ISHIGHRISK AI
Analysis

Who has to do a fundamental rights impact assessment

The Article 27 FRIA is a deployer duty, not a provider one. Who it catches, its six required elements, and why it starts on 2 December 2027.

Published Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

The fundamental rights impact assessment in Article 27 of Regulation (EU) 2024/1689 is a deployer duty and never a provider one. It reaches Annex III high-risk systems other than point 2 critical infrastructure, and only where the deployer is a body governed by public law, a private entity providing public services, or the deployer of an Annex III point 5(b) or 5(c) system, meaning credit scoring or life and health insurance pricing. It has six required content elements, it is owed before first use, and its results go to the market surveillance authority under Article 27(3). Regulation (EU) 2026/1744 rewrote paragraphs 4 and 5 so that a deployer may cross-refer to a GDPR data protection impact assessment instead of being told the FRIA complements it, and left paragraphs 1 to 3 untouched. Article 27 binds nobody as a free-standing duty today, since it applies from 2 December 2027, though the Article 5(2) cross-reference to it has been live since 2 February 2025.

Who owes a fundamental rights impact assessment

The fundamental rights impact assessment in Article 27 of Regulation (EU) 2024/1689 is a deployer duty, and only a defined subset of deployers owe it. Providers do not. Article 27(1) reads "deployers ... shall perform", and a provider appears only as the source of the Article 13 instructions for use and as the optional author of an existing impact assessment a deployer may reuse under Article 27(2). Summaries describing a FRIA obligation on providers have misread the provision.

Two conditions must both hold. The system is high-risk under Article 6(2), meaning it is listed in Annex III, and it is not one of the Annex III point 2 critical infrastructure systems, which Article 27(1) carves out expressly. And the deployer is one of three things: a body governed by public law, a private entity providing public services, or the deployer of an Annex III point 5(b) or 5(c) system. That third limb is an addition rather than a subset: it catches commercial banks and insurers providing no public service at all.

Point 5(b) is creditworthiness evaluation and credit scoring, with systems used for the purpose of detecting financial fraud expressly excluded, the population covered on the credit scoring page. Point 5(c) is risk assessment and pricing in life and health insurance only, so motor, property and travel cover sit outside it. Annex III point 5(a), eligibility for essential public assistance benefits, is not a named point; a 5(a) deployer is caught through the public-body limb, which it almost always is, because 5(a) is confined to use by or on behalf of public authorities.

Deployer and system FRIA under Article 27? Reason
Municipality running an Annex III point 5(a) benefits eligibility system Yes Body governed by public law, Article 27(1)
Commercial bank running a credit-scoring model, Annex III point 5(b) Yes Named point, no public service needed
Insurer pricing life or health cover, Annex III point 5(c) Yes Named point, Article 27(1)
Insurer pricing motor, property or travel cover No Point 5(c) covers life and health insurance only
Private retailer running an Annex III point 4 recruitment system No Not a public-law body, and point 4 is not a named point
Grid operator running an Annex III point 2 safety component No Point 2 is carved out of Article 27(1)
Provider of any Annex III system No Article 27(1) binds deployers
Deployer of an Annex I embedded high-risk system No Article 27(1) covers Article 6(2) systems only

Article 27 defines neither "bodies governed by public law" nor "private entities providing public services", and neither term is in Article 3. Recital 96 is the only steer: such entities are linked to tasks in the public interest "such as in the areas of education, healthcare, social services, housing, administration of justice". A private hospital, an academy trust or a housing association reasons from that list rather than from a test, so record the reasoning in the file.

All of this sits downstream of classification. Where the provider validly concluded under Article 6(3) that an Annex III system poses no significant risk of harm, it is not high-risk and no FRIA arises, unless it performs profiling of natural persons, which is always high-risk. Settle high-risk classification and which role you occupy first; what is high-risk AI works through Annex III.

The six elements the assessment must contain

Article 27(1) lists six things, and they are the whole of the prescribed content.

Point Element
(a) A description of the deployer's processes in which the system will be used, in line with its intended purpose
(b) The period of time within which, and the frequency with which, the system is intended to be used
(c) The categories of natural persons and groups likely to be affected by its use in the specific context
(d) The specific risks of harm likely to affect those categories, taking into account the information given by the provider under Article 13
(e) A description of the implementation of human oversight measures, according to the instructions for use
(f) The measures to be taken if those risks materialise, including internal governance arrangements and complaint mechanisms

Two of the six point back at the provider: (d) requires the deployer to take account of the information given under Article 13, and (e) requires oversight measures to be described according to the instructions for use. Article 26(9) sends the same material into the deployer's data protection impact assessment.

The deployer owes the assessment, the provider holds two of its inputs. Points (d) and (e) both resolve to the Article 13 instructions for use, and nothing in Article 27 gives a deployer a right to demand more than the provider chose to supply. The leverage exists at procurement, not at assessment time.

Article 27 prescribes no methodology, no severity scale and no threshold at which a risk becomes unacceptable. It requires measures under (f) but does not say the deployment must be abandoned where risks cannot be mitigated, and it sets no competence or seniority requirement on whoever does the work. Nor does it require consultation: recital 96 says deployers "could involve" affected groups, experts and civil society, which is a recital and not an obligation. Treat the six as the minimum contents of a file capable of being notified to a market surveillance authority, and state the method used.

First use, reuse and the update duty

Article 27 binds nobody as a free-standing duty today. It sits in Chapter III, Section 3, and point (c) of the third paragraph of Article 113, as replaced by Article 1(40)(b) of Regulation (EU) 2026/1744, splits that Section between 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and 2 August 2028 for those under Article 6(1) and Annex I. Since Article 27(1) is confined to Article 6(2) systems, only the first date can ever apply. Under the original Regulation the duty would have applied from 2 August 2026. One cross-reference to it is already live: Article 5(2), in application since 2 February 2025, conditions law enforcement use of real-time remote biometric identification on a completed assessment as provided for in Article 27.

2 Dec 2027 Article 27 applies. A FRIA is owed before first use of an Annex III high-risk system by a deployer the Article names.
2 Aug 2030 Article 111(2) backstop for legacy systems: providers and deployers of high-risk systems intended to be used by public authorities must comply in any case by this date.

Article 27(2) attaches the duty to first use, not to every use, and permits reliance "in similar cases" on a previously conducted assessment or on an existing impact assessment carried out by a provider. Similarity is not defined and nobody is named as its judge. Measure it against the six elements: reuse is supportable where the processes under (a), the affected categories under (c), the risks under (d) and the oversight measures under (e) are the same, and write the comparison down. An update duty then runs for as long as the system is in use, wherever the deployer considers an element has changed or is out of date.

The legacy carve-out matters more here than elsewhere. Under Article 111(2), as replaced by Regulation (EU) 2026/1744, systems placed on the market before the Chapter III date escape unless subject to significant changes in design from that date, but providers and deployers of high-risk systems intended to be used by public authorities must comply by 2 August 2030 regardless. Because the backstop reaches only systems intended to be used by public authorities, it is the operative deadline for the legacy public-sector deployments Article 27 catches, and not for a bank or insurer caught through Annex III point 5(b) or 5(c).

Article 27 is silent on retention, where Article 18 sets ten years for provider documentation and Article 26(6) six months for deployer logs. Keep the assessment for the life of the deployment at least: Article 27(3) presupposes a document producible to a market surveillance authority, and Article 27(2) one comparable against a later deployment.

What the Digital Omnibus changed

Regulation (EU) 2026/1744, in force since 27 July 2026, amended Article 27 in two places, paragraphs 4 and 5. Paragraphs 1, 2 and 3 are untouched, so the scope test, the six elements, the first-use trigger, the update duty and the notification duty are the 2024 text.

Paragraph 4 carries the substance. The original said that where an Article 27 obligation was already met through a data protection impact assessment under Article 35 GDPR or Article 27 of Directive (EU) 2016/680, the FRIA "shall complement" that assessment. That mandatory relationship is gone. The replacement is permissive: the deployer "may ... include cross-references to the relevant sections of that data protection impact assessment or include relevant parts thereof in the fundamental rights impact assessment". It does not merge the two instruments, and a DPIA does not discharge the FRIA. The deployer still produces a FRIA, now partly assemblable out of DPIA material. Neither paragraph 4 nor Article 26(9) says which comes first, a relationship traced in where the AI Act and the GDPR overlap.

Paragraph 5 was amended to match: the AI Office template must now, where relevant, give deployers the means to exercise that cross-referencing right. No deadline is set for producing it. Two cautions follow. Regulation (EU) 2026/1744 carries no recital explaining either amendment, so there is no stated rationale for dropping the mandatory complement. And the Commission's own AI Act Service Desk still shows the 2024 Article 27 behind a banner recording that the page has not been updated for the Digital Omnibus, so the official page currently gives superseded words.

Two disclosure routes, not one

Article 27(3) is the route most explainers cover. Once the assessment has been performed, the deployer must notify the market surveillance authority of its results, submitting the filled-out Article 27(5) template as part of the notification. A deployer may be exempt in the Article 46(1) case, the derogation from conformity assessment granted on a duly justified request for exceptional reasons of public security, life and health, environmental protection or key industrial and infrastructural assets. Article 27(3) does not say who grants that exemption, and fixes no period, form or channel.

The second route is easy to miss. A public authority deployer registering its use of an Annex III system in the EU database under Article 49(3) must enter, under Annex VIII, Section C, point 4, "a summary of the findings" of the Article 27 assessment. That is additional to the Article 27(3) notification. Registration survived the Digital Omnibus in simplified form: Article 1(42) of Regulation (EU) 2026/1744 deleted points 7 and 9 of Annex VIII Section B only, leaving Section C untouched. For Annex III points 1, 6 and 7, law enforcement, migration, asylum and border control, Article 49(4)(c) limits the entry to Section C points 1 to 3 in a secure non-public section, which excludes the summary.

Beyond those two routes there is no further notification duty, but the second route is also a publication route: under Article 71(4) the information registered in accordance with Article 49 is publicly available in the EU database, apart from the secure section referred to in Article 49(4), so the Annex VIII Section C point 4 summary of the findings is public for a public authority deployer. Nothing in the Regulation gives affected persons a right to the full assessment. Article 27 is also silent on whether an update under paragraph 2 must be notified again, paragraph 3 being keyed to the assessment "referred to in paragraph 1". Notify again where an update changes the results, since what paragraph 3 requires is notification of results.

What a missing FRIA costs

Not the figure most summaries quote. Article 99(4) sets the €15,000,000 or 3% of total worldwide annual turnover tier for an exhaustive list: Article 16 for providers, Article 22 for authorised representatives, Article 23 for importers, Article 24 for distributors, Article 25(2) and (4), Article 26 for deployers, Articles 31, 33(1), (3) and (4) and 34 for notified bodies, and Article 50 for transparency. Article 27 is absent, and deployer duties are captured only through Article 26. A missing, stale or unnotified FRIA is not of itself a 3% infringement.

It lands instead on Article 99(1), as replaced by Article 1(38)(a) of Regulation (EU) 2026/1744, which requires member states to lay down penalties and other enforcement measures, "which may also include administrative fines, warnings and non-monetary measures, applicable to any infringement of this Regulation by operators". The Omnibus added administrative fines and widened "infringements" to "any infringement", so unlisted duties are penalised under national law and the amount is set by each member state. The penalties guide covers the tiers that are fixed.

Three qualifications keep the exposure real. First, Article 27(1) says "bodies governed by public law", a term neither Article 3 nor Article 27 defines, and Articles 26(8) and 49(3) list Union institutions, bodies, offices and agencies separately from public authorities, so whether they fall inside that limb is unsettled. Where they do, Article 100(3) lets the EDPS fine up to €750,000 for "the non-compliance of the AI system with any requirements or obligations under this Regulation, other than those laid down in Article 5", wording keyed to the system rather than to a deployer's paperwork. Second, for a deployer that is a public authority a missing FRIA also leaves the Article 49(3) registration incomplete, because Annex VIII Section C point 4 calls for a summary of its findings, and Article 26(8) makes compliance with Article 49 a deployer obligation inside the 3% tier. Third, in one case the assessment is a precondition of lawful use. Article 5(2) authorises real-time remote biometric identification in publicly accessible spaces for law enforcement only where the authority has completed an Article 27 assessment and registered the system under Article 49, with an urgency carve-out for registration but not for the assessment. Without it the use is unauthorised, and falls into the Article 5 tier of up to €35,000,000 or 7% under Article 99(3). Penalties have applied since 2 August 2025. Article 27 as a free-standing duty cannot be infringed until 2 December 2027, but the Article 5(2) precondition, and with it the Article 99(3) tier, has been live since Article 5 began to apply on 2 February 2025.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

Who has to do a fundamental rights impact assessment under the AI Act?

Deployers, and only three categories of them. Article 27(1) binds deployers of Annex III high-risk systems that are bodies governed by public law, deployers that are private entities providing public services, and any deployer of an Annex III point 5(b) or 5(c) system, which is creditworthiness evaluation and credit scoring, and risk assessment and pricing in life and health insurance. Systems in the area listed in Annex III point 2, critical infrastructure, are carved out expressly. Everyone else, including every provider, owes no assessment under this Article.

Is a fundamental rights impact assessment the same as a DPIA?

No. They are separate documents owed under separate instruments. A data protection impact assessment is a controller duty under Article 35 GDPR, triggered by high-risk processing. A FRIA is a deployer duty under Article 27 of the AI Act, triggered by the classification of the system and the identity of the deployer. Article 27(4), as replaced by Regulation (EU) 2026/1744, now says only that where a DPIA already meets an Article 27 obligation the deployer may include cross-references to the relevant sections or lift relevant parts across. A DPIA does not discharge the FRIA.

When does the Article 27 FRIA obligation start?

2 December 2027, and that is the only date that can apply to it. Article 27 sits in Chapter III, Section 3, and point (c) of the third paragraph of Article 113, as replaced by Regulation (EU) 2026/1744, splits that Section between 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and 2 August 2028 for Annex I embedded products. Because Article 27(1) is confined to systems referred to in Article 6(2), the 2028 date never bites on a FRIA. Under the original Regulation the duty would have applied from 2 August 2026.

Do providers have to do a fundamental rights impact assessment?

No. Article 27(1) reads "deployers ... shall perform", and providers appear in the Article in two supporting roles only. Under point (d) the provider is the source of the Article 13 information the deployer must take into account when identifying risks of harm, and under Article 27(2) a provider may have carried out an existing impact assessment that a deployer is permitted to rely on. No Article obliges a provider to produce one, so that permission may have nothing to attach to. Provider obligations sit in Article 16.

Is there an official FRIA template from the AI Office?

Article 27(5) requires the AI Office to develop a template for a questionnaire, including through an automated tool, and as amended it must also let deployers exercise the Article 27(4) cross-referencing right. No deadline is set for delivering it, and no such template has been published on the Commission's official channels as at 6 August 2026. Article 27(3) nonetheless requires the filled-out template to be submitted with the notification, so build the assessment around the six elements in the order Article 27(1) lists them and transcribe it later.

What is the penalty for failing to carry out a FRIA?

Not the headline figure. Article 27 does not appear in the exhaustive list in Article 99(4), so the €15,000,000 or 3% of worldwide annual turnover tier does not attach to a FRIA failure of itself. It falls to Article 99(1), which requires member states to set penalties for any infringement of the Regulation, so the amount is national law. Two indirect routes matter: for a public authority deployer the missing summary leaves the Article 49(3) registration incomplete, and Article 26(8) makes compliance with Article 49 a deployer obligation inside the 3% tier; and Article 100(3) lets the EDPS fine a Union institution up to €750,000 for non-compliance of the AI system with obligations other than those in Article 5.

This article is analysis, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026, as that text stood at the last site review on 4 August 2026. Final classification for ambiguous cases needs qualified counsel.