{"answer_id":"praxikon:eu:ai-act:answer:fria-uitvoeren","canonical_page":"https://www.praxikon.com/en/antwoord/fria-uitvoeren","query":"Do we need to perform a FRIA and how do we approach it?","lang":"en","view":"full","mode":"scenario","question":"Do we need to perform a FRIA and how do we approach it?","situation":"A fundamental rights impact assessment (Article 27) for deploying a high-risk AI system.","likely_role":"Public body, public service provider or credit/insurance deployer","note":"The FRIA duty applies only to specific deployers and follows the high-risk timeline to 2 December 2027. A FRIA is not a DPIA: they overlap, but the FRIA assesses more than data protection.","matched_terms":[],"dataset":{"id":"praxikon:sys:registry:dataset:ai-act-implementation-graph","version":"2.2.0","schema_version":"1.5.0","effective_at":"2026-08-08T00:00:00.000Z","known_at":"2026-09-06T00:00:00.000Z","last_reviewed_at":"2026-08-08T00:00:00.000Z","licence":"https://www.praxikon.com/nl/legal/terms","canonical_url":"https://www.praxikon.com/api/v1/entities"},"obligations":[{"slug":"article-27-fria","label":"Article 27: FRIA","summary":"Fundamental rights impact assessment before deploying certain high-risk AI systems.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-27-fria","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)-(5)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended application schedule and Article 27 DPIA cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"A FRIA is not a generic risk assessment for every AI system. First establish the system route, Annex III category and type of deployer.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 27(1)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Link the FRIA to the AI inventory and, where relevant, the DPIA. Keep scope, affected groups, mitigations, residual risks and notification in one versioned record.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 27 amendment on DPIA inclusion or cross-reference","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"}]},{"slug":"article-26-deployer-obligations","label":"Article 26: obligations of deployers of high-risk AI systems","summary":"Twelve paragraphs governing day-to-day use: use in line with the instructions, human oversight by competent people, input data, monitoring and notification, log retention, informing workers before deployment, registration by public authorities and informing the people about whom decisions are made.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-26-deployer-obligations","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 26 imposes twelve paragraphs on deployers of high-risk AI systems. Paragraph 1 requires appropriate technical and organisational measures to ensure use in accordance with the accompanying instructions for use. Paragraph 2 requires assigning human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. Paragraph 3 leaves other obligations and the freedom to organise one's own resources unaffected. Paragraph 4 requires, to the extent the deployer exercises control over the input data, that such data is relevant and sufficiently representative in view of the intended purpose. Paragraph 5 requires monitoring on the basis of the instructions for use and informing the provider in accordance with Article 72; where there is reason to consider that use may result in a risk within the meaning of Article 79(1), the deployer shall without undue delay inform the provider or distributor and the relevant market surveillance authority and suspend use, and upon identifying a serious incident shall immediately inform first the provider and then the importer or distributor and the market surveillance authorities. Paragraph 6 requires keeping the automatically generated logs under the deployer's control for a period appropriate to the intended purpose and of at least six months, unless Union or national law provides otherwise. Paragraph 7 requires deployers who are employers to inform workers' representatives and the affected workers, before putting into service or using the system at the workplace, that they will be subject to its use. Paragraph 8 imposes the registration obligations of Article 49 on public authorities and Union institutions, bodies, offices and agencies and prohibits use of a system not registered in the EU database referred to in Article 71. Paragraph 9 links the information provided under Article 13 to the data protection impact assessment under Article 35 of Regulation (EU) 2016/679. Paragraph 10 sets additional conditions for post-remote biometric identification in law enforcement. Paragraph 11 opens with the words without prejudice to Article 50 of this Regulation and requires deployers of Annex III systems that make or assist in making decisions related to natural persons to inform those persons that they are subject to the use of the system; for high-risk AI systems used for law enforcement purposes Article 13 of Directive (EU) 2016/680 applies. The transparency obligations of Article 50 have applied since 2 August 2026 and are separate from the date on which paragraph 11 starts to apply. Paragraph 12 requires cooperation with the competent authorities.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"editorial_interpretation","statement":"The 2 December 2027 date invites postponement, but two elements are preparation work today. Paragraph 7 requires you to inform workers' representatives and the affected workers before the system is put into service at the workplace, and that information is provided, where applicable, in line with existing rules and practice on informing workers. That touches employee participation, and such a process takes months rather than weeks in practice, so a system that must go live in 2027 is discussed in 2026. Paragraph 2 also connects to the human oversight that Article 14 imposes on system design: you must designate natural persons with competence, training, authority and support. That is emphatically not the same as the measures obligation in Article 4. Article 4 requires measures supporting AI literacy and does not require you to guarantee a particular level for individuals; Article 26(2) requires identifiable overseers with a mandate. Conflating the two leaves you believing a generic e-learning is enough while still having no overseer with room to decide. A third underestimated element is paragraph 11: informing the people about whom an Annex III system makes or helps make decisions is visible customer or candidate communication that you have to design across your own organisation.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Draw up now a list of the systems likely to qualify as high-risk from 2 December 2027 and add three columns: who exercises human oversight and with what mandate, when you will inform the works council and the affected workers, and how the persons concerned will receive the notice under paragraph 11. Plan the employee participation process a year ahead.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 26(1)-(12)","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"conformity-ce-registration","label":"Articles 43-49: conformity assessment, CE and registration","summary":"The route from assessment to CE marking and EU database registration before market placement of high-risk AI.","legal_status":"applicable","deadline_at":"2026-08-02T00:00:00.000Z","high_risk_regime_from":"2027-12-02T00:00:00.000Z","human_page":"https://www.praxikon.com/en/verplichtingen/conformity-ce-registration","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","citations":[{"kind":"official_fact","statement":"Article 43 governs the conformity assessment, Article 47 the EU declaration of conformity, Article 48 the CE marking and Article 49 the registration in the EU database before market placement or putting into service, including registration of the Article 6(3) assessment.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 113, second paragraph","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"official_fact","statement":"This provision is named in none of the three points of Article 113, third paragraph, and therefore falls under the general application date in the second paragraph: 2 August 2026. The move to 2 December 2027 and 2 August 2028 in point (c) concerns only Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5). When a high-risk AI system that this provision addresses can practically exist is a second question: through Article 6(2) and Annex III that is 2 December 2027, and through Article 6(1) and Annex I 2 August 2028. That practical date sits in high_risk_regime_from and not in deadline_at. This is how decision D1 of 6 September 2026 is recorded; see data/ai-act/review/decision-d1-application-dates.json.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Article 1, point (40)(b), replacing Article 113, third paragraph, point (c)","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"For buyers this is the simplest supplier check there is: ask for the declaration of conformity and the registration number. No declaration means the system may not be there by 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Plan the conformity route backwards from 2 December 2027: standards selection, assessment, declaration and registration together take months, not weeks.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Articles 43, 47, 48 and 49","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"annex-iii-high-risk","label":"Annex III: high-risk AI","summary":"Classification route for standalone high-risk AI systems under Article 6(2) and Annex III.","legal_status":"upcoming","deadline_at":"2027-12-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/annex-iii-high-risk","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","citations":[{"kind":"official_fact","statement":"The core rules in Chapter III, Sections 1 to 3, for systems under Article 6(2) and Annex III become applicable on 2 December 2027.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amended Article 113, Article 6(2) and Annex III application date","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"The later application date does not remove the classification question. An early classification record avoids design and procurement decisions without evidence.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"},{"kind":"recommended_action","statement":"Document now the intended purpose, Annex III point, Article 6(3) assessment, profiling and selected registration path.","source_id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","source_locator":"Article 6(2)-(4), Article 49 and Annex III","source_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj"}]},{"slug":"article-4-ai-literacy","label":"Article 4: AI literacy","summary":"Providers and deployers take measures that support the development of AI literacy.","legal_status":"applicable","deadline_at":"2025-02-02T00:00:00.000Z","high_risk_regime_from":null,"human_page":"https://www.praxikon.com/en/verplichtingen/article-4-ai-literacy","api":"https://www.praxikon.com/api/v1/obligations?lang=en","official_source":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","citations":[{"kind":"official_fact","statement":"Since 27 July 2026, providers and deployers must take measures supporting the development of AI literacy. The provision does not require a guaranteed individual level.","source_id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","source_locator":"Amendment of Article 4; entry into force 27 July 2026","source_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj"},{"kind":"editorial_interpretation","statement":"Evidence is primarily a proportionate record of measures by role and context, not one prescribed course or certificate.","source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Questions on measures, formats, certificates and records","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null},{"kind":"recommended_action","statement":"Inventory roles and AI systems, select appropriate measures and record the choice, implementation and periodic review.","source_id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","source_locator":"Implementation examples and evidence guidance","source_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null}]}],"conditional":[{"slug":"article-61-informed-consent","id":"praxikon:eu:ai-act:obligation:article-61-informed-consent","label":"Article 61: informed consent of test subjects for testing in real world conditions","status":"possibly_applies","source_locator":"Article 60(4), point (i), with Article 61(1)","addressee":"reader","human_page":"https://www.praxikon.com/en/verplichtingen/article-61-informed-consent"}],"sources":[{"id":"praxikon:eu:ai-act:source:reg-eu-2024-1689","title":"EU Artificial Intelligence Act 2024/1689","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","eli":"http://data.europa.eu/eli/reg/2024/1689/oj","source_version":"original-oj-2024-07-12","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:reg-eu-2026-1744","title":"Digital Omnibus on AI 2026/1744","publisher":"European Parliament and Council","canonical_url":"https://eur-lex.europa.eu/eli/reg/2026/1744/oj","eli":"http://data.europa.eu/eli/reg/2026/1744/oj","source_version":"official-journal-2026-07-24","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-ai-literacy-qa","title":"AI literacy questions and answers","publisher":"European Commission","canonical_url":"https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers","eli":null,"source_version":"updated-2026-07-27","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:commission-draft-high-risk-classification-guidelines","title":"Draft guidelines on the classification of high-risk AI systems","publisher":"European Commission (AI Office)","canonical_url":"https://digital-strategy.ec.europa.eu/en/library/draft-commission-guidelines-classification-high-risk-ai-systems","eli":null,"source_version":"draft-for-consultation-2026-05-19","verified_at":"2026-08-08T00:00:00.000Z"},{"id":"praxikon:eu:ai-act:source:cen-cenelec-jtc21","title":"CEN-CENELEC JTC 21: European standards under standardisation request M/613","publisher":"CEN-CENELEC JTC 21","canonical_url":"https://www.cencenelec.eu/areas-of-work/cen-cenelec-topics/artificial-intelligence/","eli":null,"source_version":"work-programme-checked-2026-08-08","verified_at":"2026-08-08T00:00:00.000Z"}],"first_actions":[{"label":"Map the affected groups and their specific risks of harm","summary":"Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13."},{"label":"Assign human oversight and give those people a mandate","summary":"Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside."},{"label":"Complete the conformity route before market placement","summary":"Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database."}],"evidence":[{"label":"Notification to the market surveillance authority with the completed template","summary":"The sent notification through which you report the assessment results to the market surveillance authority, with the completed template attached, plus date of dispatch and acknowledgement of receipt.","url":null},{"label":"Deployment dossier: logs, worker information and information to affected persons","summary":"The dossier that shows you retain the logs, that you informed workers and their representatives in time, and that the people about whom decisions are made are aware of it.","url":null},{"label":"Conformity file","summary":"The assessment, EU declaration of conformity, CE marking and registration proof, per system version.","url":null}],"guidance":[{"label":"No mandatory course format, no certificate, no exam and no AI officer","statement":"The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.","source_locator":"Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)"},{"label":"Article 4 reaches beyond your own staff, and the national supervisor enforces it","statement":"The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.","source_locator":"Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)"},{"label":"Annex I lists legislation, not products","statement":"The draft guidelines of 19 May 2026, published for consultation and expressly non-binding, clarify that Annex I AI Act does not list individual products to be classified as high-risk, but Union harmonisation legislation regulating the safety aspects of certain products. Whether an AI system falls within the scope of Annex I therefore depends on whether the system, or the product of which it is a safety component, falls within the material scope of one of the listed legislative acts. According to the draft guidelines the list in Annex I is exhaustive; products can only be added or removed by amending the scope of the harmonisation legislation itself or by adding new harmonisation legislation to Annex I. The draft guidelines also state that through Article 6(1) the AI Act does not itself extend the scope of harmonisation legislation to new or additional products, and that the AI Act does not determine or change the risk profile of a product but builds on the sectoral risk classification. Products mentioned include machinery, toys, lifts, equipment and protective systems for potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, and products in the automotive and aviation sectors.","source_locator":"Draft guidelines Annex I, points (23) to (26)"},{"label":"Section A and Section B of Annex I trigger different requirement sets","statement":"The Commission draft guidelines of 19 May 2026, which are non-binding as long as the final version has not been adopted, draw a distinction that is often missed in practice. AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section A of Annex I are subject to the requirements for high-risk systems in Section 2 of Chapter III AI Act. By contrast, for AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 AI Act apply. The draft guidelines refer to Article 2(2) AI Act for this. Section A contains harmonisation legislation based on the New Legislative Framework, Section B the other Union harmonisation legislation.","source_locator":"Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act"}],"examples":[{"label":"Recidivism scoring in police work: when the assessment must be redone","situation":"A police service deploys an AI system that estimates the recidivism risk of a suspect, as an aid to the judgements later made by the prosecution service and the court. The model is subsequently retrained on newer investigative data and use is extended to a second region. The question is whether the assessment made for first use remains adequate.","outcome":"Article 27(1) requires deployers which are bodies governed by public law to perform, prior to deploying a high-risk AI system referred to in Article 6(2), an assessment of the impact on fundamental rights that its use may produce, with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment consists of a description of the processes in which the system will be used, of the period and frequency of use, of the categories of natural persons and groups likely to be affected, of the specific risks of harm taking into account the information given by the provider pursuant to Article 13, of the implementation of human oversight measures according to the instructions for use, and of the measures to be taken if those risks materialise. Article 27(2) provides that the obligation applies to the first use, that previously conducted impact assessments or existing assessments carried out by the provider may be relied on in similar cases, and that a deployer who considers during use that any element listed in paragraph 1 has changed or is no longer up to date shall take the necessary steps to update the information. Article 27(3) provides that the results are notified to the market surveillance authority together with the filled-out template, and that in the case referred to in Article 46(1) an exemption from that notification duty may apply.","lesson":"We read Article 27 as covering a police service as a body governed by public law under paragraph 1, and as an assessment that does not stop at first use: retraining on newer investigative data or extending use to a second region touches the elements of paragraph 1 and, on our reading, calls for updating the record. That retraining also raises a question Article 27 itself does not answer, namely whether the change goes far enough to count as a substantial modification, which would make you a provider in your own right under Article 25. Bear in mind as well that the exception in paragraph 3 concerns, on our reading, the notification and not the assessment itself. Finally, start that assessment only after establishing that the deployment as such is permitted, because Article 5 rules out certain predictive applications in criminal investigation.","source_locator":"Article 27(1)-(3)","provenance":"editorial"},{"label":"Selection at student admission: a DPIA is not yet a FRIA","situation":"A university of applied sciences has an AI system rank applications for a vocational programme, using the exam results of earlier students to calibrate that ranking. A data protection impact assessment already exists for this processing. The question the school asks is whether that also covers the fundamental rights side of admission.","outcome":"Article 27(1) provides that deployers which are bodies governed by public law, or private entities providing public services, and deployers of high-risk AI systems referred to in points 5(b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of systems intended to be used in the area listed in point 2 of Annex III. That assessment consists of a description of the deployer's processes in which the system will be used in line with its intended purpose, of the period and frequency of use, of the categories of natural persons and groups likely to be affected, of the specific risks of harm to those categories, of the implementation of human oversight measures, and of the measures to be taken if those risks materialise, including the arrangements for internal governance and complaint mechanisms. Article 27(2) provides that the obligation applies to the first use, that the deployer may in similar cases rely on previously conducted impact assessments or existing assessments carried out by the provider, and that a deployer who considers during use that any element listed in paragraph 1 has changed or is no longer up to date shall take the necessary steps to update the information. Article 27(4) provides that where an obligation under this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the assessment under paragraph 1 complements that data protection impact assessment.","lesson":"We read Article 27 as placing the education institution that runs this selection itself in the deployer role, but that alone does not settle the duty. Paragraph 1 names bodies governed by public law and private entities providing public services, and whether a state-funded or a private university of applied sciences answers to either description is the question you have to settle first. If it does, an existing data protection impact assessment is on our reading the starting point rather than the last word: paragraph 4 has the fundamental rights assessment sit alongside it, and since Regulation (EU) 2026/1744 that assessment may incorporate or cross-refer to relevant parts of it, so the real question is which elements of paragraph 1 are still missing. For you that means recording which groups of students may be affected, how the admissions committee or the teacher can correct an outcome, and where a rejected applicant can lodge a complaint. If the selection rule or the assessment component underpinning the ranking changes, that is on our reading the moment to update the record, rather than the start of the next academic year.","source_locator":"Article 27(1), (2) and (4)","provenance":"editorial"},{"label":"Health insurer using AI for risk assessment: public or private makes no difference","situation":"A health insurer uses AI for risk assessment and pricing of health and life insurance. The question is whether this falls under point 5(c) of Annex III, and with that whether the Article 27 FRIA duty comes into play.","outcome":"The Commission draft guidelines of 19 May 2026 state that the health and life insurance in point 5(c) may be offered on a private or a public basis: a health insurer governed by public law also falls within it, so long as the system is intended for risk assessment or pricing with regard to natural persons. Privately serviced health insurance counts as an essential private service, even in a Member State with a public healthcare system. Unlike point 5(b), point 5(c) provides no exception for fraud detection. The document is a consultation version: non-binding and not yet final.","lesson":"For the FRIA question point 5(c) counts twice: it makes the system high-risk and it makes you, as deployer, one of the parties Article 27 names. A public-law form or a public healthcare system in your Member State changes nothing there. Do not count on the fraud-detection exception from point 5(b) either: it does not apply here, and a fraud feature alongside risk assessment does not take the system out.","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (319) to (321)","provenance":"official"},{"label":"Candidate recommendation that automatically becomes a decision","situation":"An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.","outcome":"The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.","lesson":"Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.","source_locator":"Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III","provenance":"official"}],"standards":[{"label":"prEN 18285: conformity assessment framework for AI systems","summary":"The draft European standard operationalising the conformity assessment procedure of Article 43 and Annex VII.","statement":"prEN 18285 (Conformity assessment framework) is the JTC 21 deliverable under M/613 covering the conformity assessment of high-risk AI systems under Article 43 and Annex VII of the AI Act. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal. Standardisation request M/613 was amended by Implementing Decision C(2025)3871 of 23 June 2025 and expires on 28 February 2027."}],"definitions":[],"answer_page":"https://www.praxikon.com/en/antwoord/fria-uitvoeren","follow_up_questions":[{"question":"We are a public-sector organisation using AI. What needs to be in place?","url":"https://www.praxikon.com/en/antwoord/overheid-ai-gebruik"},{"question":"How do the GDPR and the AI Act relate to each other?","url":"https://www.praxikon.com/en/antwoord/avg-en-ai-act"},{"question":"We use AI for creditworthiness or insurance pricing. What applies?","url":"https://www.praxikon.com/en/antwoord/kredietscore-verzekering"}],"disclaimer":"General interpretation, not legal advice. The official source remains authoritative.","methodology":"https://www.praxikon.com/en/methodologie"}