Praxikon
Article 27 of 11324%
Nederlands

Article 27: Fundamental rights impact assessment for high-risk AI systems

EU Official:
UpcomingFRIA duty for applicable Annex III systems from 2 Dec 2027
Title III: High-Risk AI Systems

Application dates

  • : FRIA duty for applicable high-risk systems under Article 6(2) and Annex III

Article 27 introduces the FRIA: an assessment of fundamental-rights impact before certain high-risk AI systems are deployed.

Official text

||

Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.

Download AI Act (PDF)

Official guidance on this article

6

What does this mean for you?

Provider+
The FRIA is a duty for certain deployers, but providers must supply under Article 13 the information needed to assess risks, oversight measures and context of use. An existing provider impact assessment may be used as input in similar cases, but it does not transfer the deployer's responsibility.
Deployer+
Before first use, conduct a FRIA if you are a body governed by public law, a private entity providing a public service, or deploy a high-risk system under Annex III point 5(b) or 5(c) for creditworthiness or life and health insurance. Describe the process, duration and frequency of use, affected groups, specific fundamental-rights risks, human oversight and measures if risks materialise.
SME / Startup+
A private SME deployer is not inside or outside Article 27 merely because of its size. Its function and use case are decisive. An SME that provides a public service or deploys an application under Annex III point 5(b) or 5(c) may therefore be required to conduct a FRIA.
Public Sector+
A body governed by public law deploying a high-risk system under Article 6(2) must in principle conduct a FRIA before first use, except for Annex III point 2. Notify the market surveillance authority using the official template and update the assessment when relevant elements change. Regulation (EU) 2026/1744 expressly permits cross-references to, or inclusion of relevant parts from, a DPIA.

Related tools

Related Recitals

Related enforcement

No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.

Related blog posts

Cross-references

Recitals

Annexes

Frequently asked questions

What is a FRIA and when is it mandatory?+
A FRIA assesses fundamental rights impacts before first use of an applicable high-risk system under Article 6(2). The duty covers bodies governed by public law, private entities providing public services and deployers under Annex III points 5(b) and 5(c). Point 2 is excluded.
What should a FRIA contain?+
A FRIA must describe the intended use, affected persons, specific risks to fundamental rights, mitigating measures, and oversight mechanisms.
Do SMEs also need to comply with Article 27 of the AI Act?+
Article 27 of the AI Act does not provide a general exemption for SMEs. However, the AI Act includes supportive measures and potentially lighter obligations for small and medium-sized enterprises, depending on their role in the AI value chain.
How does Article 27 of the AI Act relate to the GDPR?+
Article 27 of the AI Act complements the GDPR. While the GDPR protects personal data, the AI Act focuses on the safety and trustworthiness of AI systems. Organisations must comply with both regulations when their AI system processes personal data.
What are the deadlines for Article 27 of the AI Act?+
Article 27 covers only systems under Article 6(2). The core route for the applicable Annex III systems applies from 2 December 2027.
Does Article 27 of the AI Act also apply to AI systems I purchase?+
Yes, Article 27 of the AI Act may also be relevant when you purchase AI systems. As a deployer, you have your own obligations under the AI Act, regardless of whether you developed the system yourself or purchased it from a provider.
What is the difference between provider and deployer under Article 27 of the AI Act?+
Under Article 27 of the AI Act, the provider is the entity that develops or places the AI system on the market, while the deployer is the entity that uses the system under its own authority. Both roles carry different obligations.
What documentation does Article 27 of the AI Act require?+
Article 27 of the AI Act requires that relevant documentation is maintained as part of the compliance process. This may include technical documentation, instructions for use, logs or declarations of conformity, depending on the classification of the AI system.
What is the difference between a FRIA and a DPIA?+
A FRIA assesses broader fundamental rights impacts; a DPIA concerns data protection. Regulation (EU) 2026/1744 allows the FRIA to include or cross-refer to relevant DPIA parts for duties already met through it. Each applicable assessment remains required under its own conditions.
Who must carry out a FRIA?+
Bodies governed by public law, private entities providing public services, and deployers of systems for creditworthiness or credit scoring under Annex III point 5(b) and risk assessment and pricing in life and health insurance under point 5(c).
Is there a standard template available for the FRIA?+
Article 27(5) requires the AI Office to develop a simplified questionnaire template. Since Regulation (EU) 2026/1744, that template must, where relevant, support cross-references to or parts of a DPIA.
Do I need to report the FRIA results to a supervisory authority?+
Yes, Article 27(3) requires deployers to notify the market surveillance authority of the FRIA results by submitting the filled-out template. Additionally, a summary must be registered in the EU database as per Annex VIII, Section C.