FRIA — Fundamental rights impact assessment
Assessment of the impact that the use of a high-risk AI system may have on fundamental rights, which certain deployers must carry out before deploying it (Article 27).
It is the assessment made by whoever uses the system, not whoever makes it, and only a few must do it.
Which obligations it carries
A legal obligation of the deployer, applicable from 2 December 2027, and only where one of these cases applies: the deployer is a body governed by public law or a private entity providing public services and deploys a high-risk system under Article 6(2) — except those in the area of Annex III, point 2, critical infrastructure —; or it deploys a system under Annex III, point 5, points (b) or (c): evaluating the creditworthiness or credit score of natural persons, or risk assessment and pricing in life and health insurance, and here it does not matter whether it is public or private. Outside those cases there is no mandate: a private SME that provides no public services, does not evaluate creditworthiness and does not price life or health insurance is not obliged, and doing it anyway is best practice.
What it is not
It is not a DPIA. The data protection impact assessment of Article 35 GDPR — a legal obligation applicable from 25 May 2018 — and the FRIA are structurally independent instruments: different object, different obliged party and different trigger. It is not an obligation of the provider: the provider supplies information through Article 13; the assessment is made by whoever deploys. And it is not owed by everyone who deploys high risk: Article 27(1) limits the obliged parties and expressly excludes the area of Annex III, point 2. But nor is it “public sector only”: a private entity deploying a system under Annex III, point 5, points (b) or (c) — creditworthiness or credit scoring of natural persons, life and health insurance — is obliged, whether or not it provides public services.
The nuance almost nobody captures
Regulation (EU) 2026/1744 strengthened the relationship with the DPIA in two ways, and both are permissions, not substitutions: if any of the obligations of Article 27 is already met through the data protection impact assessment, the deployer may include cross-references to its relevant sections or incorporate its relevant parts (Article 27(4)); and the AI Office will develop a template questionnaire, including an automated tool, offering that same possibility (Article 27(5)). Referencing is not replacing: the six contents of Article 27(1) — processes in which the system will be used, intended period and frequency of use, categories of persons and groups affected, specific risks of harm, human oversight measures according to the instructions for use, and measures if the risks materialise, including internal governance and complaint mechanisms — must be covered.