Skip to content
Topic Emerging debate

AI Impact Assessment

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

This new topic is needed because fundamental rights impact assessments are a specific and distinct requirement under the AI Act (Article 27) for high-risk AI systems, requiring dedicated coverage of assessment methodologies, rights considerations, and documentation requirements that are not adequately covered by existing topics.

18 linked items 3 Laws13 News2 Literature

Overview

8 sources · Jul 23, 2026

Legal Framework

The fundamental rights impact assessment (FRIA) is established under Article 27 of the AI Act, creating a distinct pre-deployment obligation for certain deployers of high-risk AI systems. Recital 96 clarifies the scope: the obligation applies to deployers that are public bodies, private entities providing public services, and private deployers of specific high-risk systems listed in the AI Act's annexes, including banking and insurance entities. The assessment must be completed prior to putting a high-risk system into use.

The FRIA operates alongside, not in substitution of, existing data protection obligations. The doctrinal commentary reinforces that joint controllership liability under Article 82(4) GDPR remains fully available to data subjects regardless of any assessment framework — meaning that a completed FRIA does not insulate deployers from individual redress claims under the GDPR. This intersection is critical: where a high-risk AI system processes personal data, the FRIA and the GDPR's accountability tools (Article 35 DPIAs, Article 30 records) create overlapping but non-identical documentation duties.

Recital 34 adds specificity for real-time remote biometric identification systems in publicly accessible spaces, requiring deployers to account for the nature of the situation triggering deployment, consequences for rights and freedoms of all affected persons, and applicable safeguards.

Key Developments

The EDPB and EDPS issued a joint warning on 30 January 2026 that simplification of AI rules must not come at the expense of fundamental rights protections, signaling regulatory resistance to any dilution of Article 27 requirements. This was followed by civil society opposition on 11 February 2026 to proposed transparency rollbacks under the so-called AI Omnibus, indicating that the FRIA framework faces political pressure but retains strong institutional backing.

No enforcement decisions under Article 27 have yet been published, given the phased application timeline. However, the WP29's earlier guidance on controller accountability under Directive 95/46 — which treated the inability to identify responsible parties as a fundamental accountability failure — provides a doctrinal baseline that supervisory authorities will likely import into FRIA enforcement. Deployers should expect regulators to scrutinize whether the assessment meaningfully identifies specific rights at risk rather than producing generic compliance documentation.

Practical Guidance

  • Map deployer status before deployment. Confirm whether your organization qualifies as a public body, a private entity providing public services, or falls within the annexed categories (banking, insurance). Article 27's scope is narrower than the general high-risk deployment obligations — but entities falling outside it may still face equivalent expectations under GDPR Article 35.

  • Conduct the FRIA prior to first use of any high-risk system, not after pilot testing begins. The assessment must address specific fundamental rights implications — including dignity, non-discrimination, privacy, and access to public services — tied to the concrete use case.

  • Document the methodology, not just the outcome. The assessment must show how rights risks were identified, evaluated, and mitigated. Retain the full record for supervisory authority inspection, paralleling the GDPR Article 30 record-keeping expectation that documentation must be produced on request.

  • Coordinate FRIA and DPIA processes where personal data is involved. The assessments serve different legal bases but overlap substantively; maintaining separate but cross-referenced documentation avoids contradictions that regulators could exploit.

  • Preserve individual redress pathways. The FRIA does not displace data subject rights under the GDPR against any controller involved in the deployment. Ensure that complaint mechanisms and joint controllership arrangements remain accessible regardless of the assessment's conclusions.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 3
Art. 5(2)(cont)(1) In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purposes of law enforcement for any … AI Act Art. 27(4) If any of the obligations laid down in this Article is already met through the data protection impact assessment conducted pursuant to Article 35 of R… AI Act art 27 Fundamental rights impact assessment for high-risk AI systems AI Act Jun 2024 rec 96 Recital 96 — fundamental rights impact assessment deployers AI Act Jun 2024 rec 34 Recital 34 — responsible use of real-time biometric identification AI Act Jun 2024
News 13
Autoriteit Persoonsgegevens De FRIA voor AI-systemen komt eraan: bereid u voor Autoriteit Persoonsgegevens Aug 2026 NL European Digital Rights AI Omnibus: Reject the proposals to undermine transparency in the AI Act European Digital Rights Feb 2026 Autoriteit Persoonsgegevens EDPB and EDPS warn: simplification of AI rules must not be at the expense of fundamental rights Autoriteit Persoonsgegevens Jan 2026 European Data Protection Board EDPB and EDPS support streamlining AI Act implementation but call for stronger safeguards to protect fundamental rights European Data Protection Board Jan 2026 European Digital Rights Why the "Digital Omnibus" threatens privacy regulations (GDPR and ePrivacy). European Digital Rights Nov 2025 Gaming Tech Law Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems? Gaming Tech Law Mar 2023 Fair Trials Europol told to hand over personal data to Dutch activist Fair Trials Sep 2022 eucrim CJEU: PNR Directive Valid if Limited to the “Strictly Necessary” eucrim Aug 2022 eucrim HvJ: De PNR-richtlijn is geldig, mits deze beperkt blijft tot wat "strikt noodzakelijk" is. eucrim Aug 2022 NL EDPS EDPB & EDPS: Proposal to combat child sexual abuse online presents serious risks for fundamental rights EDPS Jul 2022 Hunton Andrews Kurth CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR Hunton Andrews Kurth Aug 2022 Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 Hunton Andrews Kurth Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations Hunton Andrews Kurth Sep 2022
Literature 2
SCRIPTed A Journal of Law Technology & Society General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain SCRIPTed A Journal of Law Technology & Society Jun 2026 FR Law and Economy Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects Law and Economy Feb 2026