# AI Impact Assessment — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/fundamental-rights-impact-assessment-ai
> Sources are cited per item. Verify against the official texts before relying on them.

This new topic is needed because fundamental rights impact assessments are a specific and distinct requirement under the AI Act (Article 27) for high-risk AI systems, requiring dedicated coverage of assessment methodologies, rights considerations, and documentation requirements that are not adequately covered by existing topics.

## Overview

## Legal Framework

The fundamental rights impact assessment (FRIA) is established under Article 27 of the AI Act, creating a distinct pre-deployment obligation for certain deployers of high-risk AI systems. Recital 96 clarifies the scope: the obligation applies to deployers that are public bodies, private entities providing public services, and private deployers of specific high-risk systems listed in the AI Act's annexes, including banking and insurance entities. The assessment must be completed prior to putting a high-risk system into use.

The FRIA operates alongside, not in substitution of, existing data protection obligations. The doctrinal commentary reinforces that joint controllership liability under Article 82(4) GDPR remains fully available to data subjects regardless of any assessment framework — meaning that a completed FRIA does not insulate deployers from individual redress claims under the GDPR. This intersection is critical: where a high-risk AI system processes personal data, the FRIA and the GDPR's accountability tools (Article 35 DPIAs, Article 30 records) create overlapping but non-identical documentation duties.

Recital 34 adds specificity for real-time remote biometric identification systems in publicly accessible spaces, requiring deployers to account for the nature of the situation triggering deployment, consequences for rights and freedoms of all affected persons, and applicable safeguards.

## Key Developments

The EDPB and EDPS issued a joint warning on 30 January 2026 that simplification of AI rules must not come at the expense of fundamental rights protections, signaling regulatory resistance to any dilution of Article 27 requirements. This was followed by civil society opposition on 11 February 2026 to proposed transparency rollbacks under the so-called AI Omnibus, indicating that the FRIA framework faces political pressure but retains strong institutional backing.

No enforcement decisions under Article 27 have yet been published, given the phased application timeline. However, the WP29's earlier guidance on controller accountability under Directive 95/46 — which treated the inability to identify responsible parties as a fundamental accountability failure — provides a doctrinal baseline that supervisory authorities will likely import into FRIA enforcement. Deployers should expect regulators to scrutinize whether the assessment meaningfully identifies specific rights at risk rather than producing generic compliance documentation.

## Practical Guidance

- **Map deployer status before deployment.** Confirm whether your organization qualifies as a public body, a private entity providing public services, or falls within the annexed categories (banking, insurance). Article 27's scope is narrower than the general high-risk deployment obligations — but entities falling outside it may still face equivalent expectations under GDPR Article 35.

- **Conduct the FRIA prior to first use** of any high-risk system, not after pilot testing begins. The assessment must address specific fundamental rights implications — including dignity, non-discrimination, privacy, and access to public services — tied to the concrete use case.

- **Document the methodology, not just the outcome.** The assessment must show how rights risks were identified, evaluated, and mitigated. Retain the full record for supervisory authority inspection, paralleling the GDPR Article 30 record-keeping expectation that documentation must be produced on request.

- **Coordinate FRIA and DPIA processes** where personal data is involved. The assessments serve different legal bases but overlap substantively; maintaining separate but cross-referenced documentation avoids contradictions that regulators could exploit.

- **Preserve individual redress pathways.** The FRIA does not displace data subject rights under the GDPR against any controller involved in the deployment. Ensure that complaint mechanisms and joint controllership arrangements remain accessible regardless of the assessment's conclusions.

## Legislation (full text of key provisions)

### Fundamental rights impact assessment for high-risk AI systems

*Source: AI Act, aiact-art-27-en, 2024-06-12 — https://overview.legal/posts/92424*

### Recital 96 — fundamental rights impact assessment deployers

*Source: AI Act, aiact-rec-96-en, 2024-06-12 — https://overview.legal/posts/93874*

In order to efficiently ensure that fundamental rights are protected, deployers of high-risk AI systems that are bodies governed by public law, or private entities providing public services and deployers of certain high-risk AI systems listed in an annex to this Regulation, such as banking or insurance entities, should carry out a fundamental rights impact assessment prior to putting it into use. Services important for individuals that are of public nature may also be provided by private entities. Private entities providing such public services are linked to tasks in the public interest such as in the areas of education, healthcare, social services, housing, administration of justice. The aim of the fundamental rights impact assessment is for the deployer to identify the specific risks to the rights of individuals or groups of individuals likely to be affected, identify measures to be taken in the case of a materialisation of those risks. The impact assessment should be performed prior to deploying the high-risk AI system, and should be updated when the deployer considers that any of the relevant factors have changed. The impact assessment should identify the deployer’s relevant processes in which the high-risk AI system will be used in line with its intended purpose, and should include a description of the period of time and frequency in which the system is intended to be used as well as of specific categories of natural persons and groups who are likely to be affected in the specific context of use. The assessment should also include the identification of specific risks of harm likely to have an impact on the fundamental rights of those persons or groups. While performing this assessment, the deployer should take into account information relevant to a proper assessment of the impact, including but not limited to the information given by the provider of the high-risk AI system in the instructions for use. In light of the risks identified, deployers should determine measures to be taken in the case of a materialisation of those risks, including for example governance arrangements in that specific context of use, such as arrangements for human oversight according to the instructions of use or, complaint handling and redress procedures, as they could be instrumental in mitigating risks to fundamental rights in concrete use-cases. After performing that impact assessment, the deployer should notify the relevant market surveillance authority. Where appropriate, to collect relevant information necessary to perform the impact assessment, deployers of high-risk AI system, in particular when AI systems are used in the public sector, could involve relevant stakeholders, including the representatives of groups of persons likely to be affected by the AI system, independent experts, and civil society organisations in conducting such impact assessments and designing measures to be taken in the case of materialisation of the risks. The European Artificial Intelligence Office (AI Office) should develop a template for a questionnaire in order to facilitate compliance and reduce the administrative burden for deployers.

### Recital 34 — responsible use of real-time biometric identification

*Source: AI Act, aiact-rec-34-en, 2024-06-12 — https://overview.legal/posts/93750*

In order to ensure that those systems are used in a responsible and proportionate manner, it is also important to establish that, in each of those exhaustively listed and narrowly defined situations, certain elements should be taken into account, in particular as regards the nature of the situation giving rise to the request and the consequences of the use for the rights and freedoms of all persons concerned and the safeguards and conditions provided for with the use. In addition, the use of ‘real-time’ remote biometric identification systems in publicly accessible spaces for the purpose of law enforcement should be deployed only to confirm the specifically targeted individual’s identity and should be limited to what is strictly necessary concerning the period of time, as well as the geographic and personal scope, having regard in particular to the evidence or indications regarding the threats, the victims or perpetrator. The use of the real-time remote biometric identification system in publicly accessible spaces should be authorised only if the relevant law enforcement authority has completed a fundamental rights impact assessment and, unless provided otherwise in this Regulation, has registered the system in the database as set out in this Regulation. The reference database of persons should be appropriate for each use case in each of the situations mentioned above.

## Recent developments

### De FRIA voor AI-systemen komt eraan: bereid u voor

*Source: Autoriteit Persoonsgegevens, 2026-08-17 — https://overview.legal/posts/291285 — original: https://autoriteitpersoonsgegevens.nl/actueel/de-fria-voor-ai-systemen-komt-eraan-bereid-u-voor*

Bent u een overheidsorganisatie of een private organisatie die publieke diensten levert? En bent u van plan een AI-systeem met een hoog risico te gaan gebruiken? Of gaat u als publieke of private organisatie een beoordelingssysteem voor financiële risico’s gebruiken? Dan moet u vanaf december 2027 vooraf beoordelen welke gevolgen dit AI-systeem kan hebben voor de grondrechten van mensen. Zo’n beoordeling heet een ‘fundamental rights impact assessment’ (FRIA), oftewel een ‘grondrechteneffectbeoor

### AI Omnibus: Reject the proposals to undermine transparency in the AI Act

*Source: European Digital Rights, 2026-02-11 — https://overview.legal/posts/52497 — original: https://edri.org/our-work/ai-omnibus-reject-the-proposals-to-undermine-transparency-in-the-ai-act/*

The European Commission’s dangerous and misguided Digital Omnibus proposal includes a dangerous rollback of transparency requirements in the AI Act. 60 civil society organisations, independent public authorities and individuals, including EDRi, urge EU lawmakers to reject a change that would risk weakening enforcement, legal certainty, and the protection of fundamental rights, while offering negligible benefits for companies. The post AI Omnibus: Reject the proposals to undermine transparency in

### EDPB en EDPS waarschuwen: vereenvoudiging AI-regels mag niet ten koste gaan van grondrechten

*Source: Autoriteit Persoonsgegevens, 2026-01-30 — https://overview.legal/posts/52423 — original: https://autoriteitpersoonsgegevens.nl/actueel/edpb-en-edps-waarschuwen-vereenvoudiging-ai-regels-mag-niet-ten-koste-gaan-van-grondrechten*

De European Data Protection Board (EDPB) en de European Data Protection Supervisor (EDPS) hebben een gezamenlijke opinie gepubliceerd over het voorstel van de Europese Commissie om de uitvoering van de AI-verordening te vereenvoudigen. Dit voorstel wordt ook wel de ‘Digital Omnibus on AI’ genoemd.

### EDPB and EDPS support streamlining AI Act implementation but call for stronger safeguards to protect fundamental rights

*Source: European Data Protection Board, 2026-01-21 — https://overview.legal/posts/52417 — original: https://www.edpb.europa.eu/news/news/2026/edpb-and-edps-support-streamlining-ai-act-implementation-call-stronger-safeguards_en*

Brussels, 21 January - The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a Joint Opinion on the European Commission’s Proposal for the ‘Digital Omnibus on AI’. The Proposal seeks to simplify the implementation of certain harmonised rules under the AI Act to ensure their effective application.The EDPB and the EDPS support the objective of addressing practical challenges relating to the implementation of the AI Act. Administrative simplificat

### Why the "Digital Omnibus" threatens privacy regulations (GDPR and ePrivacy).

*Source: European Digital Rights, 2025-11-19 — https://overview.legal/posts/52074*

On November 19th, the European Commission published two so-called "omnibus" proposals: one revising key aspects of the General Data Protection Regulation (GDPR) and the ePrivacy rules, along with other data-related laws, and the other an amendment to the AI Act. This article focuses on the first proposal. It explains how the proposed changes could weaken fundamental rights related to data protection and the confidentiality of communications, and why the combined effect risks undermining long-standing safeguards for individuals within the EU.

## Literature

### General-Purpose AI under the EU AI Act: A Conceptual Allocation of Duties across the Value Chain

*Source: SCRIPTed A Journal of Law Technology & Society, 2026-06-30 — https://overview.legal/posts/132370 — original: https://doi.org/10.2218/scrip.12300*

This article examines how the final version of the EU Artificial Intelligence Act (“AI Act”, adopted 2024) allocates obligations across the AI value chain, with a focus on general-purpose AI (“GPAI”) or foundation models. It proposes a taxonomy of key actors – foundation model providers, fine-tuners, integrators, and deployers – and analyses the interfaces between them, including documentation tools (model cards, system cards) and logging requirements. Building on principles of control, foreseea

### Italy’s Artificial Intelligence Act and Global AI Governance: The EU Model’s Practice and Prospects

*Source: Law and Economy, 2026-02-25 — https://overview.legal/posts/132619 — original: https://doi.org/10.63593/le.2788-7049.2026.03.004*

The Italian Artificial Intelligence Act, enacted on September 17, 2025, represents the first comprehensive national implementation of the European Union’s AI Act. This study examines the Italian legislation through the theoretical lens of multi-level governance, analyzing its dual function as both a “bridging legislation” that translates EU framework into domestic practice and a site of significant regulatory innovation. Through detailed textual analysis and case studies, particularly in healthc

## Related topics

- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Supervision** — https://overview.legal/topics/toezicht
  Oversight and enforcement by supervisory authorities
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data
- **AI Value Chain Actors and Roles** — https://overview.legal/topics/ai-value-chain-actors
  The content focuses on responsibilities distributed across different actors in the AI value chain. A dedicated topic for understanding the various actors, their

---
Generated by overview.legal · https://overview.legal/topics/fundamental-rights-impact-assessment-ai · 2026-08-22
