Industry guide
Public sector & government suppliers
Governments face the strictest rules and the most public scrutiny. Canada's Treasury Board Directive requires a published Algorithmic Impact Assessment before any federal automated decision system launches; the EU AI Act treats benefits eligibility, law enforcement, migration and justice uses as high-risk and bans social scoring and most real-time biometric identification; Texas bans government social scoring and biometric identification and requires agencies to disclose AI interactions. Vendors selling to the public sector inherit these duties by contract.
Regulated uses
- Benefits, permits and eligibility decisions
- Facial recognition and biometric identification
- Predictive policing, risk scoring and fraud detection on citizens
- Citizen-facing chatbots and automated correspondence
- Procurement of AI systems from private vendors
Laws by region
| Region | Law | Status |
|---|---|---|
| EU | EU AI ActEU Artificial Intelligence Act (Regulation (EU) 2024/1689) | In force |
| EU | EU AI Omnibus 2026Digital Omnibus on AI (Regulation (EU) 2026/1744) | In force |
| US | Texas TRAIGATexas Responsible Artificial Intelligence Governance Act (HB 149) | In force |
| US | Colorado ADMT ActColorado Automated Decision-Making Technology Act (SB 26-189, replacing SB 24-205) | Upcoming |
| US | EO 14365 (federal preemption push)Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence | In force |
| Canada | Canada TBS ADM DirectiveTreasury Board Directive on Automated Decision-Making (with Algorithmic Impact Assessment) | In force |
| Canada | PIPEDA (Canada)Personal Information Protection and Electronic Documents Act (PIPEDA) | In force |
| Canada | Quebec Law 25Quebec Law 25 — Act respecting the protection of personal information in the private sector (automated decision provisions) | In force |
| Standards | NIST AI RMFNIST AI Risk Management Framework 1.0 and Generative AI Profile (NIST AI 600-1) | Voluntary |
| Standards | ISO/IEC 42001ISO/IEC 42001:2023 — Artificial intelligence management system | Voluntary |
Obligations checklist
- Complete and publish an Algorithmic Impact Assessment (or equivalent) before launch, and re-do it when the system changes.
- Disclose clearly, before or at the point of interaction, that a citizen is dealing with AI.
- Give reasons for decisions and a route to human reconsideration.
- Do not deploy social scoring or untargeted facial recognition; treat any biometric identification as requiring explicit legal authority.
- Require vendors to provide documentation, testing evidence and source-code or audit access in contracts.
- Test for bias before and after launch and publish peer-review findings.
- Register EU high-risk systems in the EU database before use.
Real cases
- Fine2024 · EUClearview AI — EUR 90 million-plus in GDPR fines across Europe
Fines totalling more than EUR 95 million across four countries (plus a UK ICO fine on separate grounds). Clearview has no EU establishment and is reported as having neither paid nor changed its practices, which is why the Dutch DPA is pursuing directors and warning customers that using the service is itself unlawful.
- Ban2023 · US-federalFTC v. Rite Aid — five-year ban on facial recognition surveillance
Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.
Where do you stand in public sector & government suppliers?
The screener is pre-filled for this sector — ten minutes to your level and gaps.
Sources
- Directive on Automated Decision-Making — Treasury Board of Canada Secretariat ↗
- Dutch DPA imposes a fine on Clearview — Autoriteit Persoonsgegevens ↗
Last reviewed Sep 25, 2026.