Local authorities — Compliance

The AI Act: what local authorities need to know

Risk levels, deployer obligations, AI literacy and the timeline of application. The complete reference for local authorities that deploy, or are considering deploying, AI systems.

The European regulation on artificial intelligence (known as the “AI Act”) came into force in August 2024. It classifies AI systems according to their level of risk and imposes progressive obligations on the actors that develop or deploy them — including public administrations and local authorities. A local authority that deploys an AI tool is, in the vast majority of cases, a deployer within the meaning of the regulation.

Source: DGE / entreprises.gouv.fr — timeline and audiences concerned.


Provider or deployer: which role for a local authority?

The provider is the entity that develops, or has developed, an AI system with a view to placing it on the market or putting it into service. If your authority has an AI tool built to order by a contractor, the contractor is the provider — and it bears the most significant obligations regarding documentation, testing and registration.

The deployer is the entity that uses an AI system developed by a third party within its own processes. This is the local authority's role in the vast majority of situations.

The deployer does not have to produce the technical documentation for the model — but it must ensure that the conditions of use set by the provider are respected, put human oversight in place, and guarantee the AI literacy of its teams.

A local authority that has a bespoke tool developed by Groupe Milestone can validate with us the precise allocation of obligations, which makes reaching compliance simpler.


The 4 risk levels and the prohibited practices

Risk levelDescriptionExamples in the public sectorRegime
Unacceptable riskExpressly prohibited practicesSocial scoring of citizens, real-time biometric identification in public spaces, behavioural manipulationProhibited since February 2025
High riskSystems that can affect fundamental rightsAI for granting social benefits, staff selection, school assessment, critical infrastructureReinforced obligations — applicable from August 2026
Limited riskSystems with transparency obligationsChatbots, content-generation systemsObligation to inform the user that they are interacting with an AI
Minimal riskSystems with no significant identified impactInternal productivity tools, spam filtersNo specific obligation under the regulation

The practices prohibited since February 2025

  • Social scoring systems (assessing citizens to assign them a score that determines access to services).
  • Real-time remote biometric identification in publicly accessible spaces, save for strictly framed exceptions.
  • Behavioural manipulation systems that exploit psychological vulnerabilities.
  • Emotion-inference systems in workplace or educational settings.

Your obligations as a deployer

For all AI systems

AI literacy: ensuring that the officers who use AI systems have a sufficient level of understanding to use them appropriately. This obligation came into application in February 2025 — it applies from today, whatever the system's risk level.

For limited-risk systems

Transparency: informing users when they are interacting with an AI system (chatbot, virtual assistant).

For high-risk systems (applicable from August 2026)

  • Human oversight: mechanisms allowing a human operator to intervene, correct or suspend the system at any time.
  • Data control: ensuring that input data is relevant and representative for the intended use.
  • Keeping an event log (logs) that makes it possible to trace the system's use.
  • Fundamental rights impact assessment before deployment.
  • Informing and training the officers who use the system.
  • Reporting incidents to the competent authorities if a system causes serious harm.

The timeline of application

DateObligation
13 March 2024Adoption of the regulation by the European Parliament (plenary vote)
12 July 2024Publication in the Official Journal of the European Union
August 2024Entry into force of the regulation
2 February 2025Application of the prohibitions (unacceptable-risk practices) + AI literacy obligation for all deployers
2 August 2025Application of the rules on general-purpose AI models (GPAI) + designation of the competent national authorities
2 August 2026Full obligations for high-risk systems
2 August 2027Extension to high-risk systems embedded in regulated products

Note: this timeline is the one published by the DGE / entreprises.gouv.fr at the time of writing (June 2026). European regulations may be further clarified in national implementing texts.


Reconciling the AI Act with a bespoke project

The good news for local authorities that have bespoke tools developed: AI Act compliance is far easier to build in from the outset than to retrofit.

A tool designed from the start with the right architecture — built-in human oversight, traceability of decisions, technical documentation, mechanisms for informing users — is compliant without any major additional cost. A generic tool bought without a compliance audit may require costly adaptations.

At Groupe Milestone, regulatory compliance is part of the initial scoping of every project: we identify the applicable AI Act risk level, the corresponding obligations, and we translate them into technical requirements in the development.

Discover our Consulting & audit service and our approach to Bespoke business applications.

For scoping within public procurement: Commissioning a bespoke AI business application for your local authority.

For the related GDPR questions, see the GDPR and AI Act section of our pillar page.

This article is an informative reference — it does not constitute legal advice. For specific projects, support from specialist legal counsel is recommended.

Frequently asked questions

Is the local authority a provider or a deployer under the AI Act?
In the vast majority of cases, a local authority that uses an AI tool — whether bought off the shelf or developed to order — is a deployer. It did not design the underlying model. The provider is the contractor or vendor that developed the system. This distinction determines how obligations are shared: the provider is responsible for the technical documentation and testing; the deployer ensures proper use and human oversight.
What is AI literacy, and how do you put it in place?
AI literacy refers to the ability of the people who use or oversee AI systems to understand how they work, their limits and their risks. This obligation came into application in February 2025. In practice, it means training and awareness measures tailored to each person's role: an officer who uses a chatbot does not need the same knowledge as an IT manager overseeing the system.
When do the obligations for high-risk systems apply?
The full obligations for systems classified as high-risk apply from 2 August 2026. A system is high-risk if it is liable to affect fundamental rights: systems linked to the granting of social benefits, to school assessment, to staff selection, to the management of critical infrastructure, and so on.
Is an information chatbot for citizens high-risk?
No, in most cases. An information chatbot (answering frequently asked questions, directing people to the right services) is generally classified as limited-risk: the obligations are mainly about transparency (informing the user that they are interacting with an AI). However, if the chatbot makes decisions that affect a citizen's rights (granting a benefit, refusing access to a service), the risk level may be reclassified upwards.
Does the AI Act apply to AI tools already in production before August 2024?
Systems put into service before the regulation came into force in principle benefit from a transitional regime, with time to reach compliance — provided they have not been substantially modified since. A compliance audit of existing systems is recommended to assess the situation.

Sources

  • DGE / entreprises.gouv.fr, “The European regulation on artificial intelligence — audiences concerned” (official source, timeline)
  • Leto.legal, competent authorities in France (AI Act)
  • CNIL, official website
  • Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act)

A project or a business challenge?

A first 30-minute conversation to understand your context and assess how we can help. No commitment.

Let's talk about your project