AIPolicyTracker
Legal requirement Public-sector use and procurement European Union Partially applicable

Public authorities must register their use of high-risk AI and must not use unregistered systems

Context fileUnder EU AI Act, Article 26(8); Article 49(3) and 49(4)

Source-linked Open official source

What does it require?

Deployers that are public authorities or Union institutions, bodies, offices or agencies must register their use of an Annex III high-risk AI system in the EU database before putting it into service. If they find that the system they intend to use has not been registered in the database by its provider, they must not use it and must inform the provider or distributor.

Practical action

Check the EU database entry for the provider's system as a procurement acceptance criterion, then register the deployment before go-live.

Who does it apply to?

Public authorities and EU bodies deploying Annex III high-risk AI systems, other than the law-enforcement and migration systems that are registered in the secure non-public section.

Applies from:

Which controls meet this duty?

Satisfies: the control, operated properly, does the work the duty asks for. Supports: it contributes but the duty needs more. Each control page lists every other duty it serves, so work done once can be counted once.

  • satisfiesProcessAgency AI officer · annual
    Public-sector AI use-case register and algorithmic transparency

    Serves 6 recorded duties · evidence: Public AI use-case inventory, Algorithmic transparency statement for one use case, Inventory review and publication sign-off

    Registration of public-authority use with the required Annex VIII information.

  • supportsProcessProcurement or vendor risk lead · once per ai system
    Vendor and third-party AI due diligence

    Serves 6 recorded duties · evidence: AI supplier due-diligence assessment, AI supplier and component register, Supplier onboarding decision

    Verifies the provider's registration before purchase.

What evidence would a reviewer expect?

Evidence examples
EvidenceTypeNotes
EU database deployer registration recordregister
Procurement acceptance checklist with registration checkrecord

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

See every European Union duty mapped this way →

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Annex A.8.2, A.8.5System documentation and information for interested parties.medium
NIST AI RMF 1.0GOVERN 1.6, MAP 1.1Inventory of deployed systems and context.medium

Cite this record

AIPolicyTracker (2026). “Public authorities must register their use of high-risk AI and must not use unregistered systems (EU AI Act)”. https://aipolicytracker.org/obligations/eu-ai-act-art-26-8-public-authority-registration-before-use (accessed 24 September 2026). Data licensed CC BY 4.0.

Cite the official text alongside it: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, Official Journal of the European Union, https://eur-lex.europa.eu/eli/reg/2024/1689/oj.

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.