Skip to main content

Fundamental rights impact assessment

A formal check that public-sector organisations must complete to understand whether using a high-risk AI system could harm people's legal rights, and to document how they will address any risks.

The Simple Version

A formal check that public-sector organisations must complete to understand whether using a high-risk AI system could harm people's legal rights, and to document how they will address any risks.

Detailed Explanation

Article 27 obliges public-body deployers and some private deployers (banks, insurance companies, providers of essential services) to conduct a fundamental rights impact assessment (FRIA) before deploying an Annex III high-risk AI system. The FRIA must identify the relevant fundamental rights (dignity, equality, data protection, fair trial, etc.), describe the deployment context, assess risk of adverse impact, and specify mitigating measures. It must be registered and made available to national authorities on request. The FRIA complements the provider's risk management but focuses on deployment-context rights rather than system-level technical risks.

Key Characteristics

  • Mandatory for public-body deployers and specified private deployers of Annex III systems
  • Covers rights under the EU Charter: dignity, equality, non-discrimination, data protection
  • Must document context of use, affected populations, and mitigation measures
  • Must be registered and available to competent authorities

Why It Matters

Local authorities using AI for benefit allocation, courts using AI in case management, and banks using AI credit scoring must integrate FRIA into their AI procurement and deployment governance processes.

Real-World Analogy

Like an Environmental Impact Assessment required before building on protected land, a FRIA systematically evaluates whether deploying a high-risk AI system will damage legally protected interests before the system goes live.

Common Misconceptions

  • The FRIA is the same as a GDPR Data Protection Impact Assessment, they overlap but differ; a DPIA focuses on data processing risks while the FRIA covers the broader spectrum of fundamental rights.
  • Only the provider conducts impact assessments, the FRIA is a deployer obligation focused on the specific deployment context.

Related Terms

Sources & Further Reading