Context: AI Deployment as a Socio-Technical Governance Challenge
With the EU AI Act, the European Union has established, for the first time, a binding regulatory framework for the use of artificial intelligence (AI). This is of particular relevance for the public sector, as algorithmic systems are increasingly embedded in decision-making processes and thus directly affect administrative acts, resource allocation, and citizens’ rights.
From an information systems perspective, AI should not be understood as an isolated technology but as part of socio-technical systems in which data, algorithms, organizational processes, and human actors closely interact. Accordingly, the EU AI Act addresses not merely technical properties but primarily governance structures across the entire system lifecycle.
Risk-Based Regulatory Approach of the EU AI Act
The EU AI Act follows a risk-based classification approach, regulating AI systems according to their potential level of harm:
- Unacceptable risk: Systems that violate fundamental rights (e.g., social scoring by public authorities) are prohibited.
- High risk: Systems with significant impact on life circumstances or fundamental rights (e.g., allocation of benefits, access to education or employment).
- Limited risk: Systems subject to transparency obligations, particularly in user interactions (e.g., chatbots).
- Minimal risk: Systems without specific regulatory requirements.
For public administration, the category of high-risk AI is particularly critical, as many use cases—such as decision support in social welfare or automated classification of applications—fall under Annex III of the EU AI Act.
High-Risk AI in Public Administration: Characteristics and Examples
An AI system is typically classified as high risk if it:
- influences access to public services or government resources,
- is used to evaluate or classify natural persons,
- operates in safety-critical or infrastructure-related contexts.
For example, a system used to prioritize housing benefit applications falls into this category, as does AI-based decision support in employment services. In contrast, purely information-providing systems are primarily subject to transparency requirements.
Governance Requirements for High-Risk AI
The EU AI Act defines a comprehensive set of requirements, which from an information systems perspective can be interpreted as an integrated governance framework:
- Risk management: Continuous identification and mitigation of risks across the lifecycle (design, development, operation).
- Data governance: Ensuring data quality, representativeness, and bias control as prerequisites for valid models.
- Technical documentation: Transparent description of model logic, training data, and system limitations.
- Logging and auditability: End-to-end traceability of system decisions as a basis for regulatory oversight.
- Transparency: Disclosure of AI use to users and clear differentiation from human decision-making.
- Human oversight: Integration of control and escalation mechanisms (human-in-the-loop / human-on-the-loop).
- Robustness and security: Protection against errors, adversarial attacks, and system manipulation.
Importantly, the EU AI Act does not impose a blanket ban on automated decision-making; however, particularly for high-risk systems, it requires effective human oversight and the ability to intervene.
Implications for Information Systems: Process and Decision Integration
The regulatory requirements cannot be fulfilled at the level of technology alone. Rather, they require integration into existing organizational and process structures. This highlights the central role of the information systems discipline:
- Business Process Management (BPM): Modeling and standardization of administrative processes as a foundation for transparency and control.
- Decision Model and Notation (DMN): Explicit representation of algorithmic decision logic to ensure traceability.
- Data governance: Establishment of responsibilities, quality standards, and data flows.
- IT governance: Embedding AI systems within compliance, risk, and control frameworks.
This makes clear that AI governance is not an isolated compliance issue but an integral component of digital administrative architectures.
Recommendations for Public Authorities
- System inventory: Identify and classify all AI systems in accordance with the EU AI Act.
- Establish an AI register: Structured documentation, particularly for high-risk systems.
- Process modeling: Comprehensive modeling of AI-relevant processes using BPMN.
- Explicit decision logic: Use of DMN to formalize rule-based decisions.
- Control architecture: Definition of human-in-the-loop structures and escalation paths.
- Integration with data protection: Alignment with existing data protection impact assessments (DPIAs).
Conclusion: AI Compliance as a Function of Organizational Maturity
The EU AI Act should be understood less as a technological constraint and more as a governance framework for responsible AI use. For public administration, this implies that compliance is primarily a function of organizational maturity—particularly in process management, data governance, and decision architecture.
Public authorities that systematically develop these capabilities not only achieve regulatory compliance but also lay the foundation for scalable, trustworthy, and efficient AI applications.