EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · ARTICLE 27 · FRIA · FUNDAMENTAL RIGHTS
A FRIA IS NOT A FORM. IT IS A RECORD OF WHY THIS DEPLOYMENT REMAINS JUSTIFIABLE.
Article 27 requires certain deployers of high-risk AI systems to assess the fundamental-rights impact of the actual context in which the system will be used. The assessment must connect the deployment process, affected people, specific risks, human oversight, mitigation, complaints, notification and later changes into one reviewable record.
BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR
EUR-Lex · Regulation (EU) 2024/1689 · Article 27
Article 27 requires covered public-law bodies, private entities providing public services, and deployers of specified creditworthiness and life/health-insurance high-risk systems to perform a fundamental-rights impact assessment before first use. The assessment must be updated when relevant elements change and generally notified to the market surveillance authority.
Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.
01
DOES ARTICLE 27 APPLY TO THIS DEPLOYER AND THIS HIGH-RISK SYSTEM?
FRIA is not universal. It applies before deployment of covered Article 6(2) high-risk systems to bodies governed by public law, private entities providing public services, and deployers of certain creditworthiness and life/health-insurance systems. Annex III point 2 critical-infrastructure systems are excluded from Article 27(1).
02
IS THIS THE FIRST USE OR HAS THE CONTEXT CHANGED?
The Article 27 duty applies to first use. A deployer may rely on a prior FRIA in similar cases, but the record must be updated when the processes, affected groups, risks, oversight, mitigation or other relevant elements change or become stale.
03
DOES THE ASSESSMENT COVER THE ACTUAL CONTEXT OF USE?
A FRIA must describe the deployer process, duration and frequency of use, affected categories of persons and groups, specific fundamental-rights risks, human-oversight measures, and measures for materialised risks including governance and complaint mechanisms.
04
CAN THE FRIA BE PROVEN TO THE MARKET SURVEILLANCE AUTHORITY?
After completing the assessment, the deployer must notify the market surveillance authority of the results using the applicable template, subject to the Regulation’s stated exception. Preserve the completed assessment, notification state, source evidence and later updates.
THE TA-14 OPERATING ROUTE
Turn the question into a governed record.
The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.
01
Confirm scope before drafting the assessment
Identify the high-risk system, Article 6 route, Annex III category, deployer type, intended purpose and whether the deployment falls within Article 27. Do not build a FRIA merely because the organisation uses AI.
02
Map the real deployment context and affected groups
Document where and how the system is used, how often, for how long, who may be affected, which groups may be vulnerable, and what provider information under Article 13 is relevant to the assessment.
03
Connect risks to oversight, mitigation, complaints and redress
For each material fundamental-rights risk, preserve the human-oversight measure, governance control, intervention path, complaint mechanism, mitigation measure and accountable decision-maker.
04
Notify, preserve and revalidate the FRIA
Record the market-surveillance notification state, coordinate overlapping DPIA evidence where applicable, and update the FRIA whenever the deployment context or Article 27 elements change or are no longer current.
READY TO OPERATE · START PAID ACCESS NOW
Move from reading about the EU AI Act to maintaining the record.
Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.
1–3 AI systems
Evidence Passport
$19/MO
Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.
Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.
Article 27 covers deployers of specified Article 6(2) high-risk systems that are bodies governed by public law or private entities providing public services, plus deployers of the high-risk systems in Annex III points 5(b) and 5(c), covering creditworthiness/credit scoring and life or health insurance risk assessment and pricing.
Does every high-risk AI system require a FRIA?
No. Article 27 has a specific scope. It applies to covered deployers and Article 6(2) high-risk systems, with an express exception for systems in Annex III point 2 concerning critical infrastructure.
What must a FRIA contain?
Article 27 requires the deployer process, intended duration and frequency of use, affected categories of persons and groups, specific risks of harm to fundamental rights, implementation of human oversight, and measures for materialised risks including internal governance and complaint mechanisms.
Can an existing DPIA replace the FRIA?
Not automatically. Where Article 27 obligations are already met through a GDPR or law-enforcement data-protection impact assessment, the FRIA complements that DPIA rather than duplicating the same work.
Does the FRIA have to be updated?
Yes. Article 27 applies to first use and requires the deployer to update the assessment information if relevant elements change or are no longer up to date. Similar cases may rely on previous FRIAs or existing provider impact assessments where appropriate.
Must the FRIA be sent to an authority?
After the assessment is performed, Article 27 requires the deployer to notify the market surveillance authority of the results using the applicable template, subject to the Regulation’s stated exception for certain Article 46(1) cases.
Does TA-14 certify a FRIA as legally sufficient?
No. TA-14 can preserve the FRIA scope decision, evidence, affected-group analysis, risk-to-control mapping, notification state, updates, gaps and revalidation history. It does not provide legal advice, certification, conformity assessment or regulatory approval.
EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION
Understand the requirement. Preserve the evidence. Revalidate when reality changes.