AI is making its way into grant management systems, and the regulatory framework governing the use of AI is also developing.
The EU’s Artificial Intelligence Act is a key piece of legislation that organisations of all types need to be familiar with. The Act introduces requirements for AI systems and their users according to the risks associated with the systems’ intended purposes.
How does that affect grant management? Factors like what decisions it supports and whether it materially influences outcomes are important to consider. Read on to learn more.
The EU AI Act, formally Regulation (EU) 2024/1689, establishes common rules for artificial intelligence across the EU. Instead of applying blanket requirements to all AI systems, it uses a risk-based approach that considers the system’s intended uses and the potential risks associated with those uses.
The Act classifies AI systems as outlined below.
These systems are prohibited and include those that:
High-risk AI systems include:
Providers of systems in this category have to disclose to users that these systems have AI functionality. For example, when users are interacting with chatbots, they must be informed that they’re talking to AI.
In some situations, AI-generated content must labelled as such. This applies to content related to matters of public interest.
These transparency obligations are now in-effect, as of August 2026.
Most systems fall into this category and they’re not subject to any new rules.
The best grant management software may use AI across the complete grant lifecycle and across multiple departments, reducing administrative burden and supporting analysis.
It may be used during programme administration, application management, assessment, award administration, and post-award monitoring, supporting activities such as:
The AI Act does not specifically classify funding management software as high-risk.
AI systems used in connection with essential private and public services could potentially fall within the AI Act's high-risk category.
For grant management, the relevant provision concerns AI systems used by public authorities, or on their behalf, to evaluate individuals' eligibility for essential public assistance benefits and services, or to determine whether those benefits or services should be granted, reduced, revoked, or reclaimed.
In other words, a system that simply handles administrative tasks will be treated differently from one that’s assesses an applicant’s eligibility or makes or supports decisions about their access to funding.
Article 6 and Annex III establish the criteria and specific use cases that determine whether an AI system falls within the high-risk framework. The rules covering Annex III high-risk systems are scheduled to apply from 2nd December 2027.
It’s not only the software provider that’s responsible for compliance with the AI Act. Organisations that use AI systems are generally considered “deployers” under the Act and may have their own obligations, depending on the type of AI system and how it’s used.
For grant makers, the requirements will depend on whether the AI functionality they use is classified as high-risk, subject to specific transparency requirements, or falls outside those categories.
If an AI-driven GMS falls within the high-risk framework, deployers have to follow a set of obligations defined in Article 26 of the Act, outlined below. Deployers that are public authorities must also register themselves in the EU’s database for high-risk AI systems, as explained in Article 49.
The AI Act requires deployers of high-risk AI systems to ensure appropriate human oversight. People assigned to this role must have the necessary competence, authority, and support to oversee the system effectively.
For grantmakers, this means establishing who’s responsible for reviewing AI outputs and ensuring that appropriate human judgement is part of relevant decision-making processes.
Organisations should also have clear processes establishing how AI-generated outputs are reviewed and how responsibility for any resulting decisions is assigned.
Where an organisation provides input data to a high-risk AI system, that data must be relevant and sufficiently representative for the system’s intended purpose.
For grantmakers, this makes it important to have clarity about what data an AI-enabled system uses, what information the organisation supplies to it, and how that data affects the system’s outputs.
High-risk AI systems are subject to requirements concerning technical documentation and automatic logging. Much of the responsibility for these requirements lies with the provider, but deployers also have responsibilities here.
Article 79 defines certain risks which require monitoring, including possible violations of fundamental rights. If deployers believe this risk is present, they must inform the provider as soon as possible as well as the relevant market surveillance authority. In addition, they must suspend use of the system.
Deployers are required to keep the system’s automatically generated logs “to the extent such logs are under their control”. They must be kept for at least six months, or “a period appropriate to the intended purpose” of the system.
Employees of an organisation that uses a high-risk AI system must be informed that they’re using such a system. When a system supports decisions related to natural persons, those individuals must also be informed.
Systems that don’t fall into the high-risk category are generally subject to fewer requirements. As mentioned earlier, certain systems are subject to transparency requirements like informing chatbot users that they’re interacting with AI, and labelling AI-generated content as such.
Grantmakers should take note of any AI functionality they’re using and seek legal advice to confirm the potential compliance risk and whether any specific transparency requirements apply.
The AI Act requires providers and deployers to take measures to ensure a sufficient level of AI literacy among staff and others who operate or use AI systems on their behalf.
Ensure that staff members using AI-enabled software understand its capabilities and limitations and have sufficient knowledge to use it appropriately. This is especially important where AI outputs contribute to decisions or other processes that affect applicants or beneficiaries.
In summary, when assessing whether AI-enabled grant management platforms are high-risk, consider:
AI can improve operational efficiency across the full grant lifecycle, reducing administrative overhead and supporting strategic priorities. However, the EU AI Act introduces a regulatory framework that grantmaking organisations will increasingly need to take into account.
The Act's transparency requirements are now in-effect, but there's time to prepare for the compliance responsibilities for high-risk systems. Establishing exactly how AI is used, determining whether those applications fall within regulated use cases, and clarifying the responsibilities of software providers and deployers can help you prepare for the requirements that apply to your organisation.
Flexigrant now offers AI features to streamline due diligence, reviewer selection, and more. To learn more or request a demo, contact us today.