Try all features for free — 3 credits included on sign-upTry for free
Skip to main content
Back to obligations
Article 27High-risk

Fundamental rights impact assessment (FRIA)

Deployer
Deadline: December 2, 2027

Article 27 requires deployers under public law and private entities providing public services to carry out a fundamental rights impact assessment before deploying a high-risk AI system. This assessment must analyze specific risks to affected persons and groups.

FRIA · Article 27 of the EU AI ActVerified on 4 August 2026

AI Act FRIA: Article 27 Impact Assessment

A FRIA assesses how a high-risk AI system may affect fundamental rights. Article 27 covers public-law bodies, private providers of public services and deployers of certain credit-scoring or life and health insurance systems. The assessment must be completed before deployment. Where a DPIA is also required, the FRIA complements it rather than replacing it.

What your FRIA file should document

Processes and intended purpose
Period and frequency of use
People and groups likely to be affected
Specific fundamental-rights risks
Human oversight, mitigation and governance
Information, complaint and redress mechanisms
Read Article 27 on EUR-Lex

Build your FRIA from your diagnostic

aiacto organises information about the use case, affected people, risks and controls into a structured FRIA file. Legal validation and the deployment decision remain your responsibility.

Check whether a FRIA applies

Frequently asked questions about FRIAs

Who must conduct a FRIA?

Article 27 covers public-law bodies, private entities providing public services and deployers of certain high-risk systems listed in points 5(b) and 5(c) of Annex III. Systems in point 2 of Annex III are excluded from this specific duty.

Does a GDPR DPIA replace a FRIA?

No. A DPIA examines personal-data processing risks; a FRIA addresses the broader fundamental-rights impact of the AI system. Evidence may be coordinated, but each requirement must remain identifiable.

When should a FRIA be updated?

It is completed before deployment and reviewed when the system, use context, affected populations or relevant risks change.

Key points

1Mandatory for public law bodies and providers of public services
2Description of AI system usage processes
3Period and frequency of intended use
4Categories of natural persons and groups likely to be affected
5Human oversight measures and planned redress procedures

Related definitions

Related articles

Check your compliance with Article 27

Our free diagnostic identifies the obligations applicable to your AI system and guides you to the necessary documentation.