Skip to Content
Rows of colorful ring binders organized on wooden shelves in an office
woman in white long sleeve shirt sitting on red couch
stacks of paper documents and file folders
A european street scene with church and flags.

AI Act Audit for Government Agencies


Deciding whether to grant access to services is high-risk. Checking a file for completeness is not

Governments have a dual role. Systems that determine whether someone is eligible for benefits or essential public services are listed in Annex III. The same applies to risk assessments in the context of enforcement. Administrative applications, such as completeness checks or deadline monitoring, are generally excluded from this.

For government agencies, there is an additional requirement that private organizations do not have: in certain cases, you must conduct an assessment of the impact on fundamental rights before putting a system into use. This is a separate obligation, distinct from the data protection impact assessment with which you may already be familiar.

And as soon as a citizen communicates directly with an AI system, the transparency requirement set forth in Article 50 applies. This requirement has been in effect since August 2, 2026.

 

1

Decision or Support

We are examining which systems play a role in deciding citizens’ rights and which merely prepare the groundwork. A completeness check is different from a score that determines which cases will undergo further review.

We are also examining whether, in practice, civil servants have the flexibility to deviate from what the system indicates.

2

Enforcement and Risk Selection

 Models that select citizens or cases for review deserve a separate review.

We assess the basis for the selection, which characteristics indirectly refer to protected grounds, and whether the outcome can be traced back to the individual concerned.

3

Fundamental Rights and Transparency

 We determine which of your systems require a fundamental rights impact assessment and how that relates to your existing DPIA’s.

In addition, we identify the situations in which citizens come into direct contact with an AI system and what information you should provide them in those situations.

4

Procured AI systems and public tenders

Most AI enters the organisation through a supplier or a framework agreement.

We determine who is the provider and who is the deployer, and which requirements you should include in your next tender to avoid taking on those obligations yourself

What you receive


An inventory of the AI systems within scope, a qualification for each system, and a prioritised list of the gaps identified. The qualification is the work of the affiliated lawyers, acting in their own name and under their own professional indemnity insurance.

We carry out the audit and compile the report. We do not assess conformity and we do not issue certificates.

After the audit,

Automation


The remediation plan is yours. You can carry it out in-house, with your existing supplier, or with us.

If the audit shows that your AI systems run on US infrastructure and you want that to change, that is a separate question.

That is what we are developing Thor for: a self-hosted environment in which your business data does not leave Europe. Development starts on 1 November 2026 and runs for six months, against thresholds set in advance. It is a separate engagement, not a follow-on from the audit.


The development timeline →