NO AI ACT.

Article 27 · High risk · Rights · Assessment

AI Act FRIA: fundamental rights impact assessment

FRIA means fundamental rights impact assessment. Article 27 of the AI Act requires certain deployers to assess, before first use, how a particular high-risk AI system may affect fundamental rights in its real context.

01When a FRIA is required

A FRIA is not required for every piece of AI software. The first filter is whether the system is high-risk under Article 6(2) and Annex III, taking account of Article 27's exclusions. The second filter is the identity of the deployer.

  • deployers that are bodies governed by public law;
  • private entities providing public services;
  • deployers of specified high-risk systems for creditworthiness and life or health insurance risk and pricing.
Practical sequence: classify the system, identify the deployer, then verify the current scope of Article 27. “It is a public body” is not enough on its own, just as “it uses personal data” does not automatically trigger a FRIA.

02What the assessment describes

The assessment concerns concrete use, not an abstract description of the technology. Article 27 identifies at least the following elements:

Minimum assessment content, in simplified form
ProcessWhere the system enters the deployer's process, for what purpose and in which procedure.
Duration and frequencyHow long and how often the system is intended to be used.
People and groupsWhich categories may be affected in the specific context, including those in vulnerable or asymmetric positions.
Risks of harmWhich rights may be affected and how, considering information supplied by the provider.
Human oversightHow oversight measures are implemented and who has authority to intervene.
Governance and remedyMitigation, internal responsibility, response when risk materialises and complaint mechanisms.

03When to conduct and update it

The assessment precedes first use. In similar cases, a deployer may rely on an earlier assessment or one carried out by the provider, but it remains responsible for checking its own context. If the process, affected groups, risks, oversight or measures change, the information must be updated.

A FRIA is therefore not a static annex closed at procurement. It works only when connected to monitoring, complaints, incidents, system updates and changes in organisational practice.

04FRIA and DPIA are not the same

Orientation-level comparison with a GDPR data protection impact assessment
AI Act FRIAGDPR DPIA
Examines how use of a high-risk AI system affects fundamental rights in the specific context.Examines risks of personal-data processing to people's rights and freedoms.
Applies to deployers and uses within Article 27.Applies where processing is likely to result in high risk under the GDPR.
Covers process, affected people, risks, oversight, governance and complaints.Covers necessity, proportionality, processing risks and measures to address them.

Article 27 says that where some duties are already met through a DPIA, the FRIA complements it. Coordinating both can reduce duplication; treating them as identical may omit rights that cannot be reduced to data protection alone.

The full comparison between the two frameworks — not just the two assessments — is on the AI Act and the GDPR.

05Questions that make the assessment concrete

  • Who may be excluded, wrongly classified or discouraged from accessing a service?
  • Which right is involved: non-discrimination, privacy, dignity, defence, work, health, education or access to benefits?
  • Does the person know that AI assists the decision and whom to ask for explanation or correction?
  • Can human overseers see more than a score, and do they have time and authority to assess it?
  • How are errors that fall unevenly across groups detected?
  • What happens when risk materialises: suspension, review, complaint, remedy and communication?

06From form to case file

In “The Suspicion Algorithm”, a system prioritises welfare fraud inspections. A useful assessment would not stop at “the model is accurate”: it would examine who is flagged, access to essential benefits, errors, contestability and the real authority of the human operator.

07Official sources and limits

The binding source is Regulation (EU) 2024/1689 on EUR-Lex, using the current consolidated text. Also consult Article 27 in the Commission AI Act Service Desk and the official Navigating the AI Act FAQ.

Simplified educational version. This page cannot determine whether a particular organisation must conduct a FRIA, does not provide a compliance template and does not replace legal or data-protection advice.