A formal check that public-sector organisations must complete to understand whether using a high-risk AI system could harm people's legal rights — and to document how they will address any risks.
A formal check that public-sector organisations must complete to understand whether using a high-risk AI system could harm people's legal rights — and to document how they will address any risks.
Article 27 obliges public-body deployers and some private deployers (banks, insurance companies, providers of essential services) to conduct a fundamental rights impact assessment (FRIA) before deploying an Annex III high-risk AI system. The FRIA must identify the relevant fundamental rights (dignity, equality, data protection, fair trial, etc.), describe the deployment context, assess risk of adverse impact, and specify mitigating measures. It must be registered and made available to national authorities on request. The FRIA complements the provider's risk management but focuses on deployment-context rights rather than system-level technical risks.
Local authorities using AI for benefit allocation, courts using AI in case management, and banks using AI credit scoring must integrate FRIA into their AI procurement and deployment governance processes.
Like an Environmental Impact Assessment required before building on protected land — a FRIA systematically evaluates whether deploying a high-risk AI system will damage legally protected interests before the system goes live.
A formal check that public-sector organisations must complete to understand whether using a high-risk AI system could harm people's legal rights — and to document how they will address any risks.
Article 27 obliges public-body deployers and some private deployers (banks, insurance companies, providers of essential services) to conduct a fundamental rights impact assessment (FRIA) before deploying an Annex III high-risk AI system. The FRIA must identify the relevant fundamental rights (dignity, equality, data protection, fair trial, etc.), describe the deployment context, assess risk of adverse impact, and specify mitigating measures. It must be registered and made available to national authorities on request. The FRIA complements the provider's risk management but focuses on deployment-context rights rather than system-level technical risks.
Local authorities using AI for benefit allocation, courts using AI in case management, and banks using AI credit scoring must integrate FRIA into their AI procurement and deployment governance processes.