Article 27 of 11324%
Article 27: Fundamental rights impact assessment for high-risk AI systems
EU Official:
UpcomingFRIA duty for applicable Annex III systems from 2 Dec 2027
Title III: High-Risk AI Systems
Application dates
- : FRIA duty for applicable high-risk systems under Article 6(2) and Annex III
Article 27 introduces the FRIA: an assessment of fundamental-rights impact before certain high-risk AI systems are deployed.
Official text
||
Source: EUR-Lex, Regulation (EU) 2024/1689. Text reproduced verbatim.
Download AI Act (PDF)→Official guidance on this article
6- Regulation (EU) 2026/1744, Digital Omnibus on AIAllows a FRIA to include or cross-refer to relevant parts of a DPIA and requires the Commission template to support that route.PublishedRegulationEuropean Parliament and Council of the European Union24 Jul 2026
- Navigating the AI Act (Questions and Answers)Describes why and by whom a fundamental rights assessment must be carried out for high-risk applicationsPublishedQ&AEuropean Commission, DG CONNECT7 Aug 2026
- Statement 3/2024 on data protection authorities' role in the Artificial Intelligence Act frameworkPoints to the expected convergence between the fundamental rights impact assessment of Article 27(4) and the DPIA under GDPR, also via Article 26(9) and Annex VIII section C point 5, such that organisations must align both assessments with each other.PublishedOpinionEDPB (European Data Protection Board)16 Jul 2024
- EDPB Work Programme 2026-2027 (announcing joint guidelines on the interplay between the AI Act and the GDPR)Is expected to determine whether the fundamental rights impact assessment under Article 27 and the data protection impact assessment under the GDPR may be drawn up in a combined document, which makes the difference between one or two processes.AnnouncedGuidelinesEDPB (European Data Protection Board)11 Feb 2026
- ISO/IEC 42005:2025 Information technology - Artificial intelligence (AI) - AI system impact assessmentProvides a developed methodology and documentation structure for impact assessments, which can serve as a practical basis for the fundamental rights impact assessment taking effect from 2 December 2027.PublishedStandardISO/IEC JTC 1/SC 42, Dutch adoption by NEN1 Jun 2025
- AI Regulation timeline (Algoritmekader)Links the fundamental rights assessment for public tasks as requirement aia-27 to the shifted high-risk date.PublishedNational guidanceMinistry of the Interior and Kingdom Relations (Algorithm Framework)17 Jul 2025
What does this mean for you?
Provider+
The FRIA is a duty for certain deployers, but providers must supply under Article 13 the information needed to assess risks, oversight measures and context of use. An existing provider impact assessment may be used as input in similar cases, but it does not transfer the deployer's responsibility.
Deployer+
Before first use, conduct a FRIA if you are a body governed by public law, a private entity providing a public service, or deploy a high-risk system under Annex III point 5(b) or 5(c) for creditworthiness or life and health insurance. Describe the process, duration and frequency of use, affected groups, specific fundamental-rights risks, human oversight and measures if risks materialise.
SME / Startup+
A private SME deployer is not inside or outside Article 27 merely because of its size. Its function and use case are decisive. An SME that provides a public service or deploys an application under Annex III point 5(b) or 5(c) may therefore be required to conduct a FRIA.
Public Sector+
A body governed by public law deploying a high-risk system under Article 6(2) must in principle conduct a FRIA before first use, except for Annex III point 2. Notify the market surveillance authority using the official template and update the assessment when relevant elements change. Regulation (EU) 2026/1744 expressly permits cross-references to, or inclusion of relevant parts from, a DPIA.
Related tools
Related Recitals
Related enforcement
No enforcement actions for this article yet. Follow developments via the Enforcement Tracker.
Related blog posts
- →DPIA vs FRIA: 5 key differences, when you need both, plus a free FRIA template (2026)
- →Article 26 AI Act: 12 deployer obligations explained
- →EU AI Act risk assessment: the 5 types explained
- →EU AI Act recruitment compliance: 2026 requirements checklist
- →AI DPIA: when it's required + free template (2026)
- →FRIA for municipalities: public sector guide
Cross-references
Annexes
Frequently asked questions
What is a FRIA and when is it mandatory?+
A FRIA assesses fundamental rights impacts before first use of an applicable high-risk system under Article 6(2). The duty covers bodies governed by public law, private entities providing public services and deployers under Annex III points 5(b) and 5(c). Point 2 is excluded.
What should a FRIA contain?+
A FRIA must describe the intended use, affected persons, specific risks to fundamental rights, mitigating measures, and oversight mechanisms.
Do SMEs also need to comply with Article 27 of the AI Act?+
Article 27 of the AI Act does not provide a general exemption for SMEs. However, the AI Act includes supportive measures and potentially lighter obligations for small and medium-sized enterprises, depending on their role in the AI value chain.
How does Article 27 of the AI Act relate to the GDPR?+
Article 27 of the AI Act complements the GDPR. While the GDPR protects personal data, the AI Act focuses on the safety and trustworthiness of AI systems. Organisations must comply with both regulations when their AI system processes personal data.
What are the deadlines for Article 27 of the AI Act?+
Article 27 covers only systems under Article 6(2). The core route for the applicable Annex III systems applies from 2 December 2027.
Does Article 27 of the AI Act also apply to AI systems I purchase?+
Yes, Article 27 of the AI Act may also be relevant when you purchase AI systems. As a deployer, you have your own obligations under the AI Act, regardless of whether you developed the system yourself or purchased it from a provider.
What is the difference between provider and deployer under Article 27 of the AI Act?+
Under Article 27 of the AI Act, the provider is the entity that develops or places the AI system on the market, while the deployer is the entity that uses the system under its own authority. Both roles carry different obligations.
What documentation does Article 27 of the AI Act require?+
Article 27 of the AI Act requires that relevant documentation is maintained as part of the compliance process. This may include technical documentation, instructions for use, logs or declarations of conformity, depending on the classification of the AI system.
What is the difference between a FRIA and a DPIA?+
A FRIA assesses broader fundamental rights impacts; a DPIA concerns data protection. Regulation (EU) 2026/1744 allows the FRIA to include or cross-refer to relevant DPIA parts for duties already met through it. Each applicable assessment remains required under its own conditions.
Who must carry out a FRIA?+
Bodies governed by public law, private entities providing public services, and deployers of systems for creditworthiness or credit scoring under Annex III point 5(b) and risk assessment and pricing in life and health insurance under point 5(c).
Is there a standard template available for the FRIA?+
Article 27(5) requires the AI Office to develop a simplified questionnaire template. Since Regulation (EU) 2026/1744, that template must, where relevant, support cross-references to or parts of a DPIA.
Do I need to report the FRIA results to a supervisory authority?+
Yes, Article 27(3) requires deployers to notify the market surveillance authority of the FRIA results by submitting the filled-out template. Additionally, a summary must be registered in the EU database as per Annex VIII, Section C.