivery, enforcement or the social domain and want grip on obligations and evidence.
Executive agencies
Organizations that decide at scale on benefits, allowances or services and use fraud detection or risk profiling.
CISO, privacy and legal affairs
Who want to bring together the AI Act, the algorithm register, the DPIA and the fundamental rights assessment.
Board and program leadership
Who need a substantiated readiness roadmap and clear priorities toward 2 December 2027.
Afterwards you know
Which use cases are high-risk under Annex III
Whether you are provider or deployer per use case
What the FRIA Article 27 requires of you
What must go into the algorithm register and when
Which actions toward 2 December 2027 are priority
Logical next steps
AI Act readiness and gap analysis
For a broader view of AI systems, roles, risks and evidence in one roadmap.
View routeFRIA and DPIA for AI systems
For the fundamental rights impact assessment and the link with the DPIA per use case.
View routeAI inventory setup
For a compact inventory of AI systems with owner, purpose and evidence status, aligned with the algorithm register.
View routeBackground and legal interpretation
Deeper analysis on the Responsible AI Platform about high-risk AI, the FRIA and the position of the public sector:
Frequently asked questions
Is the high-risk regime now postponed for government?
The political agreement on the Digital Omnibus moves the Annex III high-risk regime to 2 December 2027. That agreement is not yet applicable law: until publication in the Official Journal, the original timeline formally stands. For the public sector, postponement is moreover no reason to wait. Registration, an evidence file and a FRIA take lead time, and the Dutch algorithm register and fundamental rights assessment apply separately from the EU timeline.
Do benefits and fraud detection really fall under high-risk?
AI for access to and granting of benefits and essential public services falls under Annex III and is therefore high-risk. Risk profiling and fraud detection toward citizens are extra sensitive on fundamental rights. We test per use case whether it falls under Annex III.
What is a FRIA and when must it be ready?
A FRIA is the fundamental rights impact assessment of Article 27. Public bodies and providers of public services must carry it out for high-risk AI before the system is put into use. The duty follows the high-risk date of 2 December 2027, but building the evidence takes lead time.
How does this relate to the algorithm register and IAMA?
The Dutch algorithm register and the IAMA instrument are separate from the EU AI Act but partly overlap with it. We map the coherence with the AI Act, the GDPR and the DPIA so you build a shared evidence file instead of doing the same work four times.
Is this legal advice?
No. This is a practical readiness check and its execution. We structure use cases, risk classes, roles, FRIA and register so the board, legal affairs, privacy and IT can act in a focused way. For formal legal interpretation and fundamental rights assessments we refer to the Responsible AI Platform, and AI literacy we place with LearnWize.
Get ahead of the high-risk regime.
Start with the readiness check. We determine which AI and algorithm use cases belong in scope, which fall under Annex III and what FRIA and algorithm register require of you.