Definition · AI governance
Fundamental rights impact assessment
A fundamental rights impact assessment (FRIA) is what EU AI Act Article 27 requires before certain deployers first use a high-risk AI system in a listed use case. It covers public bodies, private entities providing public services, and those scoring people's credit or pricing their life and health insurance. It records who may be harmed, how, and the deployer's measures.
Last reviewed
Key points
- A FRIA is the deployer's job, not the provider's. It is done before the first use of a high-risk AI system and updated when the facts change.
- It applies to public bodies and private entities providing public services, except in critical infrastructure, and to any deployer using AI to score people's credit or to assess and price their life and health insurance.
- It covers six things, including who is likely to be affected, the risks of harm to them, human oversight, and the measures planned if those risks materialise.
- The deployer normally notifies its market surveillance authority, for a bank usually its financial supervisor. The duty applies from 2 December 2027; most systems already in service are caught only after a significant design change.
- Where a data protection impact assessment already covers part of a FRIA, the deployer may cross-reference it or copy its relevant parts.
How it works
The EU AI Act requires a FRIA from the deployer, the organization using an AI system under its authority, before it first uses a high-risk AI system listed in Annex III, the Act’s list of high-risk uses. Three kinds of deployer must do one:
- bodies governed by public law
- private entities providing public services, such as in education, healthcare, social services or housing
- any deployer using AI to score people’s creditworthiness, other than for fraud detection, or to assess and price their life and health insurance
Critical infrastructure is excluded.
The assessment must describe six things:
- the deployer’s processes that will use the system
- how long and how often it will be used
- the people and groups likely to be affected
- the specific risks of harm to them, using the provider’s information
- how human oversight will work
- the measures the deployer will take if the risks materialise, including governance and complaint handling
The deployer notifies the results to its market surveillance authority, on a template the AI Office must develop. That is set by sector: for a bank, usually its financial supervisor; for police and migration uses, a data protection authority or equivalent. An emergency authorisation under Article 46(1) can exempt the notice.
Why it matters
A provider must put a high-risk system through conformity assessment before placing it on the market or putting it into service, and supplies instructions for use. Article 27 puts a different question to the deployer: which of its own processes will use the system, which people it will affect “in the specific context”, and for how long.
Those answers depend on where the system is used, not only on how it was built.
In practice
The duty applies from 2 December 2027, the date set by the Digital Omnibus on AI, Regulation (EU) 2026/1744. A high-risk system placed on the market or put into service before then is caught only if its design changes significantly. Two exceptions: systems intended for public authorities must comply by 2 August 2030, and those in the EU’s large-scale IT systems, such as the Schengen Information System, by 31 December 2030. One use needed a FRIA earlier: since 2 February 2025, police may use real-time remote biometric identification in publicly accessible spaces only after completing one.
The duty covers the first use. In similar cases a deployer may rely on an earlier FRIA, or on existing impact assessments by the provider. If the deployer considers that an element has changed, it must update the information.
As adopted in 2024, the FRIA was to “complement” a data protection impact assessment that already met some of its obligations. Since the 2026 amendment, where a DPIA already meets part of the FRIA, the deployer may cross-reference it or copy its relevant parts.
Deployers that are public authorities or EU bodies must also register their use in the EU database of high-risk AI systems, with a summary of the FRIA findings. That summary is public, except for law enforcement, migration, asylum and border control uses, whose entries sit in a non-public section and leave it out.
Where definitions disagree
The Act sets a minimum. Its recital says deployers “could involve” relevant stakeholders, including representatives of affected groups, independent experts and civil society, where appropriate, to collect the information the assessment needs. A December 2025 guide by the European Center for Not-for-Profit Law and the Danish Institute for Human Rights says a FRIA “demands meaningful engagement” with affected groups. It warns that stakeholders might doubt a desk-only FRIA, and might suspect that one done after the decision to deploy downplayed the harms. That guide is advice, not law.
Questions and answers
Does a bank using AI for credit scoring need a FRIA?
Yes, if the system evaluates people's creditworthiness or sets their credit score, and it counts as high-risk. The EU AI Act lists those uses in Annex III point 5(b), and Article 27 requires a fundamental rights impact assessment from any deployer of them, public or private. AI used to detect financial fraud is excluded. The duty applies from 2 December 2027. A system placed on the market or put into service before then is caught only if its design changes significantly.
Is a FRIA the same as a DPIA?
No. A data protection impact assessment is a GDPR duty for high-risk processing of personal data. A fundamental rights impact assessment is an EU AI Act duty for certain deployers of high-risk AI systems. Since Regulation (EU) 2026/1744, where a DPIA already meets part of the FRIA, the deployer may cross-reference that DPIA or copy its relevant parts into the FRIA. Regulation (EU) 2026/1744 is the Digital Omnibus on AI.
Does a FRIA have to be published?
Not for most deployers. The deployer must notify its market surveillance authority of the results, unless an emergency authorisation under Article 46(1) exempts it. Only deployers that are public authorities or EU bodies, or act on their behalf, must also put a summary of the findings in the public EU database of high-risk AI systems. Law enforcement, migration, asylum and border control entries go in a non-public section without the summary.
What is the fine for not doing a FRIA?
Article 27 is not among the provisions Article 99(4) lists for fixed fine ceilings. That list includes deployers' Article 26 obligations, at up to €15 million or, for a company, 3% of the preceding year's worldwide turnover, whichever is higher (whichever is lower for small and medium-sized enterprises and small mid-caps). Member States must still set penalties for any infringement of the Act.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text 27 July 2026, Article 27Publications Office of the European Union, 27 Jul 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)Official Journal of the European Union, 24 Jul 2026
- Regulation (EU) 2024/1689 (Artificial Intelligence Act)Official Journal of the European Union, 12 Jul 2024
- A Guide to Fundamental Rights Impact Assessments (FRIA) under the EU Artificial Intelligence ActEuropean Center for Not-for-Profit Law and the Danish Institute for Human Rights, Dec 2025