By role · Public authority / government body
AI regulation for public bodies and government
Public bodies are deployers with extra duties: impact assessment before use, public registers of systems, procurement rules that pass duties to suppliers, and explanations to people affected by automated decisions. Several jurisdictions regulate government use of AI before, or instead of, private use.
- Jurisdictions
- 7
- Evidence items
- 64
Procurement as the control point
For a public body most AI arrives through a contract. The contractual allocation of duties, the supplier's documentation and the right to audit are where governance is won or lost, which is why contractual controls carry as much weight below as technical ones.
Transparency to the public
Registers, notices and explanations are duties in their own right, and they are the evidence an auditor or a court will ask for first.
Which controls meet these duties?
Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.
| Control | Satisfies | Supports | Owner · frequency |
|---|---|---|---|
| AI interaction and use disclosure notices Process | 4 | 2 | Product owner · at launch and on material change |
| Decision explanation, human review and appeal route Process | 4 | 1 | Customer operations lead · once per ai system |
| Prohibited and unacceptable-use screening gate Process | 4 | 1 | AI governance lead · once per ai system |
| Privacy and data-protection controls for AI Process | 3 | 3 | Data protection officer · once per ai system |
| AI impact and fundamental-rights impact assessment Process | 2 | 4 | AI system owner · once per ai system |
| Public-sector AI use-case register and algorithmic transparency Process | 2 | 4 | Agency AI officer · annual |
| Human oversight design and override procedure Process | 1 | 5 | AI system owner · once per ai system |
| Technical documentation, model cards and instructions for use Process | 1 | 2 | Product or model owner · at launch and on material change |
| Post-deployment monitoring and drift detection Technical measure | 1 | 2 | AI system owner · continuous |
| Conformity assessment, declaration and registration Process | 1 | 0 | Regulatory compliance lead · once per ai system |
| Synthetic content labelling and provenance marking Technical measure | 1 | 0 | Engineering lead · continuous |
| Data governance and dataset documentation Process | 1 | 0 | Data governance lead · once per ai system |
| AI incident management and regulatory reporting Process | 1 | 0 | Incident coordinator · continuous |
| AI risk assessment and lifecycle risk register Process | 1 | 0 | AI system owner · once per ai system |
| AI governance policy and accountability structure Policy | 0 | 5 | Executive sponsor for AI · annual |
| AI system inventory and classification Process | 0 | 3 | AI governance lead · continuous |
| Accuracy, robustness, fairness and security testing Technical measure | 0 | 2 | Quality or testing lead · at launch and on material change |
| Automatic event logging and record retention Technical measure | 0 | 2 | Engineering lead · continuous |
| Training-data provenance and copyright register Process | 0 | 1 | Model development lead · at launch and on material change |
| Quality management system for AI development and supply Policy | 0 | 1 | Quality lead · annual |
| Vendor and third-party AI due diligence Process | 0 | 1 | Procurement or vendor risk lead · once per ai system |
Which duties are recorded?
Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).
European Union 14 duties
-
Legal requirementEU AI Act · Article 27applies from 2 Aug 2026Carry out a fundamental rights impact assessment before deployment
-
Legal requirementEU AI Act · Articles 43, 47, 48 and 49; Annex VIIIapplies from 2 Aug 2026Complete conformity assessment, CE marking and EU database registration
-
Legal requirementEU AI Act · Article 50(4)applies from 2 Aug 2026Deployers must disclose deepfakes and AI-generated text published on matters of public interest
-
Legal requirementEU AI Act · Article 26(4)applies from 2 Aug 2026Deployers must ensure input data they control is relevant and representative
-
Legal requirementEU AI Act · Article 86applies from 2 Aug 2026Deployers must explain individual decisions taken with high-risk AI on request
-
Legal requirementEU AI Act · Article 26(5)applies from 2 Aug 2026Deployers must monitor high-risk AI, suspend use on risk and report serious incidents
-
Legal requirementEU AI Act · Article 26(11)applies from 2 Aug 2026Deployers must tell natural persons that a high-risk AI system is used in decisions about them
-
Legal requirementEU AI Act · Article 26(9)applies from 2 Aug 2026Deployers must use the provider's transparency information in their data protection impact assessment
-
Legal requirementEU AI Act · Article 50(3)applies from 2 Aug 2026Deployers of emotion recognition or biometric categorisation must inform exposed persons
-
Legal requirementEU AI Act · Article 5applies from 2 Feb 2025Do not deploy or provide AI for prohibited practices
-
Legal requirementEU AI Act · Article 26(7)applies from 2 Aug 2026Employers must inform workers and their representatives before using high-risk AI at work
-
Legal requirementEU AI Act · Article 26(10)applies from 2 Aug 2026Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
-
Legal requirementEU AI Act · Article 26(8); Article 49(3) and 49(4)applies from 2 Aug 2026Public authorities must register their use of high-risk AI and must not use unregistered systems
-
Legal requirementEU AI Act · Article 26applies from 2 Aug 2026Use high-risk AI as instructed, monitor it and inform affected people
Nepal 2 duties
-
Legal requirementNepal Privacy Act 2075 · Chapter on collection and protection of personal information (reviewer to cite sections)Collect and use personal information only with consent and for the stated purpose
-
VoluntaryNepal National AI Policy · Policy objectives and strategies (to be confirmed against the official text)Government bodies to promote ethical, responsible and inclusive AI (policy commitment)
South Korea 5 duties
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must be able to explain outputs and the main criteria behind them
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must ensure human management and supervision
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must establish and operate a risk management plan
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
-
VoluntaryFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 35applies from 22 Jan 2026Operators of high-impact AI should assess its impact on fundamental rights before use
Texas (United States) 4 duties
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.056applies from 1 Jan 2026Developers and deployers must not use AI with the intent to unlawfully discriminate against a protected class
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.051applies from 1 Jan 2026Government agencies must disclose to consumers that they are interacting with an AI system
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.054applies from 1 Jan 2026Governmental entities must not use AI for biometric identification from public data without consent where it infringes rights
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.053applies from 1 Jan 2026Governmental entities must not use AI for social scoring
United Arab Emirates 1 duty
-
VoluntaryUAE AI Strategy 2031 · Strategy objectives on governance and ethics (reviewer to cite the section)Government commitment to AI ethics, governance and regulation (strategy objective)
United Kingdom 3 duties
-
Legal requirementICO AI guidance · UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025Apply safeguards to solely automated decisions with significant effects
-
Legal requirementICO AI guidance · UK GDPR Article 35; ICO guidance, accountability and governance sectionCarry out a data protection impact assessment for high-risk AI processing
-
VoluntaryUK AI regulation framework · Principle 5, Part 3Provide routes to contest AI outcomes and seek redress
United States 3 duties
-
Legal requirementOMB M-25-21 · Section 4Apply minimum risk-management practices to high-impact AI
-
Legal requirementEO 14179 · Section 5Federal agencies must review and revise actions inconsistent with the new AI policy
-
Legal requirementOMB M-25-21 · Section 3Publish an annual AI use-case inventory
What evidence would a reviewer expect?
- AI data-flow and legal-basis record Register entry
- AI decision challenge and human review procedure Procedure or standard operating process
- AI governance forum minutes Governance meeting record
- AI impact assessment Impact assessment
- AI incident record Incident record
- AI incident response playbook Procedure or standard operating process
- AI intake and classification procedure Procedure or standard operating process
- AI interaction or use notice Disclosure or notice
- AI policy Policy document
- AI quality management system manual Policy document
- AI responsibility map Register entry
- AI supplier and component register Register entry
- AI supplier due-diligence assessment Supplier assessment
- AI system event logs Access or activity log
- AI system register Register entry
- AI system risk assessment Risk assessment
- Adverse-decision explanation template Disclosure or notice
- Algorithmic transparency statement for one use case Disclosure or notice
- Board or executive approval of the AI policy Approval or sign-off record
- Challenge and reversal log Monitoring record
- Conformity evidence pack Technical documentation file
- Content labelling and provenance standard Procedure or standard operating process
- Copyright and rights-reservation policy Policy document
- Data protection impact assessment for an AI system Data protection impact assessment
- Data quality and bias check report Evaluation or test report
- Dataset approval for use Approval or sign-off record
- Dataset documentation sheet Dataset documentation
- Declaration of conformity or certificate Conformity declaration or certificate
- Human oversight and override procedure Procedure or standard operating process
- Human-involvement design rationale Approval or sign-off record
- Impact assessment approval Approval or sign-off record
- Impact assessment procedure and template Procedure or standard operating process
- Incident report to an authority Regulatory filing or notification
- Independent data audit or DPO review Audit or assurance report
- Instructions for use Disclosure or notice
- Internal audit of the AI management system Audit or assurance report
- Inventory review and publication sign-off Approval or sign-off record
- Log integrity and retention check Audit or assurance report
- Log schema and retention standard Procedure or standard operating process
- Management review minutes Governance meeting record
- Model card or deployer information pack Model documentation
- Monitoring dashboard or periodic monitoring report Monitoring record
- Monitoring review decision Approval or sign-off record
- Notice catalogue Register entry
- Notice wording approval Approval or sign-off record
- Overseer training completion Training record
- Per-system AI risk register Risk register
- Post-market monitoring plan Procedure or standard operating process
- Pre-release test report Evaluation or test report
- Privacy notice section on AI use Disclosure or notice
- Prohibited-use screening record Approval or sign-off record
- Public AI use-case inventory Register entry
- Public summary of training content Disclosure or notice
- Registration record in the relevant database Regulatory filing or notification
- Release test sign-off Approval or sign-off record
- Residual-risk acceptance Approval or sign-off record
- Risk-tier classification sign-off Approval or sign-off record
- Screening list and escalation procedure Procedure or standard operating process
- Supplier onboarding decision Approval or sign-off record
- Technical documentation file Technical documentation file
- Test plan and acceptance criteria Procedure or standard operating process
- Training source register Register entry
- Visible AI-generated content label Disclosure or notice
- Watermark and provenance robustness test Evaluation or test report
Latest changes to these instruments
Texas TRAIGA takes effect
European Commission proposes Digital Omnibus adjustments to AI Act timelines
EU AI Act general-purpose AI, governance and penalty provisions start to apply
Nepal's Council of Ministers approves the National AI Policy
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Do government AI rules apply to contractors?
- Frequently, through the contract or through procurement rules that require suppliers to meet the same standard. The duty pages say which instrument and article.
- What should a public body publish?
- At minimum an inventory or register entry per system and a notice where a decision about a person is automated; several instruments require an impact assessment to be published or available on request.