Direct answer
Do we need to perform a FRIA and how do we approach it? (Private party, not credit or insurance)
This falls under Article 26: obligations of deployers of high-risk AI systems. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- Article 2(10) excludes natural persons using an AI system in the course of a purely personal, non-professional activity. For deployers that are financial institutions subject to internal governance requirements under Union financial services law, the monitoring obligation in paragraph 5 is deemed fulfilled by complying with those rules, and the logs under paragraph 6 are maintained as part of the documentation kept under that law.
First step: Assign human oversight and give those people a mandate.
You describe: A fundamental rights impact assessment (Article 27) for deploying a high-risk AI system. Likely role: deployer (you use the system).
This applies now
- Articles 43-49: conformity assessment, CE and registrationApplicable
- Article 4: AI literacyApplicable
Coming up
- Article 26: obligations of deployers of high-risk AI systemsfrom 2 December 2027
- Annex III: high-risk AIfrom 2 December 2027
Then the Article 27 fundamental-rights assessment likely does not apply to you: it targets public organisations and credit and insurance use cases. Your duties as a deployer of a high-risk system remain fully in place, and if you process personal data a GDPR data protection impact assessment may be required independently. That is a different assessment, with a different purpose and a different supervisor.
Your first actions
- Assign human oversight and give those people a mandate. Name, per high-risk system, who exercises oversight, and ensure that person has the competence, training, authority and support to actually set the output aside.
- Complete the conformity route before market placement. Select the correct assessment procedure, draw up the EU declaration of conformity, affix the CE marking and register in the EU database.
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
Record this
- Deployment dossier: logs, worker information and information to affected persons
- Conformity file
- Article 49(2) registration record for the system assessed as not high-risk
education
Candidate recommendation that automatically becomes a decision
An employer uses a system that ranks applicants and recommends a candidate to hire. In one setup a recruiter weighs that recommendation in their own assessment; in the other the outcome is applied automatically and a candidate is rejected without anyone looking at it.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
Assess a recruitment system on its intended purpose rather than on whether a recruiter reviews the output, because adding or removing human involvement does not change its high-risk classification.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
education
A three-part training for legal and public affairs staff
Booking.com built a three-part training for its legal and public affairs teams: first basic terminology and the difference between classic machine learning and language models, then how AI works inside the company, then the regulatory landscape and where it meets the law they already practise. The material was also released as a video and podcast series with subtitles and written handouts.
Provenance: This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.
The sequence is the interesting part: first the technology, then the organisation itself, and only then the law. Lawyers who reverse that order memorise the Regulation without being able to judge where their own systems land. That the training exists in several formats also helps to show it was genuinely reachable for everyone who needed it.
Living repository of AI literacy practices, practice submitted by the organisation concerned
education
A trained AI contact person in every department at a telecom company
Fastweb operates more than ninety AI systems and formally appoints an AI-SPOC in every department, a trained point of contact for AI questions from that team. These people receive separate instruction on prohibited practices and high-risk systems and are allowed to run their department's AI risk assessment themselves.
Provenance: This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.
Do not copy a practice from this repository as is, since the Commission states that replication grants no automatic presumption of compliance; first test whether the setup fits your own systems and roles.
Living repository of AI literacy practices, practice submitted by the organisation concerned
education
Weather simulation where machine learning approximates physical processes
A meteorological institute runs physics based weather models and uses machine learning to approximate complex atmospheric processes such as cloud microphysics and turbulence. The estimated values are then fed into the established physics model, which produces the actual forecast.
Provenance: The Commission guidelines on the definition of an AI system use this case to draw the line between software that does and does not fall under the regulation. The document is non-binding.
That your model can infer from input does not by itself bring it within the definition, since the guidelines justify excluding such accelerating systems precisely because they do not transcend basic data processing.
Commission Guidelines C(2025) 5053 final, 29.7.2025, borderline cases under the definition in Article 3(1)
No mandatory course format, no certificate, no exam and no AI officer
The Commission Q&A on AI literacy states that there is no one size fits all when it comes to AI literacy and that no strict requirements or mandatory trainings are imposed. On certification, the Q&A states literally that there is no need for a certificate and that organisations can keep an internal record of trainings or other guiding initiatives. On assessment, it states that Article 4 of the AI Act does not entail an obligation to measure the AI knowledge of employees. On governance, it states that no specific governance structure is mandated to comply with Article 4, so that unlike the data protection officer under the GDPR, no AI officer needs to be appointed. On the level, the Q&A states that following the Digital Omnibus amendment AI literacy remains an obligation for providers and deployers of AI systems, but that no specific or sufficient level is mandated and that the Regulation does not require guaranteeing any specific level of AI literacy of any individual. Against that, the Q&A states that simply relying on the AI systems' instructions for use or asking staff to read them might be ineffective, and that organisations should take into account general AI understanding within the organisation, whether they are a provider or a deployer, the risks associated with the systems deployed, staff knowledge gaps considering technical knowledge, experience, education and training, and contextual factors such as sector, purpose and affected populations. The Q&A further states that organisations may implement different levels of training or learning approaches depending on knowledge, experience, education and role, and that staff with a degree or experience in AI development are normally considered AI literate, while the organisation must still verify that those persons understand the specific AI systems of the organisation, know how to deal with them and are aware of all risks.
Commission Q&A on AI literacy, sections on required level, training formats, certificates, assessment of knowledge and governance structures (consulted 9 August 2026)
Article 4 reaches beyond your own staff, and the national supervisor enforces it
The Commission Q&A on AI literacy states that Article 4 applies to providers and deployers of AI systems and in addition to other persons dealing with the operation and use of AI systems on their behalf, covering persons broadly within the organisational remit, with a contractor, a service provider and a client given as examples. On clients, the Q&A states that they may need AI literacy depending on the specific risk, reasoning that affected persons should understand how decisions taken with the assistance of AI will have an impact on them. On geographic scope, the Q&A states that the AI Act's legal framework applies to both public and private actors inside and outside the EU as long as the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. On supervision, the Q&A states that the supervision and enforcement of Article 4 is not with the AI Office but under the remit of national market surveillance authorities, and that supervision and enforcement began on 2 August 2026, while Article 4 itself entered into application on 2 February 2025. On sanctions, the Q&A states that national market surveillance authorities could impose penalties and other enforcement measures for infringements of Article 4, that this will be based on national laws that Member States were due to adopt by 2 August 2025, that any sanction must be proportionate and based on the individual case taking into account factors such as the nature and gravity of the infringement and its intentional or negligent character, and that sanctions are more likely if there is proof of an incident due to a lack of appropriate training and guidance. Article 4 is not listed in the enumeration in Article 99(4) of the AI Act, which covers only Articles 16, 22, 23, 24, 26, 31, 33(1), (3) and (4), 34 and 50, so the level of any penalty for Article 4 follows from national law rather than from the Regulation's own ceilings. The Q&A further states that Article 4 reinforces the transparency provisions of Article 13 and the human oversight provisions of Article 14 and indirectly contributes to the protection of affected persons, and that for deployers of high-risk systems the Article 26 obligation to ensure staff are trained to ensure human oversight is a distinct requirement; that requirement becomes applicable on 2 December 2027 for standalone Annex III systems and on 2 August 2028 for Annex I systems.
Commission Q&A on AI literacy, sections on target groups, geographic scope, supervision and enforcement, and sanctions (consulted 9 August 2026)
Annex I lists legislation, not products
The draft guidelines of 19 May 2026, published for consultation and expressly non-binding, clarify that Annex I AI Act does not list individual products to be classified as high-risk, but Union harmonisation legislation regulating the safety aspects of certain products. Whether an AI system falls within the scope of Annex I therefore depends on whether the system, or the product of which it is a safety component, falls within the material scope of one of the listed legislative acts. According to the draft guidelines the list in Annex I is exhaustive; products can only be added or removed by amending the scope of the harmonisation legislation itself or by adding new harmonisation legislation to Annex I. The draft guidelines also state that through Article 6(1) the AI Act does not itself extend the scope of harmonisation legislation to new or additional products, and that the AI Act does not determine or change the risk profile of a product but builds on the sectoral risk classification. Products mentioned include machinery, toys, lifts, equipment and protective systems for potentially explosive atmospheres, radio equipment, pressure equipment, recreational craft, cableway installations, appliances burning gaseous fuels, medical devices, in vitro diagnostic medical devices, and products in the automotive and aviation sectors.
Draft guidelines Annex I, points (23) to (26)
Section A and Section B of Annex I trigger different requirement sets
The Commission draft guidelines of 19 May 2026, which are non-binding as long as the final version has not been adopted, draw a distinction that is often missed in practice. AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section A of Annex I are subject to the requirements for high-risk systems in Section 2 of Chapter III AI Act. By contrast, for AI systems classified as high-risk under Article 6(1) in respect of products covered by the harmonisation legislation in Section B of Annex I, only Article 6(1), Articles 102 to 109 and Article 112 AI Act apply. The draft guidelines refer to Article 2(2) AI Act for this. Section A contains harmonisation legislation based on the New Legislative Framework, Section B the other Union harmonisation legislation.
Draft guidelines Annex I, point (60), referring to Article 2(2) AI Act
prEN 18285: conformity assessment framework for AI systems
prEN 18285 (Conformity assessment framework) is the JTC 21 deliverable under M/613 covering the conformity assessment of high-risk AI systems under Article 43 and Annex VII of the AI Act. As at June 2026 the deliverable was at the drafting stage. It has not yet been published as an EN and is not cited in the Official Journal. Standardisation request M/613 was amended by Implementing Decision C(2025)3871 of 23 June 2025 and expires on 28 February 2027.
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situation