AI Assurance Institute Logo AI Assurance Institute

Fundamental Rights Impact Assessment under the EU AI Act

What, Why, Who, and How It Is Performed

Article 27 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) introduces the fundamental rights impact assessment (FRIA) as a targeted, rights-focused evaluation required in specific cases before deploying high-risk AI systems. Unlike the broader risk management system (Article 9), the FRIA concentrates on potential adverse effects on the Charter of Fundamental Rights of the European Union. This article articulates the FRIA requirement - what it is, why it exists, who must perform it, and how it is carried out - from regulatory, operational, practical, and strategic perspectives, including examples, edge cases, and its interplay with the QMS under EN 18286.

What Is a Fundamental Rights Impact Assessment?

A FRIA is a structured, documented analysis that systematically identifies, assesses, and mitigates the potential adverse impacts of a high-risk AI system on specific fundamental rights enshrined in the EU Charter (e.g., human dignity, non-discrimination, privacy, fair trial, freedom of expression, right to good administration). It is narrower and more rights-specific than the general risk management system (RMS), which covers all foreseeable risks to health, safety, and fundamental rights.

Key characteristics:

The FRIA is not a duplicate of the RMS; it provides deeper, rights-centric scrutiny where fundamental rights risks are heightened.

Why Is a Fundamental Rights Impact Assessment Required?

The FRIA exists to ensure that high-risk AI systems - especially those used in public or quasi-public contexts - do not disproportionately or foreseeably infringe fundamental rights. Its core purposes are:

Example: A public authority deploys AI for predictive policing. The FRIA reveals potential disproportionate impact on ethnic minorities (Article 21 non-discrimination). This triggers stricter safeguards (e.g., human override, transparency measures) beyond what a general RMS might require - achieving stronger rights protection.

Who Must Perform a Fundamental Rights Impact Assessment?

Article 27 places the obligation on specific actors:

Exemptions / Lower Burden: Private-sector providers of high-risk AI not used in public contexts are generally not required to conduct a FRIA unless the system poses specific high rights risks (awaiting further clarification via delegated/implementing acts or EU AI Office guidance).

Edge case: A private company provides an AI tool for social benefit scoring to a public authority. The public authority (deployer) is primarily responsible for the FRIA, but the provider may need to supply supporting documentation and cooperate under contractual or QMS obligations.

How Is a Fundamental Rights Impact Assessment Performed?

The FRIA is a structured, documented process typically conducted before deployment (and updated when significant changes occur). While the Act does not prescribe a rigid methodology, prEN 18286 (Annex A informative guidance) and EU AI Office templates suggest the following steps:

  1. Scoping & Context Analysis: Define the system's intended purpose, use cases, affected persons/groups, and relevant Charter rights at stake.
  2. Identification of Impacts: Map potential adverse effects on each relevant right (e.g., indirect discrimination, chilling effect on free expression, disproportionate surveillance).
  3. Severity & Likelihood Assessment: Evaluate the seriousness, probability, and cumulative impact of each identified risk.
  4. Mitigation Measures: Propose specific safeguards (technical, organisational, procedural); assess residual risk after mitigation.
  5. Stakeholder Consultation: Where feasible, consult affected persons, civil society, or representatives (especially for vulnerable groups).
  6. Documentation & Approval: Produce a formal FRIA report (signed/approved); integrate findings into the risk management system, technical documentation, and QMS records.
  7. Review & Update: Revisit the FRIA after substantial modifications, new evidence from post-market monitoring, or changes in context/use.

Practical example: A municipality uses AI to prioritise housing assistance (Annex III point 5). The FRIA identifies risks to Article 1 (dignity), Article 21 (non-discrimination), and Article 34 (social security). Mitigation includes explainable scoring, human review thresholds, and regular fairness audits - documented and linked to the provider's RMS and QMS change-control process.

Integration, Nuances, and Strategic Implications

Under EN 18286, the FRIA is not a standalone process but a specialised input that strengthens the risk management system (Article 9) and feeds into QMS planning, documentation, and audit trails. Outputs from the FRIA (identified rights risks, mitigations) are referenced in the RMS risk register and technical documentation (Annex IV).

Nuances: Proportionality for SMEs (simpler FRIA when required); public-private collaboration (providers often support deployers with data/evidence); ongoing nature for adaptive systems.

Strategic implications: A well-performed FRIA demonstrates due diligence, reduces rights-violation liability, builds public trust, and facilitates smoother conformity assessment/market surveillance. Challenges: resource intensity, uncertainty on exact triggers (pending guidance), and balancing transparency with commercial sensitivity. Best practice: Integrate FRIA into existing RMS workflows, use EU AI Office templates, document consultation attempts, version-control FRIA reports, and review periodically alongside post-market monitoring findings.

Summary

In summary, the fundamental rights impact assessment under the EU AI Act is a targeted, rights-specific evaluation performed primarily by public-sector deployers (and supported by providers) to systematically identify, assess, and mitigate adverse Charter rights impacts before high-risk AI deployment. It complements - but does not replace - the broader risk management system, ensuring deeper protection of fundamental rights in sensitive contexts while integrating seamlessly into the QMS framework under EN 18286.