EU AI Act · use case
EU AI Act for Public Benefits Eligibility AI: High-Risk Requirements
AI that decides eligibility for public assistance, benefits or essential public services is high-risk under Annex III(5)(a). What GovTech vendors and public bodies must do.
Classify my system in 3 minutesFree, no account. Pre-filled for this use case.
Risk tier
High-risk
High-risk (Annex III, point 5(a))
When it applies
High-risk obligations apply from 2 December 2027.
Regulation (EU) 2024/1689, Annex III(5)(a); Art. 27 fundamental rights impact assessment; Art. 26 deployer duties
AI that decides whether someone gets unemployment benefit, housing support, disability assistance, energy subsidies or access to essential public services is high-risk under the EU AI Act. This is a separate Annex III entry from credit scoring and insurance: it is about the state’s relationship with people who often have no alternative provider and no easy way to opt out.
This page is for GovTech vendors building eligibility engines, municipalities and welfare agencies automating case triage, and any company selling automated decision tools to the public sector. It also covers systems that only flag cases for human review, because Annex III looks at intended use, not at who signs off.
Classification
Why this classification applies
Annex III, point 5(a) lists AI systems “intended to be used by or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke or reclaim such benefits and services”. Eligibility scoring, fraud-risk triage that affects a real person’s benefit, and automated reduction or clawback decisions all fit this description.
The recitals are explicit about why: these systems can have a very significant impact on people’s livelihoods and can violate fundamental rights, and errors disproportionately affect people who already depend on the state. A tool that only helps caseworkers search internal policy documents, without touching an individual’s eligibility outcome, is a weaker candidate for the entry — but the moment its output changes what a specific claimant receives, it is in scope.
The Art. 6(3) narrow-procedural-task exception is unlikely to help here for the same reason it does not help recruitment tools: assessing an individual’s eligibility is profiling a natural person, and the Act treats profiling systems as high-risk regardless of how “assistive” the framing is.
Obligations
What you have to do
- Risk management system with explicit attention to discrimination against protected and socio-economic groups (Art. 9).
- Data governance: representativeness of training data for the claimant population, examination of proxies for protected characteristics such as postcode, household composition or migration status (Art. 10).
- Technical documentation, automatic logging, and record retention (Arts. 11, 12).
- Human oversight that lets a caseworker see the basis of a decision, override it, and stop the system, with safeguards against automation bias (Art. 14).
- Conformity assessment, EU declaration of conformity, CE marking, EU database registration (Arts. 43, 47, 48, 49).
- Deployers that are public authorities must complete a fundamental rights impact assessment before first use and register that assessment (Art. 27).
- Claimants affected by a decision have a right to a clear explanation of the role the AI played and a route to contest it (Art. 86).
- Post-market monitoring and serious-incident reporting, coordinated with the public body’s own complaints and appeals process (Arts. 72, 73).
Paperwork
Documents to have on file
Get these documents drafted for your system
Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.
Common mistakes
Where companies get this wrong
- Calling a fraud-risk flag “advisory only” when caseworkers routinely follow it. The Act looks at real-world effect, not the label on the feature.
- Training on historical claims data without checking whether past enforcement patterns already encode bias against particular groups or areas.
- No claimant-facing explanation. A benefits decision without a human contact point is both a compliance gap and a due-process problem.
- Assuming a procurement contract with a public body shifts all AI Act duties to the buyer. The vendor is normally still the provider with the full documentation and conformity-assessment burden.
FAQ
Frequently asked questions
Does this cover healthcare eligibility, not just cash benefits?
Yes. The Annex III(5)(a) wording explicitly includes healthcare services alongside other essential public assistance, so triage or eligibility tools for public healthcare access are covered on the same basis.
We sell a case-management tool that public bodies configure themselves. Are we the provider?
If your software performs the eligibility evaluation or decision logic, you are very likely the provider even if the public body configures thresholds. Configurability does not transfer the provider role; a substantial modification by the deployer might.
Is a chatbot that answers benefits questions in scope?
A pure information chatbot that does not affect eligibility is limited-risk under Article 50, not Annex III(5)(a). It becomes high-risk the moment its output is used to grant, reduce or deny a specific claim.
This page is general information about Regulation (EU) 2024/1689, updated 2026-09-25. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026.