AI Assurance Institute Logo AI Assurance Institute

The Fundamental Rights Impact Assessment: What the EU AI Act Actually Requires

Article 27 of the EU AI Act requires certain deployers to assess the impact on fundamental rights before they put specified high-risk AI systems into use. The assessment is about the deployer's own use of the system in a real process - not a general review of the technology in the abstract.

Fundamental rights, in this context, are those protected in Union law, including the rights in the Charter of Fundamental Rights of the European Union. Depending on the use, that can include dignity, non-discrimination, privacy and data protection, education, work, social security, a fair hearing and an effective remedy.

Who must carry out a FRIA

The duty does not apply to every organisation that uses AI, and it does not apply to every high-risk system.

It applies to deployers of high-risk AI systems referred to in Article 6(2) - systems listed in Annex III - where the deployer is:

High-risk systems intended to be used in the area listed in Annex III, point 2 (critical infrastructure) are excluded from this Article 27 obligation.

The FRIA is a deployer duty. The organisation that uses the system under its authority must perform it. The provider must supply information the deployer needs, in particular through the instructions for use under Article 13. That information supports the assessment. It does not transfer the duty to the provider.

When it must be done

The obligation applies to the first use of the high-risk AI system.

In similar cases, the deployer may rely on a FRIA already carried out, or on existing impact assessments produced by the provider. If the process, the people affected, the risks, the oversight arrangements or the response measures are different, a previous assessment will not be enough.

If, during use, any of the required elements has changed or is no longer up to date, the deployer must update the assessment.

After the assessment has been performed, the deployer must notify the market surveillance authority of the results, using the template referred to in Article 27. The Commission is required to develop that template.

Where a data protection impact assessment is also required under Article 35 of the GDPR or Article 27 of the Law Enforcement Directive, the FRIA complements that assessment. A DPIA does not replace a FRIA.

What the assessment must contain

Article 27 requires the assessment to consist of six elements:

(a) The processes in which the system will be used
A description of the deployer's processes in which the high-risk AI system will be used, in line with its intended purpose. This is the actual workflow or decision process, not a generic product description.

(b) Period and frequency of use
A description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used.

(c) Who is likely to be affected
The categories of natural persons and groups likely to be affected by its use in the specific context - for example applicants, claimants, pupils, employees or customers, including groups that may already be at a disadvantage.

(d) Specific risks of harm
The specific risks of harm likely to affect those persons or groups, taking into account the information given by the provider under Article 13. The focus is the harm this use may cause in this setting - such as unfair exclusion from credit, work or a public service, or decisions that cannot be understood or challenged.

(e) Human oversight
A description of how human oversight measures will be implemented, according to the instructions for use. Article 26 separately requires deployers to assign oversight to people with the necessary competence, training, authority and support. The FRIA must describe how that oversight will work for this deployment.

(f) Measures if the risks materialise
The measures to be taken if those risks materialise, including arrangements for internal accountability and complaint mechanisms. That means how the organisation will respond, who can intervene or stop the use, and how an affected person can raise a complaint.

How the FRIA relates to other AI Act duties

The FRIA does not replace the provider's quality management system under Article 17, and it does not replace the deployer's operational duties under Article 26. Those obligations remain. The FRIA is the additional assessment of fundamental-rights impact in the deployer's own context.

In practice, a complete FRIA therefore draws on:

What "done properly" looks like

A FRIA that meets the Article 27 list in substance will:

That is what the EU AI Act requires of the deployers who fall within Article 27.

If Article 27 applies to your deployment, start the assessment before first use.

Begin your FRIA