Operationalising AI Governance in Public Administration: An Integrated Regulatory and Risk Management Framework
Abstract
Public organisations are increasingly using Artificial Intelligence (AI) and Algorithmic Decision-making Systems (ADSs), but the rules and governance requirements that apply to them remain spread across different legal and risk-management frameworks. This study analyses the European Union (EU) AI Act, the General Data Protection Regulation (GDPR), Directive (EU) 2016/680, the Organisation for Economic Co-operation and Development (OECD) AI Principles, and the National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF 1.0) to identify where they overlap, where they differ, and where practical implementation remains difficult. The findings are brought together into an integrated EU framework built around seven governance pillars and eight lifecycle stages, linking regulatory requirements with organisational responsibilities, human oversight, operational controls, and post-deployment monitoring. The framework is illustrated through two public-sector scenarios: social-benefit eligibility and AI-supported student assessment. The analysis shows that governing AI in EU public administration requires more than compliance with individual rules; it requires a coherent process that helps organisations decide when AI is appropriate, who is responsible, what safeguards are needed, and how systems should be reviewed over time. The framework’s organisational structure may provide a basis for adaptation to other contexts, but its legal mappings are specific to the EU instruments analysed and would require jurisdiction-specific reconstruction and validation.