EuroComply
Free assessment

EU AI Act · use case

EU AI Act for Public Benefits Eligibility AI: High-Risk Requirements

AI that decides eligibility for public assistance, benefits or essential public services is high-risk under Annex III(5)(a). What GovTech vendors and public bodies must do.

Classify my system in 3 minutes

Free, no account. Pre-filled for this use case.

Risk tier

High-risk

High-risk (Annex III, point 5(a))

When it applies

High-risk obligations apply from 2 December 2027.

Regulation (EU) 2024/1689, Annex III(5)(a); Art. 27 fundamental rights impact assessment; Art. 26 deployer duties

AI that decides whether someone gets unemployment benefit, housing support, disability assistance, energy subsidies or access to essential public services is high-risk under the EU AI Act. This is a separate Annex III entry from credit scoring and insurance: it is about the state’s relationship with people who often have no alternative provider and no easy way to opt out.

This page is for GovTech vendors building eligibility engines, municipalities and welfare agencies automating case triage, and any company selling automated decision tools to the public sector. It also covers systems that only flag cases for human review, because Annex III looks at intended use, not at who signs off.

Classification

Why this classification applies

Annex III, point 5(a) lists AI systems “intended to be used by or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke or reclaim such benefits and services”. Eligibility scoring, fraud-risk triage that affects a real person’s benefit, and automated reduction or clawback decisions all fit this description.

The recitals are explicit about why: these systems can have a very significant impact on people’s livelihoods and can violate fundamental rights, and errors disproportionately affect people who already depend on the state. A tool that only helps caseworkers search internal policy documents, without touching an individual’s eligibility outcome, is a weaker candidate for the entry — but the moment its output changes what a specific claimant receives, it is in scope.

The Art. 6(3) narrow-procedural-task exception is unlikely to help here for the same reason it does not help recruitment tools: assessing an individual’s eligibility is profiling a natural person, and the Act treats profiling systems as high-risk regardless of how “assistive” the framing is.

Obligations

What you have to do

  • Risk management system with explicit attention to discrimination against protected and socio-economic groups (Art. 9).
  • Data governance: representativeness of training data for the claimant population, examination of proxies for protected characteristics such as postcode, household composition or migration status (Art. 10).
  • Technical documentation, automatic logging, and record retention (Arts. 11, 12).
  • Human oversight that lets a caseworker see the basis of a decision, override it, and stop the system, with safeguards against automation bias (Art. 14).
  • Conformity assessment, EU declaration of conformity, CE marking, EU database registration (Arts. 43, 47, 48, 49).
  • Deployers that are public authorities must complete a fundamental rights impact assessment before first use and register that assessment (Art. 27).
  • Claimants affected by a decision have a right to a clear explanation of the role the AI played and a route to contest it (Art. 86).
  • Post-market monitoring and serious-incident reporting, coordinated with the public body’s own complaints and appeals process (Arts. 72, 73).

Paperwork

Documents to have on file

Annex IV technical documentation
Risk management file with socio-economic bias analysis
Data governance records
Human oversight procedure for caseworkers
Fundamental rights impact assessment (Art. 27)
Instructions for use for the public body
EU declaration of conformity and EU database registration
Claimant-facing explanation and appeal notice

Get these documents drafted for your system

Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.

Start free assessment

Common mistakes

Where companies get this wrong

  • Calling a fraud-risk flag “advisory only” when caseworkers routinely follow it. The Act looks at real-world effect, not the label on the feature.
  • Training on historical claims data without checking whether past enforcement patterns already encode bias against particular groups or areas.
  • No claimant-facing explanation. A benefits decision without a human contact point is both a compliance gap and a due-process problem.
  • Assuming a procurement contract with a public body shifts all AI Act duties to the buyer. The vendor is normally still the provider with the full documentation and conformity-assessment burden.

FAQ

Frequently asked questions

Does this cover healthcare eligibility, not just cash benefits?

Yes. The Annex III(5)(a) wording explicitly includes healthcare services alongside other essential public assistance, so triage or eligibility tools for public healthcare access are covered on the same basis.

We sell a case-management tool that public bodies configure themselves. Are we the provider?

If your software performs the eligibility evaluation or decision logic, you are very likely the provider even if the public body configures thresholds. Configurability does not transfer the provider role; a substantial modification by the deployer might.

Is a chatbot that answers benefits questions in scope?

A pure information chatbot that does not affect eligibility is limited-risk under Article 50, not Annex III(5)(a). It becomes high-risk the moment its output is used to grant, reduce or deny a specific claim.

This page is general information about Regulation (EU) 2024/1689, updated 2026-09-25. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026.

Related use cases

High-risk

Credit scoring & lending

Read →

Depends on use

Insurance risk assessment & pricing

Read →

High-risk

Recruitment & CV screening

Read →

Guide

EU AI Act compliance guide

Read →