Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Article 27

UpcomingFrom 2 Dec 2027

Conduct a Fundamental Rights Impact Assessment Before Applicable High-Risk AI Deployment

Applies to Deployer that is a body governed by public law or a private entity providing public services; or Deployer of Annex III point 5(b) or 5(c) High-Risk AI.

Actors
Deployer
AI class
Annex III High-Risk AI
Themes
Governance & AccountabilityPeople & Culture

Tracker Guidance

Before first using an Article 6(2)/Annex III high-risk AI system, perform a fundamental rights impact assessment if your organization is a body governed by public law, a private entity providing public services, or a deployer of the Annex III point 5(b) or 5(c) systems. Assess the required process, use, affected-person, risk, oversight and mitigation information. Update the assessment when relevant information changes and notify the market-surveillance authority of the results. If a GDPR or law-enforcement DPIA already addresses part of the Article 27 requirements, you may cross-reference or incorporate the relevant DPIA sections instead of duplicating that work.

Official text

Article 27Official source
1. Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing public services, and deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights that the use of such system may produce. For that purpose, deployers shall perform an assessment consisting of: (a) a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose; (b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used; (c) the categories of natural persons and groups likely to be affected by its use in the specific context; (d) the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13; (e) a description of the implementation of human oversight measures, according to the instructions for use; (f) the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms. [Excerpt - see official source for complete provision]

Excerpt stored at a complete legal-unit boundary. See the official source for the full provision.

Sub-obligations

These are independently assessable parts of the parent requirement.

  1. Article 27(1)(a)-(c)

    Upcoming

    Document the Intended Process, Use Period and Frequency, and Affected Persons in the FRIA

    Tracker Guidance

    Document the processes in which the high-risk AI system will be used, the intended period and frequency of use, and the categories of natural persons and groups likely to be affected in the specific context.

    Official text

    Article 27(1)(a)-(c)Official source
    (a) a description of the deployer’s processes in which the high-risk AI system will be used in line with its intended purpose; (b) a description of the period of time within which, and the frequency with which, each high-risk AI system is intended to be used; (c) the categories of natural persons and groups likely to be affected by its use in the specific context;
  2. Article 27(1)(d)-(e)

    Upcoming

    Assess Fundamental Rights Risks and Document Human Oversight in the FRIA

    Tracker Guidance

    Identify the specific risks of harm that may affect the people or groups identified in the FRIA, taking the provider's Article 13 information into account, and document how the required human-oversight measures will be implemented.

    Official text

    Article 27(1)(d)-(e)Official source
    (d) the specific risks of harm likely to have an impact on the categories of natural persons or groups of persons identified pursuant to point (c) of this paragraph, taking into account the information given by the provider pursuant to Article 13; (e) a description of the implementation of human oversight measures, according to the instructions for use;
  3. Article 27(1)(f)

    Upcoming

    Define FRIA Mitigation, Internal Governance and Complaint Arrangements

    Tracker Guidance

    Document the measures your organization will take if the identified fundamental-rights risks materialise, including relevant internal-governance arrangements and complaint mechanisms.

    Official text

    Article 27(1)(f)Official source
    (f) the measures to be taken in the case of the materialisation of those risks, including the arrangements for internal governance and complaint mechanisms.
  4. Article 27(2)

    Upcoming

    Update the Fundamental Rights Impact Assessment When Relevant Circumstances Change

    Tracker Guidance

    The FRIA requirement applies to the first use of the high-risk AI system. In similar cases, your organization may rely on previously conducted FRIAs or existing provider impact assessments. If relevant FRIA information changes or is no longer current during use, update the assessment information.

    Official text

    Article 27(2)Official source
    2. The obligation laid down in paragraph 1 applies to the first use of the high-risk AI system. The deployer may, in similar cases, rely on previously conducted fundamental rights impact assessments or existing impact assessments carried out by provider. If, during the use of the high-risk AI system, the deployer considers that any of the elements listed in paragraph 1 has changed or is no longer up to date, the deployer shall take the necessary steps to update the information.
  5. Article 27(3)

    Upcoming

    Notify the Market-Surveillance Authority of the FRIA Results

    Tracker Guidance

    After completing the FRIA, notify the market-surveillance authority of the results using the Article 27 template. The Article 46(1) derogation may exempt a deployer from this notification requirement.

    Official text

    Article 27(3)Official source
    3. Once the assessment referred to in paragraph 1 of this Article has been performed, the deployer shall notify the market surveillance authority of its results, submitting the filled-out template referred to in paragraph 5 of this Article as part of the notification. In the case referred to in Article 46(1), deployers may be exempt from that obligation to notify.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Article 27: Conduct a Fundamental Rights Impact Assessment Before Applicable High-Risk AI Deployment | EU AI Act Library