DepthThe conclusion and your first steps
Direct answer
Do we need to perform a FRIA and how do we approach it?
You describe: A fundamental rights impact assessment (Article 27) for deploying a high-risk AI system. Likely role: public body, public service provider or credit/insurance deployer.
This applies now
- For this situation, the preparation phase matters most right now.
Coming up
- Article 27: FRIAfrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
The FRIA duty applies only to specific deployers and follows the high-risk timeline to 2 December 2027. A FRIA is not a DPIA: they overlap, but the FRIA assesses more than data protection.
Your first actions
- Map the affected groups and their specific risks of harm. Name the categories of natural persons and groups likely to be affected by the use in this specific context, and work out the specific risks of harm per category, using the information the provider supplied under Article 13.
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation