Industry Guide 11 min read

Government AI Procurement: How Public Sector Bodies Must Adapt Their Purchasing Rules

Public authorities are among the largest deployers of AI systems in Europe. The EU AI Act places specific obligations on government bodies — and fundamentally changes how they must procure and oversee AI.

By Dr. Henri Dubois · Published

Government as AI Deployer: Unique Obligations

From social benefits assessment to border control, public sector bodies across the EU rely on AI systems to make or assist in decisions that directly affect citizens' lives. Unlike commercial organizations that might exit markets to avoid AI Act obligations, government bodies have statutory duties to continue operating — they must comply with the AI Act in everything they do.

Which Government AI Applications Are High-Risk?

Public sector AI spans several high-risk Annex III categories: biometric identification (border control, identity verification), critical infrastructure management (power grids, water systems), law enforcement AI (predictive policing, forensic AI, crime risk assessment), migration and border AI (visa assessment, asylum claim processing), administration of justice AI, and AI determining access to social benefits and essential services.

The FRIA Requirement

Public bodies deploying high-risk AI must conduct Fundamental Rights Impact Assessments (FRIAs) before deployment. A FRIA requires identifying all fundamental rights that may be affected, assessing the severity of impact on each right, identifying groups most at risk of disproportionate impact, determining mitigation measures, and consulting relevant stakeholders including civil society organizations. FRIAs must be documented, registered with relevant authorities, and updated whenever the AI system materially changes.

Transforming Procurement Processes

Government AI procurement must change fundamentally. Before any AI procurement, public bodies should determine whether the proposed system is high-risk under Annex III. Procurement specifications for high-risk AI must now include requirements for Annex IV technical documentation, demonstrated bias testing results, post-market monitoring capabilities, human oversight interfaces, and contractual commitments to maintain compliance as the system evolves.

Need AI Act compliance support for public sector organizations? Browse our directory of consultants with government and public administration AI expertise.