EU AI Act article explainer · Last verified 2026-08-02

EU AI Act Art. 27Fundamental rights impact assessment (FRIA)

Article 27 obliges certain deployers of high-risk AI to run a fundamental rights impact assessment before deployment: how the system could harm people's rights, and what you will do about it.

Regulation (EU) 2024/1689Plain-English explainer · Not legal advice

At a glance

What this article requires

  • FRIA applies to deployers that are public-law bodies or private providers of public services.
  • It also applies to any deployer of Annex III §5(b)/(c) systems — life and health insurance pricing, and emergency-call dispatch.
  • It must be completed before deployment and repeated when the use changes materially.
  • Contents: description of the use, period and frequency, affected people, risks to fundamental rights, human oversight measures, and harm-response plan.
  • Results go to the market surveillance authority; records are retained.
  • SMEs get a simplified reporting route — but still must do the assessment.
  • Member states may extend the obligation to further high-risk systems in national law.

Scope

Who this applies to

Deployers, not providers: bodies governed by public law, private entities providing public services, and deployers of Annex III §5(b)/(c) essential-service systems (life/health insurance pricing and emergency-call dispatch). Member states may extend the duty to additional high-risk systems — check your national implementation.

Obligations

What you must actually do

Assess before you deploy

Run the FRIA before the system goes live. Identify the affected groups, the risks to their fundamental rights, and the specific harms the system could cause.

Document the mitigation plan

Show the human-oversight measures, the safeguards, and what you will do if harm occurs. The quality of the plan matters as much as the risk list.

Notify and retain

Report the completed assessment to the relevant market surveillance authority and keep records. Re-run when the system's use or data materially changes.

Action plan

Practical first steps

  1. 1

    Determine whether your deployment triggers FRIA — the trigger is wider than most teams expect.

  2. 2

    Use the AI Act's FRIA template (Art. 27(2)) as your skeleton and fill it with system-specific detail.

  3. 3

    Involve legal, HR/data protection, and the system owner in one review, then schedule the follow-ups.

  4. 4

    File the assessment before go-live, not after an incident forces it.

Penalty exposure

Missing or inadequate FRIA is penalised in the general tier: up to €15 million or 3% of global annual turnover.

FAQ

Questions about Art. 27

Is FRIA the same as a DPIA under GDPR?

No, but they overlap. A DPIA covers data-protection risks under GDPR; a FRIA covers the broader fundamental-rights impacts under the AI Act. In practice, run them together so evidence is reused and gaps close.

Does every company deploying high-risk AI need a FRIA?

Not every one. The trigger is specific: public-law bodies, private providers of public services, and deployers of Annex III §5(b)/(c) systems (insurance pricing and emergency dispatch). A purely private employer screening candidates is not automatically in scope — it becomes so if it is a public body, provides public services, or its member state extended the obligation in national law.

Sources

Citations & further reading

Related

More article explainers

Wondering which articles apply to your AI?

Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.

Check my use case

Preliminary EU AI Act clarity summary. Not legal advice.