When does Article 27 require a FRIA?
Article 27 requires the assessment before deployment of a high-risk AI system referred to in Article 6(2), which points to the Annex III high-risk areas. The rule expressly excludes high-risk AI systems intended to be used in the area listed in point 2 of Annex III, the critical-infrastructure area.
The trigger then depends on the deployer. A is required for deployers that are bodies governed by public law, private entities providing public services, and deployers of high-risk systems in Annex III points 5(b) and 5(c), which cover creditworthiness or credit scoring and risk assessment or pricing for life and health insurance.
The duty applies to the first use. A deployer may rely on a previous or an existing provider assessment in a similar case, but it remains responsible for checking that the system, process, affected groups, risks, oversight, and mitigations match its own deployment. If a required element changes or becomes outdated during use, the deployer must update the information.
- Start with Article 6(2): confirm that the system is an Annex III high-risk AI system.
- Check the carve-out: Annex III point 2 critical-infrastructure systems are excluded from Article 27 , even though they may still be high-risk and are registered at national level under Article 49(5).
- Check the deployer category: public-law bodies, private entities providing public services, and deployers using Annex III point 5(b) or 5(c) systems are the Article 27 categories.
- Do not treat a provider's high-risk classification memo as a ; Article 27 is a deployer-side assessment of the specific use.
- After completing the , notify the of the results by submitting the completed Article 27 template, unless the Article 46(1) exemption from notification applies.
Does every EU AI Act high-risk system need a ?
No. Article 27 applies to specified deployers before deploying Article 6(2) Annex III high-risk systems, with an express exception for the Annex III point 2 critical-infrastructure area. Product-safety high-risk systems classified under Article 6(1), and Annex III systems outside the named deployer categories, should still be assessed for other AI Act duties, but Article 27 is not automatically triggered by the high-risk label alone.
Which deployers are named in Article 27?
Article 27 names deployers that are bodies governed by public law, private entities providing public services, and deployers of high-risk systems referred to in Annex III points 5(b) and 5(c). Recital 96 explains that private public-service examples can be linked to public-interest tasks such as education, healthcare, social services, housing, and administration of justice.
What happens to critical-infrastructure AI systems under Annex III point 2?
Article 27 excludes high-risk AI systems intended for the Annex III point 2 critical-infrastructure area from the duty. That does not remove all AI Act obligations: Annex III point 2 covers safety components in critical digital infrastructure, road traffic, and water, gas, heating, or electricity supply, and Article 49(5) says those high-risk systems are registered at national level.
When does the EU AI Act duty start to apply?
Regulation (EU) 2026/1744, published on 24 July 2026 and entering into force on 27 July 2026, moves Chapter III Sections 1 to 3 to 2 December 2027 for Article 6(2) Annex III high-risk systems. Because Article 27 covers specified Annex III deployments, that is the relevant application date. Public-authority systems already on the market or in service have a separate Article 111 deadline of 2 August 2030, while other legacy systems depend on whether their design changes significantly after the applicable date.
Supports the Article 27 trigger, covered deployer categories, critical-infrastructure carve-out, first-use rule, notification duty, DPIA complement rule, FRIA content list, and the related deployer registration requirements.
Commission-hosted AI Act Explorer page for Article 27 used to cross-check the FRIA article citation and official article title.