What Is a Fundamental Rights Impact Assessment (FRIA) Under the EU AI Act?

Executive Summary

A Fundamental Rights Impact Assessment (FRIA) is a mandatory assessment under Article 27 of the EU AI Act for deployers of certain high-risk AI systems.

The purpose of a FRIA is to identify, evaluate, and mitigate potential impacts on fundamental rights before an AI system is deployed.

Unlike a Data Protection Impact Assessment (DPIA), a FRIA examines a broader range of rights, including equality, non-discrimination, human dignity, freedom of expression, workers’ rights, and access to justice.

Fundamental Rights Impact Assessment is grounded in Article 27 of the EU AI ActIt is an obligation placed on deployers — the organisations that put a high-risk AI system into use — rather than on the providers that build or sell it. The assessment must be carried out before the system is deployed for the first timeand forms part of the wider set of governance obligations the AI Act places on deployers of high-risk systems. 

AI systems increasingly influence decisions that shape people’s lives — who is offered credit, shortlisted for a job, or flagged for closer scrutiny by a public authorityExisting frameworks such as the GDPR were designed to govern how personal data is processed, but they were not built to catch every way automated decision-making can disadvantage people: algorithmic discrimination that reproduces or amplifies bias, opaque scoring that is difficult to challenge, or disproportionate effects on vulnerable groups. The FRIA was introduced to close that gap, requiring certain deployers to assess fundamental rights risk specificallyrather than relying on data protection compliance alone. 

Explain Annex III scope AND Article 27’s narrower trigger: FRIA is not required for every Annex III high-risk system. It applies only to (i) deployers that are public bodies or private entities providing public services, for any Annex III system they use except point 2 (critical infrastructure, e.g. safety components in critical digital infrastructure, road traffic, or water/gas/heating/electricity supply), and (ii) any deployer, public or private, of high-risk AI systems under Annex III points 5(b) and 5(c) — creditworthiness/credit scoring and life or health insurance risk assessment and pricing. 

Examples: 

Credit Scoring Systems — Annex III 5(b); triggers FRIA for any deployer 

Life/Health Insurance Risk Assessment AI — Annex III 5(c); triggers FRIA for any deployer 

Recruitment AI — Annex III high-risk; triggers FRIA only if the deployer is a public body or public-service provider 

Employee Monitoring AI — Annex III high-risk; same public-body/public-service caveat 

Educational Assessment AI — Annex III high-risk; same caveat 

Biometric Identification Systems — Annex III high-risk; same caveat 

A FRIA looks well beyond data protection. Drawing on the Charter of Fundamental Rights of the EU, it must consider the full range of rights an AI system could affect, including: 

Human Dignity (Charter, Art. 1): whether the system reduces a person to a data point or exposes them to degrading treatment. 

Equality and Non-Discrimination (Charter, Art. 21): whether the system produces discriminatory outcomes, directly or indirectly, against a protected characteristic. 

Rights of Children (Charter, Art. 24): whether children are affected by, or able to access, the system, and what extra safeguards that requires. 

Rights of Persons with Disabilities (Charter, Art. 26): whether the system is accessible and avoids excluding people with disabilities. 

Freedom of Expression (Charter, Art. 11): whether the system moderates, filters, or otherwise chills lawful speech. 

Workers’ Rights (Charter, Title IV, Solidarity): whether the system, when used in recruitment, monitoring, or performance management, undermines fair treatment at work. 

Access to Justice (Charter, Art. 47): whether people affected by an AI-driven decision can understand it and challenge it effectively. 

Responsibility for the FRIA sits with the deployer — the organisation that puts the high-risk AI system into use — not the provider that developed it. The AI Act treats the two roles separatelyproviders must give deployers the information needed to understand a system’s risksbut it is the deployer who must carry out and own the fundamental rights impact assessment before using the systemThis holds even where the AI is bought in from a third-party vendor — using someone else’s AI system does not transfer or remove the deployer’s obligation to assess its impact on fundamental rights. 

  • Article 27(1) sets out six elements a FRIA must cover, which in practice translate into the following sections: 
  • System description: how the AI system will be used in the deployer’s processes, in line with its intended purpose, and the period and frequency of that use. 
  • Purpose: the specific goal the system is being deployed to achieve. 
  • Stakeholder mapping: the categories of people and groups likely to be affected by the system in that specific context. 
  • Rights analysis: which fundamental rights are engaged and how. 
  • Risk assessment: the specific risks of harm to the people and groups identified, taking into account the information the provider is required to supply. 
  • Mitigation measures: the human oversight arrangements built into the system’s use. 

Governance controls: what happens if the risks materialise, including internal governance and complaint mechanisms. 

FRIA vs DPIA 

A DPIA and a FRIA overlap but are not interchangeable. A DPIA, required under Article 35 GDPR, focuses on risks arising from the processing of personal data — lawfulness, necessity, proportionality, and data security. A FRIA, required under Article 27 of the AI Act, looks at the wider set of fundamental rights an AI system can affect, including rights that have nothing to do with personal data, such as freedom of expression, workers’ rights, or access to justice. The two are not run in isolation from each other, however: under Article 27(4), where a deployer’s DPIA already addresses some of the same ground, the FRIA can build on and complement that DPIA rather than duplicating it. In practice, most deployers of high-risk AI systems that process personal data will need both assessments, with the FRIA extending the DPIA’s analysis into the fundamental-rights areas a DPIA does not cover. Learn more here.

Common FRIA Mistakes 

✅  Assuming a DPIA is enough: a DPIA covers data protection risk, not the full range of fundamental rights a FRIA must assess — the two need to be read together, not treated as substitutes. 

✅  Ignoring vulnerable groups: failing to consider how the system may disproportionately affect children, people with disabilities, or other at-risk groups. 

✅  Treating the FRIA as a legal-only exercise: leaving the assessment solely to legal or compliance teams, without input from the people who understand how the system actually works. 

✅  Not involving business stakeholders: excluding the product, operations, or HR teams deploying the system, which leads to a FRIA that doesn't reflect how the system is used in practice. 

Frequently Asked Questions 

Only certain deployerspublic bodies and private entities providing public servicesfor most Annex III high-risk systems (excluding critical infrastructure under Annex III point 2), plus any deployer — public or private — using AI for creditworthiness/credit scoring or life and health insurance risk assessment and pricing under Annex III points 5(b) and 5(c). 

No — different scopebut the two can be run together. A DPIA looks at data protection risk; a FRIA looks at the wider set of fundamental rights an AI system may affectand under Article 27(4) can build on an existing DPIA rather than duplicating it. 

Under the original AI Act textArticle 27 was due to apply from 2 August 2026. However, the EU’s Digital Omnibus on AI — formally adopted by the Council on 29 June 2026 after European Parliament approval on 16 June 2026 — defers standalone Annex III high-risk obligationsincluding the FRIA, to 2 December 2027. This takes legal effect once published in the Official Journal (expected imminentlyentering into force three days after publication). Treat the extension as additional runway to preparenot as a reason to pauseand confirm the current status before relying on either date. 

The deployer must notify the relevant market surveillance authority of the resultsusing the template the EU AI Office is developingunless an exemption applies. 

Yes — a deployer may rely on a previously conducted FRIA, or an impact assessment carried out by the providerin similar casesbut must update it if the way the system is usedor the risks it posessubsequently changes. 

2026-07-17T10:51:47+01:00July 15th, 2026|Data Governance, Data Protection, GDPR, Policies|