Examples
Worked examples
- Is an instance
A public university deploying a high-risk automated admissions-screening tool completes a FRIA before first use, documenting who is affected, the specific fundamental-rights risks (e.g. discriminatory outcomes), the human-oversight process, and its complaint-handling mechanism, then reports the results to its national market surveillance authority.
Counter-examples
Looks similar, but isn't
- Not an instance
A private research company using an internal AI tool that does not fall into the Article 6(2)/Annex III high-risk categories -- for example, an internal literature-screening assistant -- is not subject to Article 27's FRIA requirement at all, since the obligation applies only to specific high-risk deployer categories, not to AI use generally.
Editorial commentary
Article 27 of the EU AI Act creates the Fundamental Rights Impact Assessment (FRIA) obligation, layered on top of (not replacing) the Article 6 high-risk classification test itself.
Who must complete one
The obligation applies to public bodies and to private entities providing public services deploying a high-risk AI system under Article 6(2), plus deployers of the specific Annex III(5)(b)/(c) use cases (credit-scoring/creditworthiness and life/health-insurance risk assessment and pricing) regardless of who deploys them — with an exception for the Annex III point 2 (critical infrastructure) category.
What it must contain
- A description of the deployer’s processes in which the system will be used, consistent with its intended purpose;
- The timeline and frequency of intended use;
- The categories of natural persons and groups likely to be affected;
- The specific risks of harm likely to affect those groups;
- A description of the human-oversight measures implemented; and
- The mitigation measures to be taken if those risks materialize, including complaint-handling mechanisms.
Timing and relationship to GDPR
The FRIA must be completed before the system’s first deployment, and its results reported to the relevant market surveillance authority. A GDPR Data Protection Impact Assessment can complement a FRIA where the two overlap, but does not substitute for it — the FRIA’s scope is broader than data protection alone, covering the full range of fundamental rights. See the related GDPR Article 22 (automated decision-making) and special category data terms for the data-protection-specific angle. The European AI Office is responsible for issuing the FRIA template. An assessment must be updated if the circumstances of use change materially.
Frequently Asked Questions
Is a FRIA required for every high-risk AI system?
No — it applies specifically to public-body/public-service deployers and to the two named Annex III(5) use cases, not to every deployer of every high-risk system.
Who reviews the completed FRIA?
Results are reported to the relevant national market surveillance authority; the assessment is not submitted to the European AI Office directly, though the AI Office provides the template used to complete it.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Fundamental Rights Impact Assessment (FRIA)"
vocab-term-identifier="https://casrai.org/dictionary/term/fundamental-rights-impact-assessment" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/fundamental-rights-impact-assessment",
"name": "Fundamental Rights Impact Assessment (FRIA)",
"identifier": "https://casrai.org/dictionary/term/fundamental-rights-impact-assessment",
"description": "A Fundamental Rights Impact Assessment (FRIA) is the pre-deployment assessment that Article 27 of the EU AI Act requires certain deployers of high-risk AI systems -- public bodies, private entities providing public services, and deployers of the Annex III(5)(b)/(c) credit-scoring and life/health-insurance risk-assessment use cases -- to complete before first use. It must describe the intended deployment process, the categories of people likely affected, the specific risks of harm to their fundamental rights, the human-oversight arrangements, and the mitigation measures in place, using a template the European AI Office is required to provide.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/fundamental-rights-impact-assessment",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-08-22T10:45:01",
"dateModified": "2026-09-04T07:25:43",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}







