Vigilis
EU AI Act

Fundamental Rights Impact Assessments: who needs one and when (Article 27)

Sourced from Regulation (EU) 2024/1689 (the EU AI Act), Article 27

In short

The fundamental rights impact assessment (Article 27) is one of the few EU AI Act obligations that falls on the deployer, not the provider, because deployers control the real-world context. It applies to three deployer categories using a high-risk system: bodies governed by public law, private operators providing public services, and any deployer using the system for creditworthiness evaluation or life/health insurance risk assessment and pricing. It must describe the deployment process, affected people, specific risks of harm, and the oversight and complaint-handling measures, completed before first use, updated on material change, and able to draw on a GDPR DPIA where they overlap.

Article 27 is one of the few EU AI Act obligations that falls on the deployer rather than the provider, specifically because deployers, not providers, control the real-world context a high-risk system is used in, which is what actually determines its impact on people’s fundamental rights.

Who this applies to

The obligation covers three categories of deployer using a high-risk AI system:

  • Bodies governed by public law.
  • Private operators providing public services.
  • Any deployer (public or private) using the system for creditworthiness evaluation, or for life or health insurance risk assessment and pricing.

A deployer outside these three categories generally does not carry this specific obligation, even if it deploys a high-risk system in another context.

What the assessment must cover

Article 27(1) requires the assessment to describe:

  • The deployment process: intended use, timeline, and frequency of use.
  • The categories of natural persons and groups likely to be affected by the specific use.
  • The specific risks of harm to those categories, taking into account the information the provider supplied under Article 13.
  • The human oversight measures in place, and the complaint-handling process available to affected individuals.

Timing and reuse

The assessment must be completed before first use, not after deployment has already begun. It must be updated whenever a relevant element changes or becomes outdated, but a prior assessment covering a materially similar scenario can be reused rather than started from scratch each time, provided it genuinely still reflects the current deployment.

Relationship to a GDPR data protection impact assessment

Where a deployer already has to carry out a data protection impact assessment under GDPR for the same processing, the fundamental rights impact assessment can draw on and complement it rather than duplicate it from scratch, but the two serve different legal bases and the AI Act assessment specifically has to address the Article 27(1) elements above, even where there is substantial overlap.

Because this obligation is triggered by deployment context rather than by anything the provider does, it is easy for a deployer to overlook, particularly one relying on a third-party high-risk system and assuming the vendor’s own compliance package already covers it. It does not; this is squarely the deploying organisation’s own responsibility.

Frequently asked questions

Who must complete a fundamental rights impact assessment?
Three deployer categories using a high-risk system: bodies governed by public law, private operators providing public services, and any deployer (public or private) using the system for creditworthiness evaluation or for life or health insurance risk assessment and pricing.
When must a fundamental rights impact assessment be completed?
Before first use, not after deployment has begun, and it must be updated whenever a relevant element changes or becomes outdated. A prior assessment covering a materially similar scenario can be reused if it still genuinely reflects the current deployment.
Is a FRIA the same as a GDPR data protection impact assessment?
No. Where a DPIA is already required for the same processing, the FRIA can draw on and complement it rather than duplicate it, but they serve different legal bases, and the FRIA must specifically address the Article 27(1) elements even where there is substantial overlap.

Related guides

Not sure where your company stands?

Our free assessment gives you an indicative result in minutes (free and anonymous) no account needed.

Start the free check