Skip to main content
Praxikon
Article 27 of 11324%
Nederlands

Article 27: Fundamental rights impact assessment for high-risk AI systems

Praxikon tracks Article 27 (Fundamental rights impact assessment for high-risk AI systems) under the EU AI Act, citing the source for every statement.

EU Official:
UpcomingFRIA duty for applicable Annex III systems from 2 Dec 2027
Title III: High-Risk AI Systems

Application dates

  • : FRIA duty for applicable high-risk systems under Article 6(2) and Annex III

Article 27 introduces the FRIA: an assessment of fundamental-rights impact before certain high-risk AI systems are deployed.

Official text

||

Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.

Download AI Act (PDF)

Official guidance on this article

6

What does this mean for you?

Provider+
The FRIA is a duty for certain deployers, but providers must supply under Article 13 the information needed to assess risks, oversight measures and context of use. An existing provider impact assessment may be used as input in similar cases, but it does not transfer the deployer's responsibility.
Deployer+
Before first use, conduct a FRIA if you are a body governed by public law, a private entity providing a public service, or deploy a high-risk system under Annex III point 5(b) or 5(c) for creditworthiness or life and health insurance. Describe the process, duration and frequency of use, affected groups, specific fundamental-rights risks, human oversight and measures if risks materialise.
SME / Startup+
A private SME deployer is not inside or outside Article 27 merely because of its size. Its function and use case are decisive. An SME that provides a public service or deploys an application under Annex III point 5(b) or 5(c) may therefore be required to conduct a FRIA.
Public Sector+
A body governed by public law deploying a high-risk system under Article 6(2) must in principle conduct a FRIA before first use, except for Annex III point 2. Notify the market surveillance authority using the official template and update the assessment when relevant elements change. Regulation (EU) 2026/1744 expressly permits cross-references to, or inclusion of relevant parts from, a DPIA.

Related tools

Related Recitals

Related enforcement

No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.

Related blog posts

Cross-references

Recitals

Annexes

Frequently asked questions

What is a FRIA and when is it mandatory?+
A FRIA assesses fundamental rights impacts before first use of an applicable high-risk system under Article 6(2). The duty covers bodies governed by public law, private entities providing public services and deployers under Annex III points 5(b) and 5(c). Point 2 is excluded.
What should a FRIA contain?+
A FRIA must describe the intended use, affected persons, specific risks to fundamental rights, mitigating measures, and oversight mechanisms.
What documentation does Article 27 of the AI Act require?+
Article 27 of the AI Act requires that relevant documentation is maintained as part of the compliance process. This may include technical documentation, instructions for use, logs or declarations of conformity, depending on the classification of the AI system.
What is the difference between a FRIA and a DPIA?+
A FRIA assesses broader fundamental rights impacts; a DPIA concerns data protection. Regulation (EU) 2026/1744 allows the FRIA to include or cross-refer to relevant DPIA parts for duties already met through it. Each applicable assessment remains required under its own conditions.
Who must carry out a FRIA?+
Bodies governed by public law, private entities providing public services, and deployers of systems for creditworthiness or credit scoring under Annex III point 5(b) and risk assessment and pricing in life and health insurance under point 5(c).
Is there a standard template available for the FRIA?+
Article 27(5) requires the AI Office to develop a simplified questionnaire template. Since Regulation (EU) 2026/1744, that template must, where relevant, support cross-references to or parts of a DPIA.
Do I need to report the FRIA results to a supervisory authority?+
Yes, Article 27(3) requires deployers to notify the market surveillance authority of the FRIA results by submitting the filled-out template. Additionally, a summary must be registered in the EU database as per Annex VIII, Section C.

What Article 27 requires in practice