Skip to content
SimpleAct Logo

AI Act · Article 27

As of 7 October 2026, after the Digital Omnibus

Fundamental rights impact assessment (FRIA) under Article 27 of the AI Act

Certain deployers of high-risk AI must assess, before putting the system into use, how it may affect the fundamental rights of the people concerned. This page covers who is affected, what the assessment must contain, whom you notify and how it relates to the data protection impact assessment.

Short answer

A fundamental rights impact assessment (FRIA) must be carried out by deployers of high-risk AI systems under Article 6(2) that are bodies governed by public law or private entities providing public services, and by all deployers of systems for creditworthiness assessment and for risk assessment and pricing in life and health insurance (Art. 27(1), Annex III point 5(b) and (c)). Systems in the area of critical infrastructure (Annex III point 2) are excluded. The assessment covers six elements (Art. 27(1)(a) to (f)) and its results are notified to the market surveillance authority (para. 3). For high-risk systems under Annex III, the obligations in Chapter III Section 3, which includes Article 27, apply from 2 December 2027 (Art. 113, third paragraph, point (c)(i) as amended by Regulation (EU) 2026/1744).

Scope

Who has to carry out a fundamental rights impact assessment

The duty lies with deployers, not providers. It covers only high-risk AI systems under Article 6(2), i.e. the areas in Annex III, and not systems in Annex III point 2 (critical infrastructure).

  • Art. 27(1)

    Bodies governed by public law

    Public authorities and other public-law bodies deploying a high-risk AI system under Annex III.

  • Art. 27(1)

    Private entities providing public services

    Private companies that provide public services and deploy a high-risk AI system under Annex III. Article 27 does not list which services qualify; this needs to be assessed case by case.

  • Annex III point 5(b)

    Creditworthiness and credit scoring

    All deployers of AI systems used to evaluate the creditworthiness of natural persons or establish their credit score, public or private. AI systems used to detect financial fraud are excluded.

  • Annex III point 5(c)

    Life and health insurance

    All deployers of AI systems used for risk assessment and pricing in relation to natural persons in the case of life and health insurance.

Timing: prior to deploying the system, for its first use. In similar cases the deployer may rely on previously conducted fundamental rights impact assessments or on existing impact assessments carried out by the provider. If any element of paragraph 1 changes during use, the deployer must update the information (Art. 27(1) and (2)).

Contents

What the assessment must contain: Article 27(1)(a) to (f)

ElementContentSource
ProcessesA description of the deployer’s processes in which the system will be used in line with its intended purposeArt. 27(1)(a)
Period and frequencyA description of the period of time within which, and the frequency with which, the system is intended to be usedArt. 27(1)(b)
Affected personsThe categories of natural persons and groups likely to be affected in the specific contextArt. 27(1)(c)
Risks of harmThe specific risks of harm to those persons or groups, taking into account the provider’s information under Article 13Art. 27(1)(d)
Human oversightA description of how human oversight measures are implemented according to the instructions for useArt. 27(1)(e)
Measures if risks materialiseMeasures to be taken if the risks materialise, including internal governance arrangements and complaint mechanismsArt. 27(1)(f)

Notification

Notify the market surveillance authority

Once the assessment has been performed, the deployer notifies the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 as part of the notification (Art. 27(3), first sentence).

In the case referred to in Article 46(1), an exceptional authorisation to place on the market or put into service without conformity assessment, deployers may be exempt from the obligation to notify (Art. 27(3), second sentence).

The template is a questionnaire developed by the AI Office, including through an automated tool, to help deployers comply in a simplified manner. Since Regulation (EU) 2026/1744 it shall, where relevant, also allow cross-references to the data protection impact assessment (Art. 27(5) as amended).

Link to the DPIA

Fundamental rights impact assessment and data protection impact assessment

The FRIA does not replace the data protection impact assessment (DPIA) under Article 35 GDPR, nor the other way round. If an obligation in Article 27 is already met through a DPIA under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may include cross-references to the relevant sections of that DPIA or include relevant parts of it in the FRIA (Art. 27(4) as amended by Regulation (EU) 2026/1744).

In practice: do not rewrite the description of processing, affected persons and mitigation measures from the DPIA, refer to them. The DPIA looks at risks to rights and freedoms arising from processing personal data; the FRIA asks about every fundamental right that the use of the AI system may affect.

Template

A simple outline for your fundamental rights impact assessment

An outline suggested by SimpleAct, not an official template. Items 3 to 8 correspond to Article 27(1)(a) to (f). For the notification under paragraph 3, use the AI Office template.

  • 1. Master data: AI system, provider, version, intended purpose, high-risk area under Annex III, responsible person, date
  • 2. Applicability: why Article 27 applies (public body, public service or Annex III point 5(b)/(c))
  • 3. Processes in which the system is used (point a)
  • 4. Period and frequency of use (point b)
  • 5. Affected persons and groups in the specific context (point c)
  • 6. Specific risks of harm per group, with reference to the Article 13 instructions (point d)
  • 7. Implementation of human oversight according to the instructions for use (point e)
  • 8. Measures if risks materialise, internal governance, complaint route (point f)
  • 9. Cross-references to the DPIA where it already covers obligations (para. 4)
  • 10. Notification to the market surveillance authority: date, authority, template attached (para. 3)
  • 11. Review: trigger and date of the next update (para. 2)

Application

When does the obligation apply?

QuestionAnswerSource
When does Article 27 apply to Annex III systems?From 2 December 2027 (Chapter III Section 3)Art. 113, third para., point (c)(i) as amended
What about legacy systems used by public authorities?Providers and deployers of high-risk AI systems intended to be used by public authorities must comply with the requirements and obligations by 2 August 2030Art. 111(2) as amended
When must the assessment be done?Prior to deployment, for the first use; update when elements changeArt. 27(1) and (2)

Dates are based on Articles 113 and 111 as amended by Regulation (EU) 2026/1744. Other legacy systems are only covered under Article 111(2) as amended if they are subsequently subject to significant changes in their design.

Implementation

How SimpleAct helps with the fundamental rights impact assessment

  • Inventory

    Spot the duty per system

    The AI register records every system with its high-risk area and your role, so you can see which systems need a fundamental rights impact assessment.

  • Documentation

    Connect DPIA and FRIA

    Data protection impact assessments and AI documentation live in the same system, so you can refer to existing sections instead of rewriting them.

FAQ

Frequently asked questions about the FRIA

No. Private companies are only covered if they provide public services or deploy a system for creditworthiness assessment of natural persons or for risk assessment and pricing in life and health insurance (Art. 27(1), Annex III point 5(b) and (c)). Bodies governed by public law are covered for all Annex III high-risk systems except point 2.
No, the duty lies with the deployer. In similar cases, however, the deployer may rely on existing impact assessments carried out by the provider (Art. 27(2)). The provider’s information under Article 13 feeds into the risk assessment (Art. 27(1)(d)).
No. Where the DPIA already meets obligations under Article 27, the deployer may refer to the relevant sections or include them (Art. 27(4) as amended by Regulation (EU) 2026/1744).
The market surveillance authority, together with the filled-out AI Office template (Art. 27(3) and (5)). In the case referred to in Article 46(1), deployers may be exempt from notification.
It applies to the first use. If any element of paragraph 1 changes or is no longer up to date, the deployer must update the information (Art. 27(2)).
Article 99(4) does not list Article 27 among the obligations with their own fine tier. Since the Digital Omnibus, however, Article 99(1) requires Member States to lay down penalties for any infringement of the Regulation. How a breach of Article 27 is sanctioned is therefore a matter of national law.

More questions? We're happy to help. Send email · Get started

Sources and status

As of · SimpleAct editorial team

Editorial information, not legal advice. The text published in the Official Journal is authoritative; interpretation and national implementation can differ in individual cases. For specific questions, seek legal advice.

First know which systems are affected

Record your AI systems with their high-risk area and your role, and keep the DPIA and the FRIA in one place. We will show you what that looks like in SimpleAct.