A local council that launches a virtual assistant to serve its residents already falls within the scope of the EU AI Act, Regulation (EU) 2024/1689. The good news is that most of these assistants are not high-risk systems and their obligations are manageable; the bad news is that the timeline has changed three times, and many tender specifications and consultants are still quoting dates that no longer exist. This guide explains, on the basis of the text in force as at 16 September 2026 following the Digital Omnibus on AI, what a public authority that deploys AI is required to do today, what it will be required to do from December 2027, how to tell whether a system is high-risk and what the public body should require of its supplier. CEDESA has deployed conversational AI assistants in 33 rural municipalities in Extremadura, so we are writing from practical experience.
The timeline in force, after the Digital Omnibus
The AI Act entered into force on 1 August 2024 and applies in stages. Regulation (EU) 2026/1744 of 8 July 2026, known as the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force three days later. It moved the dates for high-risk systems and left the rest as they were. This is how the timeline now stands:
| Obligation | Date of application | Status as at 16 Sep 2026 |
|---|---|---|
| Prohibited practices (Article 5) and AI literacy measures (Article 4) | 2 February 2025 | In force |
| General-purpose AI models (Chapter V) | 2 August 2025 | In force |
| Transparency (Article 50): informing people that they are interacting with an AI, marking generated content | 2 August 2026 | In force, with a four-month grace period for marking in generative systems that predate that date |
| Governance, national authorities and penalties | 2 August 2026 | In force |
| High-risk systems in Annex III (those affecting public services, employment, education, biometrics, migration, justice) | 2 December 2027 (previously 2 August 2026) | Postponed by the Omnibus |
| High-risk systems in Annex I (safety components of regulated products) | 2 August 2028 (previously 2 August 2027) | Postponed by the Omnibus |
In Spain, the supervisory authority is the Spanish Agency for the Supervision of Artificial Intelligence (Agencia Española de Supervisión de la Inteligencia Artificial, AESIA), based in A Coruña, in coordination with the Spanish Data Protection Agency (AEPD) on matters relating to personal data and biometrics. The Spanish law that implements the penalty regime and the governance arrangements, the Organic Law Bill on the good use and governance of artificial intelligence (Proyecto de Ley Orgánica para el buen uso y la gobernanza de la inteligencia artificial), was approved by the Council of Ministers (the Spanish cabinet) on 26 May 2026 and published in the Boletín Oficial de las Cortes Generales (the official gazette of the Spanish parliament) on 12 June 2026; as at the date of this article it is still going through parliament and is not in the BOE (Boletín Oficial del Estado, the official state gazette).
The first question: is the assistant a high-risk system?
Annex III classifies as high-risk, among others, systems used by public authorities to evaluate people’s eligibility for essential public benefits and services, or to grant, reduce or withdraw them; systems that evaluate emergency calls and prioritise the response; remote biometric identification systems; and systems used in migration, asylum, border control and the administration of justice.
A virtual assistant that provides information (opening hours, procedures, requirements, the status of a case that citizens look up for themselves, referral to the competent department) does not fall into those categories: it is a limited-risk system, subject to the transparency obligations of Article 50. It becomes high-risk when it decides, or prepares the decision, on a right or a benefit: if it scores grant applications, if it filters who can access a social service, if it prioritises emergency alerts. The dividing line lies in the effect on the person, not in the technology.
In addition, whatever the category, the prohibitions in Article 5 have applied since February 2025: social scoring by public authorities, exploitation of vulnerabilities, inference of emotions in the workplace and in education, biometric categorisation based on sensitive data, and real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, subject to narrowly defined exceptions.
What a council with a limited-risk assistant is required to do today
- Transparency (Article 50). Citizens must know that they are interacting with an AI system, unless that is obvious. In practice: a clear notice at the start of the conversation, in the voice prompt of the kiosk or the telephone system, and in the service’s policy. If the system generates text or audio that is published, it must be possible to identify it as generated.
- AI literacy (Article 4). Following the Omnibus, the obligation is to take measures that support the AI literacy of the staff who operate or oversee the system, not to guarantee a particular level. A short training session for front-line staff and for whoever reviews the answers meets it and leaves evidence.
- Data protection. The assistant processes personal data: legal basis, information for the data subject, data minimisation, an impact assessment where required and a data processing agreement with the supplier. Conversations are not used to train third-party models without a legal basis.
- Automated administrative action. If the system produces acts with legal effect without human intervention, Article 41 of Law 40/2015 on the legal regime of the public sector (Ley 40/2015) requires the system, the body responsible and the audit mechanism to be identified, and the body’s electronic seal (sello electrónico de órgano) to be used.
- National Security Framework (Esquema Nacional de Seguridad, ENS). The assistant is one of the public body’s information systems and must be categorised and protected in accordance with Royal Decree 311/2022 (Real Decreto 311/2022), with the supplier demonstrating its conformity. We explain this in what the ENS is and why your supplier must have it.
- Accessibility and non-discrimination. The service must be accessible and must offer a human alternative, and the answers must not vary according to a person’s protected characteristics.
- Human oversight and an incident log, even though the regulation does not require them for limited-risk systems: they are what makes it possible to correct wrong answers before they turn into a complaint.
What it will be required to do from 2 December 2027 if the system is high-risk
If the council uses, or is going to use, AI to decide on benefits or services, it is worth preparing now, because the obligations on the deployer (Article 26) are substantial:
- Using the system in accordance with the supplier’s instructions (the supplier being the “provider”, in the Act’s terms), with human oversight by people who are competent and have the authority to intervene.
- A fundamental rights impact assessment (Article 27), mandatory for public bodies before first use. The Omnibus simplifies it: it can draw on the data protection impact assessment where one exists, and the AI Office will publish a simplified questionnaire.
- Registration of the use in the EU database (Article 49), with requirements streamlined by the Omnibus.
- Keeping the logs that the system generates, informing the workers affected, informing the people about whom decisions are made and guaranteeing the right to an explanation.
- Requiring the supplier to provide the technical documentation, the declaration of conformity and the CE marking for the high-risk system.
Starting ahead of the date is not overzealous: the impact assessment and the supplier’s documentation are asked for in the tender specifications, and the specifications are being drafted now.
What to require of the supplier in the tender specifications
What separates an uneventful project from a complaint is what is put in writing before the contract is awarded:
- A reasoned risk classification of the proposed system, with reference to Annex III and to the specific uses envisaged.
- A transparency notice built into every channel (website, kiosk, voice, messaging), with wording reviewed by the public body.
- Traceability: a log of conversations and of the sources used in each answer, with defined retention periods, and a dashboard for reviewing wrong answers.
- Human oversight: handover to a person at any point, and a correction procedure.
- Data and models: where the data is hosted, which models are used, whether conversations are used for training and who the data processor is; a contract under Article 28 of the GDPR.
- ENS: the category of the system and the supplier’s current certification or declaration of conformity, with a conformity mark that can be checked.
- Ownership and exit: code, prompts, knowledge bases and logs owned by the public body, so that it can change supplier without losing the system.
- Training for staff as an AI literacy measure, with a record kept.
- A commitment to adapt to the high-risk obligations if the use changes, and to the Spanish law once it is published.
CEDESA’s experience
For the Regional Ministry of Digitalisation (Consejería de Digitalización) of the Junta de Extremadura (the regional government), CEDESA developed conversational AI virtual assistants, in text and voice, deployed in 33 rural municipalities and financed by Next Generation EU funds and PERTE (Spain’s strategic projects for economic recovery and transformation), with integration into physical kiosks for places where households have no connectivity. They are limited-risk systems designed with a transparency notice, handover to a person, traceability of answers and ENS-compliant hosting. We describe the project in artificial intelligence applied to the public sector and our other AI projects on the innovation page. And because these projects are usually financed with EU funds, we also have a guide to Next Generation EU for digitalisation.
Frequently asked questions about the AI Act in the public sector
Is a municipal chatbot a high-risk system under the AI Act?
No, if it does no more than inform, guide and refer. It is a limited-risk system subject to the transparency obligation of Article 50, in force since 2 August 2026. It becomes high-risk, with obligations that apply from 2 December 2027, if it evaluates or decides on access to essential public benefits or services, prioritises emergencies or carries out biometric identification.
Since when has the AI Act applied to public authorities?
The prohibitions and the literacy measures since 2 February 2025; transparency and the regime of authorities and penalties since 2 August 2026; high-risk systems in Annex III from 2 December 2027 and those in Annex I from 2 August 2028, following the postponement introduced by Regulation (EU) 2026/1744, in force since 27 July 2026.
Does a council have to carry out an impact assessment in order to use AI?
For high-risk systems, yes: Article 27 requires public bodies to carry out a fundamental rights impact assessment before first use, which the Omnibus allows them to base on the data protection impact assessment. For a limited-risk assistant the regulation does not require one, but a data protection impact assessment may be mandatory under the GDPR, depending on the data processed.
Who supervises compliance in Spain?
The Spanish Agency for the Supervision of Artificial Intelligence (AESIA), in coordination with the Spanish Data Protection Agency on personal data and biometrics. The Spanish law that implements governance and penalties, the organic law bill on the good use and governance of AI, has been going through the Cortes (the Spanish parliament) since June 2026.
What should the tender specifications for a virtual assistant say about the AI Act?
The reasoned risk classification, the transparency notice in every channel, traceability of answers, human oversight, data processing and the data processing agreement, conformity with the ENS, ownership of the code and the knowledge base, staff training, and the commitment to adapt if the use changes or when the Spanish law is published.
Conclusion
The EU AI Act does not stop a council from deploying a virtual assistant; it asks the council to say that it is an AI, to train its staff, to protect the data, to secure the system in accordance with the ENS and not to use it to decide on rights without the safeguards for high-risk systems, which arrive in December 2027. Almost all of that is settled in the tender specifications and in the design. If your organisation wants an assistant that complies from day one, at CEDESA we have already done it for 33 municipalities; tell us about your project via our contact page.