AI Impact Assessment
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because fundamental rights impact assessments are a specific and distinct requirement under the AI Act (Article 27) for high-risk AI systems, requiring dedicated coverage of assessment methodologies, rights considerations, and documentation requirements that are not adequately covered by existing topics.
Overview
8 sources · Sep 25, 2026Legal Framework
The fundamental rights impact assessment (FRIA) is governed by Article 27 of the AI Act, which imposes a mandatory pre-deployment assessment on specific deployers of high-risk AI systems. The obligation targets deployers that are bodies governed by public law, private entities providing public services, and deployers of systems listed in points 5(b) and (c) of Annex III — covering creditworthiness assessment and risk assessment in life insurance.
"shall perform an assessment of the impact on fundamental rights that the use of such system may produce"
— AI Act Art. 27
The assessment under Article 27(1) must encompass six elements: (a) a description of the deployer's processes in which the system will be used; (b) the period and frequency of use; (c) categories of natural persons likely to be affected; (d) specific risks of harm, taking into account provider information under Article 13; (e) implementation of human oversight measures; and (f) measures upon materialization of risks, including internal governance and complaint mechanisms.
Recital 96 clarifies the rationale: the assessment targets deployers in public-interest domains — education, healthcare, social services, housing, and the administration of justice — where AI-mediated decisions can substantially affect individuals' rights.
"The aim of the fundamental rights impact assessment is for the deployer to identify the specific risks to the rights of individuals or groups of individuals likely to be affected"
— AI Act Rec. 96
Article 27(2) limits the obligation to the first use, permitting reliance on prior assessments in similar cases.
Key Developments
No court rulings or DPA enforcement decisions have yet interpreted Article 27. The provision enters an enforcement landscape already shaped by Recital 34, which established an earlier, narrower FRIA concept for law enforcement use of real-time remote biometric identification:
"The use of the real-time remote biometric identification system in publicly accessible spaces should be authorised only if the relevant law enforcement authority has completed a fundamental rights impact assessment"
— AI Act Rec. 34
This precedent suggests that authorities will expect documented, substantive assessments — not pro forma checklists — before deployment proceeds.
Status of the Debate
This topic is an emerging debate. The debate runs ahead of binding authority: Article 27 creates a novel, free-standing FRIA obligation distinct from the DPIA framework under GDPR Article 35. Scholarly discussion is actively addressing how FRIA methodologies should integrate with existing data protection assessments, whether the six-element template in Article 27(1) is exhaustive or a floor, and what "similar cases" means for reusing prior assessments under Article 27(2). No court has spoken on these questions. What would resolve the open questions: guidance from the AI Office and national competent authorities on minimum FRIA methodology, followed by early enforcement decisions testing the sufficiency of assessments.
Practical Guidance
Scope the obligation precisely. Article 27 applies only to public-law deployers, private entities providing public services, and Annex III points 5(b)–(c) deployers. Confirm whether your role is "deployer" rather than "provider."
Integrate provider information. Article 27(1)(d) requires assessment of specific risks of harm using information provided by the provider under Article 13. Request and retain that documentation before completing the FRIA.
Identify affected categories concretely. Article 27(1)(c) requires identification of categories of natural persons and groups likely to be affected. Map these against protected characteristics and vulnerability factors.
Document human oversight and escalation. Article 27(1)(e)–(f) requires description of human oversight implementation and measures upon risk materialization, including complaint mechanisms. Link these to existing governance structures.
Build in update triggers. Per Recital 96, the assessment should be updated when relevant factors change. Establish monitoring processes to identify triggering changes in system use, affected populations, or risk profiles.
Nothing of this type on this topic.