Skip to main content
Praxikon
All obligations
Upcomingv1.0.0

Article 27: FRIA

Fundamental rights impact assessment before deploying certain high-risk AI systems.

The listed deployers must perform a FRIA before deployment.

Praxikon tracks Article 27: FRIA under the EU AI Act, checked against the official source on 8 August 2026, citing the source for every statement.

Status
Upcoming
Application date
2 December 2027
Version
1.0.0
Last reviewed
8 August 2026

Review status: placed against the official source (8 August 2026). Next check due by 4 February 2027. The check date is the knowledge date of this version; no later recheck has been recorded.

From source to evidence

Why this obligation applies, what it asks of you, and what you show for it.

Applies

Upcoming · 2 December 2027

For whom

  • Credit or insurance deployer
  • Body governed by public law
  • Private provider of public services

What you do

Perform a FRIA before deployment

What you record

FRIA report and notification

Official source

Article 27(1)-(5)

Who this is relevant to

When this applies

  • Credit or insurance deployer

    A deployer of the relevant creditworthiness or life and health insurance systems in Annex III point 5(b) or 5(c).

  • Body governed by public law

    A deployer that is a body governed by public law.

  • Private provider of public services

    A private deployer providing public services.

  1. 1The system is high-risk under Article 6(2) and Annex III, excluding Annex III point 2.
  2. 2The deployer is a body governed by public law, a private provider of public services or uses a relevant system in Annex III point 5(b) or 5(c).

What the official source establishes

The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.

Our interpretation

The official source remains authoritative. This general interpretation is not legal advice.

A FRIA is not a generic risk assessment for every AI system. First establish the system route, Annex III category and type of deployer.

What you can do now

Link the FRIA to the AI inventory and, where relevant, the DPIA. Keep scope, affected groups, mitigations, residual risks and notification in one versioned record.

  1. 01

    Perform a FRIA before deployment

    Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.

What to retain

FRIA report and notification

Dated impact assessment, measures, residual risks and, where required, notification to the market surveillance authority.

Control and reassessment

  • Pre-deployment FRIA go/no-go

    Block deployment until applicability, assessment, mitigation and notification have been completed.

Public tools

Conditions and exceptions

  • In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself.

Official sources and locators

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 27(1)-(5)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Amended application schedule and Article 27 DPIA cross-reference

  • EU Artificial Intelligence Act 2024/1689

    European Parliament and Council | original-oj-2024-07-12

    Source locator: Article 27(1)

  • Digital Omnibus on AI 2026/1744

    European Parliament and Council | official-journal-2026-07-24

    Source locator: Article 27 amendment on DPIA inclusion or cross-reference

Referring to this object

Citation block

Copy this reference into your advice, article or file. The identifier, the version and the hash keep the statement findable later, even once the dataset has moved on.

Reference

Praxikon, "Article 27: FRIA",
praxikon:eu:ai-act:obligation:article-27-fria@1.0.0,
dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0 (schema 1.5.0),
effective_at 2026-07-27T00:00:00.000Z, known_at 2026-08-08T00:00:00.000Z,
sha256 498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e,
https://www.praxikon.com/en/verplichtingen/article-27-fria
(https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-27-fria&effective_at=2026-07-27&known_at=2026-08-08&lang=en, accessed 2026-09-07)

Short form

praxikon:eu:ai-act:obligation:article-27-fria@1.0.0 (sha256 498c9350)

BibTeX

@misc{praxikon-eu-ai-act-obligation-article-27-fria-1-0-0,
  author       = {{Praxikon}},
  title        = {Article 27: FRIA},
  year         = {2026},
  version      = {1.0.0},
  number       = {praxikon:eu:ai-act:obligation:article-27-fria},
  howpublished = {AI Act Change \& Evidence Graph, dataset 2.2.0, schema 1.5.0},
  note         = {effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e},
  url          = {https://www.praxikon.com/en/verplichtingen/article-27-fria},
  urldate      = {2026-09-07},
  language     = {en}
}

CSL JSON

[
  {
    "id": "praxikon:eu:ai-act:obligation:article-27-fria@1.0.0",
    "type": "dataset",
    "title": "Article 27: FRIA",
    "container-title": "AI Act Change & Evidence Graph",
    "publisher": "Praxikon",
    "version": "1.0.0",
    "number": "praxikon:eu:ai-act:obligation:article-27-fria",
    "URL": "https://www.praxikon.com/en/verplichtingen/article-27-fria",
    "language": "en",
    "issued": {
      "date-parts": [
        [
          2026,
          8,
          8
        ]
      ]
    },
    "accessed": {
      "date-parts": [
        [
          2026,
          9,
          7
        ]
      ]
    },
    "note": "dataset praxikon:sys:registry:dataset:ai-act-implementation-graph 2.2.0; schema 1.5.0; effective_at 2026-07-27T00:00:00.000Z; known_at 2026-08-08T00:00:00.000Z; sha256 498c93501f9972d34831aea9c643908d910568bd188c1f76ddb2786c3836b98e; retrieved_from https://www.praxikon.com/api/v1/obligations?id=praxikon%3Aeu%3Aai-act%3Aobligation%3Aarticle-27-fria&effective_at=2026-07-27&known_at=2026-08-08&lang=en; licence https://www.praxikon.com/nl/legal/terms"
  }
]

How to verify a reference later is set out in the methodology. Terms

What changed in this

Moments when this obligation took effect, moved or received official guidance.

  • 2027-12-02 | binding law

    FRIA follows new date and may cross-reference a DPIA

    The FRIA for the relevant Annex III route follows 2 December 2027 and may include or cross-reference relevant DPIA elements.

See the full timeline

Version history

  1. v1.0.0

    27 July 2026

    Article 27: FRIA

    Fundamental rights impact assessment before deploying certain high-risk AI systems.

Corrections to this obligation

No substantive correction to this object has been recorded.

Open the correction log
Zahed Ashkara, lawyer and AI governance specialist

Expert behind this page

Zahed Ashkara

Lawyer and AI governance specialist

Execution

Carry out the FRIA in a structured way

A FRIA touches DPIA, register and human oversight. Embed AI runs the assessment together with your team and delivers the evidence file.

See the Embed AI approach

For AI agents and integrations

This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.