EU AI Act guide · updated 2 August 2026
The FRIA: who must run a fundamental rights impact assessment
Article 27 of the EU AI Act adds one more gate before certain high-risk deployments: a Fundamental Rights Impact Assessment — a structured, documented analysis of how the deployment could affect the people it touches, completed before first use and notified to the market-surveillance authority. It became enforceable, with the rest of the Annex III regime, on 2 August 2026.
Who must run one
- Bodies governed by public law deploying high-risk systems;
- Private entities providing public services — education, healthcare, social services, housing;
- Deployers of credit-scoring AI (Annex III 5(b), excluding pure financial-fraud detection);
- Deployers of life/health insurance risk-pricing AI (Annex III 5(c)).
What the FRIA must contain
Deployment context
The deployer's processes in which the system will be used, aligned with its intended purpose.
Time and frequency
The period and frequency of intended use.
Affected persons
The categories of natural persons and groups likely to be affected in the specific context.
Specific risks of harm
The risks to those groups' fundamental rights, taking the provider's instructions for use into account.
Human oversight
How the Article 14 oversight measures are implemented in this deployment.
Mitigation and governance
Measures if risks materialise: internal governance arrangements and complaint mechanisms.
Doing it without a six-month project
Almost every FRIA input is a fact you either already hold or can extract from the provider’s instructions for use: what the system does, where it sits in your process, who it touches, what oversight exists. The practical sequence:
- Classify the system first — confirm it is actually high-risk and in a FRIA-triggering category.
- Reuse your DPIA where one exists; the FRIA complements rather than repeats it.
- Draft the six elements from a structured template, name the governance owners, and route to counsel for review.
- Notify the authority; diarise review on material change.
Classify the system and export a FRIA draft from your answers
The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.
Run the free assessment →Like most of the Act’s paperwork, the FRIA rewards being early and structured: it is a modest document when produced calmly before deployment, and an uncomfortable one when reconstructed after an authority’s letter. The compliance checklist places it in the full sequence.
Frequently asked questions
→Is a FRIA the same as a GDPR DPIA?
No, but they are cousins and the Act lets them travel together: where a DPIA already covers part of the ground, the FRIA complements it rather than repeating it (Art. 27(4)). The FRIA is broader than data protection — it asks about impacts on fundamental rights generally: non-discrimination, access to services, workers' rights, effective remedy.
→Do private companies really have to do FRIAs?
Two private groups do: deployers of AI that evaluates creditworthiness (outside pure fraud detection), and deployers of AI that prices risk for life and health insurance. Plus any private entity providing public services. A bank using a credit-scoring model or an insurer using AI risk pricing is squarely in scope.
→When must the FRIA be done?
Before the first use of the high-risk system. It then stays valid while the circumstances hold; update it when relevant elements change. The deployer must notify the market-surveillance authority of the outcome, using the template the AI Office provides.
→How long does a FRIA take?
For a well-understood system with a completed classification, the structured content — processes, affected groups, risks, oversight and mitigation measures — is days of focused work, not months. The hard part is having the system-level facts organised; if you've already produced a gap report and classification record, most FRIA inputs exist.
Where does your AI system actually stand?
The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.
Run the free assessment →Keep reading
AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page.