Digitalising the Pact: EUAA State of Asylum Conference
September 15th, 2026
Digitalising the Pact: EUAA State of Asylum Conference
Since 12 June 2026, the EU's Pact on Migration and Asylum has been in full application across Member States. Behind the policy language, the Pact is also a digital infrastructure project: a new Eurodac biometric database, expanded screening procedures, and border-procedure IT systems that Member States are still finishing testing. On September 28th, at the European Union Agency for Asylum's (EUAA) State of Asylum Conference 2026 in Malta, a dedicated panel called "Digitalising the Pact" will bring together the people responsible for making that infrastructure work — including our Founder & CEO, Gemma Galdon Clavell, PhD.
The conversation matters well beyond the conference room, because "digitalising" an asylum system is not a neutral technical upgrade. It means deciding which AI systems get to flag, score, verify or identify the people who pass through it; and under EU law, several categories of those systems are legally defined as high-risk.
What counts as high-risk AI in migration and asylum
Under Annex III of the EU AI Act, four categories of AI use in migration, asylum, and border control are explicitly classified as high-risk:
Deception-detection tools: "polygraph-like" systems that assess the credibility of what someone says during a border or asylum interview.
Risk-assessment systems: tools that produce a score, flag, or rank for an individual, such as migration or security risk scoring, or health-risk flags based on biometric data.
Application-examination assistance: systems that help evaluate asylum, visa, or residence applications by checking document authenticity, testing the plausibility of an account, or flagging inconsistencies.
Person detection and identification: including facial recognition and other biometric identification used in border operations.
High-risk classification is not a formality. It brings binding obligations: risk management, human oversight and a fundamental rights impact assessment before deployment. Eurodac, the biometric database at the center of the Pact's implementation, sits close to several of these categories — which is why the European Commission flagged it as the most pressing operational gap in its May 2026 progress report on the Pact's implementation.
The gap between meeting the requirements and proving it
Passing a fundamental rights impact assessment on paper and behaving safely in production are two different things. A system can be built with every safeguard the AI Act requires and still drift once it starts scoring real applicants, in real queues, under real operational pressure. Compliance documentation describes what a system was designed to do. It doesn't measure what the system is actually doing, at scale, months into deployment.
That distinction is the reason independent evaluation exists as a category separate from compliance and certification. Governance platforms and compliance frameworks are useful for keeping a record of policies and processes. But knowing that a fundamental rights impact assessment was filed is not the same as knowing whether a risk-assessment tool is scoring comparable cases consistently, or whether a document-verification system produces more false positives for applicants from a particular country. Only structured, evidence-based testing of the system in its actual operating environment can answer that.
Why this needs a track record, not just a framework
This is where Gemma Galdon Clavell's own track record is relevant to the panel she's joining. She led the independent evaluation of Spain's VioGén domestic-violence risk-scoring system, contributed to the European Data Protection Board's Checklist for AI Auditing, co-authored a Responsible AI Assessments guide for Germany's GIZ, and helped produce the Guide to Algorithmic Auditing commissioned by Spain's Data Protection Agency. That kind of applied, public-sector audit experience — not just familiarity with the regulatory text — is the profile the Pact's monitoring mechanism will need if it is to be more than a paperwork exercise.
It is also the premise Eticas.ai's evaluation work is built on: AI systems should be tested where they actually run, not only in a lab or against a benchmark. For public-sector systems processing asylum claims or scoring border-crossing risk, "where they actually run" means live data, live queues, and the actual populations the system was deployed to serve. Independent, in-production evaluation is what lets an agency demonstrate — not simply claim — that a high-risk migration AI system is doing what it was built to do, and is not doing what it wasn't.
What to watch as the Pact's digital layer matures
Three things are worth tracking as Member States close the gaps the Commission identified in May: whether Eurodac and related screening systems are independently tested against the four Annex III(7) risk categories before they scale further; whether the Pact's fundamental rights monitoring mechanism has the technical capacity to evaluate AI behavior, not just process compliance paperwork; and whether "digitalising the Pact" ends up meaning faster processing with the same accountability gaps, or faster processing backed by better evidence.
That is the question the panel in Malta is set up to explore. If your organization is developing, deploying, or procuring AI systems for migration, asylum, or border management, the same question is worth answering before a regulator or a fundamental rights body asks it for you: Can you show, not just claim, that your system is behaving as intended?
Learn more about the EUAA State of Asylum Conference 2026: https://www.euaa.europa.eu/euaa-state-of-asylum-conference, or get in touch with us to talk about independent evaluation of high-risk migration and border AI systems.
FAQs
What is the EU Pact on Migration and Asylum?
Adopted in May 2024, the Pact is a package of EU laws reforming how Member States manage asylum applications, border procedures, and migration more broadly. It entered full application on 12 June 2026.
Which AI systems are classified as high-risk under the EU AI Act in this area?
Annex III of the AI Act classifies four uses as high-risk: deception-detection tools, risk-assessment and scoring systems, application-examination assistance, and biometric person detection or identification used in migration, asylum and border control.
What does independent evaluation of these systems involve?
It means testing an AI system's actual behavior in its live operating environment — not only its design documentation or lab performance — against risks like bias, inconsistency and drift, and producing evidence of how it performs with real applicants over time.
Where can I find out more about the conference where this is being discussed?
The EUAA's State of Asylum Conference 2026 takes place on 28 September in Malta. Details are available on the EUAA conference page: https://www.euaa.europa.eu/euaa-state-of-asylum-conference