Article 27: FRIA
Fundamental rights impact assessment before deploying certain high-risk AI systems.
The official source remains authoritative. This general interpretation is not legal advice.
- Status
- Upcoming
- Application date
- 2 December 2027
- Version
- 1.0.0
- Last reviewed
- 8 August 2026
Who this is relevant to
When this applies
Credit or insurance deployer
A deployer of the relevant creditworthiness or life and health insurance systems in Annex III point 5(b) or 5(c).
Body governed by public law
A deployer that is a body governed by public law.
Private provider of public services
A private deployer providing public services.
- 1The system is high-risk under Article 6(2) and Annex III, excluding Annex III point 2.
- 2The deployer is a body governed by public law, a private provider of public services or uses a relevant system in Annex III point 5(b) or 5(c).
What the official source establishes
The listed deployers must perform a FRIA before deployment. For this Annex III route, the obligation follows the application date of 2 December 2027.
Our interpretation
A FRIA is not a generic risk assessment for every AI system. First establish the system route, Annex III category and type of deployer.
What you can do now
Link the FRIA to the AI inventory and, where relevant, the DPIA. Keep scope, affected groups, mitigations, residual risks and notification in one versioned record.
- 01
Perform a FRIA before deployment
Assess process, duration, affected persons, risks, oversight, mitigation and complaint mechanisms and notify results where required.
What to retain
FRIA report and notification
Dated impact assessment, measures, residual risks and, where required, notification to the market surveillance authority.
Control and reassessment
Pre-deployment FRIA go/no-go
Block deployment until applicability, assessment, mitigation and notification have been completed.
Public tools
FRIA questionnaire
Public generator for structuring a fundamental rights impact assessment.
Conditions and exceptions
- In the situation covered by Article 46(1), an exemption from notification may apply. This does not generally remove the assessment itself.
Official sources and locators
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 27(1)-(5)
Digital Omnibus on AI 2026/1744
European Parliament and Council | official-journal-2026-07-24
Source locator: Amended application schedule and Article 27 DPIA cross-reference
EU Artificial Intelligence Act 2024/1689
European Parliament and Council | original-oj-2024-07-12
Source locator: Article 27(1)
Digital Omnibus on AI 2026/1744
European Parliament and Council | official-journal-2026-07-24
Source locator: Article 27 amendment on DPIA inclusion or cross-reference
What changed in this
Moments when this obligation took effect, moved or received official guidance.
2027-12-02 | binding law
FRIA follows new date and may cross-reference a DPIA
The FRIA for the relevant Annex III route follows 2 December 2027 and may include or cross-reference relevant DPIA elements.
Version history
v1.0.0
27 July 2026
Article 27: FRIA
Fundamental rights impact assessment before deploying certain high-risk AI systems.
Execution
Carry out the FRIA in a structured way
A FRIA touches DPIA, register and human oversight. Embed AI runs the assessment together with your team and delivers the evidence file.
See the Embed AI approachFor AI agents and integrations
This page and the machine output derive from the same versioned object. Use the API for deterministic filters by role, topic and time.