EU AI Act Art. 27 — Fundamental rights impact assessment (FRIA)
Article 27 obliges certain deployers of high-risk AI to run a fundamental rights impact assessment before deployment: how the system could harm people's rights, and what you will do about it.
At a glance
What this article requires
- FRIA applies to deployers that are public-law bodies or private providers of public services.
- It also applies to any deployer of Annex III §5(b)/(c) systems — life and health insurance pricing, and emergency-call dispatch.
- It must be completed before deployment and repeated when the use changes materially.
- Contents: description of the use, period and frequency, affected people, risks to fundamental rights, human oversight measures, and harm-response plan.
- Results go to the market surveillance authority; records are retained.
- SMEs get a simplified reporting route — but still must do the assessment.
- Member states may extend the obligation to further high-risk systems in national law.
Scope
Who this applies to
Deployers, not providers: bodies governed by public law, private entities providing public services, and deployers of Annex III §5(b)/(c) essential-service systems (life/health insurance pricing and emergency-call dispatch). Member states may extend the duty to additional high-risk systems — check your national implementation.
Obligations
What you must actually do
Assess before you deploy
Run the FRIA before the system goes live. Identify the affected groups, the risks to their fundamental rights, and the specific harms the system could cause.
Document the mitigation plan
Show the human-oversight measures, the safeguards, and what you will do if harm occurs. The quality of the plan matters as much as the risk list.
Notify and retain
Report the completed assessment to the relevant market surveillance authority and keep records. Re-run when the system's use or data materially changes.
Action plan
Practical first steps
- 1
Determine whether your deployment triggers FRIA — the trigger is wider than most teams expect.
- 2
Use the AI Act's FRIA template (Art. 27(2)) as your skeleton and fill it with system-specific detail.
- 3
Involve legal, HR/data protection, and the system owner in one review, then schedule the follow-ups.
- 4
File the assessment before go-live, not after an incident forces it.
Penalty exposure
Missing or inadequate FRIA is penalised in the general tier: up to €15 million or 3% of global annual turnover.
FAQ
Questions about Art. 27
Is FRIA the same as a DPIA under GDPR?
No, but they overlap. A DPIA covers data-protection risks under GDPR; a FRIA covers the broader fundamental-rights impacts under the AI Act. In practice, run them together so evidence is reused and gaps close.
Does every company deploying high-risk AI need a FRIA?
Not every one. The trigger is specific: public-law bodies, private providers of public services, and deployers of Annex III §5(b)/(c) systems (insurance pricing and emergency dispatch). A purely private employer screening candidates is not automatically in scope — it becomes so if it is a public body, provides public services, or its member state extended the obligation in national law.
Sources
Citations & further reading
Related
More article explainers
Wondering which articles apply to your AI?
Describe your system in the free Risk Scanner and get a preliminary risk read with the obligations that likely apply — in seconds.
Check my use casePreliminary EU AI Act clarity summary. Not legal advice.