AI Impact Assessment
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.This new topic is needed because fundamental rights impact assessments are a specific and distinct requirement under the AI Act (Article 27) for high-risk AI systems, requiring dedicated coverage of assessment methodologies, rights considerations, and documentation requirements that are not adequately covered by existing topics.
Overview
8 sources · Jul 23, 2026Legal Framework
The fundamental rights impact assessment (FRIA) is established under Article 27 of the AI Act, creating a distinct pre-deployment obligation for certain deployers of high-risk AI systems. Recital 96 clarifies the scope: the obligation applies to deployers that are public bodies, private entities providing public services, and private deployers of specific high-risk systems listed in the AI Act's annexes, including banking and insurance entities. The assessment must be completed prior to putting a high-risk system into use.
The FRIA operates alongside, not in substitution of, existing data protection obligations. The doctrinal commentary reinforces that joint controllership liability under Article 82(4) GDPR remains fully available to data subjects regardless of any assessment framework — meaning that a completed FRIA does not insulate deployers from individual redress claims under the GDPR. This intersection is critical: where a high-risk AI system processes personal data, the FRIA and the GDPR's accountability tools (Article 35 DPIAs, Article 30 records) create overlapping but non-identical documentation duties.
Recital 34 adds specificity for real-time remote biometric identification systems in publicly accessible spaces, requiring deployers to account for the nature of the situation triggering deployment, consequences for rights and freedoms of all affected persons, and applicable safeguards.
Key Developments
The EDPB and EDPS issued a joint warning on 30 January 2026 that simplification of AI rules must not come at the expense of fundamental rights protections, signaling regulatory resistance to any dilution of Article 27 requirements. This was followed by civil society opposition on 11 February 2026 to proposed transparency rollbacks under the so-called AI Omnibus, indicating that the FRIA framework faces political pressure but retains strong institutional backing.
No enforcement decisions under Article 27 have yet been published, given the phased application timeline. However, the WP29's earlier guidance on controller accountability under Directive 95/46 — which treated the inability to identify responsible parties as a fundamental accountability failure — provides a doctrinal baseline that supervisory authorities will likely import into FRIA enforcement. Deployers should expect regulators to scrutinize whether the assessment meaningfully identifies specific rights at risk rather than producing generic compliance documentation.
Practical Guidance
Map deployer status before deployment. Confirm whether your organization qualifies as a public body, a private entity providing public services, or falls within the annexed categories (banking, insurance). Article 27's scope is narrower than the general high-risk deployment obligations — but entities falling outside it may still face equivalent expectations under GDPR Article 35.
Conduct the FRIA prior to first use of any high-risk system, not after pilot testing begins. The assessment must address specific fundamental rights implications — including dignity, non-discrimination, privacy, and access to public services — tied to the concrete use case.
Document the methodology, not just the outcome. The assessment must show how rights risks were identified, evaluated, and mitigated. Retain the full record for supervisory authority inspection, paralleling the GDPR Article 30 record-keeping expectation that documentation must be produced on request.
Coordinate FRIA and DPIA processes where personal data is involved. The assessments serve different legal bases but overlap substantively; maintaining separate but cross-referenced documentation avoids contradictions that regulators could exploit.
Preserve individual redress pathways. The FRIA does not displace data subject rights under the GDPR against any controller involved in the deployment. Ensure that complaint mechanisms and joint controllership arrangements remain accessible regardless of the assessment's conclusions.