Part of 2026 May 19, 2026 ·
--- days
-- hrs
-- min
-- sec
Content Hub Build Article
Build Aug 5, 2026 · 10 min read

Article 27 of the EU AI Act: The FRIA Obligation That Most Teams Haven't Started

Article 27 of the EU AI Act: The FRIA Obligation That Most Teams Haven't Started

Three days ago, the FRIA requirement under Article 27 became enforceable. For public bodies and private organisations delivering public services, the Fundamental Rights Impact Assessment (FRIA) is no longer a planning exercise. It's a legal obligation with teeth.

Most organisations haven't started. That's not speculation. Over half of enterprises lack systematic AI inventories, which means they can't even identify which systems require a FRIA, let alone complete one. The harmonised technical standards that were supposed to guide compliance arrived eight months late, compressing implementation timelines further.

Here's what Article 27 actually requires, who it applies to, and how to build a FRIA that survives regulatory scrutiny.

What Article 27 Demands

The FRIA is a pre-deployment assessment. Before putting a high-risk AI system into use, certain deployers must evaluate how that system affects the fundamental rights of individuals and groups likely to be impacted. The official text of Article 27 specifies six mandatory elements:

  • A description of the deployer's processes in which the high-risk AI system will be used, aligned with its intended purpose
  • The period of time and frequency of intended use
  • Categories of natural persons and groups likely to be affected
  • Specific risks of harm to those categories, informed by the provider's documentation under Article 13
  • A description of human oversight measures, following the instructions for use
  • Measures to be taken if those risks materialise, including internal governance and complaint mechanisms

Once completed, the deployer must notify the market surveillance authority of the results. This isn't optional. The notification requirement is explicit in Article 27(3).

Who Must Conduct a FRIA

The obligation applies to three categories of deployers:

Public bodies deploying high-risk AI systems. This includes national, regional, and local government entities.

Private organisations delivering public services, such as utilities, transport operators, or public infrastructure providers.

Companies operating in specific high-risk domains listed in Annex III, including creditworthiness evaluation and life and health insurance pricing.

As compliance guidance notes, if an organisation falls into one of these categories and deploys a high-risk AI system as defined under Annex III, Article 27 applies.

Private sector deployers outside these categories are not legally required to conduct a FRIA. But treating it as best practice makes sense. The questions a FRIA forces you to answer are the same questions regulators, auditors, and affected individuals will ask when something goes wrong.

The FRIA Is Not a DPIA

Most compliance teams assume their existing Data Protection Impact Assessment (DPIA) covers the territory. It covers part of it. That assumption is precisely where the gap opens.

The core difference: a DPIA covers privacy risks of data processing under the GDPR. A FRIA assesses the full spectrum of fundamental rights when deploying high-risk AI systems under the EU AI Act.

A DPIA focuses on what data is collected, how it's stored, and whether processing is lawful. A FRIA focuses on people: whether the system treats them fairly, whether it creates systemic disadvantage, and whether those affected by its decisions have a meaningful path to challenge them.

The scope difference is significant. A DPIA addresses Articles 7 and 8 of the EU Charter (privacy and data protection). A FRIA must assess impact across the entire Charter of Fundamental Rights, including human dignity, non-discrimination, freedom of expression, workers' rights, the right to an effective remedy, and children's rights.

Article 27(4) provides a bridge: if any FRIA obligations are already met through a DPIA conducted under GDPR Article 35, that work can be reused. But the DPIA alone is insufficient. The FRIA requires explicit assessment of rights the DPIA was never designed to cover.

The Six Questions a FRIA Must Answer

Strip away the legal language, and a FRIA forces deployers to answer questions that most organisations avoid until something breaks:

Which fundamental rights does this AI system affect? Not just privacy. Dignity, equality, access to legal remedy, freedom from discrimination.

How might it compromise those rights? What happens when the system is wrong? What does "wrong" even look like for this use case?

Who is affected? Not "users" in the abstract. Specific categories of natural persons and groups, with attention to vulnerable populations.

What oversight exists? Human oversight measures must be described in operational terms, not aspirational ones.

Who is accountable? Internal governance arrangements must be documented. When the system fails, who gets paged?

How can affected persons challenge decisions? Complaint mechanisms must exist before deployment, not after the first lawsuit.

Timing and Updates

The FRIA obligation applies to the first use of the high-risk AI system. Article 27(2) specifies that deployers may rely on previously conducted FRIAs or existing impact assessments carried out by the provider for similar cases. But if any element listed in paragraph 1 changes or is no longer up to date, the deployer must update the assessment.

This makes the FRIA a living document, not a one-time compliance exercise. Material changes to the system, the deployment context, or the affected populations trigger an update obligation.

The Penalty Structure

Non-compliance with Article 27 carries fines of up to €15 million or 3% of global annual turnover, whichever is higher. This is not a theoretical risk. The deadline has either been met or missed.

For organisations that haven't started, the question isn't whether to conduct a FRIA. It's how to conduct one quickly enough to limit exposure while building a process that's sustainable for ongoing compliance.

The Template Question

Article 27(5) requires the AI Office to develop a template questionnaire, including through an automated tool, to facilitate deployers in complying with their FRIA obligations. The European Network of National Human Rights Institutions has published recommendations for what that template should include, emphasising meaningful stakeholder engagement, fundamental rights expertise, and iterative assessment throughout the AI lifecycle.

Until the official template is finalised, deployers should document their methodology, benchmark against the EU Charter of Fundamental Rights, and ensure the assessment is conducted by individuals with relevant fundamental rights expertise or with access to such expertise.

What Good Looks Like

A FRIA that survives regulatory scrutiny has three characteristics:

Specificity. Generic statements about "respecting human rights" are worthless. The assessment must identify specific rights, specific risks, and specific mitigations for the specific deployment context.

Operational detail. Human oversight measures must be described in terms of who does what, when, and with what authority. Complaint mechanisms must have defined intake processes, response timelines, and escalation paths.

Evidence of process. The FRIA should document how affected groups were identified, what information from the provider was used, and how risk severity was assessed. Regulators will ask how you reached your conclusions, not just what they were.

The Omnibus Complication

The EU's Digital Omnibus deal, provisionally agreed in May 2026, would defer high-risk deadlines to December 2027. But it is not yet law. The original dates remain binding until the Omnibus is published in the Official Journal.

As of late July 2026, the Council adopted the Digital Omnibus, but Official Journal publication is still pending. The practical advice: keep preparing on the original timeline. Organisations that assumed the deferral would arrive in time and stood down on compliance are now scrambling.

The Path Forward

For organisations that haven't started, the minimum viable approach:

1. Inventory high-risk AI systems. Identify which systems fall under Annex III categories and which deployment contexts trigger Article 27.

2. Gather provider documentation. Article 13 requires providers to supply information deployers need to conduct their FRIA. Request it explicitly.

3. Identify affected groups. Map the categories of natural persons and groups likely to be affected by each system's use.

4. Assess specific risks. For each affected group, identify specific risks to specific fundamental rights, informed by the provider's documentation.

5. Document oversight and remediation. Describe human oversight measures and complaint mechanisms in operational terms.

6. Notify the market surveillance authority. Submit the completed assessment as required by Article 27(3).

The FRIA is not a checkbox exercise. It's a structured way to answer the questions that matter before deployment, rather than after something goes wrong. Organisations that treat it as a governance tool rather than a compliance burden will be better positioned when the inevitable edge cases emerge.

For those tracking the evolving landscape of AI governance in Europe, the Human × AI Content Hub offers ongoing coverage where regulatory developments meet practical implementation challenges.

Frequently Asked Questions

Q: What is a FRIA under the EU AI Act?

A: A Fundamental Rights Impact Assessment (FRIA) is a mandatory pre-deployment evaluation required under Article 27 of the EU AI Act. It assesses how a high-risk AI system affects the fundamental rights of individuals and groups likely to be impacted, covering rights beyond data protection including dignity, equality, and access to legal remedy.

Q: When did the FRIA requirement become enforceable?

A: The FRIA obligation under Article 27 became enforceable on 2 August 2026. The EU's Digital Omnibus proposal would defer this to December 2027, but until that proposal is published in the Official Journal, the original date remains legally binding.

Q: Who must conduct a FRIA?

A: Three categories of deployers must conduct a FRIA: public bodies deploying high-risk AI systems, private organisations delivering public services (utilities, transport, infrastructure), and companies operating in specific Annex III domains including creditworthiness evaluation and life/health insurance pricing.

Q: How is a FRIA different from a DPIA?

A: A DPIA under GDPR Article 35 focuses on privacy and data protection risks. A FRIA covers the full spectrum of EU Charter rights including non-discrimination, human dignity, workers' rights, and access to justice. Article 27(4) allows reuse of DPIA work, but a DPIA alone is insufficient for FRIA compliance.

Q: What happens if an organisation fails to conduct a FRIA?

A: Non-compliance with Article 27 carries fines of up to €15 million or 3% of global annual turnover, whichever is higher. The assessment must be completed before first deployment and results must be notified to the market surveillance authority.

Q: What must a FRIA contain?

A: Article 27(1) requires six elements: description of deployment processes, period and frequency of use, categories of affected persons, specific risks of harm, description of human oversight measures, and measures to address risk materialisation including internal governance and complaint mechanisms.

Enjoyed this? Get the Daily Brief.

Curated AI insights for European leaders — straight to your inbox.

Created by People. Powered by AI. Enabled by Cities.

One day to shape
Europe's AI future

Secure your place at the most important AI convergence event in Central Europe.