Public-Sector Transparency After the AI Act Became Applicable

The AI Act has been generally applicable in the European Union since 2 August 2026. This is an important regulatory milestone, but it does not mean that every major transparency obligation is already operational. For public authorities, one fact is especially important: the regime governing most high-risk systems listed in Annex III—including systems used in public services, education, employment, migration, law enforcement and the administration of justice—will apply from 2 December 2027.

That interval creates the first serious test of institutional accountability.

What are public authorities not yet required to do, and what can they do immediately?

Once the delayed regime becomes applicable, public authorities using covered high-risk AI systems will have to register their use in the European database. Subject to certain exceptions, that database should be public, easy to navigate and machine-readable. The public record will include information about the system, its intended purpose and a summary of the fundamental-rights impact assessment.

The delay in the statutory deadline does not mean that institutions should remain silent until then. Nothing prevents them from publishing now:

  • an inventory of AI systems that have been procured, tested or are already in use;
  • the name of the provider, model or product;
  • the purpose of the system and the processes it affects;
  • the institution’s assessment of whether the system falls within a high-risk category;
  • data-protection and fundamental-rights impact assessments;
  • human-oversight rules and complaint mechanisms;
  • a plan for future registration in the EU database.

The transition period as a space for institutional opacity

The public sector may already procure, test or use algorithmic systems while the harmonised public-registration duty has not yet begun. Information about those systems therefore remains scattered across procurement notices, contracts, budget documents, data-protection impact assessments, internal rules, audit reports and freedom-of-information responses.

This fragmentation creates at least three risks.

Invisible deployment

A system may move from procurement or pilot status into routine use without a clear public notice. Citizens may then be unaware that an algorithm is affecting a procedure, assessment or decision that directly concerns them.

Rebranding without scrutiny

An institution or provider may describe a system as “analytics,” “automation,” “administrative support” or a “decision-support tool” without publishing the reasoning behind the conclusion that the system is not high-risk.

Late and incomplete registration

When the registration obligation begins, the public record may show only the current situation, omitting earlier pilots, provider changes, model versions, discontinued projects or informal forms of use.

The EU database will not be evidence by itself

The future European database will be an important tool for public oversight, but it will primarily contain what institutions and providers have declared. It should therefore be treated as an index of institutional claims, not as conclusive proof that a declaration is complete and accurate.

Real verification requires comparing database entries with procurement records, contracts, technical specifications, impact assessments, testing records, budget allocations, internal policies and operational logs.

Verification principle: registration shows what an institution claims. Procurement documents, impact assessments and operational records show whether that claim is complete and credible.

What questions should public authorities answer now?

  • Which AI systems are currently being procured, tested, piloted or used in routine operations?
  • Who is responsible for each system and its classification?
  • Which systems process personal data or affect access to rights and public services?
  • Is there a complete internal inventory, including experimental and provider-operated tools?
  • When will fundamental-rights impact assessments be completed?
  • Will full assessments be made public, or only the statutory minimum?
  • How will the history of earlier system use be preserved?
  • How will the institution verify the information entered by the provider in the EU database?

The first test is not the deadline, but conduct before the deadline

The central question for 2026–2027 is not whether public authorities may formally wait for the registration obligation to begin. It is whether they will use that time to build complete, public and verifiable inventories—or preserve institutional opacity until the last possible moment.

An institution preparing seriously should, by 2027 at the latest, be able to clearly identify its systems, their owners, purposes, legal classifications, impact assessments, oversight arrangements and registration plans. If it cannot do so, the deficiency is no longer merely technical. It becomes a finding about the quality of governance.


This article was prepared on the basis of the first EU Compliance Watch publication: Watch Report ECW-WR-001, “The AI Act Is Now Applicable — But Will Public Authorities Disclose Their AI Systems?”

Leave a Comment