AI Act · Article 27
As of 7 October 2026, after the Digital Omnibus
Fundamental rights impact assessment (FRIA) under Article 27 of the AI Act
Certain deployers of high-risk AI must assess, before putting the system into use, how it may affect the fundamental rights of the people concerned. This page covers who is affected, what the assessment must contain, whom you notify and how it relates to the data protection impact assessment.
Short answer
A fundamental rights impact assessment (FRIA) must be carried out by deployers of high-risk AI systems under Article 6(2) that are bodies governed by public law or private entities providing public services, and by all deployers of systems for creditworthiness assessment and for risk assessment and pricing in life and health insurance (Art. 27(1), Annex III point 5(b) and (c)). Systems in the area of critical infrastructure (Annex III point 2) are excluded. The assessment covers six elements (Art. 27(1)(a) to (f)) and its results are notified to the market surveillance authority (para. 3). For high-risk systems under Annex III, the obligations in Chapter III Section 3, which includes Article 27, apply from 2 December 2027 (Art. 113, third paragraph, point (c)(i) as amended by Regulation (EU) 2026/1744).
Scope
Who has to carry out a fundamental rights impact assessment
The duty lies with deployers, not providers. It covers only high-risk AI systems under Article 6(2), i.e. the areas in Annex III, and not systems in Annex III point 2 (critical infrastructure).
Art. 27(1)
Bodies governed by public law
Public authorities and other public-law bodies deploying a high-risk AI system under Annex III.
Art. 27(1)
Private entities providing public services
Private companies that provide public services and deploy a high-risk AI system under Annex III. Article 27 does not list which services qualify; this needs to be assessed case by case.
Annex III point 5(b)
Creditworthiness and credit scoring
All deployers of AI systems used to evaluate the creditworthiness of natural persons or establish their credit score, public or private. AI systems used to detect financial fraud are excluded.
Annex III point 5(c)
Life and health insurance
All deployers of AI systems used for risk assessment and pricing in relation to natural persons in the case of life and health insurance.
Timing: prior to deploying the system, for its first use. In similar cases the deployer may rely on previously conducted fundamental rights impact assessments or on existing impact assessments carried out by the provider. If any element of paragraph 1 changes during use, the deployer must update the information (Art. 27(1) and (2)).
Contents
What the assessment must contain: Article 27(1)(a) to (f)
| Element | Content | Source |
|---|---|---|
| Processes | A description of the deployer’s processes in which the system will be used in line with its intended purpose | Art. 27(1)(a) |
| Period and frequency | A description of the period of time within which, and the frequency with which, the system is intended to be used | Art. 27(1)(b) |
| Affected persons | The categories of natural persons and groups likely to be affected in the specific context | Art. 27(1)(c) |
| Risks of harm | The specific risks of harm to those persons or groups, taking into account the provider’s information under Article 13 | Art. 27(1)(d) |
| Human oversight | A description of how human oversight measures are implemented according to the instructions for use | Art. 27(1)(e) |
| Measures if risks materialise | Measures to be taken if the risks materialise, including internal governance arrangements and complaint mechanisms | Art. 27(1)(f) |
Notification
Notify the market surveillance authority
Once the assessment has been performed, the deployer notifies the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 as part of the notification (Art. 27(3), first sentence).
In the case referred to in Article 46(1), an exceptional authorisation to place on the market or put into service without conformity assessment, deployers may be exempt from the obligation to notify (Art. 27(3), second sentence).
The template is a questionnaire developed by the AI Office, including through an automated tool, to help deployers comply in a simplified manner. Since Regulation (EU) 2026/1744 it shall, where relevant, also allow cross-references to the data protection impact assessment (Art. 27(5) as amended).
Link to the DPIA
Fundamental rights impact assessment and data protection impact assessment
The FRIA does not replace the data protection impact assessment (DPIA) under Article 35 GDPR, nor the other way round. If an obligation in Article 27 is already met through a DPIA under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the deployer may include cross-references to the relevant sections of that DPIA or include relevant parts of it in the FRIA (Art. 27(4) as amended by Regulation (EU) 2026/1744).
In practice: do not rewrite the description of processing, affected persons and mitigation measures from the DPIA, refer to them. The DPIA looks at risks to rights and freedoms arising from processing personal data; the FRIA asks about every fundamental right that the use of the AI system may affect.
Template
A simple outline for your fundamental rights impact assessment
An outline suggested by SimpleAct, not an official template. Items 3 to 8 correspond to Article 27(1)(a) to (f). For the notification under paragraph 3, use the AI Office template.
- 1. Master data: AI system, provider, version, intended purpose, high-risk area under Annex III, responsible person, date
- 2. Applicability: why Article 27 applies (public body, public service or Annex III point 5(b)/(c))
- 3. Processes in which the system is used (point a)
- 4. Period and frequency of use (point b)
- 5. Affected persons and groups in the specific context (point c)
- 6. Specific risks of harm per group, with reference to the Article 13 instructions (point d)
- 7. Implementation of human oversight according to the instructions for use (point e)
- 8. Measures if risks materialise, internal governance, complaint route (point f)
- 9. Cross-references to the DPIA where it already covers obligations (para. 4)
- 10. Notification to the market surveillance authority: date, authority, template attached (para. 3)
- 11. Review: trigger and date of the next update (para. 2)
Application
When does the obligation apply?
| Question | Answer | Source |
|---|---|---|
| When does Article 27 apply to Annex III systems? | From 2 December 2027 (Chapter III Section 3) | Art. 113, third para., point (c)(i) as amended |
| What about legacy systems used by public authorities? | Providers and deployers of high-risk AI systems intended to be used by public authorities must comply with the requirements and obligations by 2 August 2030 | Art. 111(2) as amended |
| When must the assessment be done? | Prior to deployment, for the first use; update when elements change | Art. 27(1) and (2) |
Dates are based on Articles 113 and 111 as amended by Regulation (EU) 2026/1744. Other legacy systems are only covered under Article 111(2) as amended if they are subsequently subject to significant changes in their design.
Implementation
How SimpleAct helps with the fundamental rights impact assessment
Inventory
Spot the duty per system
The AI register records every system with its high-risk area and your role, so you can see which systems need a fundamental rights impact assessment.
Documentation
Connect DPIA and FRIA
Data protection impact assessments and AI documentation live in the same system, so you can refer to existing sections instead of rewriting them.
FAQ
Frequently asked questions about the FRIA
More questions? We're happy to help. Send email · Get started
Sources and status
As of · SimpleAct editorial team
- Regulation (EU) 2024/1689 (AI Act), Official Journal
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal
Editorial information, not legal advice. The text published in the Official Journal is authoritative; interpretation and national implementation can differ in individual cases. For specific questions, seek legal advice.
First know which systems are affected
Record your AI systems with their high-risk area and your role, and keep the DPIA and the FRIA in one place. We will show you what that looks like in SimpleAct.