Skip to content
AI Act Art. 27 EN
LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this article. Contains: the article text, related recitals, cases citing it, enforcement stats and top fines, guidance, and related topics. Everything links back to its source on overview.legal — legal information, not advice.

Fundamental rights impact assessment for high-risk AI systems

In force — consolidated2026-07-27 · CELEX 02024R1689-20260727 · ELI ↗
Version history 2
  • 2026-07-27in force CELEX 02024R1689-20260727
  • 2024-07-12 CELEX 02024R1689-20240712
  1. 1.

    Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of:

    1. a)
      a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose;
    2. b)
      a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used;
    3. c)
      the categories of natural persons and groups likely to be affected by its use in the specific context;
    4. d)
      the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13;
    5. e)
      a description of the implementation of human oversight measures, according to the instructions for use;
    6. f)
      the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.
  2. 2.

    The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.

  3. 3.

    Once the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.

  4. 4.

    If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680, the fundamental rights impact assessment referred to in paragraph 1 of this Article shall complement that data protection impact assessment.

  5. 5.

    The AI Office shall develop a template for a questionnaire, including through an automated tool, to facilitate deployers in complying with their obligations under this Article in a simplified manner.

Related across sources

Opinion 1/2026 EDPB-EDPS Joint opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence EDPB, EDPB-EDPS Joint opinion 1/2026 on the Proposal for a Regulation as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital… Opinion Jan 21, 2026 Artificial Intelligence Entry Into Force Mutual Assistance Between Member States for AI Oversight
2026 If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Dariusz Kloza, Laura Drechsler, Elora Fernandes, Arian Birth et al. — Computer law & security review Computer law & security review ·full text Jan 23, 2026 Right to Explanation Privacy by Design Privacy by Default
2025 EDPB Annual Report 2024 De EDPB heeft het Jaarraport van 2024 gepubliceerd. Met ook een handzame samenvatting voor degene die geen tijd hebben. Er wordt ook een lijst met zaken van enkele DPAs… Apr 23, 2025 Direct Marketing Legitimate Interest Privacy by Design
The FRIA for AI systems is coming: prepare yourself ⇄ Bent u een overheidsorganisatie of een private organisatie die publieke diensten levert? En bent u van plan een AI-systeem met een hoog risico te gaan gebruiken? Of gaat u als… Aug 17, 2026 AI Impact Assessment Artificial Intelligence AI Act Procedures
Statement 3/2024 data protection authorities’ role in the Artificial Intelligence Act framework Final 1 Statement 3/2024 on data protection authorities’ role in the Artificial Intelligence Act framework Adopted on 16 July 2024 The European Data Protection Board has adopted… Statement ·EDPB Jul 16, 2024 Artificial Intelligence Single Point of Contact for AI Regulation Authority Cooperation