The AI Act: what local authorities need to know
Risk levels, deployer obligations, AI literacy and the timeline of application. The complete reference for local authorities that deploy, or are considering deploying, AI systems.
The European regulation on artificial intelligence (known as the “AI Act”) came into force in August 2024. It classifies AI systems according to their level of risk and imposes progressive obligations on the actors that develop or deploy them — including public administrations and local authorities. A local authority that deploys an AI tool is, in the vast majority of cases, a deployer within the meaning of the regulation.
Source: DGE / entreprises.gouv.fr — timeline and audiences concerned.
Provider or deployer: which role for a local authority?
The provider is the entity that develops, or has developed, an AI system with a view to placing it on the market or putting it into service. If your authority has an AI tool built to order by a contractor, the contractor is the provider — and it bears the most significant obligations regarding documentation, testing and registration.
The deployer is the entity that uses an AI system developed by a third party within its own processes. This is the local authority's role in the vast majority of situations.
The deployer does not have to produce the technical documentation for the model — but it must ensure that the conditions of use set by the provider are respected, put human oversight in place, and guarantee the AI literacy of its teams.
A local authority that has a bespoke tool developed by Groupe Milestone can validate with us the precise allocation of obligations, which makes reaching compliance simpler.
The 4 risk levels and the prohibited practices
| Risk level | Description | Examples in the public sector | Regime |
|---|---|---|---|
| Unacceptable risk | Expressly prohibited practices | Social scoring of citizens, real-time biometric identification in public spaces, behavioural manipulation | Prohibited since February 2025 |
| High risk | Systems that can affect fundamental rights | AI for granting social benefits, staff selection, school assessment, critical infrastructure | Reinforced obligations — applicable from August 2026 |
| Limited risk | Systems with transparency obligations | Chatbots, content-generation systems | Obligation to inform the user that they are interacting with an AI |
| Minimal risk | Systems with no significant identified impact | Internal productivity tools, spam filters | No specific obligation under the regulation |
The practices prohibited since February 2025
- Social scoring systems (assessing citizens to assign them a score that determines access to services).
- Real-time remote biometric identification in publicly accessible spaces, save for strictly framed exceptions.
- Behavioural manipulation systems that exploit psychological vulnerabilities.
- Emotion-inference systems in workplace or educational settings.
Your obligations as a deployer
For all AI systems
AI literacy: ensuring that the officers who use AI systems have a sufficient level of understanding to use them appropriately. This obligation came into application in February 2025 — it applies from today, whatever the system's risk level.
For limited-risk systems
Transparency: informing users when they are interacting with an AI system (chatbot, virtual assistant).
For high-risk systems (applicable from August 2026)
- Human oversight: mechanisms allowing a human operator to intervene, correct or suspend the system at any time.
- Data control: ensuring that input data is relevant and representative for the intended use.
- Keeping an event log (logs) that makes it possible to trace the system's use.
- Fundamental rights impact assessment before deployment.
- Informing and training the officers who use the system.
- Reporting incidents to the competent authorities if a system causes serious harm.
The timeline of application
| Date | Obligation |
|---|---|
| 13 March 2024 | Adoption of the regulation by the European Parliament (plenary vote) |
| 12 July 2024 | Publication in the Official Journal of the European Union |
| August 2024 | Entry into force of the regulation |
| 2 February 2025 | Application of the prohibitions (unacceptable-risk practices) + AI literacy obligation for all deployers |
| 2 August 2025 | Application of the rules on general-purpose AI models (GPAI) + designation of the competent national authorities |
| 2 August 2026 | Full obligations for high-risk systems |
| 2 August 2027 | Extension to high-risk systems embedded in regulated products |
Note: this timeline is the one published by the DGE / entreprises.gouv.fr at the time of writing (June 2026). European regulations may be further clarified in national implementing texts.
Reconciling the AI Act with a bespoke project
The good news for local authorities that have bespoke tools developed: AI Act compliance is far easier to build in from the outset than to retrofit.
A tool designed from the start with the right architecture — built-in human oversight, traceability of decisions, technical documentation, mechanisms for informing users — is compliant without any major additional cost. A generic tool bought without a compliance audit may require costly adaptations.
At Groupe Milestone, regulatory compliance is part of the initial scoping of every project: we identify the applicable AI Act risk level, the corresponding obligations, and we translate them into technical requirements in the development.
Discover our Consulting & audit service and our approach to Bespoke business applications.
For scoping within public procurement: Commissioning a bespoke AI business application for your local authority.
For the related GDPR questions, see the GDPR and AI Act section of our pillar page.
This article is an informative reference — it does not constitute legal advice. For specific projects, support from specialist legal counsel is recommended.
Frequently asked questions
Is the local authority a provider or a deployer under the AI Act?
What is AI literacy, and how do you put it in place?
When do the obligations for high-risk systems apply?
Is an information chatbot for citizens high-risk?
Does the AI Act apply to AI tools already in production before August 2024?
Sources
- DGE / entreprises.gouv.fr, “The European regulation on artificial intelligence — audiences concerned” (official source, timeline)
- Leto.legal, competent authorities in France (AI Act)
- CNIL, official website
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act)
A project or a business challenge?
A first 30-minute conversation to understand your context and assess how we can help. No commitment.
Let's talk about your project →