What changed?

Obligations now attach to the deployer of an AI system, not only to the provider. A municipality that buys and operates a system carries duties of its own.

Why does it matter for cities?

Cities procure AI capability inside larger platform contracts, where the AI component is often not described as such. The obligations attach anyway.

What should cities do?

  1. Inventory where automated decision support already exists, including inside systems bought before anyone called them AI.
  2. Classify each use against the risk categories, and document the reasoning rather than the conclusion.
  3. Name the human review point for every use that affects an individual decision.
  4. Put transparency and logging obligations into the procurement documents, not into a side letter.

The deployer obligation

The change that matters for municipalities is that duties follow use, not only supply. Buying a compliant product does not discharge the obligation to operate it properly.

Where the risk actually concentrates

Social benefit triage, housing allocation, school placement and enforcement prioritisation. These are the services where automation is most attractive because volume is high, and they are also the services where an error affects an individual with a right to a remedy.

Documentation is the deliverable

Supervision reads documents. A city that cannot produce a classification note, a review procedure and a log will be treated as non-compliant regardless of how well the system performs.

Procurement is the leverage point

Requirements written into the tender documents are cheaper than obligations negotiated after award. The specification is where a city has power.

Related

Briefs in the same sectors

Policy Brief DEMO

NIS2 and municipalities: what actually changes at city level

Cybersecurity obligations reach further into municipal operations than most administrations have assumed, and the accountability sits with management, not with the IT department.

Cybersecurity Public services
Published