Article 27 of the EU AI Act requires certain deployers to assess the impact on fundamental rights before they put specified high-risk AI systems into use. The assessment is about the deployer's own use of the system in a real process - not a general review of the technology in the abstract.
Fundamental rights, in this context, are those protected in Union law, including the rights in the Charter of Fundamental Rights of the European Union. Depending on the use, that can include dignity, non-discrimination, privacy and data protection, education, work, social security, a fair hearing and an effective remedy.
Who must carry out a FRIA
The duty does not apply to every organisation that uses AI, and it does not apply to every high-risk system.
It applies to deployers of high-risk AI systems referred to in Article 6(2) - systems listed in Annex III - where the deployer is:
- a body governed by public law, or
- a private entity providing public services, or
-
a deployer of the systems listed in Annex III, points 5(b) and 5(c):
- creditworthiness assessment or credit scoring
- risk assessment and pricing in relation to natural persons for life and health insurance
High-risk systems intended to be used in the area listed in Annex III, point 2 (critical infrastructure) are excluded from this Article 27 obligation.
The FRIA is a deployer duty. The organisation that uses the system under its authority must perform it. The provider must supply information the deployer needs, in particular through the instructions for use under Article 13. That information supports the assessment. It does not transfer the duty to the provider.
When it must be done
The obligation applies to the first use of the high-risk AI system.
In similar cases, the deployer may rely on a FRIA already carried out, or on existing impact assessments produced by the provider. If the process, the people affected, the risks, the oversight arrangements or the response measures are different, a previous assessment will not be enough.
If, during use, any of the required elements has changed or is no longer up to date, the deployer must update the assessment.
After the assessment has been performed, the deployer must notify the market surveillance authority of the results, using the template referred to in Article 27. The Commission is required to develop that template.
Where a data protection impact assessment is also required under Article 35 of the GDPR or Article 27 of the Law Enforcement Directive, the FRIA complements that assessment. A DPIA does not replace a FRIA.
What the assessment must contain
Article 27 requires the assessment to consist of six elements:
(a) The processes in which the system will be used
A description of the deployer's processes in which the high-risk AI system will be used, in line with its intended purpose. This is the actual workflow or decision process, not a generic product description.
(b) Period and frequency of use
A description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used.
(c) Who is likely to be affected
The categories of natural persons and groups likely to be affected by its use in the specific context - for example applicants, claimants, pupils, employees or customers, including groups that may already be at a disadvantage.
(d) Specific risks of harm
The specific risks of harm likely to affect those persons or groups, taking into account the information given by the provider under Article 13. The focus is the harm this use may cause in this setting - such as unfair exclusion from credit, work or a public service, or decisions that cannot be understood or challenged.
(e) Human oversight
A description of how human oversight measures will be implemented, according to the instructions for use. Article 26 separately requires deployers to assign oversight to people with the necessary competence, training, authority and support. The FRIA must describe how that oversight will work for this deployment.
(f) Measures if the risks materialise
The measures to be taken if those risks materialise, including arrangements for internal accountability and complaint mechanisms. That means how the organisation will respond, who can intervene or stop the use, and how an affected person can raise a complaint.
How the FRIA relates to other AI Act duties
The FRIA does not replace the provider's quality management system under Article 17, and it does not replace the deployer's operational duties under Article 26. Those obligations remain. The FRIA is the additional assessment of fundamental-rights impact in the deployer's own context.
In practice, a complete FRIA therefore draws on:
- the provider's instructions and other Article 13 information
- the deployer's description of its own process and affected people
- the human oversight that will actually be applied
- the complaint and response arrangements that will be available if harm occurs
What "done properly" looks like
A FRIA that meets the Article 27 list in substance will:
- describe the real process in which the system will be used
- state how long and how often it will be used
- identify the people and groups likely to be affected
- set out specific risks of harm to those people, not only generic AI concerns
- describe human oversight as it will be implemented
- set out what happens if those risks materialise, including how complaints will be handled
- be completed before first use
- be updated when the relevant facts change
- be notified to the market surveillance authority in the required form
That is what the EU AI Act requires of the deployers who fall within Article 27.
If Article 27 applies to your deployment, start the assessment before first use.
Begin your FRIA